|
342401
|
7.5 |
HIGH
|
open-xchange
|
open-xchange
|
The open source version of Open-Xchange 0.8.2 and earlier uses a static default username and password with a valid login shell in the initfile for the ldap-server, which allows remote attackers to ac…
|
NVD-CWE-Other
|
CVE-2006-2738
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342402
|
7.5 |
HIGH
|
open-xchange
|
open-xchange
|
Exploit only works on Open Source versions of this product.
|
NVD-CWE-Other
|
CVE-2006-2738
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342403
|
5.1 |
MEDIUM
|
epic_designs
|
tinybb
|
PHP remote file inclusion vulnerability in footers.php in Epicdesigns tinyBB 0.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the tinybb_foote…
|
NVD-CWE-Other
|
CVE-2006-2739
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342404
|
5.1 |
MEDIUM
|
epic_designs
|
tinybb
|
Successful exploitation requires that "register_globals" is enabled.
|
NVD-CWE-Other
|
CVE-2006-2739
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342405
|
6.8 |
MEDIUM
|
epic_designs
|
tinybb
|
Multiple SQL injection vulnerabilities in Epicdesigns tinyBB 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) q parameter in (a) forgot.php, and the (2) username and (3) passw…
|
NVD-CWE-Other
|
CVE-2006-2740
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342406
|
6.8 |
MEDIUM
|
epic_designs
|
tinybb
|
Successful exploitation requires that "magic_quotes_gpc" is disabled.
|
NVD-CWE-Other
|
CVE-2006-2740
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342407
|
6.8 |
MEDIUM
|
epic_designs
|
tinybb
|
Cross-site scripting (XSS) vulnerability in Epicdesigns tinyBB 0.3 allow remote attackers to inject arbitrary web script or HTML via the q parameter in forgot.php, which is echoed in an error message…
|
NVD-CWE-Other
|
CVE-2006-2741
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342408
|
7.5 |
HIGH
|
drupal
|
drupal
|
SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) da…
|
NVD-CWE-Other
|
CVE-2006-2742
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342409
|
7.5 |
HIGH
|
drupal
|
drupal
|
This vulnerability is addressed in the following product releases:
Drupal, Drupal, 4.6.7
Drupal, Drupal, 4.7.1
|
NVD-CWE-Other
|
CVE-2006-2742
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342410
|
5.1 |
MEDIUM
|
drupal
|
drupal
|
Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitra…
|
NVD-CWE-Other
|
CVE-2006-2743
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342411
|
5.1 |
MEDIUM
|
drupal
|
drupal
|
Successful exploitation requires that the "mod_mime" module is installed in Apache, and that a " .htaccess" file has not been used to restrict access to the directory.
This vulnerability is addresse…
|
NVD-CWE-Other
|
CVE-2006-2743
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342412
|
7.5 |
HIGH
|
facile_interactive_web
|
facile_interactive_web
|
PHP remote file inclusion vulnerability in p-popupgallery.php in F@cile Interactive Web 0.8.41 through 0.8.5 allows remote attackers to execute arbitrary PHP code via a URL in the l parameter.
|
NVD-CWE-Other
|
CVE-2006-2744
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342413
|
5.1 |
MEDIUM
|
facile_interactive_web
|
facile_interactive_web
|
Multiple PHP remote file inclusion vulnerabilities in F@cile Interactive Web 0.8.5 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the…
|
NVD-CWE-Other
|
CVE-2006-2745
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342414
|
5.1 |
MEDIUM
|
facile_interactive_web
|
facile_interactive_web
|
Successful exploitation requires that "register_globals" is enabled.
|
NVD-CWE-Other
|
CVE-2006-2745
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342415
|
6.8 |
MEDIUM
|
facile_interactive_web
|
facile_interactive_web
|
Multiple cross-site scripting (XSS) vulnerabilities in F@cile Interactive Web 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) lang parameter in index.php, …
|
NVD-CWE-Other
|
CVE-2006-2746
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342416
|
5.1 |
MEDIUM
|
fredi_bach
|
phpmydesktop_arcade
|
Directory traversal vulnerability in index.php in PhpMyDesktop|arcade 1.0 FINAL allows remote attackers to read arbitrary files or execute PHP code via a .. (dot dot) sequence and trailing null (%00)…
|
NVD-CWE-Other
|
CVE-2006-2747
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342417
|
5.1 |
MEDIUM
|
fredi_bach
|
phpmydesktop_arcade
|
Successful exploitation requires that "magic_quotes_gpc" is disabled.
