NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59648 | CVE-2006-0921 | Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackers to list and create arbitrary directories via a .. (dot dot) in the CurrentFolder parameter to (1) GetFoldersAndFiles and (2) CreateFolder. | 2 | 6.4 | Medium | 2016-12-20 | 2008-09-05 | View | |
59904 | CVE-2006-1190 | Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code. | 2 | 10 | High | 2016-12-20 | 2011-03-07 | View | |
60160 | CVE-2006-1451 | MySQL Manager in Apple Mac OS X 10.3.9 and 10.4.6, when setting up a new MySQL database server, does not use the "New MySQL root password" that is provided, which causes the MySQL root password to be blank and allows local users to gain full privileges to that database. | 2 | 7.2 | High | 2016-12-20 | 2011-03-07 | View | |
60416 | CVE-2006-1711 | Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
60672 | CVE-2006-1967 | Cross-site scripting (XSS) vulnerability in calendar/Visitor.cgi in KCScripts Calendar, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter. | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View |
Page 2 of 17672, showing 5 records out of 88360 total, starting on record 6, ending on 10