NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
65648 | CVE-2006-7105 | ** DISPUTED ** PHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty 2.6.9 allows remote attackers to execute arbitrary PHP code via a URL in the filename parameter. NOTE: in the original disclosure, filename is used in a function definition, so this report is probably incorrect. | 2 | 7.5 | High | 2016-12-20 | 2009-03-16 | View | |
72304 | CVE-2004-1926 | Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or the (5) Name, (6) Description, (7) URL, or (8) Country fields in a Directory/Add Site operation. | 2 | 7.5 | High | 2016-12-20 | 2016-10-17 | View | |
72560 | CVE-2004-2183 | Unknown vulnerability in WeHelpBUS 0.1 allows remote attackers to execute arbitrary shell commands via the query string. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
73072 | CVE-2004-2695 | SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows remote attackers to execute arbitrary SQL statements via the x_invoice_num parameter. NOTE: this issue might be related to CVE-2006-4267. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
58992 | CVE-2006-0252 | SQL injection vulnerability in Benders Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by the (1) year, (2) month, and (3) day parameters. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 646 of 17672, showing 5 records out of 88360 total, starting on record 3226, ending on 3230