|
343151
|
5.0 |
MEDIUM
|
softbb
|
softbb
|
index.php in SoftBB 0.1, and possibly earlier, allows remote attackers to obtain the installation path via a null or invalid page[] parameter.
|
NVD-CWE-Other
|
CVE-2006-4633
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343152
|
4.3 |
MEDIUM
|
vbzoom
|
vbzoom
|
Cross-site scripting (XSS) vulnerability in index.php in VBZooM allows remote attackers to inject arbitrary web script or HTML via the UserID parameter, a different vector than CVE-2006-1133 and CVE-…
|
NVD-CWE-Other
|
CVE-2006-4634
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343153
|
5.1 |
MEDIUM
|
acgv_news
|
acgv_news
|
Multiple PHP remote file inclusion vulnerabilities in ACGV News 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the PathNews parameter in (1) header.php or (2) news.php. NOTE…
|
CWE-94
Code Injection
|
CVE-2006-4637
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343154
|
5.1 |
MEDIUM
|
acgv_news
|
acgv_news
|
Successful exploitation requires that "register_globals" is enabled.
|
CWE-94
Code Injection
|
CVE-2006-4637
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343155
|
5.1 |
MEDIUM
|
c-news.fr
|
c-news
|
Multiple PHP remote file inclusion vulnerabilities in C-News.fr C-News 1.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path …
|
CWE-94
Code Injection
|
CVE-2006-4639
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343156
|
1.7 |
LOW
|
auditwizard
|
auditwizard
|
AuditWizard 6.3.2, when using "Remote Audit," logs the administrator password in plaintext to LaytonCmdSvc.log, which allows local users to obtain sensitive information by reading the file.
|
NVD-CWE-Other
|
CVE-2006-4642
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343157
|
7.5 |
HIGH
|
akarru
|
social_bookmarking_engine
|
PHP remote file inclusion vulnerability in akarru.gui/main_content.php in Akarru Social BookMarking Engine 0.4.3.34 and earlier, and possibly 0.4.4.120, allows remote attackers to execute arbitrary P…
|
NVD-CWE-Other
|
CVE-2006-4645
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343158
|
7.5 |
HIGH
|
bingo_news
|
bingo_news
|
PHP remote file inclusion vulnerability in bp_ncom.php in BinGo News (BP News) 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter.
|
NVD-CWE-Other
|
CVE-2006-4648
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343159
|
7.5 |
HIGH
|
bingo_news
|
bingo_news
|
PHP remote file inclusion vulnerability in bp_news.php in BinGo News (BP News) 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter.
|
CWE-94
Code Injection
|
CVE-2006-4649
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343160
|
2.6 |
LOW
|
cisco
|
ios
|
Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an in…
|
NVD-CWE-Other
|
CVE-2006-4650
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343161
|
5.0 |
MEDIUM
|
threesquared.net
|
php_download_script
|
Directory traversal vulnerability in download/index.php, and possibly download.php, in threesquared.net (aka Ben Speakman) Php download allows remote attackers to overwrite arbitrary local files via …
|
NVD-CWE-Other
|
CVE-2006-4651
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343162
|
7.5 |
HIGH
|
amazing_little_picture_poll amazing_little_poll
|
amazing_little_picture_poll amazing_little_poll
|
(1) Amazing Little Poll and (2) Amazing Little Picture Poll have a default password of "dsapoll", which allows remote attackers to create a new poll by entering default credentials via lp_admin.php.
