NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
62612 | CVE-2006-3954 | Directory traversal vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to read arbitrary files via a .. (dot dot) in the gallery parameter in a (1) avatar or (2) do_avatar action. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
62868 | CVE-2006-4227 | MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine"s definer instead of the routine"s caller, which allows remote authenticated users to gain privileges through a routine that has been made available using GRANT EXECUTE. | 2 | 6.5 | Medium | 2016-12-20 | 2011-09-01 | View | |
63124 | CVE-2006-4489 | Multiple PHP remote file inclusion vulnerabilities in MiniBill 2006-07-14 (1.2.2) allow remote attackers to execute arbitrary PHP code via (1) a URL in the config[include_dir] parameter in actions/ipn.php or (2) an FTP path in the config[plugin_dir] parameter in include/initPlugins.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
63380 | CVE-2006-4756 | SQL injection vulnerability in alpha.php in phpMyDirectory 10.4.6 and earlier allows remote attackers to execute arbitrary SQL commands via the letter parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | 2 | 7.5 | High | 2016-12-20 | 2012-10-22 | View | |
63636 | CVE-2006-5030 | SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sort parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 865 of 17672, showing 5 records out of 88360 total, starting on record 4321, ending on 4325