|
342651
|
4.3 |
MEDIUM
|
bitdamaged
|
geoblog
|
Cross-site scripting (XSS) vulnerability in viewcat.php in geoBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
|
NVD-CWE-Other
|
CVE-2006-2177
|
2018-10-19 01:38 |
2006-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342652
|
5.0 |
MEDIUM
|
zenphoto
|
zenphoto
|
zenphoto 1.0.1 beta and earlier allow remote attackers to obtain sensitive information via a direct request for the (1) /photos/themes/default/ and (2) /photos/themes/testing/ URIs, which reveals the…
|
NVD-CWE-Other
|
CVE-2006-2186
|
2018-10-19 01:38 |
2006-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342653
|
6.8 |
MEDIUM
|
zenphoto
|
zenphoto
|
Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) a parameter in i.php, and the (2) albu…
|
NVD-CWE-Other
|
CVE-2006-2187
|
2018-10-19 01:38 |
2006-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342654
|
6.8 |
MEDIUM
|
zenphoto
|
zenphoto
|
This vulnerability is addressed in the following product release:
zenphoto, zenphoto, 1.0.2 beta
|
NVD-CWE-Other
|
CVE-2006-2187
|
2018-10-19 01:38 |
2006-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342655
|
6.8 |
MEDIUM
|
cmscout
|
cmscout
|
Multiple cross-site scripting (XSS) vulnerabilities in CMScout 1.10 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Body field of a private message (PM), (2) BBC…
|
NVD-CWE-Other
|
CVE-2006-2188
|
2018-10-19 01:38 |
2006-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342656
|
6.8 |
MEDIUM
|
cmscout
|
cmscout
|
This vulnerability is addressed in the following product release:
CMScout, CMScout, 1.21
|
NVD-CWE-Other
|
CVE-2006-2188
|
2018-10-19 01:38 |
2006-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342657
|
10.0 |
HIGH
|
servous
|
sblog
|
SQL injection vulnerability in search.php in Servous sBLOG 0.7.2 allows remote attackers to execute arbitrary SQL commands via the keyword parameter. NOTE: this issue can be used to trigger path dis…
|
NVD-CWE-Other
|
CVE-2006-2189
|
2018-10-19 01:38 |
2006-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342658
|
7.6 |
HIGH
|
openoffice sun
|
openoffice staroffice
|
OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an OpenOffice document with a malicious BASIC macro, whi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-2198
|
2018-10-19 01:38 |
2006-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342659
|
7.6 |
HIGH
|
openoffice sun
|
openoffice staroffice
|
Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to escape the Java sandbox and conduct unauthorize…
|
NVD-CWE-noinfo
|
CVE-2006-2199
|
2018-10-19 01:38 |
2006-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342660
|
6.4 |
MEDIUM
|
invision_power_services
|
invision_gallery
|
SQL injection vulnerability in post.php in Invision Gallery 2.0.6 allows remote attackers to execute arbitrary SQL commands via the album parameter.
|
NVD-CWE-Other
|
CVE-2006-2202
|
2018-10-19 01:38 |
2006-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342661
|
5.5 |
MEDIUM
|
invision_power_services
|
invision_power_board
|
SQL injection vulnerability in the topic deletion functionality (post_delete function in func_mod.php) for Invision Power Board 2.1.5 allows remote authenticated moderators to execute arbitrary SQL c…
|
NVD-CWE-Other
|
CVE-2006-2204
|
2018-10-19 01:38 |
2006-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342662
|
5.8 |
MEDIUM
|
321soft
|
php-gallery
|
Cross-site scripting (XSS) vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: this issue might be resu…
|
NVD-CWE-Other
|
CVE-2006-2210
|
2018-10-19 01:38 |
2006-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342663
|
5.0 |
MEDIUM
|
321soft
|
php-gallery
|
Absolute path traversal vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to browse arbitrary directories via the path parameter.
|
NVD-CWE-Other
|
CVE-2006-2211
|
2018-10-19 01:38 |
2006-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342664
|
6.4 |
MEDIUM
|
karjasoft
|
sami_ftp_server
|
Buffer overflow in KarjaSoft Sami FTP Server 2.0.2 and earlier allows remote attackers to execute arbitrary code via a long (1) USER or (2) PASS command.