|
NVD-CWE-Other
|
CVE-2006-4652
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343163
|
5.0 |
MEDIUM
|
amazing_little_picture_poll amazing_little_poll
|
amazing_little_picture_poll amazing_little_poll
|
(1) Amazing Little Poll and (2) Amazing Little Picture Poll store sensitive information under the web root with insufficient access control, which allows remote attackers to read the admin password v…
|
NVD-CWE-Other
|
CVE-2006-4653
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343164
|
5.1 |
MEDIUM
|
efs_software
|
easy_address_book_web_server
|
Format string vulnerability in Easy Address Book Web Server 1.2 allows remote attackers to cause a denial of service (crash) or "compromise the server" via encoded format string specifiers in the que…
|
NVD-CWE-Other
|
CVE-2006-4654
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343165
|
4.6 |
MEDIUM
|
sco sun
|
unixware solaris
|
Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and earlier, as used in SCO UnixWare 7.1.3 and Sun Solaris 8 through 10, allows local users to gain privil…
|
NVD-CWE-Other
|
CVE-2006-4655
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343166
|
7.5 |
HIGH
|
web-provence
|
sl_site
|
PHP remote file inclusion vulnerability in admin/editeur/spaw_control.class.php in Web Provence SL_Site 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the spaw_roo…
|
NVD-CWE-Other
|
CVE-2006-4656
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343167
|
7.2 |
HIGH
|
panda
|
panda_platinum_internet_security
|
Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 stores service executables under the product's installation directory with weak permissions, which allows local users to obtain LocalS…
|
NVD-CWE-Other
|
CVE-2006-4657
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343168
|
5.0 |
MEDIUM
|
panda
|
panda_platinum_internet_security
|
Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 uses sequential message numbers in generated URLs that are not filtered if the user replies to a message, which might allow remote att…
|
NVD-CWE-Other
|
CVE-2006-4658
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343169
|
5.0 |
MEDIUM
|
panda
|
panda_platinum_internet_security
|
The Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 uses predictable URLs for the spam classification of each message, which allows remote attackers to cause Panda to classify arbitr…
|
NVD-CWE-Other
|
CVE-2006-4659
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343170
|
5.8 |
MEDIUM
|
icq_inc
|
icq_toolbar
|
Multiple cross-site scripting (XSS) vulnerabilities in the RSS Feed module in AOL ICQ Toolbar 1.3 for Internet Explorer (toolbaru.dll) allow remote attackers to process arbitrary web script or HTML i…
|
NVD-CWE-Other
|
CVE-2006-4660
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343171
|
2.6 |
LOW
|
icq_inc
|
icq_toolbar
|
AOL ICQ Toolbar 1.3 for Internet Explorer (toolbaru.dll) does not properly validate the origin of the configuration web page (options2.html), which allows user-assisted remote attackers to provide a …
|
NVD-CWE-Other
|
CVE-2006-4661
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343172
|
7.5 |
HIGH
|
mirabilis
|
icq
|
Heap-based buffer overflow in the MCRegEx__Search function in AOL ICQ Pro 2003b Build 3916 and earlier allows remote attackers to execute arbitrary code via an inconsistent length field of a Message …
|
NVD-CWE-Other
|
CVE-2006-4662
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343173
|
4.3 |
MEDIUM
|
mkportal
|
mkportal
|
Cross-site scripting (XSS) vulnerability in index.php in MKPortal M1.1 Rc1 allows remote attackers to inject arbitrary web script or HTML via the ind parameter, possibly related to the PHP_SELF varia…
|
NVD-CWE-Other
|
CVE-2006-4665
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343174
|
7.5 |
HIGH
|
stefan_ernst
|
newsscript
|
Multiple PHP remote file inclusion vulnerabilities in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) ide parameter in (a) art…
|
CWE-94
Code Injection
|
CVE-2006-4666
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343175
|
7.5 |
HIGH
|
runcms
|
runcms
|
Multiple SQL injection vulnerabilities in RunCMS 1.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) uid parameter in (a) class/sessions.class.php, and the (2) timezone_offset …
