NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60840 | CVE-2006-2135 | SQL injection vulnerability in login.php in Ruperts News allows remote attackers to execute arbitrary SQL commands via the username parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61096 | CVE-2006-2397 | Multiple cross-site scripting (XSS) vulnerabilities in GPhotos 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) rep parameter to (a) index.php or (b) diapo.php or (2) image parameter to (c) affich.php. NOTE: item 1a might be resultant from directory traversal. | 2 | 5.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
61352 | CVE-2006-2667 | Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into files in (1) wp-content/cache/userlogins/ (2) wp-content/cache/users/ which are later included by cache.php, as demonstrated using the displayname argument. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61608 | CVE-2006-2924 | Ingate Firewall in the SIP module before 4.4.1 and SIParator before 4.4.1, when TLS is enabled or when SSL/TLS is enabled in the web server, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
61864 | CVE-2006-3185 | PHP remote file inclusion vulnerability in data/header.php in CMS Faethon 1.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the mainpath parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 985 of 17672, showing 5 records out of 88360 total, starting on record 4921, ending on 4925