|
343051
|
5.0 |
MEDIUM
|
skull-splitter
|
download_counter_wallpaper
|
SQL injection vulnerability in count.php in Skull-Splitter PHP Downloadcounter for Wallpapers 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) count_fieldname, (2) url_fieldn…
|
NVD-CWE-Other
|
CVE-2006-1328
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343052
|
7.5 |
HIGH
|
phpwebsite
|
phpwebsite
|
Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid parameter to (1) friend.php or (2) article.php.
|
CWE-89
SQL Injection
|
CVE-2006-1330
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343053
|
6.4 |
MEDIUM
|
maian_script_world
|
maian_weblog
|
Multiple SQL injection vulnerabilities in Maian Weblog 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) entry and (2) email parameters to (a) print.php and (b) mail.php.
|
NVD-CWE-Other
|
CVE-2006-1334
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343054
|
5.0 |
MEDIUM
|
extcalendar
|
extcalendar
|
Cross-site scripting vulnerability in calendar.php in ExtCalendar 1.0 and possibly other versions before 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) year, (2) month…
|
NVD-CWE-Other
|
CVE-2006-1336
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343055
|
5.0 |
MEDIUM
|
extcalendar
|
extcalendar
|
This issue is reportedly addressed in ExtCalendar 2.0. Symantec has not confirmed this fix. Affected users are advised to contact the vendor for further information.
|
NVD-CWE-Other
|
CVE-2006-1336
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343056
|
5.0 |
MEDIUM
|
cutephp
|
cutenews
|
Directory traversal vulnerability in inc/functions.inc.php in CuteNews 1.4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to include arbitrary files via a ..…
|
NVD-CWE-Other
|
CVE-2006-1339
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343057
|
5.0 |
MEDIUM
|
cutephp
|
cutenews
|
CuteNews 1.4.1 and possibly other versions allows remote attackers to obtain the installation path via unspecified vectors involving an invalid file path.
|
NVD-CWE-Other
|
CVE-2006-1340
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343058
|
5.0 |
MEDIUM
|
cutephp
|
cutenews
|
Successful exploitation requires that the "register_globals" parameter is enabled.
|
NVD-CWE-Other
|
CVE-2006-1340
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343059
|
7.5 |
HIGH
|
maian_events
|
maian_events
|
SQL injection vulnerability in events.php in Maian Events 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters.
|
NVD-CWE-Other
|
CVE-2006-1341
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343060
|
4.3 |
MEDIUM
|
verisign
|
mpki
|
Cross-site scripting (XSS) vulnerability in VeriSign haydn.exe, as used in Managed PKI (MPKI) 6.0, allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the VHTML_FIL…
|
NVD-CWE-Other
|
CVE-2006-1344
|
2018-10-19 01:32 |
2006-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343061
|
5.0 |
MEDIUM
|
mybulletinboard
|
mybulletinboard
|
polls.php in MyBB (aka MyBulletinBoard) 1.10 allows remote attackers to obtain sensitive information via a vote action with an "option[]=null" parameter value, which reveals the path in an error mess…
|
NVD-CWE-Other
|
CVE-2006-1345
|
2018-10-19 01:32 |
2006-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343062
|
4.3 |
MEDIUM
|
musicbox
|
musicbox
|
Multiple cross-site scripting (XSS) vulnerabilities in Musicbox 2.3 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) id and (2) type and (3) show parameters in a top a…
|
NVD-CWE-Other
|
CVE-2006-1349
|
2018-10-19 01:32 |
2006-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343063
|
7.5 |
HIGH
|
articlesone
|
99articles_directory
|
PHP remote file include vulnerability in index.php in 99Articles.com (aka ArticlesOne.com) Free articles directory allows remote attackers to include and execute arbitrary PHP code via a URL in the p…
|
NVD-CWE-Other
|
CVE-2006-1350
|
2018-10-19 01:32 |
2006-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343064
|
7.5 |
HIGH
|
aspportal
|
aspportal
|
Multiple SQL injection vulnerabilities in ASPPortal 3.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the downloadid parameter in download_click.asp and (2) content_I…
|
NVD-CWE-Other
|
CVE-2006-1353
|
2018-10-19 01:32 |
2006-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343065
|
4.3 |
MEDIUM
|
f5
|
firepass_4100
|
Cross-site scripting (XSS) vulnerability in my.support.php3 in F5 Firepass 4100 SSL VPN 5.4.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.