|
NVD-CWE-Other
|
CVE-2006-2212
|
2018-10-19 01:38 |
2006-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342665
|
5.0 |
MEDIUM
|
devsyn
|
open_bulletin_board
|
Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to obtain the full path of the web server via an invalid pforums parameter to (1) misc.php and (2) member.php.
|
NVD-CWE-Other
|
CVE-2006-2216
|
2018-10-19 01:38 |
2006-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342666
|
2.1 |
LOW
|
bitrock process-one
|
install_builder ejabberd
|
A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an installer that allows local users to cau…
|
NVD-CWE-Other
|
CVE-2006-2221
|
2018-10-19 01:38 |
2006-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342667
|
2.1 |
LOW
|
bitrock process-one
|
install_builder ejabberd
|
This vulnerability is addressed in the following product releases:
Process-one, ejabberd, 1.1.1_2
BitRock, Install Builder, 3.7.0
|
NVD-CWE-Other
|
CVE-2006-2221
|
2018-10-19 01:38 |
2006-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342668
|
5.0 |
MEDIUM
|
norz
|
zawhttpd
|
Buffer overflow in zawhttpd 0.8.23, and possibly previous versions, allows remote attackers to cause a denial of service (daemon crash) via a request for a URI composed of several "\" (backslash) cha…
|
NVD-CWE-Other
|
CVE-2006-2222
|
2018-10-19 01:38 |
2006-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342669
|
5.0 |
MEDIUM
|
quagga
|
quagga
|
RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain …
|
CWE-20
Improper Input Validation
|
CVE-2006-2223
|
2018-10-19 01:38 |
2006-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342670
|
5.0 |
MEDIUM
|
quagga
|
quagga_routing_software_suite
|
RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.
|
CWE-287
Improper Authentication
|
CVE-2006-2224
|
2018-10-19 01:38 |
2006-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342671
|
7.5 |
HIGH
|
dxmsoft
|
xm_easy_personal_ftp_server
|
Buffer overflow in XM Easy Personal FTP Server 4.3 and earlier allows remote attackers to execute arbitrary code, probably via a USER command with a long username.
|
NVD-CWE-Other
|
CVE-2006-2225
|
2018-10-19 01:38 |
2006-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342672
|
4.3 |
MEDIUM
|
punbb
|
punbb
|
Cross-site scripting (XSS) vulnerability in misc.php in PunBB 1.2.11 allows remote attackers to inject arbitrary web script or HTML via the req_message parameter, because the value of the redirect_ur…
|
NVD-CWE-Other
|
CVE-2006-2227
|
2018-10-19 01:38 |
2006-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342673
|
4.3 |
MEDIUM
|
w-agora
|
w-agora
|
Cross-site scripting (XSS) vulnerability in w-Agora (aka Web-Agora) 4.2.0 allows remote attackers to inject arbitrary web script or HTML via a post with a BBCode tag that contains a JavaScript event …
|
NVD-CWE-Other
|
CVE-2006-2228
|
2018-10-19 01:38 |
2006-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342674
|
5.0 |
MEDIUM
|
xine
|
xine
|
Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.4 might allow attackers to cause a denial of service via format string specifiers in an MP3 filename specified on the command…
|
NVD-CWE-Other
|
CVE-2006-2230
|
2018-10-19 01:38 |
2006-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342675
|
4.3 |
MEDIUM
|
big_webmaster
|
big_webmaster_guestbook_script
|
Multiple cross-site scripting (XSS) vulnerabilities in addguest.cgi in Big Webmaster Guestbook Script 1.02 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mail, …
|
NVD-CWE-Other
|
CVE-2006-2231
|
2018-10-19 01:38 |
2006-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342676
|
4.3 |
MEDIUM
|
scriptsez
|
cute_guestbook
|
Cross-site scripting (XSS) vulnerability in Scriptsez Cute Guestbook 20060211 allows remote attackers to inject arbitrary web script or HTML via the Comments field when signing the guestbook.
