|
342851
|
5.0 |
MEDIUM
|
georges_auberger
|
pajax
|
Users of PAJAX should upgrade to the latest version pajax-0.5.2 [1].
|
NVD-CWE-Other
|
CVE-2006-1789
|
2018-10-19 01:36 |
2006-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342852
|
10.0 |
HIGH
|
mozilla
|
firefox
|
A regression fix in Mozilla Firefox 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the InstallTrigger.install method, which leads to memory…
|
CWE-399
Resource Management Errors
|
CVE-2006-1790
|
2018-10-19 01:36 |
2006-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342853
|
7.5 |
HIGH
|
jl_webworks
|
quickblogger
|
Directory traversal vulnerability in acc.php in QuickBlogger 1.4 allows remote attackers to read or include arbitrary local files via the request parameter. NOTE: this issue can also produce resulta…
|
NVD-CWE-Other
|
CVE-2006-1791
|
2018-10-19 01:36 |
2006-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342854
|
7.5 |
HIGH
|
rateit
|
rateit
|
SQL injection vulnerability in rateit.php in RateIt 2.2 allows remote attackers to execute arbitrary SQL commands via the rateit_id parameter.
|
NVD-CWE-Other
|
CVE-2006-1798
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342855
|
4.3 |
MEDIUM
|
planet_concept
|
planetsearch\+
|
Cross-site scripting (XSS) vulnerability in planetsearchplus.php in planetSearch+ allows remote attackers to inject arbitrary web script or HTML via the search_exp parameter.
|
NVD-CWE-Other
|
CVE-2006-1801
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342856
|
4.3 |
MEDIUM
|
tinywebgallery
|
tinywebgallery
|
Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the twg_album parameter.
|
NVD-CWE-Other
|
CVE-2006-1802
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342857
|
4.3 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
Cross-site scripting (XSS) vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to inject arbitrary web script or HTML via the sql_query parameter.
|
NVD-CWE-Other
|
CVE-2006-1803
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342858
|
7.5 |
HIGH
|
phpmyadmin
|
phpmyadmin
|
SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter.
|
NVD-CWE-Other
|
CVE-2006-1804
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342859
|
7.5 |
HIGH
|
phpmyadmin
|
phpmyadmin
|
This vulnerbability may affect earlier versions of phpMyAdmin as well.
|
NVD-CWE-Other
|
CVE-2006-1804
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342860
|
7.5 |
HIGH
|
powerscripts
|
powerclan
|
SQL injection vulnerability in member.php in PowerClan 1.14 allows remote attackers to execute arbitrary SQL commands via the memberid parameter.
|
NVD-CWE-Other
|
CVE-2006-1805
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342861
|
2.6 |
LOW
|
musicbox
|
musicbox
|
Cross-site scripting (XSS) vulnerability in index.php in Musicbox 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter in a search action.
|
NVD-CWE-Other
|
CVE-2006-1806
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342862
|
7.5 |
HIGH
|
musicbox
|
musicbox
|
Multiple SQL injection vulnerabilities in index.php in Musicbox 2.3.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start parameter in a search action or (2) type p…
|
NVD-CWE-Other
|
CVE-2006-1807
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342863
|
2.6 |
LOW
|
lifetype
|
lifetype
|
Cross-site scripting (XSS) vulnerability in index.php in Lifetype 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the show parameter in a Template operation.
|
NVD-CWE-Other
|
CVE-2006-1808
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342864
|
5.0 |
MEDIUM
|
lifetype
|
lifetype
|
index.php in Lifetype 1.0.3 allows remote attackers to obtain sensitive information via an invalid show parameter, which reveals the path in an error message.
|
NVD-CWE-Other
|
CVE-2006-1809
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342865
|
1.9 |
LOW
|
flexbb
|
flexbb
|
Multiple cross-site scripting (XSS) vulnerabilities in FlexBB 0.5.5 BETA allow remote attackers to inject arbitrary web script or HTML via the (1) ICQ, (2) AIM, (3) MSN, (4) Google Talk, (5) Website …
|
NVD-CWE-Other
|
CVE-2006-1810
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342866
|
6.4 |
MEDIUM
|
flexbb
|
flexbb
|
Multiple SQL injection vulnerabilities in FlexBB 0.5.5 BETA allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) forumid, or (3) threadid parameter to index.php; the (4) ICQ, …
|
NVD-CWE-Other
|
CVE-2006-1811
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342867
|
6.4 |
MEDIUM
|
phpwebftp
|
phpwebftp
|
phpWebFTP 3.2 and earlier stores script.js under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.
|
NVD-CWE-Other
|
CVE-2006-1812
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342868
|
6.4 |
MEDIUM
|
phpwebftp
|
phpwebftp
|
Directory traversal vulnerability in index.php in phpWebFTP 3.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter.