|
NVD-CWE-Other
|
CVE-2006-2747
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342418
|
6.4 |
MEDIUM
|
open_searchable_image_catalogue
|
open_searchable_image_catalogue
|
SQL injection vulnerability in the do_mysql_query function in core.php for Open Searchable Image Catalogue (OSIC) before 0.7.0.1 allows remote attackers to inject arbitrary SQL commands via multiple …
|
NVD-CWE-Other
|
CVE-2006-2748
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342419
|
6.4 |
MEDIUM
|
open_searchable_image_catalogue
|
open_searchable_image_catalogue
|
Upgrade to Version 0.7.0.1
|
NVD-CWE-Other
|
CVE-2006-2748
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342420
|
6.4 |
MEDIUM
|
open_searchable_image_catalogue
|
open_searchable_image_catalogue
|
SQL injection vulnerability in search.php in Open Searchable Image Catalogue (OSIC) 0.7.0.1 and earlier allows remote attackers to inject arbitrary SQL commands via the (1) txtCustomField and (2) Cus…
|
NVD-CWE-Other
|
CVE-2006-2749
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342421
|
6.4 |
MEDIUM
|
open_searchable_image_catalogue
|
open_searchable_image_catalogue
|
Upgrade to version 0.7.0.1
|
NVD-CWE-Other
|
CVE-2006-2749
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342422
|
4.3 |
MEDIUM
|
open_searchable_image_catalogue
|
open_searchable_image_catalogue
|
Cross-site scripting (XSS) vulnerability in the do_mysql_query function in core.php for Open Searchable Image Catalogue (OSIC) before 0.7.0.1 allows remote attackers to inject arbitrary web scripts o…
|
NVD-CWE-Other
|
CVE-2006-2750
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342423
|
4.3 |
MEDIUM
|
open_searchable_image_catalogue
|
open_searchable_image_catalogue
|
Upgrade to version 0.7.0.1
|
NVD-CWE-Other
|
CVE-2006-2750
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342424
|
4.3 |
MEDIUM
|
open_searchable_image_catalogue
|
open_searchable_image_catalogue
|
Cross-site scripting (XSS) vulnerability in Open Searchable Image Catalogue (OSIC) 0.7.0.1 and earlier allows remote attackers to inject arbitrary web scripts or HTML via the item_list parameter in s…
|
NVD-CWE-Other
|
CVE-2006-2751
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342425
|
4.3 |
MEDIUM
|
open_searchable_image_catalogue
|
open_searchable_image_catalogue
|
Upgrade to version 0.7.0.1
|
NVD-CWE-Other
|
CVE-2006-2751
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342426
|
6.4 |
MEDIUM
|
suse
|
suse_linux
|
The RedCarpet /etc/ximian/rcd.conf configuration file in Novell Linux Desktop 9 and SUSE SLES 9 has world-readable permissions, which allows attackers to obtain the rc (RedCarpet) password.
|
NVD-CWE-Other
|
CVE-2006-2752
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342427
|
5.0 |
MEDIUM
|
openldap
|
openldap
|
Stack-based buffer overflow in st.c in slurpd for OpenLDAP before 2.3.22 might allow attackers to execute arbitrary code via a long hostname.
|
NVD-CWE-Other
|
CVE-2006-2754
|
2018-10-19 01:41 |
2006-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342428
|
4.3 |
MEDIUM
|
ubbcentral
|
ubb.threads
|
Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script or HTML via the debug parameter, as demonstrated by stealing…
|
NVD-CWE-Other
|
CVE-2006-2755
|
2018-10-19 01:41 |
2006-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342429
|
4.3 |
MEDIUM
|
chipmunk_scripts
|
chipmunk_guestbook
|
Cross-site scripting (XSS) vulnerability in Chipmunk guestbook allows remote attackers to inject arbitrary web script or HTML via the (1) start parameter in (a) index.php; (2) forumID parameter in in…
|
NVD-CWE-Other
|
CVE-2006-2757
|
2018-10-19 01:41 |
2006-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342430
|
6.4 |
MEDIUM
|
webcalendar
|
webcalendar
|
PHP remote file inclusion vulnerability in includes/config.php in WebCalendar 1.0.3 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter, which is remotely acce…
|
NVD-CWE-Other
|
CVE-2006-2762
|
2018-10-19 01:41 |
2006-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342431
|
6.4 |
MEDIUM
|
pre_projects
|
pre_news_manager
|
SQL injection vulnerability in Pre News Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) index.php, and the (2) nid parameter to (b) news_detail.p…
|
NVD-CWE-Other
|
CVE-2006-2763
|
2018-10-19 01:41 |
2006-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342432
|
5.0 |
MEDIUM
|
sourcefire
|
snort
|
The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent" rules via a carriage return (\r) after the URL and before the HTTP declaration.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-2769
|
2018-10-19 01:41 |
2006-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342433
|
5.0 |
MEDIUM
|
sourcefire
|
snort
|
This vulnerability is addressed in the following product release:
Snort, 2.4.4 source with uricontent patch
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-2769
|
2018-10-19 01:41 |
2006-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342434
|
5.4 |
MEDIUM
|
pppblog
|
pppblog
|
Directory traversal vulnerability in randompic.php in pppBLOG 0.3.8 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) sequence in an in…
|
NVD-CWE-Other
|
CVE-2006-2770
|
2018-10-19 01:41 |
2006-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342435
|
5.4 |
MEDIUM
|
pppblog
|
pppblog
|
Successful exploitation requires that "register_globals" is enabled.
