|
343201
|
7.5 |
HIGH
|
ageet
|
agephone
|
This vulnerability is addressed in the following product release:
AGEphone 1.40
|
NVD-CWE-Other
|
CVE-2006-4029
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343202
|
5.1 |
MEDIUM
|
lhaplus
|
lhaplus
|
Heap-based buffer overflow in Lhaplus.exe in Lhaplus 1.52, and possibly earlier versions, allows remote attackers to execute arbitrary code via an LZH archive with a long header, as specified by the …
|
NVD-CWE-Other
|
CVE-2006-4033
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343203
|
7.5 |
HIGH
|
moderngigabyte
|
modernbill
|
PHP remote file inclusion vulnerability in include/html/config.php in ModernGigabyte ModernBill 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the DIR parameter.
|
NVD-CWE-Other
|
CVE-2006-4034
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343204
|
7.5 |
HIGH
|
zonemetrics
|
zonex_publishers_gold_edition
|
PHP remote file inclusion vulnerability in includes/usercp_register.php in ZoneMetrics ZoneX Publishers Gold Edition 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL …
|
NVD-CWE-Other
|
CVE-2006-4036
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343205
|
4.3 |
MEDIUM
|
chaossoft
|
gaestechaos
|
Multiple cross-site scripting (XSS) vulnerabilities in eintragen.php in GaesteChaos 0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gastname or (2) gastwohno…
|
CWE-79
Cross-site Scripting
|
CVE-2006-4038
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343206
|
7.5 |
HIGH
|
chaossoft
|
gaestechaos
|
Multiple SQL injection vulnerabilities in eintragen.php in GaesteChaos 0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) gastname, (2) gastwohnort, or (3) gasteintr…
|
CWE-89
SQL Injection
|
CVE-2006-4039
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343207
|
7.5 |
HIGH
|
mywebland
|
mybloggie
|
Multiple SQL injection vulnerabilities in trackback.php in myWebland myBloggie 2.1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) title, (2) url, (3) excerpt, or (…
|
CWE-89
SQL Injection
|
CVE-2006-4042
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343208
|
5.0 |
MEDIUM
|
mywebland
|
mybloggie
|
index.php in myWebland myBloggie 2.1.4 and earlier allows remote attackers to obtain sensitive information via a query that only specifies the viewdate mode, which reveals the table prefix in a SQL e…
|
NVD-CWE-Other
|
CVE-2006-4043
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343209
|
7.5 |
HIGH
|
open_cubic_player
|
open_cubic_player
|
Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 and earlier for Windows, and 0.1.10_rc5 and earlier on Linux/BSD, allow remote attackers to execute arbitrary code via (1) a large…
|
NVD-CWE-Other
|
CVE-2006-4046
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343210
|
7.5 |
HIGH
|
david_walker
|
phpautomembersarea
|
PHP remote file inclusion vulnerability in auto_check_renewals.php in phpAutoMembersArea (phpAMA) 3.2.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the installed_co…
|
NVD-CWE-Other
|
CVE-2006-4050
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343211
|
7.5 |
HIGH
|
david_walker
|
phpautomembersarea
|
This vulnerability is addressed in the following product release:
David Walker, phpAutoMembersArea, 3.2.5
|
NVD-CWE-Other
|
CVE-2006-4050
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343212
|
7.5 |
HIGH
|
turnkey_web_tools
|
php_live_helper
|
PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter.
|
NVD-CWE-Other
|
CVE-2006-4051
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343213
|
7.5 |
HIGH
|
turnkey_web_tools
|
php_simple_shop
|
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Simple Shop 2.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1)…
|
NVD-CWE-Other
|
CVE-2006-4052
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343214
|
5.1 |
MEDIUM
|
ehmig
|
me_download_system
|
PHP remote file inclusion vulnerability in templates/header.php in ME Download System 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the Vb8878b936c2bd8ae0cab parameter.
|
NVD-CWE-Other
|
CVE-2006-4053
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343215
|
5.1 |
MEDIUM
|
ehmig
|
me_download_system
|
Successful exploitation requires that "register_globals" is enabled.
