NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
62352 | CVE-2006-3684 | PHP remote file inclusion vulnerability in calendar.php in SoftComplex PHP Event Calendar 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_calendar parameter, which overwrites the $path_to_calendar variable from an extract function call. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
62608 | CVE-2006-3950 | SQL injection vulnerability in x-statistics.php in X-Scripts X-Statistics 1.20 allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
62864 | CVE-2006-4223 | IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors related to "JSP source code exposure" (PK23475), which occurs when ibm-web-ext.xmi sets fileServingEnabled to true or ExtendedDocumentRoot is used to place a JSP outside a WAR.file; (3) the First Failure Data Capture (ffdc) log file (PK24834); and (4) traces (PK25568), a different issue than CVE-2006-4137. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
63120 | CVE-2006-4485 | The stripos function in PHP before 5.1.5 has unknown impact and attack vectors related to an out-of-bounds read. | 2 | 10 | High | 2016-12-20 | 2011-03-07 | View | |
63376 | CVE-2006-4752 | Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5.1 allows remote attackers to obtain the installation path via a query to the engine module, probably with an invalid action parameter. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 840 of 17672, showing 5 records out of 88360 total, starting on record 4196, ending on 4200