NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
61571  CVE-2006-2886  view.php in KnowledgeTree Open Source 3.0.3 and earlier allows remote attackers to obtain the full installation path via a crafted fDocumentId parameter, which displays the path in the resulting error message. NOTE: this might be resultant from another vulnerability, since this vector also produces XSS.    4.3  Medium  2016-12-20  2008-11-09  View
61827  CVE-2006-3148  SQL injection vulnerability, possibly in search.inc.php, in Open-Realty 2.3.1 allows remote attackers to execute arbitrary SQL commands via the sorttype parameter to index.php.    7.5  High  2016-12-20  2011-03-07  View
62083  CVE-2006-3405  Cross-site scripting (XSS) vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) delete, (2) pathext, and (3) edit parameters.    5.8  Medium  2016-12-20  2008-09-05  View
62339  CVE-2006-3671  Cross-site request forgery (CSRF) vulnerability in the communicate function in estmaster.c for Hyper Estraier before 1.3.3 allows remote attackers to perform unauthorized actions as other users via unknown vectors.    7.5  High  2016-12-20  2011-03-07  View
62595  CVE-2006-3937  post.php in x_atrix xGuestBook 1.02 allows remote attackers to obtain sensitive information via a request without the (1) user, (2) mail, (3) p, or (4) url parameter, which reveals the installation path in an error message.    Medium  2016-12-20  2008-09-05  View

Page 762 of 17672, showing 5 records out of 88360 total, starting on record 3806, ending on 3810

Actions