|
NVD-CWE-Other
|
CVE-2006-4053
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343216
|
7.5 |
HIGH
|
tsep
|
tsep
|
Multiple PHP remote file inclusion vulnerabilities in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the tsep_confi…
|
NVD-CWE-Other
|
CVE-2006-4055
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343217
|
7.5 |
HIGH
|
mitch_murray
|
eremove
|
Buffer overflow in the preview_create function in gui.cpp in Mitch Murray Eremove 1.4 allows remote attackers to cause a denial of service (application crash), and possibly execute arbitrary code, vi…
|
NVD-CWE-Other
|
CVE-2006-4057
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343218
|
6.8 |
MEDIUM
|
simplog
|
simplog
|
Cross-site scripting (XSS) vulnerability in archive.php in Simplog 0.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyw parameter when performing a search. N…
|
NVD-CWE-Other
|
CVE-2006-4058
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343219
|
7.5 |
HIGH
|
usolved
|
newsolved_lite
|
Multiple PHP remote file inclusion vulnerabilities in USOLVED NEWSolved Lite 1.9.2, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (…
|
NVD-CWE-Other
|
CVE-2006-4059
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343220
|
7.5 |
HIGH
|
web-scripts
|
visual_events_calendar
|
PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_dir parameter.
|
NVD-CWE-Other
|
CVE-2006-4060
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343221
|
7.5 |
HIGH
|
yenerturk
|
yenerturk_haber_script
|
SQL injection vulnerability in default.asp in YenerTurk Haber Script 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it was later reported repor…
|
CWE-89
SQL Injection
|
CVE-2006-4064
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343222
|
2.6 |
LOW
|
microsoft
|
windows_xp
|
The Graphical Device Interface Plus library (gdiplus.dll) in Microsoft Windows XP SP2 allows context-dependent attackers to cause a denial of service (application crash) via certain images that trigg…
|
NVD-CWE-Other
|
CVE-2006-4066
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343223
|
4.3 |
MEDIUM
|
ozjournals
|
ozjournals
|
Multiple cross-site scripting (XSS) vulnerabilities in Elaine Aquino Online Zone Journals (OZJournals) 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) m and (2) c parame…
|
NVD-CWE-Other
|
CVE-2006-4069
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343224
|
5.1 |
MEDIUM
|
imendio_planner
|
imendio_planner
|
Format string vulnerability in Imendio Planner 0.13 allows user-assisted attackers to execute arbitrary code via format string specifiers in a filename.
|
NVD-CWE-Other
|
CVE-2006-4070
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343225
|
2.6 |
LOW
|
microsoft
|
windows_2003_server windows_xp
|
Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to ca…
|
NVD-CWE-Other
|
CVE-2006-4071
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343226
|
7.5 |
HIGH
|
phpcc
|
phpcc
|
Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz phpCC Beta 4.2 allow remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter to (1) login.php, (2) reacti…
|
NVD-CWE-Other
|
CVE-2006-4073
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343227
|
5.1 |
MEDIUM
|
wim_fleischhauer
|
docpile_we
|
Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the INIT…
|
NVD-CWE-Other
|
CVE-2006-4075
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343228
|
5.1 |
MEDIUM
|
wim_fleischhauer
|
docpile_we
|
Successful exploitation requires that "register_globals" is enabled.
|
NVD-CWE-Other
|
CVE-2006-4075
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343229
|
7.5 |
HIGH
|
deluxebb
|
deluxebb
|
pm.php (aka the PM system) in DeluxeBB 1.08, and possibly earlier, allows remote attackers to bypass authentication by providing an arbitrary username in the membercookie cookie parameter.
|
NVD-CWE-Other
|
CVE-2006-4078
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343230
|
6.8 |
MEDIUM
|
deluxebb
|
deluxebb
|
Cross-site scripting (XSS) vulnerability in newpost.php in DeluxeBB 1.08, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the subject parameter (aka the topic…
|
NVD-CWE-Other
|
CVE-2006-4079
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343231
|
2.6 |
LOW
|
deluxebb
|
deluxebb
|
DeluxeBB 1.08, and possibly earlier, uses cookies that include the MD5 hash of a password, which allows remote attackers to gain privileges by sniffing or cross-site scripting (XSS) and conduct passw…
|
NVD-CWE-Other
|
CVE-2006-4080
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343232
|
7.5 |
HIGH
|
barracuda_networks
|
barracuda_spam_firewall
|
preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote attackers to execute commands via shell metacharacters ("|" pipe symbol) in the file parameter. NOTE: t…
|
NVD-CWE-Other
|
CVE-2006-4081
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343233
|
7.2 |
HIGH
|
barracuda_networks
|
barracuda_spam_firewall
|
Barracuda Spam Firewall (BSF), possibly 3.3.03.053, contains a hardcoded password for the admin account for logins from 127.0.0.1 (localhost), which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2006-4082
