NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60505 | CVE-2006-1800 | Directory traversal vulnerability in posts.php in SimpleBBS 1.0.6 through 1.1 allows remote attackers to include and execute arbitrary files via ".." sequences in the language cookie, as demonstrated by by injecting the code into the gl_session cookie of users.php, which is stored in error.log. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
61785 | CVE-2006-3105 | CRLF injection vulnerability in Bitweaver 1.3 allows remote attackers to conduct HTTP response splitting attacks by via CRLF sequences in multiple unspecified parameters that are injected into HTTP headers, as demonstrated by the BWSESSION parameter in index.php. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
62041 | CVE-2006-3363 | PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the pa parameter. | 2 | 5.1 | Medium | 2016-12-20 | 2008-09-05 | View | |
62809 | CVE-2006-4162 | Cross-site scripting (XSS) vulnerability in Dragonfly CMS 9.0.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search field. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
63065 | CVE-2006-4430 | The Cisco Network Admission Control (NAC) 3.6.4.1 and earlier allows remote attackers to prevent installation of the Cisco Clean Access (CCA) Agent and bypass local and remote protection mechanisms by modifying (1) the HTTP User-Agent header or (2) the behavior of the TCP/IP stack. NOTE: the vendor has disputed the severity of this issue, stating that users cannot bypass authentication mechanisms. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 570 of 17672, showing 5 records out of 88360 total, starting on record 2846, ending on 2850