|
343101
|
2.6 |
LOW
|
microsoft
|
windows_xp
|
Windows Firewall in Microsoft Windows XP SP2 produces incorrect application block alerts when the application filename is ".exe" (with no characters before the "."), which might allow local user-assi…
|
NVD-CWE-Other
|
CVE-2006-1476
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343102
|
7.5 |
HIGH
|
turnkey_web_tools
|
php_live_helper
|
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Live Helper 1.8 allow remote attackers to include and execute arbitrary PHP code via the abs_path parameter in (1) initiate…
|
NVD-CWE-Other
|
CVE-2006-1477
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343103
|
7.5 |
HIGH
|
turnkey_web_tools
|
php_live_helper
|
This vulnerability may affect all versions prior to 1.8 as well.
|
NVD-CWE-Other
|
CVE-2006-1477
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343104
|
7.5 |
HIGH
|
turnkey_web_tools
|
php_live_helper
|
Directory traversal vulnerability in (1) initiate.php and (2) possibly other PHP scripts in Turnkey Web Tools PHP Live Helper 1.8, and possibly later versions, allows remote authenticated users to in…
|
NVD-CWE-Other
|
CVE-2006-1478
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343105
|
7.5 |
HIGH
|
turnkey_web_tools
|
php_live_helper
|
This vulnerability may affect all other versions of Turnkey Web Tools, PHP Live Helper.
|
NVD-CWE-Other
|
CVE-2006-1478
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343106
|
4.3 |
MEDIUM
|
conftool
|
conftool
|
Cross-site scripting (XSS) vulnerability in index.php in ConfTool 1.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
NVD-CWE-Other
|
CVE-2006-1482
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343107
|
5.0 |
MEDIUM
|
desiderata_software
|
blazix_web_server
|
Blazix Web Server before 1.2.6, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot), (2) space, and (3) slash characters in the extension of a URL.
|
NVD-CWE-Other
|
CVE-2006-1483
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343108
|
7.2 |
HIGH
|
kye
|
genius_videocam_nb
|
Genius VideoCAM NB Driver does not drop privileges when saving files, which allows local users to gain privileges by opening arbitrary files via the "save as" dialog.
|
NVD-CWE-Other
|
CVE-2006-1484
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343109
|
7.5 |
HIGH
|
source_workshop
|
vcounter
|
SQL injection vulnerability in vCounter.php in vCounter 1.0 allows remote attackers to execute arbitrary SQL commands via the URI (_SERVER[REQUEST_URI] variable).
|
NVD-CWE-Other
|
CVE-2006-1499
|
2018-10-19 01:32 |
2006-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343110
|
5.1 |
MEDIUM
|
mplayer
|
mplayer
|
Multiple integer overflows in MPlayer 1.0pre7try2 allow remote attackers to cause a denial of service and trigger heap-based buffer overflows via (1) a certain ASF file handled by asfheader.c that ca…
|
NVD-CWE-Other
|
CVE-2006-1502
|
2018-10-19 01:32 |
2006-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343111
|
5.1 |
MEDIUM
|
vwar
|
virtual_war
|
PHP remote file inclusion vulnerability in includes/functions_install.php in Virtual War (VWar) 1.5.0 R11 and earlier allows remote attackers to include and execute arbitrary PHP code via a URL in th…
|
CWE-94
Code Injection
|
CVE-2006-1503
|
2018-10-19 01:32 |
2006-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343112
|
5.1 |
MEDIUM
|
vwar
|
virtual_war
|
Successful exploitation requires that the "register_globals" parameter is enabled.
|
CWE-94
Code Injection
|
CVE-2006-1503
|
2018-10-19 01:32 |
2006-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343113
|
5.1 |
MEDIUM
|
arab_portal
|
arab_portal
|
Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0 (aka Arab Dynamic Portal or ADP) stable allow remote attackers to inject arbitrary web script or HTML via the title parameter in…
|
NVD-CWE-Other
|
CVE-2006-1504
|
2018-10-19 01:32 |
2006-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343114
|
5.1 |
MEDIUM
|
arab_portal
|
arab_portal
|
Successful exploitation requires that the "register_globals" parameter is enabled.
|
NVD-CWE-Other
|
CVE-2006-1504
|
2018-10-19 01:32 |
2006-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343115
|
6.8 |
MEDIUM
|
phpkit
|
phpkit
|
Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the error parameter to include.php, possibly due to a problem in login/log…
|
NVD-CWE-Other
|
CVE-2006-1507
|
2018-10-19 01:32 |
2006-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343116
|
5.0 |
MEDIUM
|
m_phorum
|
m_phorum
|
Cross-site scripting vulnerability in index.php in M-Phorum 0.2 allows remote attackers to inject arbitrary web script or HTML via the go parameter.
