NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60021 | CVE-2006-1309 | Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption. | 2 | 9.3 | High | 2016-12-20 | 2011-03-07 | View | |
60277 | CVE-2006-1569 | Multiple SQL injection vulnerabilities in RedCMS 0.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters to (a) login.php or (b) register.php; or (3) u parameter to (c) profile.php. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View | |
60533 | CVE-2006-1828 | SQL injection vulnerability in php121language.php in PHP121 1.4 allows remote attackers to execute arbitrary SQL commands and execute arbitrary code via the sess_username variable, as set by the php121un HTTP COOKIE parameter, which is used in multiple files including php121login.php. NOTE: the code execution occurs because the SQL query results are used in an include statement. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View | |
60789 | CVE-2006-2084 | Multiple cross-site scripting (XSS) vulnerabilities in FarsiNews 2.5.3 Pro and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameters in (a) index.php, and the (3) mod parameter in (b) admin.php. | 2 | 4.3 | Medium | 2016-12-20 | 2013-01-03 | View | |
61045 | CVE-2006-2343 | Cross-site scripting (XSS) vulnerability in Search.do in ManageEngine OpManager 6.0 allows remote attackers to inject arbitrary web script or HTML via the searchTerm parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | 2 | 5.8 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 678 of 17672, showing 5 records out of 88360 total, starting on record 3386, ending on 3390