NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
59418  CVE-2006-0687  process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows remote attackers to include arbitrary local files or possibly remote files via a modified includeModule and siteModInfo variable.    Medium  2016-12-20  2011-03-07  View
59930  CVE-2006-1216  Cross-site scripting (XSS) vulnerability in bigshow.php in Runcms 1.x allows remote attackers to inject arbitrary web script or HTML via the id parameter.    4.3  Medium  2016-12-20  2008-09-05  View
60698  CVE-2006-1993  Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain Javascript that is not properly handled by the contentWindow.focus method in an iframe, which causes a reference to a deleted controller context object. NOTE: this was originally claimed to be a buffer overflow in (1) js320.dll and (2) xpcom_core.dll, but the vendor disputes this claim.    5.1  Medium  2016-12-20  2011-03-07  View
60954  CVE-2006-2251  SQL injection vulnerability in the do_mmod function in mod.php in Invision Community Blog (ICB) 1.1.2 final through 1.2 allows remote attackers with moderator privileges to execute arbitrary SQL commands via the selectedbids parameter.    6.4  Medium  2016-12-20  2008-09-05  View
61210  CVE-2006-2515  Cross-site scripting (XSS) vulnerability in index.php in Hiox Guestbook 3.1 allows remote attackers to inject arbitrary web script or HTML via the input forms for signing the guestbook.    6.8  Medium  2016-12-20  2011-03-07  View

Page 968 of 17672, showing 5 records out of 88360 total, starting on record 4836, ending on 4840

Actions