NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
60048  CVE-2006-1339  Directory traversal vulnerability in inc/functions.inc.php in CuteNews 1.4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the archive parameter in an HTTP POST or COOKIE request, which bypasses a sanity check that is only applied to a GET request.    Medium  2016-12-20  2008-09-05  View
61328  CVE-2006-2643  Cross-site scripting (XSS) vulnerability in index.php in Monster Top List (MTL) 1.4 allows remote attackers to inject arbitrary web script or HTML via the user_error_message parameter.    4.3  Medium  2016-12-20  2008-09-05  View
61584  CVE-2006-2899  Unspecified vulnerability in ESTsoft InternetDISK versions before 2006/04/20 allows remote authenticated users to execute arbitrary code, possibly by uploading a file with multiple extensions into the WebLink directory.    6.5  Medium  2016-12-20  2008-09-05  View
61840  CVE-2006-3161  SQL injection vulnerability in misc.php in SaphpLesson 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the action parameter.    7.5  High  2016-12-20  2008-09-05  View
62096  CVE-2006-3418  Tor before 0.1.1.20 does not validate that a server descriptor"s fingerprint line matches its identity key, which allows remote attackers to spoof the fingerprint line, which might be trusted by users or other applications.    Medium  2016-12-20  2008-09-05  View

Page 967 of 17672, showing 5 records out of 88360 total, starting on record 4831, ending on 4835

Actions