|
346751
|
10.0 |
HIGH
|
david_walker
|
phpautomembersarea
|
Upgrade to 3.2.4
|
NVD-CWE-Other
|
CVE-2006-4084
|
2008-09-6 06:08 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346752
|
6.4 |
MEDIUM
|
tor
|
tor
|
TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier for remote attackers to conduct brute force attacks on the en…
|
NVD-CWE-Other
|
CVE-2006-3411
|
2008-09-6 06:07 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346753
|
6.4 |
MEDIUM
|
tor
|
tor
|
Tor before 0.1.1.20 does not sufficiently obey certain firewall options, which allows remote attackers to bypass intended access restrictions for dirservers, direct connections, or proxy servers.
|
NVD-CWE-Other
|
CVE-2006-3412
|
2008-09-6 06:07 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346754
|
5.0 |
MEDIUM
|
tor
|
tor
|
The privoxy configuration file in Tor before 0.1.1.20, when run on Apple OS X, logs all data via the "logfile", which allows attackers to obtain potentially sensitive information.
|
NVD-CWE-Other
|
CVE-2006-3413
|
2008-09-6 06:07 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346755
|
5.0 |
MEDIUM
|
tor
|
tor
|
Tor before 0.1.1.20 supports server descriptors that contain hostnames instead of IP addresses, which allows remote attackers to arbitrarily group users by providing preferential address resolution.
|
NVD-CWE-Other
|
CVE-2006-3414
|
2008-09-6 06:07 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346756
|
6.4 |
MEDIUM
|
tor
|
tor
|
Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITM) attack via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-3415
|
2008-09-6 06:07 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346757
|
6.4 |
MEDIUM
|
tor
|
tor
|
Tor client before 0.1.1.20 prefers entry points based on is_fast or is_stable flags, which could allow remote attackers to be preferred over nodes that are identified as more trustworthy "entry guard…
|
NVD-CWE-Other
|
CVE-2006-3417
|
2008-09-6 06:07 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346758
|
5.0 |
MEDIUM
|
tor
|
tor
|
Tor before 0.1.1.20 does not validate that a server descriptor's fingerprint line matches its identity key, which allows remote attackers to spoof the fingerprint line, which might be trusted by user…
|
NVD-CWE-Other
|
CVE-2006-3418
|
2008-09-6 06:07 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346759
|
5.0 |
MEDIUM
|
tor
|
tor
|
Tor before 0.1.1.20 uses OpenSSL pseudo-random bytes (RAND_pseudo_bytes) instead of cryptographically strong RAND_bytes, and seeds the entropy value at start-up with 160-bit chunks without reseeding,…
|
NVD-CWE-Other
|
CVE-2006-3419
|
2008-09-6 06:07 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346760
|
5.0 |
MEDIUM
|
phpmaillist
|
phpmaillist
|
PHPMailList 1.8.0 stores sensitive information under the web document root iwth insufficient access control, which allows remote attackers to obtain email addresses of subscribers, configuration info…
|
NVD-CWE-Other
|
CVE-2006-3483
|
2008-09-6 06:07 |
2006-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346761
|
5.0 |
MEDIUM
|
virtuastore
|
virtuastore
|
VirtuaStore 2.0 stores sensitive files under the web root with insufficient access control, which allows remote attackers to obtain local database information by directly accessing database/virtuasto…
|
NVD-CWE-Other
|
CVE-2006-3487
|
2008-09-6 06:07 |
2006-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346762
|
5.0 |
MEDIUM
|
virtuastore
|
virtuastore
|
Absolute path traversal vulnerability in administrador.asp in VirtuaStore 2.0 allows remote attackers to possibly read arbitrary directories or files via an absolute path with Windows drive letter in…
|
NVD-CWE-Other
|
CVE-2006-3488
|
2008-09-6 06:07 |
2006-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346763
|
7.5 |
HIGH
|
sensesites
|
commonsense_cms
|
SQL injection vulnerability in search.php in SenseSites CommonSense CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the Date parameter. NOTE: the provenance of this information…
|
NVD-CWE-Other
|
CVE-2006-3576
|
2008-09-6 06:07 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346764
|
7.5 |
HIGH
|
lifetype
|
lifetype
|
SQL injection vulnerability in index.php in LifeType 1.0.5 allows remote attackers to execute arbitrary SQL commands via the Date parameter in a Default op.
