NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
61450 | CVE-2006-2765 | Cross-site scripting (XSS) vulnerability in news_information.php in Interlink Advantage allows remote attackers to inject arbitrary web script or HTML via the flag parameter. | 2 | 2.6 | Low | 2016-12-20 | 2008-09-05 | View | |
61706 | CVE-2006-3022 | Cross-site scripting (XSS) vulnerability in zoom.php in fipsGallery 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the path parameter. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
61962 | CVE-2006-3283 | SQL injection vulnerability in Dating Agent PRO 4.7.1 allows remote attackers to execute arbitrary SQL commands via the (1) pid parameter in picture.php, (2) mid parameter in mem.php, and the (3) sex and (4) relationship parameters in search.php. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
62218 | CVE-2006-3544 | ** DISPUTED ** Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.3 Final allow remote attackers to execute arbitrary SQL commands via the CODE parameter in a (1) Stats, (2) Mail, and (3) Reg action in index.php. NOTE: the developer has disputed this issue, stating that "At no point does the CODE parameter touch the database. The CODE parameter is used in a SWITCH statement to determine which function to run." | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
62474 | CVE-2006-3806 | Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSource method of the Object, Array, and String objects; and (2) unspecified "string function arguments." | 2 | 7.5 | High | 2016-12-20 | 2011-09-08 | View |
Page 59 of 17672, showing 5 records out of 88360 total, starting on record 291, ending on 295