|
NVD-CWE-Other
|
CVE-2006-2232
|
2018-10-19 01:38 |
2006-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342677
|
7.5 |
HIGH
|
banktown
|
btcxctl20com_activex_control
|
Buffer overflow in BankTown Client Control (aka BtCxCtl20Com) 1.4.2.51817, and possibly 1.5.2.50209, allows remote attackers to execute arbitrary code via a long string in the first argument to SetBa…
|
NVD-CWE-Other
|
CVE-2006-2233
|
2018-10-19 01:38 |
2006-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342678
|
6.8 |
MEDIUM
|
tyrocms
|
tyrocms
|
Multiple cross-site scripting (XSS) vulnerabilities in TyroCMS beta 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) a javascript URI in an img BBCode tag, or a JavaScript ev…
|
NVD-CWE-Other
|
CVE-2006-2234
|
2018-10-19 01:38 |
2006-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342679
|
7.6 |
HIGH
|
codemunkyx
|
simple_poll
|
CodeMunkyX (aka free-php.net) Simple Poll 1.0, when authentication is not required for the admin directory, allows remote attackers to gain administrative privileges by appending /admin/ to the top-l…
|
NVD-CWE-Other
|
CVE-2006-2235
|
2018-10-19 01:38 |
2006-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342680
|
7.6 |
HIGH
|
codemunkyx
|
simple_poll
|
This vulnerability can only be exploited when authentication is not required for the admin directory.
|
NVD-CWE-Other
|
CVE-2006-2235
|
2018-10-19 01:38 |
2006-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342681
|
7.6 |
HIGH
|
id_software
|
quake_3_arena quake_3_engine return_to_castle_wolfenstein wolfenstein_enemy_territory
|
Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary commands via a long re…
|
NVD-CWE-Other
|
CVE-2006-2236
|
2018-10-19 01:38 |
2006-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342682
|
6.4 |
MEDIUM
|
ftrainsoft
|
fast_click
|
PHP remote file inclusion vulnerability in show.php in Fast Click SQL Lite 1.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: This is a di…
|
NVD-CWE-Other
|
CVE-2006-2241
|
2018-10-19 01:38 |
2006-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342683
|
5.8 |
MEDIUM
|
uapplication
|
ublog
|
Cross-site scripting (XSS) vulnerability in UBlog 1.6 Access Edition allows remote attackers to inject arbitrary web script or HTML via text fields when adding a blog entry.
|
NVD-CWE-Other
|
CVE-2006-2246
|
2018-10-19 01:38 |
2006-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342684
|
5.0 |
MEDIUM
|
webcalendar
|
webcalendar
|
WebCalendar 1.0.1 to 1.0.3 generates different error messages depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames.
|
NVD-CWE-Other
|
CVE-2006-2247
|
2018-10-19 01:38 |
2006-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342685
|
4.3 |
MEDIUM
|
cutephp
|
cutenews
|
Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2…
|
NVD-CWE-Other
|
CVE-2006-2249
|
2018-10-19 01:38 |
2006-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342686
|
6.4 |
MEDIUM
|
cutephp
|
cutenews
|
CuteNews 1.4.1 allows remote attackers to obtain sensitive information via a direct request to (1) /inc/show.inc.php or (2) /inc/functions.inc.php, which reveal the path in an error message.
|
NVD-CWE-Other
|
CVE-2006-2250
|
2018-10-19 01:38 |
2006-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342687
|
6.4 |
MEDIUM
|
openfaq
|
openfaq
|
Cross-site scripting vulnerability in submit.php in OpenFAQ 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
|
NVD-CWE-Other
|
CVE-2006-2252
|
2018-10-19 01:38 |
2006-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342688
|
2.6 |
LOW
|
singapore
|
singapore
|
Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.7 allows remote attackers to inject arbitrary web script or HTML via the image parameter.
|
NVD-CWE-Other
|
CVE-2006-2262
|
2018-10-19 01:38 |
2006-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342689
|
5.0 |
MEDIUM
|
kerio
|
winroute_firewall
|
Kerio WinRoute Firewall before 6.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors in the "email protocol inspectors," possibly (1) SMTP and (2) POP3.
