NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
62866 | CVE-2006-4225 | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-3139. Reason: This candidate is a duplicate of CVE-2006-3139. Notes: All CVE users should reference CVE-2006-3139 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. | 1 | 2016-12-20 | 2008-09-10 | View | |||
63122 | CVE-2006-4487 | DUware DUpoll 3.0 and 3.1 stores _private/Dupoll.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and passwords. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
63378 | CVE-2006-4754 | Cross-site scripting (XSS) vulnerability in index.php in PHProg before 1.1 allows remote attackers to inject arbitrary web script or HTML via the album parameter, which is used in an opendir call. NOTE: the same primary issue can be used for full path disclosure with an invalid parameter that reveals the installation path in an error message. | 2 | 6.8 | Medium | 2016-12-20 | 2016-10-17 | View | |
63634 | CVE-2006-5028 | Directory traversal vulnerability in filemanager/filemanager.php in SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows allows remote attackers to list arbitrary directories via a ../ (dot dot slash) in the file parameter in a chdir action. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
63890 | CVE-2006-5287 | Multiple SQL injection vulnerabilities in sign.php in Xeobook 0.93 allow remote attackers to execute arbitrary SQL commands via (1) the User-Agent HTTP header, or the (2) gb_entry_text, (3) gb_location, (4) gb_fullname, or (5) gb_sex parameters. | 2 | 5.1 | Medium | 2016-12-20 | 2016-10-17 | View |
Page 853 of 17672, showing 5 records out of 88360 total, starting on record 4261, ending on 4265