NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
63307 | CVE-2006-4674 | Direct static code injection vulnerability in doku.php in DokuWiki before 2006-030-09c allows remote attackers to execute arbitrary PHP code via the X-FORWARDED-FOR HTTP header, which is stored in config.php. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
63563 | CVE-2006-4955 | Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the (1) savefolder and (2) savefilename parameters. | 2 | 5 | Medium | 2016-12-20 | 2016-11-28 | View | |
63819 | CVE-2006-5213 | Sun Solaris 10 before 20061006 uses "incorrect and insufficient permission checks" that allow local users to intercept or spoof packets by creating a raw socket on a link aggregation (network device aggregation). | 2 | 3.6 | Low | 2016-12-20 | 2011-03-07 | View | |
64075 | CVE-2006-5474 | The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
64331 | CVE-2006-5756 | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2006. Notes: none. | 1 | 2016-12-20 | 2008-09-10 | View |
Page 433 of 17672, showing 5 records out of 88360 total, starting on record 2161, ending on 2165