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343234
|
4.3 |
MEDIUM
|
civicspace
|
civicspace
|
Multiple cross-site scripting (XSS) vulnerabilities in CivicSpace 0.8.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Subject, (2) Comment, and (3) Add new comment section…
|
NVD-CWE-Other
|
CVE-2006-4088
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343235
|
5.0 |
MEDIUM
|
andy_lo-a-foe
|
alsaplayer
|
Multiple buffer overflows in Andy Lo-A-Foe AlsaPlayer 0.99.76 and earlier allow remote attackers to cause a denial of service (application crash), or have other unknown impact, via (1) a long Locatio…
|
NVD-CWE-Other
|
CVE-2006-4089
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343236
|
4.3 |
MEDIUM
|
webligo
|
bloghoster
|
Cross-site scripting (XSS) vulnerability in Webligo BlogHoster 2.2 allows remote attackers to inject arbitrary web script or HTML via the "From: part of the comment post," probably involving the nick…
|
NVD-CWE-Other
|
CVE-2006-4090
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343237
|
4.3 |
MEDIUM
|
archangelmgt
|
weblog
|
Multiple cross-site scripting (XSS) vulnerabilities in Archangel Management Archangel Weblog 0.90.02 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Comment sect…
|
NVD-CWE-Other
|
CVE-2006-4091
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343238
|
3.6 |
LOW
|
simpliciti
|
locked_browser
|
Simpliciti Locked Browser does not properly limit a user's actions to ones within the intended Internet Explorer environment, which allows local users to perform unauthorized actions by visiting a we…
|
NVD-CWE-Other
|
CVE-2006-4092
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343239
|
5.0 |
MEDIUM
|
isc
|
bind
|
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is receiv…
|
NVD-CWE-Other
|
CVE-2006-4096
|
2018-10-18 06:33 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343240
|
7.5 |
HIGH
|
jason_alexander
|
phnntp
|
PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter.
|
NVD-CWE-Other
|
CVE-2006-4103
|
2018-10-18 06:33 |
2006-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343241
|
4.3 |
MEDIUM
|
fill_threads_database
|
fill_threads_database
|
Cross-site scripting (XSS) vulnerability in Fill Threads Database (FTD) 3.7.3 allows remote attackers to inject arbitrary web script or HTML via the (1) search field or (2) an e-mail message.
|
NVD-CWE-Other
|
CVE-2006-4105
|
2018-10-18 06:33 |
2006-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343242
|
4.3 |
MEDIUM
|
blursoft
|
blur6ex
|
Cross-site scripting (XSS) vulnerability in blursoft blur6ex 0.3 allows remote attackers to inject arbitrary web script or HTML via a comment title.
|
NVD-CWE-Other
|
CVE-2006-4106
|
2018-10-18 06:33 |
2006-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343243
|
4.3 |
MEDIUM
|
apache
|
http_server
|
Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive …
|
NVD-CWE-Other
|
CVE-2006-4110
|
2018-10-18 06:33 |
2006-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343244
|
7.5 |
HIGH
|
phpmyring
|
phpmyring
|
SQL injection vulnerability in view_com.php in Nicolas Grandjean PHPMyRing 4.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idsite parameter.
|
NVD-CWE-Other
|
CVE-2006-4114
|
2018-10-18 06:33 |
2006-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343245
|
5.1 |
MEDIUM
|
e-zest_solutions
|
pgmarket
|
PHP remote file inclusion vulnerability in common.inc.php in PgMarket 2.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the CFG[libdir] parameter.
|
NVD-CWE-Other
|
CVE-2006-4115
|
2018-10-18 06:33 |
2006-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343246
|
5.1 |
MEDIUM
|
e-zest_solutions
|
pgmarket
|
Successful exploitation requires that "register_globals" is enabled.
|
NVD-CWE-Other
|
CVE-2006-4115
|
2018-10-18 06:33 |
2006-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343247
|
5.1 |
MEDIUM
|
lhaz
|
lhaz
|
Multiple stack-based buffer overflows in Lhaz before 1.32 allow user-assisted attackers to execute arbitrary code via a long filename in (1) an LHZ archive, when saving the filename during extraction…
|
NVD-CWE-Other
|
CVE-2006-4116
|
2018-10-18 06:33 |
2006-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343248
|
5.1 |
MEDIUM
|
lhaz
|
lhaz
|
This vulnerability is addressed in the following product release:
Lhaz, Lhaz, 1.32
|
NVD-CWE-Other
|
CVE-2006-4116
|
2018-10-18 06:33 |
2006-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343249
|
5.1 |
MEDIUM
|
chaossoft
|
geheimchaos
|
Multiple SQL injection vulnerabilities in GeheimChaos 0.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Temp_entered_login or (2) Temp_entered_email parameters to (…
|
NVD-CWE-Other
|
CVE-2006-4118
|
2018-10-18 06:33 |
2006-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343250
|
5.1 |
MEDIUM
|
chaossoft
|
geheimchaos
|
Successful exploitation requires that "magic_quotes_gpc" is disabled.
|
NVD-CWE-Other
|
CVE-2006-4118
|
2018-10-18 06:33 |
2006-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|