NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59914 | CVE-2006-1200 | Direct static code injection vulnerability in add_link.txt in daverave Link Bank allows remote attackers to execute arbitrary PHP code via the url_name parameter, which is not sanitized before being stored in links.txt, which is later used in an include statement. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
60938 | CVE-2006-2235 | CodeMunkyX (aka free-php.net) Simple Poll 1.0, when authentication is not required for the admin directory, allows remote attackers to gain administrative privileges by appending /admin/ to the top-level URI of the application. | 2 | 7.6 | High | 2016-12-20 | 2008-09-05 | View | |
61194 | CVE-2006-2499 | SQL injection vulnerability in default.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to execute arbitrary SQL commands via the password field. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61962 | CVE-2006-3283 | SQL injection vulnerability in Dating Agent PRO 4.7.1 allows remote attackers to execute arbitrary SQL commands via the (1) pid parameter in picture.php, (2) mid parameter in mem.php, and the (3) sex and (4) relationship parameters in search.php. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
62218 | CVE-2006-3544 | ** DISPUTED ** Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.3 Final allow remote attackers to execute arbitrary SQL commands via the CODE parameter in a (1) Stats, (2) Mail, and (3) Reg action in index.php. NOTE: the developer has disputed this issue, stating that "At no point does the CODE parameter touch the database. The CODE parameter is used in a SWITCH statement to determine which function to run." | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 641 of 17672, showing 5 records out of 88360 total, starting on record 3201, ending on 3205