|
313701
|
5.1 |
MEDIUM
|
telekorn
|
signkorn_guestbook
|
Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a UR…
|
NVD-CWE-Other
|
CVE-2006-4889
|
2024-02-14 10:17 |
2006-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313702
|
7.5 |
HIGH
|
all_enthusiast_inc
|
reviewpost_php_pro
|
PHP remote file inclusion vulnerability in index.php in All Enthusiast ReviewPost 2.5 allows remote attackers to execute arbitrary PHP code via a URL in the RP_PATH parameter.
|
NVD-CWE-Other
|
CVE-2006-4864
|
2024-02-14 10:17 |
2006-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313703
|
7.5 |
HIGH
|
phpquiz
|
phpquiz
|
PHP remote file inclusion vulnerability in index.php in Jule Slootbeek phpQuiz 0.01 allows remote attackers to execute arbitrary PHP code via a URL in the pagename parameter.
|
NVD-CWE-Other
|
CVE-2006-4834
|
2024-02-14 10:17 |
2006-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313704
|
5.1 |
MEDIUM
|
telekorn
|
signkorn_guestbook
|
PHP remote file inclusion vulnerability in includes/log.inc.php in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled and _SESSION[permission] parameter is set to "yes…
|
NVD-CWE-Other
|
CVE-2006-4788
|
2024-02-14 10:17 |
2006-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313705
|
5.0 |
MEDIUM
|
comscripts
|
phprog
|
Directory traversal vulnerability in index.php in PHProg before 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
|
NVD-CWE-Other
|
CVE-2006-4753
|
2024-02-14 10:17 |
2006-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313706
|
6.8 |
MEDIUM
|
comscripts
|
phprog
|
Cross-site scripting (XSS) vulnerability in index.php in PHProg before 1.1 allows remote attackers to inject arbitrary web script or HTML via the album parameter, which is used in an opendir call. N…
|
NVD-CWE-Other
|
CVE-2006-4754
|
2024-02-14 10:17 |
2006-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313707
|
7.5 |
HIGH
|
microsoft
|
ie windows_2003_server windows_xp windows_2000
|
Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060912, allows remote attackers to cause a denial o…
|
NVD-CWE-Other
|
CVE-2006-3873
|
2024-02-14 10:17 |
2006-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313708
|
7.5 |
HIGH
|
mcgallery
|
mcgallery_pro
|
PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.
|
NVD-CWE-Other
|
CVE-2006-4720
|
2024-02-14 10:17 |
2006-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313709
|
5.1 |
MEDIUM
|
premod_shadow
|
premod_shadow
|
PHP remote file inclusion vulnerability in includes/functions_portal.php in Premod Shadow 2.7.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path para…
|
NVD-CWE-Other
|
CVE-2006-4664
|
2024-02-14 10:17 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313710
|
7.8 |
HIGH
|
securecomputing
|
snapgear_sg710 snapgear_sg560 snapgear_sg565 snapgear_sg580
|
Multiple unspecified vulnerabilities in SnapGear before 3.1.4u1 allow remote attackers to cause a denial of service via unspecified vectors involving (1) IPSec replay windows and (2) the use of vulne…
|
NVD-CWE-Other
|
CVE-2006-4613
|
2024-02-14 10:17 |
2006-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313711
|
5.1 |
MEDIUM
|
becubed
|
compression_plus
|
Stack-based buffer overflow in the ReadFile function in the ZOO-processing exports in the BeCubed Compression Plus before 5.0.1.28, as used in products including (1) Tumbleweed EMF, (2) VCOM/Ontrack …
|
NVD-CWE-Other
|
CVE-2006-4554
|
2024-02-14 10:17 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313712
|
7.5 |
HIGH
|
bernard_pacques
|
yet_another_community_system_cms
|
Multiple PHP remote file inclusion vulnerabilities in Yet Another Community System (YACS) CMS 6.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the context[path_to_root] paramet…
|
NVD-CWE-Other
|
CVE-2006-4559
|
2024-02-14 10:17 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313713
|
7.5 |
HIGH
|
microsoft
|
ie
|
Internet Explorer 6 on Windows XP SP2 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server, by hosting script on an In…