|
NVD-CWE-Other
|
CVE-2006-2267
|
2018-10-19 01:38 |
2006-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342690
|
5.0 |
MEDIUM
|
kerio
|
winroute_firewall
|
This vulnerability is addressed in the following product release:
Kerio, WinRoute Firewall, 6.2.1
|
NVD-CWE-Other
|
CVE-2006-2267
|
2018-10-19 01:38 |
2006-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342691
|
7.5 |
HIGH
|
flexcustomer
|
flexcustomer
|
SQL injection vulnerability in FlexCustomer 0.0.4 and earlier allows remote attackers to bypass authentication and execute arbitrary SQL commands via the admin and ordinary user interface, probably i…
|
CWE-89
SQL Injection
|
CVE-2006-2268
|
2018-10-19 01:38 |
2006-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342692
|
4.3 |
MEDIUM
|
mywebland
|
mybloggie
|
Cross-site scripting (XSS) vulnerability in myWebland MyBloggie 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode img tag.
|
NVD-CWE-Other
|
CVE-2006-2269
|
2018-10-19 01:38 |
2006-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342693
|
7.5 |
HIGH
|
jetbox
|
jetbox_cms
|
PHP remote file inclusion vulnerability in includes/config.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary code via a URL in the relative_script_path parameter.
|
NVD-CWE-Other
|
CVE-2006-2270
|
2018-10-19 01:38 |
2006-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342694
|
9.3 |
HIGH
|
verisign
|
i-nav
|
The InstallProduct routine in the Verisign VUpdater.Install (aka i-Nav) ActiveX control does not verify Microsoft Cabinet (.CAB) files, which allows remote attackers to run an arbitrary executable fi…
|
NVD-CWE-Other
|
CVE-2006-2273
|
2018-10-19 01:38 |
2006-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342695
|
5.0 |
MEDIUM
|
apple
|
mac_os_x
|
Multiple Apple Mac OS X 10.4 applications might allow context-dependent attackers to cause a denial of service (application crash) via a crafted OpenEXR (.exr) image file, which triggers the crash wh…
|
NVD-CWE-Other
|
CVE-2006-2277
|
2018-10-19 01:38 |
2006-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342696
|
5.0 |
MEDIUM
|
arabless
|
saphplesson
|
SaphpLesson 3.0 does not initialize array variables, which allows remote attackers to obtain the full path via an non-array (1) hrow parameter to (a) show.php or (b) index.php; the (2) Lsnrow paramet…
|
NVD-CWE-Other
|
CVE-2006-2278
|
2018-10-19 01:38 |
2006-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342697
|
7.5 |
HIGH
|
arabless
|
saphplesson
|
Multiple SQL injection vulnerabilities in SaphpLesson 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the Find parameter in (a) search.php, and the (2) LID and (3) Rate parameter…
|
NVD-CWE-Other
|
CVE-2006-2279
|
2018-10-19 01:38 |
2006-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342698
|
5.0 |
MEDIUM
|
openengine
|
openengine
|
Directory traversal vulnerability in website.php in openEngine 1.8 Beta 2 and earlier allows remote attackers to list arbitrary directories and read arbitrary files via a .. (dot dot) in the template…
|
NVD-CWE-Other
|
CVE-2006-2280
|
2018-10-19 01:38 |
2006-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342699
|
7.5 |
HIGH
|
x-scripts
|
x-poll
|
X-Scripts X-Poll (xpoll) 2.30 allows remote attackers to execute arbitrary PHP code by using admin/images/add.php to upload a PHP file, then access it.
|
CWE-94
Code Injection
|
CVE-2006-2281
|
2018-10-19 01:38 |
2006-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342700
|
4.3 |
MEDIUM
|
x7_group
|
x7_chat
|
Cross-site scripting (XSS) vulnerability in X7 Chat 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the URL of an avatar, possibly related to …
|
NVD-CWE-Other
|
CVE-2006-2282
|
2018-10-19 01:38 |
2006-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|