|
NVD-CWE-Other
|
CVE-2006-3577
|
2008-09-6 06:07 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346765
|
5.0 |
MEDIUM
|
fujitsu
|
serverview
|
Directory traversal vulnerability in Fujitsu ServerView 2.50 up to 3.60L98 and 4.10L11 up to 4.11L81 allows remote attackers to read arbitrary files via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-3578
|
2008-09-6 06:07 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346766
|
4.3 |
MEDIUM
|
fujitsu
|
serverview
|
Cross-site scripting (XSS) vulnerability in Fujitsu ServerView 2.50 up to 3.60L98 and 4.10L11 up to 4.11L81 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2006-3579
|
2008-09-6 06:07 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346767
|
4.3 |
MEDIUM
|
fujitsu
|
serverview
|
This vulnerability is addressed in the following product releases:
Fujitsu, ServerView, 3.60L99
Fujitsu, ServerView, 4.20L11B
|
CWE-79
Cross-site Scripting
|
CVE-2006-3579
|
2008-09-6 06:07 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346768
|
7.2 |
HIGH
|
ubuntu
|
ubuntu_linux
|
passwd before 1:4.0.13 on Ubuntu 6.06 LTS leaves the root password blank instead of locking it when the administrator selects the "Go Back" option after the final "Installation complete" message and …
|
NVD-CWE-Other
|
CVE-2006-3597
|
2008-09-6 06:07 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346769
|
2.6 |
LOW
|
cutephp
|
cutenews
|
Cross-site scripting (XSS) vulnerability in Index.PHP in CuteNews 1.4.5 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information i…
|
NVD-CWE-Other
|
CVE-2006-3661
|
2008-09-6 06:07 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346770
|
10.0 |
HIGH
|
kde
|
kdebase
|
The KDE PAM configuration shipped with Fedora Core 5 causes KDM passwords to be cached, which allows attackers to login without a password by attempting to log in multiple times.
|
NVD-CWE-Other
|
CVE-2006-3742
|
2008-09-6 06:07 |
2006-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346771
|
6.8 |
MEDIUM
|
lucid_designs
|
lucid_calendar
|
Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea Lucid Calendar 0.22 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: the provenance …
|
NVD-CWE-Other
|
CVE-2006-3025
|
2008-09-6 06:06 |
2006-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346772
|
6.8 |
MEDIUM
|
lucid_designs
|
lucid_calendar
|
Lucid Designs, Lucid Calendar, 0.22 is unsupported. A new, supported version of this product will be released in the near future.
|
NVD-CWE-Other
|
CVE-2006-3025
|
2008-09-6 06:06 |
2006-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346773
|
4.3 |
MEDIUM
|
emailarchitect
|
email_server
|
Cross-site scripting (XSS) vulnerability in EmailArchitect Email Server 6.1 allows remote attackers to inject arbitrary Javascript via an HTML div tag with a carriage return between the onmouseover a…
|
NVD-CWE-Other
|
CVE-2006-3108
|
2008-09-6 06:06 |
2006-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346774
|
1.2 |
LOW
|
canonical
|
spread
|
spread uses a temporary file with a static filename based on the port number, which allows local users to cause a denial of service by creating the file during a race condition between unlink and bin…
|
NVD-CWE-Other
|
CVE-2006-3118
|
2008-09-6 06:06 |
2006-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346775
|
7.5 |
HIGH
|
mambo
|
mambo
|
SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.
