NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
64129 | CVE-2006-5528 | Directory traversal vulnerability in mod.php in SchoolAlumni Portal 2.26 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter. NOTE: some of these details are obtained from third party information. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
64385 | CVE-2006-5810 | Cross-site scripting (XSS) vulnerability in modules/wfdownloads/newlist.php in XOOPS 1.0 allows remote attackers to inject arbitrary web script or HTML via the newdownloadshowdays parameter. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
64641 | CVE-2006-6080 | Multiple SQL injection vulnerabilities in categories.asp in gNews Publisher allow remote attackers to execute arbitrary SQL commands via the (1) catID or (2) editorID parameter. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
64897 | CVE-2006-6351 | KhaledMuratList stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) CL2F9R1A2C1N.mdb or (2) Data2F9R1A2C1N.mdb. | 2 | 10 | High | 2016-12-20 | 2008-09-05 | View | |
65666 | CVE-2006-7123 | Multiple SQL injection vulnerabilities in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allow remote attackers to execute arbitrary SQL commands via (1) unspecified parameters when importing the (a) ip-to-country.csv file; and the (2) HTTP Referer, (3) HTTP User Agent, and (4) HTTP Accept Language headers to (b) bsqtemplateinc.php. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 864 of 17672, showing 5 records out of 88360 total, starting on record 4316, ending on 4320