NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
64375 | CVE-2006-5800 | Cross-site scripting (XSS) vulnerability in default.asp in xenis.creator CMS allows remote attackers to inject arbitrary web script or HTML via the nav parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 2.6 | Low | 2016-12-20 | 2008-09-05 | View | |
64631 | CVE-2006-6070 | SQL injection vulnerability in module/account/register/register.asp in ASP Nuke 0.80 and earlier allows remote attackers to execute arbitrary SQL commands via the StateCode parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
64887 | CVE-2006-6341 | Multiple PHP remote file inclusion vulnerabilities in mg.applanix 1.3.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the apx_root_path parameter to (1) act/act_check_access.php, (2) dsp/dsp_form_booking_ctl.php, and (3) dsp/dsp_bookings.php. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
65143 | CVE-2006-6599 | maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters (";" semicolon) in the announce parameter. | 2 | 6 | Medium | 2016-12-20 | 2011-03-07 | View | |
65399 | CVE-2006-6856 | Direct static code injection vulnerability in WebText CMS 0.4.5.2 and earlier allows remote attackers to inject arbitrary PHP code into a script in wt/users/ via the im parameter during a profile edit (edycja) operation, which is then executed via a direct request for this script. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 693 of 17672, showing 5 records out of 88360 total, starting on record 3461, ending on 3465