|
NVD-CWE-Other
|
CVE-2006-1357
|
2018-10-19 01:32 |
2006-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343066
|
7.5 |
HIGH
|
musicbox
|
musicbox
|
Multiple SQL injection vulnerabilities in MusicBox 2.3 Beta 2 allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) type, or (3) show parameter to (a) index.php; or the (4) mes…
|
CWE-89
SQL Injection
|
CVE-2006-1360
|
2018-10-19 01:32 |
2006-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343067
|
7.5 |
HIGH
|
mini-nuke
|
mini-nuke_cms
|
Multiple SQL injection vulnerabilities in Mini-Nuke CMS System 1.8.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter in (a) members.asp, the (2) catid p…
|
NVD-CWE-Other
|
CVE-2006-1362
|
2018-10-19 01:32 |
2006-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343068
|
7.5 |
HIGH
Network
|
microsoft
|
asp.net
|
Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2006-1364
|
2018-10-19 01:32 |
2006-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343069
|
4.3 |
MEDIUM
|
php_live
|
php_live
|
Cross-site scripting (XSS) vulnerability in status_image.php in PHP Live! 3.0 allows remote attackers to inject arbitrary web script or HTML via the base_url parameter.
|
NVD-CWE-Other
|
CVE-2006-1373
|
2018-10-19 01:32 |
2006-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343070
|
4.9 |
MEDIUM
|
counterpane
|
password_safe
|
PasswordSafe 3.0 beta, when running on Windows before XP, uses a weak random number generator (C++ rand function) during generation of the database encryption key, which makes it easier for attackers…
|
NVD-CWE-Other
|
CVE-2006-1378
|
2018-10-19 01:32 |
2006-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343071
|
4.9 |
MEDIUM
|
counterpane
|
password_safe
|
This vulnerability exists only in Windows OS environments before XP. For some reason it would not let me notate that in the "vulnerable software" section.
|
NVD-CWE-Other
|
CVE-2006-1378
|
2018-10-19 01:32 |
2006-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343072
|
7.5 |
HIGH
|
jelsoft
|
impex
|
PHP remote file inclusion vulnerability in impex/ImpExData.php in vBulletin ImpEx module 1.74, when register_globals is disabled, allows remote attackers to include arbitrary files via the systempath…
|
NVD-CWE-Other
|
CVE-2006-1382
|
2018-10-19 01:32 |
2006-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343073
|
5.1 |
MEDIUM
|
kismac
|
kismac
|
Stack-based buffer overflow in the parseTaggedData function in WavePacket.mm in KisMAC R54 through R73p allows remote attackers to execute arbitrary code via multiple SSIDs in a Cisco vendor tag in a…
|
NVD-CWE-Other
|
CVE-2006-1385
|
2018-10-19 01:32 |
2006-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343074
|
5.1 |
MEDIUM
|
kismac
|
kismac
|
Update to version R73p.
|
NVD-CWE-Other
|
CVE-2006-1385
|
2018-10-19 01:32 |
2006-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343075
|
4.6 |
MEDIUM
|
gentoo
|
linux
|
The configuration of NetHack 3.4.3-r1 and earlier, Falcon's Eye 1.9.4a and earlier, and Slash'EM 0.0.760 and earlier on Gentoo Linux allows local users in the games group to modify saved games files …
|
NVD-CWE-Other
|
CVE-2006-1390
|
2018-10-19 01:32 |
2006-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343076
|
4.6 |
MEDIUM
|
gentoo
|
linux
|
This vulnerability applies only to the following games/versions:
1) NetHack 3.4.3-r1 and previous
2) Falcon's Eye 1.9.4a and previous
3) Slash'EM 0.0.760 and previous
|
NVD-CWE-Other
|
CVE-2006-1390
|
2018-10-19 01:32 |
2006-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343077
|
5.0 |
MEDIUM
|
pablo_software_solutions
|
baby_asp_web_server quick_and_easy_web_server
|
The (a) Quick 'n Easy Web Server before 3.1.1 and (b) Baby ASP Web Server 2.7.2 allows remote attackers to obtain the source code of ASP files via (1) . (dot) and (2) space characters in the extensio…
|
NVD-CWE-Other
|
CVE-2006-1391
|
2018-10-19 01:32 |
2006-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343078
|
4.3 |
MEDIUM
|
phpadsnew phppgads
|
phpadsnew phppgads
|
Multiple cross-site scripting (XSS) vulnerabilities in (a) phpAdsNew and (b) phpPgAds before 2.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) certain parameters to the …
|
NVD-CWE-Other
|
CVE-2006-1397
|
2018-10-19 01:32 |
2006-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343079
|
4.3 |
MEDIUM
|
sixal
|
g-book
|
Cross-site scripting (XSS) vulnerability in guestbook.php in G-Book 1.0 allows remote attackers to inject arbitrary web script or HTML via the g_message parameter.
|
NVD-CWE-Other
|
CVE-2006-1398
|
2018-10-19 01:32 |
2006-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343080
|
5.0 |
MEDIUM
|
tft_gallery
|
tft_gallery
|
TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin password file and obtain password hashes via a d…
|
NVD-CWE-Other
|
CVE-2006-1412
|
2018-10-19 01:32 |
2006-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343081
|
5.0 |
MEDIUM
|
nuked-klan
|
nuked-klan
|
SQL injection vulnerability in the Calendar module in nuked-klan 1.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter to index.php.