|
NVD-CWE-Other
|
CVE-2006-3263
|
2008-09-6 06:06 |
2006-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346776
|
7.5 |
HIGH
|
mpg123
|
mpg123
|
Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not properly terminated before being used with the strnc…
|
NVD-CWE-Other
|
CVE-2006-3355
|
2008-09-6 06:06 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346777
|
7.2 |
HIGH
|
ubuntu
|
ubuntu_linux
|
passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileg…
|
NVD-CWE-Other
|
CVE-2006-3378
|
2008-09-6 06:06 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346778
|
5.0 |
MEDIUM
|
amule
|
amule
|
Multiple unspecified vulnerabilities in aMuleWeb for AMule before 2.1.2 allow remote attackers to read arbitrary image, HTML, or PHP files via unknown vectors, probably related to directory traversal.
|
NVD-CWE-Other
|
CVE-2006-2692
|
2008-09-6 06:05 |
2006-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346779
|
5.0 |
MEDIUM
|
amule
|
amule
|
Successful exploitation requires that the full pathname of the file is known.
This vulnerability is addressed in the following product release:
aMule, aMule, 2.1.2
|
NVD-CWE-Other
|
CVE-2006-2692
|
2008-09-6 06:05 |
2006-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346780
|
5.0 |
MEDIUM
|
jetty
|
jetty
|
Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the same issue as CVE-2…
|
CWE-22
Path Traversal
|
CVE-2006-2758
|
2008-09-6 06:05 |
2006-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346781
|
5.0 |
MEDIUM
|
jetty
|
jetty
|
jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary script source code via a capital P in the .jsp extension, and probably other mixed case manipulations.
|
NVD-CWE-Other
|
CVE-2006-2759
|
2008-09-6 06:05 |
2006-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346782
|
6.8 |
MEDIUM
|
xiti
|
xiti_tracking_script
|
Multiple cross-site scripting (XSS) vulnerabilities in XiTi Tracking Script 6 and 7 RC allow remote attackers to inject arbitrary web script or HTML via (1) the xtref parameter in xiti.js and (2) an …
|
NVD-CWE-Other
|
CVE-2006-2795
|
2008-09-6 06:05 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346783
|
5.0 |
MEDIUM
|
jelsoft
|
vbulletin
|
SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter.
|
NVD-CWE-Other
|
CVE-2006-2805
|
2008-09-6 06:05 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346784
|
4.3 |
MEDIUM
|
visiongate
|
visiongate_portal_system
|
Cross-site scripting (XSS) vulnerability in Print.PHP in VisionGate Portal System allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: The provenance of t…
|
NVD-CWE-Other
|
CVE-2006-2846
|
2008-09-6 06:05 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346785
|
4.3 |
MEDIUM
|
skoom
|
i.list
|
Cross-site scripting (XSS) vulnerability in i.List 1.5 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the banurl parameter to add.php. NOTE: the provenance of th…
|
NVD-CWE-Other
|
CVE-2006-2957
|
2008-09-6 06:05 |
2006-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346786
|
7.5 |
HIGH
|
arantius
|
vice_stats
|
SQL injection vulnerability in vs_search.php in Arantius Vice Stats before 1.0.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors, a different issue than CVE-2006-2972.
|
NVD-CWE-Other
|
CVE-2006-2981
|
2008-09-6 06:05 |
2006-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346787
|
5.8 |
MEDIUM
|
vizra
|
vizra
|
Cross-site scripting (XSS) vulnerability in a_login.php in Vizra allows remote attackers to inject arbitrary web script or HTML via the message parameter.
|
NVD-CWE-Other
|
CVE-2006-2365
|
2008-09-6 06:04 |
2006-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346788
|
2.6 |
LOW
|
unclassified_newsboard
|
unclassified_newsboard
|
Directory traversal vulnerability in bb_lib/abbc.css.php in Unclassified NewsBoard (UNB) 1.5.3-d and possibly earlier versions, when register_globals is enabled, allows remote attackers to include ar…
|
NVD-CWE-Other
|
CVE-2006-2406
|
2008-09-6 06:04 |
2006-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346789
|
5.0 |
MEDIUM
|
pioneers
|
pioneers_meta-server
|
Pioneers meta-server before 0.9.55, when the server-console is not installed, allows remote attackers to cause a denial of service (crash) via certain requests from an older gnocatan client to create…
|
NVD-CWE-Other
|
CVE-2006-2441
|
2008-09-6 06:04 |
2006-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346790
|
5.0 |
MEDIUM
|
pioneers
|
pioneers_meta-server
|
Successful exploitation requires that the server-console is not installed.