|
NVD-CWE-Other
|
CVE-2006-1151
|
2018-10-19 01:31 |
2006-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343117
|
4.3 |
MEDIUM
|
adp
|
adp_forum
|
Cross-site scripting (XSS) vulnerability in Vz Scripts ADP Forum 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the Subject field (possibly messaggio parameter) …
|
NVD-CWE-Other
|
CVE-2006-1157
|
2018-10-19 01:31 |
2006-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343118
|
7.8 |
HIGH
|
kerio
|
kerio_mailserver
|
Kerio MailServer before 6.1.3 Patch 1 allows remote attackers to cause a denial of service (application crash) via a crafted IMAP LOGIN command.
|
NVD-CWE-Other
|
CVE-2006-1158
|
2018-10-19 01:31 |
2006-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343119
|
7.8 |
HIGH
|
efs_software
|
efs_web_server
|
Format string vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifi…
|
NVD-CWE-Other
|
CVE-2006-1159
|
2018-10-19 01:31 |
2006-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343120
|
4.3 |
MEDIUM
|
efs_software
|
efs_web_server
|
Cross-site scripting (XSS) vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote attackers to inject arbitrary web script or HTML via the Description field in creating a folder or upl…
|
NVD-CWE-Other
|
CVE-2006-1160
|
2018-10-19 01:31 |
2006-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343121
|
6.5 |
MEDIUM
|
efs_software
|
efs_web_server
|
Absolute path traversal vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote registered users to execute arbitrary code by uploading a malicious file to the Windows startup folder.
|
NVD-CWE-Other
|
CVE-2006-1161
|
2018-10-19 01:31 |
2006-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343122
|
5.0 |
MEDIUM
|
tdc
|
cryptomathic_cenroll_activex_control
|
Stack-based buffer overflow in the createPKCS10 function in Cryptomathic Cenroll ActiveX Control 1.1.0.0 allows remote attackers to execute arbitrary code via vectors related to the TDC Digital signa…
|
NVD-CWE-Other
|
CVE-2006-1172
|
2018-10-19 01:31 |
2006-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343123
|
5.0 |
MEDIUM
|
sendmail
|
sendmail
|
Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for perf…
|
CWE-399
Resource Management Errors
|
CVE-2006-1173
|
2018-10-19 01:31 |
2006-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343124
|
2.6 |
LOW
|
adobe
|
document_server graphics_server
|
Adobe Graphics Server 2.0 and 2.1 (formerly AlterCast) and Adobe Document Server (ADS) 5.0 and 6.0 allows local users to read files with certain extensions or overwrite arbitrary files and execute co…
|
NVD-CWE-Other
|
CVE-2006-1182
|
2018-10-19 01:31 |
2006-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343125
|
5.0 |
MEDIUM
|
enet
|
enet_library
|
Integer signedness error in the enet_protocol_handle_incoming_commands function in protocol.c for ENet library CVS version Jul 2005 and earlier, as used in products including (1) Cube, (2) Sauerbrate…
|
NVD-CWE-Other
|
CVE-2006-1194
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343126
|
5.0 |
MEDIUM
|
enet
|
enet_library
|
The enet_protocol_handle_send_fragment function in protocol.c for ENet library CVS version Jul 2005 and earlier, as used in products including (1) Cube, (2) Sauerbraten, and (3) Duke3d_w32, allows re…
|
NVD-CWE-Other
|
CVE-2006-1195
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343127
|
7.2 |
HIGH
|
macrovision
|
safedisc
|
SafeDisc installs the driver service for the secdrv.sys driver with insecure permissions, which allows local users to gain privileges by changing the configuration to reference a malicious program.
|
NVD-CWE-Other
|
CVE-2006-1197
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343128
|
3.7 |
LOW
|
comvigo
|
im_lock
|
Comvigo IM Lock 2006 uses a simple substitution cipher to encrypt a password stored in the msnvs\prc registry value, for which all users have Read permission, which allows local users to bypass the p…
|
NVD-CWE-Other
|
CVE-2006-1198
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343129
|
4.3 |
MEDIUM
|
daverave
|
link_bank
|
Cross-site scripting (XSS) vulnerability in iframe.php in daverave Link Bank allows remote attackers to inject arbitrary web script or HTML via the site parameter.