|
NVD-CWE-Other
|
CVE-2006-1419
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343082
|
5.0 |
MEDIUM
|
arabless
|
saphplesson
|
SQL injection vulnerability in print.php in SaphpLesson 2.0 allows remote attackers to execute arbitrary SQL commands via the lessid parameter.
|
NVD-CWE-Other
|
CVE-2006-1420
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343083
|
5.1 |
MEDIUM
|
arthur_konze_webdesign
|
akocomment
|
Multiple SQL injection vulnerabilities in akocomment.php in AkoComment 2.0 module for Mambo, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) acnam…
|
NVD-CWE-Other
|
CVE-2006-1421
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343084
|
5.1 |
MEDIUM
|
arthur_konze_webdesign
|
akocomment
|
In order to exploit this vulnerability, the 'magic_quotes_gpc' parameter must be disabled.
|
NVD-CWE-Other
|
CVE-2006-1421
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343085
|
5.0 |
MEDIUM
|
ubbcentral
|
ubb.threads
|
SQL injection vulnerability in showflat.php in UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2, and earlier, allows remote attackers to execute arbitrary SQL commands via the Number parameter.
|
CWE-89
SQL Injection
|
CVE-2006-1423
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343086
|
4.3 |
MEDIUM
|
phpmyfamily
|
phpmyfamily
|
Cross-site scripting (XSS) vulnerability in track.php in phpmyfamily 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.
|
NVD-CWE-Other
|
CVE-2006-1425
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343087
|
7.5 |
HIGH
|
pixel_motion
|
pixel_motion_blog
|
Multiple SQL injection vulnerabilities in Pixel Motion Blog allow remote attackers to execute arbitrary SQL commands via the (1) date parameter in index.php or bypass authentication via the (2) passw…
|
NVD-CWE-Other
|
CVE-2006-1426
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343088
|
5.1 |
MEDIUM
|
apple
|
quicktime
|
Stack-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickDraw PICT image format file containing malformed font information.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-1453
|
2018-10-19 01:32 |
2006-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343089
|
5.1 |
MEDIUM
|
apple
|
quicktime
|
Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickDraw PICT image format file with malformed image data.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-1454
|
2018-10-19 01:32 |
2006-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343090
|
5.1 |
MEDIUM
|
apple
|
quicktime
|
Multiple integer overflows in Apple QuickTime before 7.1 allow remote attackers to cause a denial of service or execute arbitrary code via a crafted QuickTime movie (.MOV).
|
CWE-189
Numeric Errors
|
CVE-2006-1459
|
2018-10-19 01:32 |
2006-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343091
|
5.1 |
MEDIUM
|
apple
|
quicktime
|
Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime movie (.MOV), as demonstrated via a large size for a udta Atom.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-1460
|
2018-10-19 01:32 |
2006-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343092
|
5.1 |
MEDIUM
|
apple
|
quicktime
|
Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime Flash (SWF) file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-1461
|
2018-10-19 01:32 |
2006-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343093
|
5.1 |
MEDIUM
|
apple
|
quicktime
|
Multiple integer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime H.264 (M4V) video format file.
|
CWE-189
Numeric Errors
|
CVE-2006-1462
|
2018-10-19 01:32 |
2006-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343094
|
5.1 |
MEDIUM
|
apple
|
quicktime
|
Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a H.264 (M4V) video format file with a certain modified size value.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-1463
|
2018-10-19 01:32 |
2006-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343095
|
5.1 |
MEDIUM
|
apple
|
quicktime
|
Buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickTime MPEG4 (M4P) video format file.
|
NVD-CWE-Other
|
CVE-2006-1464
|
2018-10-19 01:32 |
2006-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343096
|
5.1 |
MEDIUM
|
apple
|
quicktime
|
Buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickTime AVI video format file.
|
NVD-CWE-Other
|
CVE-2006-1465
|
2018-10-19 01:32 |
2006-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343097
|
5.1 |
MEDIUM
|
apple
|
itunes
|
Integer overflow in the AAC file parsing code in Apple iTunes before 6.0.5 on Mac OS X 10.2.8 or later, and Windows XP and 2000, allows remote user-assisted attackers to execute arbitrary code via an…
|
CWE-189
Numeric Errors
|
CVE-2006-1467
|
2018-10-19 01:32 |
2006-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343098
|
4.6 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that are not properly handl…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2006-1471
|
2018-10-19 01:32 |
2006-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343099
|
4.3 |
MEDIUM
|
raindance
|
web_conferencing_pro
|
Cross-site scripting (XSS) vulnerability in the "failed" functionality in Raindance Web Conferencing Pro allows remote attackers to inject arbitrary web script or HTML via the browser parameter.
|
NVD-CWE-Other
|
CVE-2006-1474
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343100
|
2.1 |
LOW
|
microsoft
|
windows_xp
|
Windows Firewall in Microsoft Windows XP SP2 does not produce application alerts when an application is executed using the NTFS Alternate Data Streams (ADS) filename:stream syntax, which might allow …
|
NVD-CWE-Other
|
CVE-2006-1475
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|