|
NVD-CWE-Other
|
CVE-2006-4667
|
2018-10-18 06:38 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343176
|
7.5 |
HIGH
|
bigace
|
bigace
|
Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[_BIGACE][DIR][admin] parameter in (a) system/comma…
|
NVD-CWE-Other
|
CVE-2006-4423
|
2018-10-18 06:37 |
2006-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343177
|
5.1 |
MEDIUM
|
albert
|
albert-easysite
|
PHP remote file inclusion vulnerability in AES/modules/auth/phpsecurityadmin/include/logout.php in AlberT-EasySite (AES) 1.0a5 and earlier allows remote attackers to execute arbitrary PHP code via a …
|
NVD-CWE-Other
|
CVE-2006-4426
|
2018-10-18 06:37 |
2006-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343178
|
7.5 |
HIGH
|
zend
|
zend_platform
|
Multiple buffer overflows in the (a) Session Clustering Daemon and the (b) mod_cluster module in the Zend Platform 2.2.1 and earlier allow remote attackers to cause a denial of service (crash) or exe…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-4431
|
2018-10-18 06:37 |
2006-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343179
|
7.5 |
HIGH
|
zend
|
zend_platform
|
Directory traversal vulnerability in Zend Platform 2.2.1 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the final component of the PHP session identif…
|
NVD-CWE-Other
|
CVE-2006-4432
|
2018-10-18 06:37 |
2006-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343180
|
7.5 |
HIGH
|
venture_nine
|
tagger_le
|
Eval injection vulnerability in Tagger LE allows remote attackers to execute arbitrary PHP code via the query string in (1) tags.php, (2) sign.php, and (3) admin/index.php.
|
NVD-CWE-Other
|
CVE-2006-4437
|
2018-10-18 06:37 |
2006-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343181
|
7.5 |
HIGH
|
alstrasoft
|
video_share_enterprise
|
PHP remote file inclusion vulnerability in myajaxphp.php in AlstraSoft Video Share Enterprise allows remote attackers to execute arbitrary PHP code via a URL in the config[BASE_DIR] parameter.
|
NVD-CWE-Other
|
CVE-2006-4443
|
2018-10-18 06:37 |
2006-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343182
|
5.0 |
MEDIUM
|
microsoft
|
ie
|
Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service and possibly execute arb…
|
NVD-CWE-Other
|
CVE-2006-4446
|
2018-10-18 06:37 |
2006-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343183
|
5.1 |
MEDIUM
|
interact_learning_community_environment
|
interact
|
Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[BASE_PATH] param…
|
NVD-CWE-Other
|
CVE-2006-4448
|
2018-10-18 06:37 |
2006-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343184
|
5.1 |
MEDIUM
|
mybulletinboard
|
mybulletinboard
|
Cross-site scripting (XSS) vulnerability in attachment.php in MyBulletinBoard (MyBB) 1.1.7 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via a GIF image t…
|
NVD-CWE-Other
|
CVE-2006-4449
|
2018-10-18 06:37 |
2006-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343185
|
7.5 |
HIGH
|
digi_international_inc
|
anywhere_usb5
|
Integer overflow in AnywhereUSB/5 1.80.00 allows local users to cause a denial of service (crash) via a 1 byte header size specified in the USB string descriptor.
|
NVD-CWE-Other
|
CVE-2006-4459
|
2018-10-18 06:37 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343186
|
7.5 |
HIGH
|
gonafish.com
|
linkscaffe
|
Gonafish.com LinksCaffe 2.0 and 3.0 do not properly restrict access to administrator functions, which allows remote attackers to gain full administration rights via a direct request to Admin/admin195…
|
NVD-CWE-Other
|
CVE-2006-4462
|
2018-10-18 06:37 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343187
|
7.5 |
HIGH
|
jetstat.com
|
js_asp_faq_manager
|
SQL injection vulnerability in the administrator control panel in Jetstat.com JS ASP Faq Manager 1.10 allows remote attackers to execute arbitrary SQL commands via the pwd parameter (aka the Password…
|
NVD-CWE-Other
|
CVE-2006-4463
|
2018-10-18 06:37 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343188
|
5.0 |
MEDIUM
|
nokia
|
symbian
|
The Nokia Browser, possibly Nokia Symbian 60 Browser 3rd edition, allows remote attackers to cause a denial of service (crash) via JavaScript that constructs a large Unicode string.
