NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60499 | CVE-2006-1794 | SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function in (a) includes/mambo.php; and (3) the $filter variable to the showCategory function in the com_content component (content.php). | 2 | 7.6 | High | 2016-12-20 | 2011-03-07 | View | |
60755 | CVE-2006-2050 | SQL injection vulnerability in dcboard.cgi in DCScripts DCForumLite 3.0 allows remote attackers to execute arbitrary SQL commands via the az parameter. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
61011 | CVE-2006-2309 | The HTTP service in EServ/3 3.25 allows remote attackers to obtain sensitive information via crafted HTTP requests containing dot, space, and slash characters, which reveals the source code of script files. | 2 | 4 | Medium | 2016-12-20 | 2011-03-07 | View | |
61267 | CVE-2006-2572 | Cross-site scripting (XSS) vulnerability in index.php in DGBook 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) homepage, (3) email, and (4) address parameters. | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View | |
61523 | CVE-2006-2838 | Buffer overflow in the web console in F-Secure Anti-Virus for Microsoft Exchange 6.40, and Internet Gatekeeper 6.40 through 6.42 and 6.50 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors. NOTE: By default, the connections are only allowed from the local host. | 2 | 7.6 | High | 2016-12-20 | 2011-03-07 | View |
Page 478 of 17672, showing 5 records out of 88360 total, starting on record 2386, ending on 2390