NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
62352  CVE-2006-3684  PHP remote file inclusion vulnerability in calendar.php in SoftComplex PHP Event Calendar 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_calendar parameter, which overwrites the $path_to_calendar variable from an extract function call.    7.5  High  2016-12-20  2011-03-07  View
62608  CVE-2006-3950  SQL injection vulnerability in x-statistics.php in X-Scripts X-Statistics 1.20 allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.    7.5  High  2016-12-20  2011-03-07  View
62864  CVE-2006-4223  IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors related to "JSP source code exposure" (PK23475), which occurs when ibm-web-ext.xmi sets fileServingEnabled to true or ExtendedDocumentRoot is used to place a JSP outside a WAR.file; (3) the First Failure Data Capture (ffdc) log file (PK24834); and (4) traces (PK25568), a different issue than CVE-2006-4137.    Medium  2016-12-20  2011-03-07  View
63120  CVE-2006-4485  The stripos function in PHP before 5.1.5 has unknown impact and attack vectors related to an out-of-bounds read.    10  High  2016-12-20  2011-03-07  View
63376  CVE-2006-4752  Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5.1 allows remote attackers to obtain the installation path via a query to the engine module, probably with an invalid action parameter.    Medium  2016-12-20  2011-03-07  View

Page 840 of 17672, showing 5 records out of 88360 total, starting on record 4196, ending on 4200

Actions