|
NVD-CWE-Other
|
CVE-2006-4464
|
2018-10-18 06:37 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343189
|
7.5 |
HIGH
|
simple_machines
|
simple_machines_forum
|
Simple Machines Forum (SMF) 1.1RCx before 1.1RC3, and 1.0.x before 1.0.8, does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric para…
|
NVD-CWE-Other
|
CVE-2006-4467
|
2018-10-18 06:37 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343190
|
7.5 |
HIGH
|
visualshapers
|
ezcontents
|
SQL injection vulnerability in headeruserdata.php in Visual Shapers ezContents 2.0.3 allows remote attackers to execute arbitrary SQL commands via the groupname parameter.
|
NVD-CWE-Other
|
CVE-2006-4478
|
2018-10-18 06:37 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343191
|
7.5 |
HIGH
|
visualshapers
|
ezcontents
|
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute arbitrary PHP code via an empty GLOBALS[rootdp] parameter and an ftps URL in th…
|
NVD-CWE-Other
|
CVE-2006-4477
|
2018-10-18 06:37 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343192
|
4.3 |
MEDIUM
|
visualshapers
|
ezcontents
|
Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the subgroupname parameter.
|
NVD-CWE-Other
|
CVE-2006-4479
|
2018-10-18 06:37 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343193
|
4.3 |
MEDIUM
|
nuked-klan
|
nuked-klan
|
Incomplete blacklist vulnerability in the nk_CSS function in nuked.php in Nuked-Klan 1.7 SP4.3 allows remote attackers to bypass anti-XSS features and inject arbitrary web script or HTML via JavaScri…
|
NVD-CWE-Other
|
CVE-2006-4480
|
2018-10-18 06:37 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343194
|
5.0 |
MEDIUM
|
duware
|
dupoll
|
DUware DUpoll 3.0 and 3.1 stores _private/Dupoll.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and …
|
NVD-CWE-Other
|
CVE-2006-4487
|
2018-10-18 06:37 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343195
|
7.5 |
HIGH
|
microsoft
|
visual_studio
|
Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Visual Studio 6.0 ActiveX COM Objects…
|
NVD-CWE-Other
|
CVE-2006-4494
|
2018-10-18 06:37 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343196
|
7.5 |
HIGH
|
microsoft
|
ie windows_2003_server
|
Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects incl…
|
NVD-CWE-Other
|
CVE-2006-4495
|
2018-10-18 06:37 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343197
|
4.3 |
MEDIUM
|
iwebnegar
|
iwebnegar
|
Cross-site scripting (XSS) vulnerability in comments.php in IwebNegar 1.1 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.
|
NVD-CWE-Other
|
CVE-2006-4496
|
2018-10-18 06:37 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343198
|
7.5 |
HIGH
|
iwebnegar
|
iwebnegar
|
SQL injection vulnerability in comments.php in IwebNegar 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2006-4497
|
2018-10-18 06:37 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343199
|
7.5 |
HIGH
|
phpalbum.net
|
phpalbum
|
PHP remote file inclusion vulnerability in sommaire_admin.php in PhpAlbum (mod_phpalbum) 2.15 for PortailPHP allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter, a…
|
NVD-CWE-Other
|
CVE-2006-4498
|
2018-10-18 06:37 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343200
|
4.3 |
MEDIUM
|
ztml
|
ezportal_ztml_cms
|
Cross-site scripting (XSS) vulnerability in index.php in ezPortal/ztml CMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) about, (2) again, (3) lastname, (4) email, (5…
|
NVD-CWE-Other
|
CVE-2006-4500
|
2018-10-18 06:37 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|