|
NVD-CWE-Other
|
CVE-2006-1199
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343130
|
7.5 |
HIGH
|
daverave
|
link_bank
|
Direct static code injection vulnerability in add_link.txt in daverave Link Bank allows remote attackers to execute arbitrary PHP code via the url_name parameter, which is not sanitized before being …
|
NVD-CWE-Other
|
CVE-2006-1200
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343131
|
5.0 |
MEDIUM
|
eschew.net
|
phpbannerexchange
|
Directory traversal vulnerability in resetpw.php in eschew.net phpBannerExchange 2.0 and earlier, and other versions before 2.0 Update 5, allows remote attackers to read arbitrary files via a .. (dot…
|
NVD-CWE-Other
|
CVE-2006-1201
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343132
|
7.5 |
HIGH
|
txtforum
|
txtforum
|
PHP remote file include vulnerability in common.php in txtForum 1.0.4-dev and earlier allows remote attackers to include and execute arbitrary PHP code via a URL in the skin parameter to login.php, a…
|
NVD-CWE-Other
|
CVE-2006-1203
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343133
|
7.5 |
HIGH
|
micromuse
|
netcool_neusecure
|
The web interface for IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 includes the MySQL database username and password in cleartext in body.phtml, which allows remote attackers to gain privileges by …
|
NVD-CWE-Other
|
CVE-2006-1210
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343134
|
7.5 |
HIGH
|
micromuse
|
netcool_neusecure
|
IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 configures a MySQL database to allow connections from any source IP address with the ns database account, which allows remote attackers to bypass the Ne…
|
NVD-CWE-Other
|
CVE-2006-1211
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343135
|
7.5 |
HIGH
|
corenews
|
corenews
|
Unspecified vulnerability in index.php in Core CoreNews 2.0.1 allows remote attackers to execute arbitrary commands via the page parameter, possibly due to a PHP remote file include vulnerability. N…
|
NVD-CWE-Other
|
CVE-2006-1212
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343136
|
4.3 |
MEDIUM
|
txtforum
|
txtforum
|
Multiple cross-site scripting (XSS) vulnerabilities in txtForum 1.0.4-dev and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prev, (2) next, and (3) rand5 parameter…
|
NVD-CWE-Other
|
CVE-2006-1204
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343137
|
4.3 |
MEDIUM
|
mywebland
|
mybloggie
|
Multiple cross-site scripting (XSS) vulnerabilities in myWebland myBloggie 2.1.3 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) confirmredirect and (2) pos…
|
NVD-CWE-Other
|
CVE-2006-1205
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343138
|
7.5 |
HIGH
|
jiro
|
banner_system
|
JiRo's Banner System Experience and Professional 1.0 and earlier allows remote attackers to bypass access restrictions and gain privileges via a direct request to certain scripts in the files directo…
|
NVD-CWE-Other
|
CVE-2006-1213
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343139
|
5.0 |
MEDIUM
|
unreal
|
unrealircd
|
UnrealIRCd 3.2.3 allows remote attackers to cause an unspecified denial of service by causing a linked server to send malformed TKL Q:Line commands, as demonstrated by "TKL - q\x08Q *\x08PoC."
|
NVD-CWE-Other
|
CVE-2006-1214
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343140
|
7.5 |
HIGH
|
dsportal
|
dspoll
|
SQL injection vulnerability in DSPoll 1.1 allows remote attackers to execute arbitrary SQL commands via the pollid parameter to (1) results.php, (2) topolls.php, (3) pollit.php.
|
NVD-CWE-Other
|
CVE-2006-1217
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343141
|
4.3 |
MEDIUM
|
zeroboard
|
zeroboard
|
Multiple cross-site scripting (XSS) vulnerabilities in zeroboard 4.1 pl7 allows allow remote attackers to inject arbitrary web script or HTML via the (1) memo box title, (2) user email, and (3) homep…
|
NVD-CWE-Other
|
CVE-2006-1222
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343142
|
4.3 |
MEDIUM
|
jupiter_cms
|
jupiter_cms
|
Cross-site scripting (XSS) vulnerability in Jupiter Content Manager 1.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in the image BBcode tag.
|
NVD-CWE-Other
|
CVE-2006-1223
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343143
|
2.6 |
LOW
|
guppy
|
guppy
|
Directory traversal vulnerability in dwnld.php in GuppY 4.5.11 allows remote attackers to overwrite arbitrary files via a "%2E." (mixed encoding) in the pg parameter.
|
NVD-CWE-Other
|
CVE-2006-1224
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343144
|
5.0 |
MEDIUM
|
drupal
|
drupal
|
CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.
|
NVD-CWE-Other
|
CVE-2006-1225
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343145
|
4.3 |
MEDIUM
|
drupal
|
drupal
|
Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-1226
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343146
|
6.2 |
MEDIUM
|
zonelabs
|
zonealarm_security_suite
|
Untrusted search path vulnerability in the TrueVector service (VSMON.exe) in Zone Labs ZoneAlarm 6.x and Integrity does not search ZoneAlarm's own folders before other folders that are specified in a…
|
NVD-CWE-Other
|
CVE-2006-1221
|
2018-10-19 01:31 |
2006-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343147
|
4.6 |
MEDIUM
|
drupal
|
drupal
|
Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8, when menu.module is used to create a menu item, does not implement access control for the page that is referenced, which might allow remote attackers…
|
NVD-CWE-Other
|
CVE-2006-1227
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343148
|
5.1 |
MEDIUM
|
drupal
|
drupal
|
Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.
|
CWE-287
Improper Authentication
|
CVE-2006-1228
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343149
|
5.1 |
MEDIUM
|
drupal
|
drupal
|
This vulnerability affects Drupal versions 4.6.x before 4.6.6, as well as versions 4.5.x before 4.5.8
|
CWE-287
Improper Authentication
|
CVE-2006-1228
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343150
|
4.3 |
MEDIUM
|
belchior_foundry
|
vcard
|
Multiple cross-site scripting (XSS) vulnerabilities in create.php in vCard 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) card_id, (2) uploaded, (3) card_fontsize, or (…
|
CWE-79
Cross-site Scripting
|
CVE-2006-1230
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|