|
NVD-CWE-Other
|
CVE-2006-1813
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342869
|
5.0 |
MEDIUM
|
jelsoft
|
vbulletin
|
PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers to execute arbitrary code via a URL in the systempath parameter to (1) ImpExModule.php, (2) ImpExC…
|
NVD-CWE-Other
|
CVE-2006-1816
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342870
|
2.6 |
LOW
|
the_war_forge
|
warforge.news
|
SQL injection vulnerability in authcheck.php in warforge.NEWS 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) authusername and possibly the …
|
NVD-CWE-Other
|
CVE-2006-1817
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342871
|
2.6 |
LOW
|
the_war_forge
|
warforge.news
|
Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly including the (1) first_name a…
|
NVD-CWE-Other
|
CVE-2006-1818
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342872
|
5.8 |
MEDIUM
|
modxcms
|
modxcms
|
Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this might be resultant from the direct…
|
NVD-CWE-Other
|
CVE-2006-1820
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342873
|
6.4 |
MEDIUM
|
modxcms
|
modxcms
|
Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the id parameter.
|
NVD-CWE-Other
|
CVE-2006-1821
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342874
|
6.4 |
MEDIUM
|
modxcms
|
modxcms
|
To address this issue, the vendor has released a patch available at the following location:
http://modxcms.com/forums/index.php/topic,3982.0.html
|
NVD-CWE-Other
|
CVE-2006-1821
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342875
|
5.8 |
MEDIUM
|
farsinews
|
farsinews
|
Cross-site scripting (XSS) vulnerability in search.php in FarsiNews 2.5.3 Pro and earlier allows remote attackers to inject arbitrary web script or HTML via the selected_search_arch parameter.
|
NVD-CWE-Other
|
CVE-2006-1822
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342876
|
6.4 |
MEDIUM
|
farsinews
|
farsinews
|
Directory traversal vulnerability in FarsiNews 2.5.3 Pro and earlier allows remote attackers to obtain the installation path via ".." sequences in the archive parameter to index.php, which leaks the …
|
NVD-CWE-Other
|
CVE-2006-1823
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342877
|
1.2 |
LOW
|
phpguestbook
|
phpguestbook
|
Multiple cross-site scripting (XSS) vulnerabilities in PhpGuestbook.php in PhpGuestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Website, and (3) Commen…
|
NVD-CWE-Other
|
CVE-2006-1824
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342878
|
4.3 |
MEDIUM
|
snipegallery
|
snipe_gallery
|
Multiple cross-site scripting (XSS) vulnerabilities in Snipe Gallery 3.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in view.php, (2) …
|
CWE-79
Cross-site Scripting
|
CVE-2006-1826
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342879
|
5.1 |
MEDIUM
|
opera
|
opera_browser
|
Integer signedness error in Opera before 8.54 allows remote attackers to execute arbitrary code via long values in a stylesheet attribute, which pass a length check. NOTE: a sign extension problem m…
|
CWE-189
Numeric Errors
|
CVE-2006-1834
|
2018-10-19 01:36 |
2006-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342880
|
2.6 |
LOW
|
vincent_hor
|
calendarix calendarix_advanced
|
Cross-site scripting (XSS) vulnerability in yearcal.php in Calendarix allows remote attackers to inject arbitrary web script or HTML via the ycyear parameter.
|
NVD-CWE-Other
|
CVE-2006-1835
|
2018-10-19 01:36 |
2006-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342881
|
6.8 |
MEDIUM
|
symantec
|
liveupdate norton_antivirus norton_internet_security norton_personal_firewall norton_system_works norton_utilities
|
Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a…
|
NVD-CWE-Other
|
CVE-2006-1836
|
2018-10-19 01:36 |
2006-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342882
|
7.5 |
HIGH
|
php_album
|
php_album
|
PHP remote file inclusion vulnerability in language.php in PHP Album 0.3.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary code via an FTP URL in the data_dir parame…
|
NVD-CWE-Other
|
CVE-2006-1839
|
2018-10-19 01:36 |
2006-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342883
|
2.6 |
LOW
|
kailash_nadh
|
boastmachine
|
Cross-site scripting (XSS) vulnerability in search.php in boastMachine (bMachine) 2.7, and possibly other versions before 2.9b, allows remote attackers to inject arbitrary web script or HTML via the …
|
NVD-CWE-Other
|
CVE-2006-1841
|
2018-10-19 01:36 |
2006-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342884
|
2.6 |
LOW
|
cynical_games
|
shoutbook
|
Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) NAME and (2) COMMENTS parameters.
