NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
61787 | CVE-2006-3107 | Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in (1) GLOBALS[where_framework] to (a) admin/modules/news/news_class.php and (b) admin/modules/content/content_class.php, and (2) GLOBALS[where_cms] to (c) admin/modules/block_media/util.media.php. NOTE: this issue might be resultant from a global overwrite vulnerability. This issue is similar to CVE-2006-2576, but the vectors are different. | 2 | 5.1 | Medium | 2016-12-20 | 2008-09-05 | View | |
62299 | CVE-2006-3625 | FLV Players 8 allows remote attackers to obtain sensitive information via (1) a direct request to paginate.php or (2) an invalid p parameter to player.php, which reveal the path in an error message. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
64859 | CVE-2006-6298 | SQL injection vulnerability in uye_giris_islem.asp in Metyus Okul Yonetim Sistemi 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) kullanici_ismi and (2) sifre parameters. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
65115 | CVE-2006-6571 | Multiple cross-site scripting (XSS) vulnerabilities in form.php in GenesisTrader 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cuve, (2) chem, (3) do, and possibly other parameters. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
65628 | CVE-2006-7085 | Rigter Portal System (RPS) 1.0, 2.0, and 3.0 allows remote attackers to add arbitrary content and conduct XSS attacks via a direct request to add_art.php. NOTE: this issue was originally reported as SQL injection, but this is not likely. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 583 of 17672, showing 5 records out of 88360 total, starting on record 2911, ending on 2915