NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
64920 | CVE-2006-6374 | Multiple CRLF injection vulnerabilities in PhpMyAdmin 2.7.0-pl2 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a phpMyAdmin cookie in (1) css/phpmyadmin.css.php, (2) db_create.php, (3) index.php, (4) left.php, (5) libraries/session.inc.php, (6) libraries/transformations/overview.php, (7) querywindow.php, (8) server_engines.php, and possibly other files. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
65176 | CVE-2006-6632 | PHP remote file inclusion vulnerability in genepi.php in Genepi 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the topdir parameter. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
65432 | CVE-2006-6889 | FreeStyle Wiki (fswiki) 3.6.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request for config/user.dat. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
65689 | CVE-2006-7146 | ** DISPUTED ** PHP remote file inclusion vulnerability in bug.php in Leicestershire communityPortals 1.0 build 20051018 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter, a different vector than CVE-2006-5280. NOTE: CVE disputes this issue, since bug.php is not in communityPortals source distributions. | 2 | 7.5 | High | 2016-12-20 | 2009-03-16 | View | |
73113 | CVE-2004-2736 | Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cookie. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 891 of 17672, showing 5 records out of 88360 total, starting on record 4451, ending on 4455