|
NVD-CWE-Other
|
CVE-2006-4560
|
2024-02-14 10:17 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313714
|
7.5 |
HIGH
|
mozilla
|
firefox
|
Mozilla Firefox 1.5.0.6 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server, by hosting script on an Internet web ser…
|
NVD-CWE-Other
|
CVE-2006-4561
|
2024-02-14 10:17 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313715
|
5.0 |
MEDIUM
|
2wire_inc
|
officeportal homeportal
|
The web-based management interface in 2Wire, Inc. HomePortal and OfficePortal Series modems and routers allows remote attackers to cause a denial of service (crash) via a CRLF sequence in a GET reque…
|
NVD-CWE-Other
|
CVE-2006-4523
|
2024-02-14 10:17 |
2006-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313716
|
7.5 |
HIGH
|
bernard_pacques
|
yet_another_community_system_cms
|
PHP remote file inclusion vulnerability in articles/article.php in Yet Another Community System (YACS) CMS 6.6.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the con…
|
NVD-CWE-Other
|
CVE-2006-4532
|
2024-02-14 10:17 |
2006-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313717
|
4.0 |
MEDIUM
|
tor scatterchat
|
tor scatterchat
|
Unspecified vulnerability in (1) Tor 0.1.0.x before 0.1.0.18 and 0.1.1.x before 0.1.1.23, and (2) ScatterChat before 1.0.2, allows remote attackers operating a Tor entry node to route arbitrary Tor t…
|
NVD-CWE-Other
|
CVE-2006-4508
|
2024-02-14 10:17 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313718
|
7.6 |
HIGH
|
mozilla netscape k-meleon_project
|
firefox navigator k-meleon
|
Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-4253
|
2024-02-14 10:17 |
2006-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313719
|
2.6 |
LOW
|
scatterchat
|
scatterchat
|
The cryptographic module in ScatterChat 1.0.x allows attackers to identify patterns in large numbers of messages by identifying collisions using a birthday attack on the custom padding mechanism for …
|
NVD-CWE-Other
|
CVE-2006-4021
|
2024-02-14 10:17 |
2006-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313720
|
4.6 |
MEDIUM
|
php
|
php
|
scanf.c in PHP 5.1.4 and earlier, and 4.4.3 and earlier, allows context-dependent attackers to execute arbitrary code via a sscanf PHP function call that performs argument swapping, which increments …
|
NVD-CWE-Other
|
CVE-2006-4020
|
2024-02-14 10:17 |
2006-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313721
|
7.5 |
HIGH
|
bosdev
|
bosdates
|
PHP remote file inclusion vulnerability in payment.php in BosDev BosDates allows remote attackers to execute arbitrary PHP code via a URL in the insPath parameter.
|
NVD-CWE-Other
|
CVE-2006-3957
|
2024-02-14 10:17 |
2006-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313722
|
4.3 |
MEDIUM
|
pkr_internet
|
taskjitsu
|
Multiple unspecified cross-site scripting (XSS) vulnerabilities in Taskjitsu 2.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the Search Tasks system, or authenticated user…
|
NVD-CWE-noinfo
|
CVE-2006-3958
|
2024-02-14 10:17 |
2006-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313723
|
5.0 |
MEDIUM
|
siemens
|
speedstream_wireless_router
|
Siemens SpeedStream 2624 allows remote attackers to cause a denial of service (device hang) by sending a crafted packet to the web administrative interface.
|
NVD-CWE-Other
|
CVE-2006-3907
|
2024-02-14 10:17 |
2006-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313724
|
4.3 |
MEDIUM
|
softbiz
|
banner_exchange
|
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Banner Exchange Script (aka Banner Exchange Network Script) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) th…
|
NVD-CWE-Other
|
CVE-2006-3607
|
2024-02-14 10:17 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313725
|
5.8 |
MEDIUM
|
seyeon
|
flexwatch_network_camera
|
Cross-site scripting (XSS) vulnerability in index.php in FlexWATCH Network Camera 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL.