|
NVD-CWE-Other
|
CVE-2006-2770
|
2018-10-19 01:41 |
2006-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342436
|
6.8 |
MEDIUM
|
qontentone
|
qontentone_cms
|
Cross-site scripting (XSS) vulnerability in search.php in QontentOne CMS allows remote attackers to inject arbitrary web script or HTML via the search_phrase parameter.
|
NVD-CWE-Other
|
CVE-2006-2774
|
2018-10-19 01:41 |
2006-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342437
|
7.5 |
HIGH
|
mozilla
|
firefox thunderbird
|
Mozilla Firefox and Thunderbird before 1.5.0.4 associates XUL attributes with the wrong URL under certain unspecified circumstances, which might allow remote attackers to bypass restrictions by causi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-2775
|
2018-10-19 01:41 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342438
|
7.5 |
HIGH
|
mozilla
|
firefox thunderbird
|
Mozilla, Thunderbird versions are only vulnerable if you turn on JavaScript in mail.
This vulnerability is addressed in the following product release:
Mozilla, Firefox, 1.5.0.4
Mozilla, Thunderbir…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-2775
|
2018-10-19 01:41 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342439
|
7.5 |
HIGH
|
mozilla
|
firefox thunderbird
|
Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 calls content-defined setters on an object prototype, which allows remote attackers to execute code at a higher privilege …
|
NVD-CWE-Other
|
CVE-2006-2776
|
2018-10-19 01:41 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342440
|
7.5 |
HIGH
|
mozilla
|
firefox thunderbird
|
This vulnerability is addressed in the following product releases:
Mozilla, Firefox, 1.5.0.4
Mozilla, Thunderbird, 1.5.0.4
|
NVD-CWE-Other
|
CVE-2006-2776
|
2018-10-19 01:41 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342441
|
7.6 |
HIGH
|
zipcentral
|
zipcentral
|
Stack-based buffer overflow in ZipCentral 4.01 allows remote user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-2439
|
2018-10-19 01:40 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342442
|
5.1 |
MEDIUM
|
apache
|
spamassassin
|
SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invok…
|
NVD-CWE-noinfo
|
CVE-2006-2447
|
2018-10-19 01:40 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342443
|
4.0 |
MEDIUM
|
kde
|
kde
|
KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for login.
|
NVD-CWE-Other
|
CVE-2006-2449
|
2018-10-19 01:40 |
2006-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342444
|
4.0 |
MEDIUM
|
kde
|
kde
|
Vendor links provide patches for each version affected.
|
NVD-CWE-Other
|
CVE-2006-2449
|
2018-10-19 01:40 |
2006-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342445
|
4.0 |
MEDIUM
|
libextractor
|
libextractor
|
Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow remote attackers to execute arbitrary code via (1) the asf_read_header function in the ASF plugin (plugins/asfextractor.c…
|
NVD-CWE-Other
|
CVE-2006-2458
|
2018-10-19 01:40 |
2006-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342446
|
6.4 |
MEDIUM
|
php_fusion
|
php_fusion
|
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL commands via the srch_where parameter.
|
NVD-CWE-Other
|
CVE-2006-2459
|
2018-10-19 01:40 |
2006-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342447
|
6.4 |
MEDIUM
|
sugarcrm
|
sugarcrm
|
Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESSION from modification, which allows remote attack…
|
NVD-CWE-Other
|
CVE-2006-2460
|
2018-10-19 01:40 |
2006-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342448
|
7.5 |
HIGH
|
cosmoshop
|
cosmoshop
|
SQL injection vulnerability in lshop.cgi in Cosmoshop 8.11.106 and earlier allows remote attackers to execute arbitrary SQL commands via the artnum parameter.
|
NVD-CWE-Other
|
CVE-2006-2474
|
2018-10-19 01:40 |
2006-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342449
|
7.8 |
HIGH
|
cosmoshop
|
cosmoshop
|
Directory traversal vulnerability in (1) edit_mailtexte.cgi and (2) bestmail.cgi in Cosmoshop 8.11.106 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file …
|
NVD-CWE-Other
|
CVE-2006-2475
|
2018-10-19 01:40 |
2006-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342450
|
5.0 |
MEDIUM
|
bitrix
|
bitrix_site_manager
|
Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.
|
NVD-CWE-Other
|
CVE-2006-2476
|
2018-10-19 01:40 |
2006-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|