This vulnerability is addressed in the following product release:
Pioneers, Pioneers, 0.9.49
|
NVD-CWE-Other
|
CVE-2006-2441
|
2008-09-6 06:04 |
2006-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346791
|
4.6 |
MEDIUM
|
knowledgetree
|
knowledgetree
|
The Debian package of knowledgetree 2.0.7 creates environment.php with world-readable permissions, which allows local users to obtain sensitive information such as the username and password for the K…
|
NVD-CWE-Other
|
CVE-2006-2443
|
2008-09-6 06:04 |
2006-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346792
|
5.0 |
MEDIUM
|
out_of_the_trees_web_design
|
selectapix
|
view_album.php in SelectaPix 1.31 and earlier allows remote attackers to obtain the installation path via a certain request, which displays the path in an error message, possibly due to an invalid or…
|
NVD-CWE-Other
|
CVE-2006-2463
|
2008-09-6 06:04 |
2006-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346793
|
7.5 |
HIGH
|
s9y
|
serendipity
|
config.php in S9Y Serendipity 1.0 beta 2 allows remote attackers to inject arbitrary PHP code by editing values that are stored in config.php and later executed. NOTE: the provenance of this informa…
|
NVD-CWE-Other
|
CVE-2006-1910
|
2008-09-6 06:03 |
2006-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346794
|
5.0 |
MEDIUM
|
dbbs
|
dbbs
|
SQL injection vulnerability in topics.php in DbbS 2.0-alpha and earlier allows remote attackers to execute arbitrary SQL commands via the fcategoryid parameter.
|
NVD-CWE-Other
|
CVE-2006-1915
|
2008-09-6 06:03 |
2006-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346795
|
4.0 |
MEDIUM
|
ibm
|
lotus_notes
|
The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Boo…
|
NVD-CWE-Other
|
CVE-2006-1948
|
2008-09-6 06:03 |
2006-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346796
|
7.5 |
HIGH
|
mybulletinboard
|
mybulletinboard
|
SQL injection vulnerability in index.php in MyBB (MyBulletinBoard) before 1.04 allows remote attackers to execute arbitrary SQL commands via the referrer parameter.
|
NVD-CWE-Other
|
CVE-2006-1974
|
2008-09-6 06:03 |
2006-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346797
|
2.6 |
LOW
|
stadtaus.com
|
php-gastebuch
|
Cross-site scripting (XSS) vulnerability in guestbook_newentry.php in PHP-Gastebuch 1.61 allows remote attackers to inject arbitrary web script or HTML via the Kommentar field.
|
NVD-CWE-Other
|
CVE-2006-1975
|
2008-09-6 06:03 |
2006-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346798
|
2.6 |
LOW
|
geekforgod.net
|
prayer_request_board
|
Cross-site scripting (XSS) vulnerability in addRequest.php in Prayer Request Board (PRB) Beta 1 before 20060320 allows remote attackers to inject arbitrary web script or HTML via the Request field.
|
NVD-CWE-Other
|
CVE-2006-1976
|
2008-09-6 06:03 |
2006-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346799
|
7.5 |
HIGH
|
php_thumbnail_autoindex
|
php_thumbnail_autoindex
|
PHP remote file inclusion vulnerability in Thumbnail AutoIndex before 2.0 allows remote attackers to execute arbitrary PHP code via (1) README.html or (2) HEADER.html.
|
NVD-CWE-Other
|
CVE-2006-2098
|
2008-09-6 06:03 |
2006-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346800
|
5.0 |
MEDIUM
|
jupiter_cms
|
jupiter_cms
|
Directory traversal vulnerability in index.php in Jupiter CMS 1.1.4 and 1.1.5 allows remote attackers to read arbitrary files via ".." sequences terminated by a %00 (null) character in the n paramete…
|
NVD-CWE-Other
|
CVE-2006-2105
|
2008-09-6 06:03 |
2006-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|