NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
62539  CVE-2006-3878  Opsware Network Automation System (NAS) 6.0 installs /etc/init.d/mysql with insecure permissions, which allows local users to read the root password for the MySQL MAX database or gain privileges by modifying /etc/init.d/mysql.    2.1  Low  2016-12-20  2008-09-05  View
62795  CVE-2006-4141  SQL injection vulnerability in news.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) sortby and (2) sortorder parameters.    7.5  High  2016-12-20  2008-09-05  View
63307  CVE-2006-4674  Direct static code injection vulnerability in doku.php in DokuWiki before 2006-030-09c allows remote attackers to execute arbitrary PHP code via the X-FORWARDED-FOR HTTP header, which is stored in config.php.    7.5  High  2016-12-20  2008-09-05  View
64075  CVE-2006-5474  The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset.    7.5  High  2016-12-20  2008-09-05  View
64843  CVE-2006-6282  members.php in Vikingboard 0.1.2 allows remote attackers to trigger a forced SQL error via an invalid s parameter, a different vector than CVE-2006-4709. NOTE: might only be an exposure if display_errors is enabled, but due to lack of details, even this is not clear.    9.3  High  2016-12-20  2008-09-05  View

Page 476 of 17672, showing 5 records out of 88360 total, starting on record 2376, ending on 2380

Actions