|
NVD-CWE-Other
|
CVE-2006-3603
|
2024-02-14 10:17 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313726
|
7.5 |
HIGH
|
seyeon
|
flexwatch_network_camera
|
Directory traversal vulnerability in FlexWATCH Network Camera 3.0 and earlier allows remote attackers to bypass access restrictions for (1) admin/aindex.asp or (2) admin/aindex.html via a .. (dot dot…
|
NVD-CWE-Other
|
CVE-2006-3604
|
2024-02-14 10:17 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313727
|
7.5 |
HIGH
|
bosdev
|
bosclassifieds_classified_ads
|
Multiple PHP remote file inclusion vulnerabilities in BosClassifieds Classified Ads allow remote attackers to execute arbitrary PHP code via a URL in the insPath parameter to (1) index.php, (2) recen…
|
NVD-CWE-Other
|
CVE-2006-3527
|
2024-02-14 10:17 |
2006-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313728
|
5.1 |
MEDIUM
|
webdesignhq
|
sitebuilder-fx
|
PHP remote file inclusion vulnerability in top.php in SiteBuilder-FX 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter.
|
CWE-94
Code Injection
|
CVE-2006-3395
|
2024-02-14 10:17 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313729
|
4.3 |
MEDIUM
|
pkr_internet
|
taskjitsu
|
Multiple cross-site scripting (XSS) vulnerabilities in Taskjitsu before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters, including the (1) titl…
|
NVD-CWE-Other
|
CVE-2006-3397
|
2024-02-14 10:17 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313730
|
5.0 |
MEDIUM
|
pkr_internet
|
taskjitsu
|
The "change password forms" in Taskjitsu before 2.0.1 includes password hashes in hidden form fields, which allows remote attackers to obtain sensitive information from the (1) Category Editor and (2…
|
NVD-CWE-Other
|
CVE-2006-3398
|
2024-02-14 10:17 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313731
|
7.5 |
HIGH
|
siemens
|
speedstream_wireless_router
|
Siemens Speedstream Wireless Router 2624 allows local users to bypass authentication and access protected files by using the Universal Plug and Play UPnP/1.0 component.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-3344
|
2024-02-14 10:17 |
2006-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313732
|
2.6 |
LOW
|
netsoft
|
smartnet
|
Cross-site scripting (XSS) vulnerability in search.jsp in Netsoft smartNet 2.0 allows remote attackers to inject arbitrary web script or HTML via the keyWord parameter.
|
NVD-CWE-Other
|
CVE-2006-3313
|
2024-02-14 10:17 |
2006-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313733
|
2.6 |
LOW
|
namo
|
deepsearch
|
Cross-site scripting (XSS) vulnerability in mclient.cgi in Namo DeepSearch 4.5 allows remote attackers to inject arbitrary web script or HTML via the p parameter.
|
NVD-CWE-Other
|
CVE-2006-3264
|
2024-02-14 10:17 |
2006-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313734
|
5.1 |
MEDIUM
|
microsoft
|
windows_live_messenger
|
Heap-based buffer overflow in Windows Live Messenger 8.0 allows user-assisted attackers to execute arbitrary code via a crafted Contact List (.ctt) file, which triggers the overflow when it is import…
|
NVD-CWE-Other
|
CVE-2006-3250
|
2024-02-14 10:17 |
2006-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313735
|
10.0 |
HIGH
|
ultimate_php_board
|
ultimate_php_board
|
The installation of Ultimate PHP Board (UPB) 1.9.6 and earlier includes a default administrator login account and password, which allows remote attackers to gain privileges.
