NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
61025 | CVE-2006-2323 | Multiple PHP remote file inclusion vulnerabilities in SmartISoft phpListPro 2.01 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the returnpath parameter in (1) editsite.php, (2) addsite.php, and (3) in.php. NOTE: The config.php vector is already covered by CVE-2006-1749. | 2 | 5.1 | Medium | 2016-12-20 | 2008-09-05 | View | |
61281 | CVE-2006-2586 | Cross-site scripting (XSS) vulnerability in IpLogger 1.7 and earlier allows remote attackers to inject arbitrary HTML or web script via the HTTP_REFERER header in an HTTP request. | 2 | 5.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
61537 | CVE-2006-2852 | PHP remote file inclusion vulnerability in dotWidget CMS 1.0.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the file_path parameter in (1) index.php, (2) feedback.php, and (3) printfriendly.php. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
61793 | CVE-2006-3113 | Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via simultaneous XPCOM events, which causes a timer object to be deleted in a way that triggers memory corruption. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
62049 | CVE-2006-3371 | Eupla Foros 1.0 stores the inc/config.inc file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information, including the database configuration. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 559 of 17672, showing 5 records out of 88360 total, starting on record 2791, ending on 2795