NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60240 | CVE-2006-1532 | Cross-site scripting (XSS) vulnerability in search.php in PHP Classifieds 6.18, 6.20, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchword parameter. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
60496 | CVE-2006-1791 | Directory traversal vulnerability in acc.php in QuickBlogger 1.4 allows remote attackers to read or include arbitrary local files via the request parameter. NOTE: this issue can also produce resultant XSS when the associated include statement fails. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
60752 | CVE-2006-2047 | Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allows remote attackers to obtain sensitive information via an invalid (1) secondary, (2) PageNum_Results, (3) category, or (4) keywords parameter in (a) Results.cfm; or an invalid (5) ProdID parameter in (b) Details.cfm; which reveal the path in various error messages. NOTE: the behavior for the category, keywords, and ProdID parameters might be resultant from SQL injection. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
61008 | CVE-2006-2306 | Cross-site scripting (XSS) vulnerability in moreinfo.asp in EPublisherPro allows remote attackers to inject arbitrary web script or HTML via the title parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 9.3 | High | 2016-12-20 | 2011-03-07 | View | |
61264 | CVE-2006-2569 | SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows remote attackers to execute arbitrary SQL commands via the cat parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 460 of 17672, showing 5 records out of 88360 total, starting on record 2296, ending on 2300