|
CWE-255
Credentials Management
|
CVE-2006-3203
|
2024-02-14 10:17 |
2006-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313736
|
5.0 |
MEDIUM
|
ultimate_php_board
|
ultimate_php_board
|
Ultimate PHP Board (UPB) 1.9.6 and earlier uses a cryptographically weak block cipher with a large key collision space, which allows remote attackers to determine a suitable decryption key given the …
|
NVD-CWE-Other
|
CVE-2006-3204
|
2024-02-14 10:17 |
2006-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313737
|
5.0 |
MEDIUM
|
ultimate_php_board
|
ultimate_php_board
|
Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to gain access via modified user_env, pass_env, power_env, and id_env parameters in a cookie, which comprise a persistent logon that…
|
NVD-CWE-Other
|
CVE-2006-3205
|
2024-02-14 10:17 |
2006-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313738
|
6.5 |
MEDIUM
|
ultimate_php_board
|
ultimate_php_board
|
Direct static code injection vulnerability in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote authenticated administrators to execute arbitrary PHP code via multiple unspecified "configurati…
|
NVD-CWE-Other
|
CVE-2006-3208
|
2024-02-14 10:17 |
2006-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313739
|
2.6 |
LOW
|
viart
|
shop
|
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Free 2.5.5, and possibly other distributions including Light, Standard, and Enterprise, allow remote attackers to inject arbitrary we…
|
NVD-CWE-Other
|
CVE-2006-2979
|
2024-02-14 10:17 |
2006-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313740
|
7.5 |
HIGH
|
viart_ltd
|
viart_shop_free
|
SQL injection vulnerability in block_forum_topic_new.php in ViArt Shop Free 2.5.5, and possibly other distributions including Light, Standard, and Enterprise, might allow remote attackers to execute …
|
NVD-CWE-Other
|
CVE-2006-2980
|
2024-02-14 10:17 |
2006-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313741
|
7.5 |
HIGH
|
linksys
|
wrt54g wrt54g_v5
|
Linksys WRT54G Wireless-G Broadband Router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which…
|
NVD-CWE-Other
|
CVE-2006-2559
|
2024-02-14 10:17 |
2006-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313742
|
7.5 |
HIGH
|
sitecom
|
wl-153_router_firmware wl-153
|
Sitecom WL-153 router firmware before 1.38 allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-2560
|
2024-02-14 10:17 |
2006-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313743
|
7.5 |
HIGH
|
edimax
|
br_6104k
|
Edimax BR-6104K router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter (possibly within NewIntern…
|
NVD-CWE-Other
|
CVE-2006-2561
|
2024-02-14 10:17 |
2006-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313744
|
7.5 |
HIGH
|
zyxel
|
p-335wt_router
|
ZyXEL P-335WT router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-2562
|
2024-02-14 10:17 |
2006-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313745
|
6.4 |
MEDIUM
|
lighthouse_development
|
squirrelcart
|
PHP remote file inclusion vulnerability in cart_content.php in Squirrelcart 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cart_isp_root parameter.
|
NVD-CWE-Other
|
CVE-2006-2483
|
2024-02-14 10:17 |
2006-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313746
|
5.0 |
MEDIUM
|
popsoft_digital
|
popphoto
|
PHP remote file inclusion vulnerability in resources/includes/popp.config.loader.inc.php in PopSoft Digital PopPhoto Studio 3.5.4 and earlier allows remote attackers to execute arbitrary PHP code via…
|
CWE-94
Code Injection
|
CVE-2006-2395
|
2024-02-14 10:17 |
2006-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313747
|
2.6 |
LOW
|
mozilla
|
firefox
|
Mozilla Firefox 1.5.0.3 allows remote attackers to cause a denial of service via a web page with a large number of IMG elements in which the SRC attribute is a mailto URI. NOTE: another researcher f…
|
NVD-CWE-Other
|
CVE-2006-2332
|
2024-02-14 10:17 |
2006-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313748
|
4.3 |
MEDIUM
|
planetluc
|
mynews
|
Multiple cross-site scripting (XSS) vulnerabilities in mynews.inc.php in MyNews 1.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) hash and (2) page parameters.
|
NVD-CWE-Other
|
CVE-2006-2208
|
2024-02-14 10:17 |
2006-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313749
|
10.0 |
HIGH
|
ethereal_group
|
ethereal
|
Off-by-one error in the OID printing routine in Ethereal 0.10.x up to 0.10.14 has unknown impact and remote attack vectors.
|
NVD-CWE-Other
|
CVE-2006-1932
|
2024-02-14 10:17 |
2006-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313750
|
5.0 |
MEDIUM
|
ethereal_group
|
ethereal
|
Multiple unspecified vulnerabilities in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (large or infinite loops) viarafted packets to the (1) UMA and (2) BER dissec…
|
NVD-CWE-Other
|
CVE-2006-1933
|
2024-02-14 10:17 |
2006-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|