NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59418 | CVE-2006-0687 | process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows remote attackers to include arbitrary local files or possibly remote files via a modified includeModule and siteModInfo variable. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
59930 | CVE-2006-1216 | Cross-site scripting (XSS) vulnerability in bigshow.php in Runcms 1.x allows remote attackers to inject arbitrary web script or HTML via the id parameter. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
60698 | CVE-2006-1993 | Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain Javascript that is not properly handled by the contentWindow.focus method in an iframe, which causes a reference to a deleted controller context object. NOTE: this was originally claimed to be a buffer overflow in (1) js320.dll and (2) xpcom_core.dll, but the vendor disputes this claim. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View | |
60954 | CVE-2006-2251 | SQL injection vulnerability in the do_mmod function in mod.php in Invision Community Blog (ICB) 1.1.2 final through 1.2 allows remote attackers with moderator privileges to execute arbitrary SQL commands via the selectedbids parameter. | 2 | 6.4 | Medium | 2016-12-20 | 2008-09-05 | View | |
61210 | CVE-2006-2515 | Cross-site scripting (XSS) vulnerability in index.php in Hiox Guestbook 3.1 allows remote attackers to inject arbitrary web script or HTML via the input forms for signing the guestbook. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 968 of 17672, showing 5 records out of 88360 total, starting on record 4836, ending on 4840