NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
61808  CVE-2006-3128  choose_file.php in easy-CMS 0.1.2, when mod_mime is installed, does not restrict uploads of filenames with multiple extensions, which allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a GIF file extension, then directly accessing that file in the Repositories directory.    4.6  Medium  2016-12-20  2011-03-07  View
62064  CVE-2006-3386  index.php in Vincent Leclercq News 5.2 allows remote attackers to obtain sensitive information, such as the installation path, via a mail[] parameter with invalid values.    Medium  2016-12-20  2008-09-05  View
62320  CVE-2006-3652  Microsoft Internet Security and Acceleration (ISA) Server 2004 allows remote attackers to bypass file extension filters via a request with a trailing "#" character. NOTE: as of 20060715, this could not be reproduced by third parties.    7.5  High  2016-12-20  2008-09-05  View
62576  CVE-2006-3918  http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.    4.3  Medium  2016-12-20  2012-11-05  View
62832  CVE-2006-4191  Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by header.php.    5.1  Medium  2016-12-20  2011-03-07  View

Page 649 of 17672, showing 5 records out of 88360 total, starting on record 3241, ending on 3245

Actions