|
NVD-CWE-Other
|
CVE-2006-1842
|
2018-10-19 01:36 |
2006-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342885
|
2.6 |
LOW
|
linpha
|
linpha
|
Multiple cross-site scripting (XSS) vulnerabilities in stats_view.php in LinPHA 1.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date_from, (2) date_to, and (3) date pa…
|
NVD-CWE-Other
|
CVE-2006-1848
|
2018-10-19 01:36 |
2006-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342886
|
4.6 |
MEDIUM
|
linux
|
linux_kernel
|
Directory traversal vulnerability in smbfs in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences, a similar vulnerability to …
|
NVD-CWE-Other
|
CVE-2006-1864
|
2018-10-19 01:36 |
2006-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342887
|
9.7 |
HIGH
|
oracle
|
database_server
|
Multiple unspecified vulnerabilities in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and other versions have unknown impact and attack vectors in the (1) Advanced Replication component…
|
NVD-CWE-noinfo
|
CVE-2006-1866
|
2018-10-19 01:36 |
2006-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342888
|
10.0 |
HIGH
|
oracle
|
database_server
|
Unspecified vulnerability in Oracle Database Server 9.2.0.6 has unknown impact and attack vectors in the Advanced Replication component, aka Vuln# DB02.
|
NVD-CWE-Other
|
CVE-2006-1867
|
2018-10-19 01:36 |
2006-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342889
|
7.5 |
HIGH
|
oracle
|
database_server
|
Buffer overflow in the Advanced Replication component in Oracle Database Server 10.1.0.4 allows database users to execute arbitrary code via the VERIFY_LOG procedure of the DBMS_SNAPSHOT_UTL package,…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-1868
|
2018-10-19 01:36 |
2006-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342890
|
10.0 |
HIGH
|
oracle
|
database_server
|
Unspecified vulnerability in Oracle Database Server 8.1.7.4 and 9.0.1.5 has unknown impact and attack vectors in the Dictionary component, aka Vuln# DB04.
|
NVD-CWE-Other
|
CVE-2006-1869
|
2018-10-19 01:36 |
2006-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342891
|
9.0 |
HIGH
|
oracle
|
database_server
|
Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.2 has unknown impact and attack vectors in the Export component, aka Vuln# DB05. NOTE: details are…
|
NVD-CWE-noinfo
|
CVE-2006-1870
|
2018-10-19 01:36 |
2006-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342892
|
6.8 |
MEDIUM
|
mozilla
|
firefox mozilla_suite seamonkey thunderbird
|
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protect the compilation scope of privileged built-in XBL…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-1733
|
2018-10-19 01:35 |
2006-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342893
|
6.8 |
MEDIUM
|
mozilla
|
firefox mozilla_suite seamonkey thunderbird
|
This vulnerability also affects Mozilla, SeaMonkey, 1.0 and Mozilla, Suite, 1.7.13
This vulnerabiloity is addressed in the following product releases:
Mozilla, Firefox, 1.5
Mozilla, Firefox, 1.0…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-1733
|
2018-10-19 01:35 |
2006-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342894
|
6.8 |
MEDIUM
|
mozilla
|
firefox mozilla_suite seamonkey thunderbird
|
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using the Object.watc…
|
NVD-CWE-Other
|
CVE-2006-1734
|
2018-10-19 01:35 |
2006-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342895
|
6.8 |
MEDIUM
|
mozilla
|
firefox mozilla_suite seamonkey thunderbird
|
Fixed in: Firefox 1.5
Firefox 1.0.8
Thunderbird 1.5
Thunderbird 1.0.8
SeaMonkey 1.0
Mozilla Suite 1.7.13
|
NVD-CWE-Other
|
CVE-2006-1734
|
2018-10-19 01:35 |
2006-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342896
|
9.3 |
HIGH
|
mozilla
|
firefox mozilla_suite seamonkey thunderbird
|
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using an eval in an X…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-1735
|
2018-10-19 01:35 |
2006-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342897
|
9.3 |
HIGH
|
mozilla
|
firefox mozilla_suite seamonkey thunderbird
|
Fixed in: Firefox 1.5
Firefox 1.0.8
Thunderbird 1.5
Thunderbird 1.0.8
SeaMonkey 1.0
Mozilla Suite 1.7.13
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-1735
|
2018-10-19 01:35 |
2006-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342898
|
2.6 |
LOW
|
mozilla
|
firefox mozilla_suite seamonkey thunderbird
|
Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to trick users into downloading and saving an executable file via …
|
NVD-CWE-Other
|
CVE-2006-1736
|
2018-10-19 01:35 |
2006-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342899
|
2.6 |
LOW
|
mozilla
|
firefox mozilla_suite seamonkey thunderbird
|
Fixed in: Firefox 1.5
Firefox 1.0.8
SeaMonkey 1.0
Mozilla Suite 1.7.13
|
NVD-CWE-Other
|
CVE-2006-1736
|
2018-10-19 01:35 |
2006-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342900
|
9.3 |
HIGH
|
mozilla
|
firefox mozilla_suite seamonkey thunderbird
|
Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (…
|
CWE-189
Numeric Errors
|
CVE-2006-1737
|
2018-10-19 01:35 |
2006-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|