NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
64519 | CVE-2006-5944 | Cross-site scripting (XSS) vulnerability in csm/asp/listings.asp in MGinternet Car Site Manager (CSM) allows remote attackers to inject arbitrary web script or HTML via the s parameter. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
64775 | CVE-2006-6214 | SQL injection vulnerability in wallpaper.php in Wallpaper Website (Wallpaper Complete Website) 1.0.09 allows remote attackers to execute arbitrary SQL commands via the wallpaperid parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
65031 | CVE-2006-6486 | SQL injection vulnerability in EasyPage allows remote attackers to execute arbitrary SQL commands via unspecified vectors in sptrees/default.aspx, possibly involving the docId parameter. NOTE: this issue appears to have been disputed by a third party researcher, stating that SQL injection is not possible. However, insufficient details were provided to evaluate the dispute. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
65287 | CVE-2006-6743 | phpProfiles before 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc.php and (2) users/include/copy.inc.php. | 2 | 4.6 | Medium | 2016-12-20 | 2011-03-07 | View | |
65544 | CVE-2006-7001 | Directory traversal vulnerability in avatar.php in PhpMyChat Plus 1.9 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the L parameter, a different issue than CVE-2006-5897. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 7.1 | High | 2016-12-20 | 2008-09-05 | View |
Page 45 of 17672, showing 5 records out of 88360 total, starting on record 221, ending on 225