NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59997 | CVE-2006-1283 | opiepasswd in One-Time Passwords in Everything (OPIE) in FreeBSD 4.10-RELEASE-p22 through 6.1-STABLE before 20060322 uses the getlogin function to determine the invoking user account, which might allow local users to configure OPIE access to the root account and possibly gain root privileges if a root shell is permitted by the configuration of the wheel group or sshd. | 2 | 7.2 | High | 2016-12-20 | 2011-08-25 | View | |
60253 | CVE-2006-1545 | Direct static code injection vulnerability in admin/config.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allows remote authenticated administrators to execute code by inserting the code into variables that are stored in admin/config.php. | 2 | 9 | High | 2016-12-20 | 2011-03-07 | View | |
60509 | CVE-2006-1804 | SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
60765 | CVE-2006-2060 | Directory traversal vulnerability in action_admin/paysubscriptions.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote authenticated administrators to include and execute arbitrary local PHP files via a .. (dot dot) in the name parameter, preceded by enough backspace (%08) characters to erase the initial static portion of a filename. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View | |
61021 | CVE-2006-2319 | Ideal Science Ideal BB 1.5.4a and earlier does not properly check file extensions before permitting an upload, which allows remote attackers to upload and execute an ASP script via a 0x00 character before the ".asp" portion of the filename. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 535 of 17672, showing 5 records out of 88360 total, starting on record 2671, ending on 2675