NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
64116 | CVE-2006-5515 | Cross-site scripting (XSS) vulnerability in lib-history.inc.php in phpAdsNew and phpPgAds before 2.0.8-pr1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to injected data that is stored by a delivery script and displayed by the admin interface. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
64372 | CVE-2006-5797 | Multiple SQL injection vulnerabilities in default.asp in Xenis.creator CMS allow remote attackers to execute arbitrary SQL commands via the (1) nav, (2) s, or (3) print parameters. | 2 | 7.5 | High | 2016-12-20 | 2016-10-17 | View | |
64628 | CVE-2006-6067 | Multiple SQL injection vulnerabilities in 20/20 DataShed (aka Real Estate Listing System) allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) f-email.asp, or the (2) peopleID and (2) sort_order parameters to (b) listings.asp, different vectors than CVE-2006-5955. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
64884 | CVE-2006-6338 | Unrestricted file upload vulnerability in upload/index.php in deV!L`z Clanportal (DZCP) before 1.3.6.1 allows remote attackers to upload and execute arbitrary .php files by embedding PHP code in a JPEG or GIF file that is uploaded to inc/images/uploads/userpics/. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
65140 | CVE-2006-6596 | HyperAccess 8.4 allows user-assisted remote attackers to execute arbitrary vbscript and commands via a session (HAW) file, which can be automatically opened using Internet Explorer. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 675 of 17672, showing 5 records out of 88360 total, starting on record 3371, ending on 3375