274541
|
- |
|
s9y
|
serendipity
|
Cross-site request forgery (CSRF) vulnerability in the Entry Manager in Serendipity before 1.0-beta3 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag.
|
NVD-CWE-Other
|
CVE-2006-2495
|
2011-03-8 11:36 |
2006-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274542
|
- |
|
fckeditor
|
fckeditor
|
editor/filemanager/upload/php/upload.php in FCKeditor before 2.3 Beta, when the upload feature is enabled, does not verify the Type parameter, which allows remote attackers to upload arbitrary file t…
|
NVD-CWE-Other
|
CVE-2006-2529
|
2011-03-8 11:36 |
2006-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274543
|
- |
|
xtreme_scripts
|
xtreme_topsites
|
Multiple SQL injection vulnerabilities in Xtreme Topsites 1.1, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchthis parameter in lostid.php …
|
NVD-CWE-Other
|
CVE-2006-2544
|
2011-03-8 11:36 |
2006-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274544
|
- |
|
florian_amrhein
|
newsportal
|
Cross-site scripting (XSS) vulnerability in Florian Amrhein NewsPortal before 0.37, and possibly TR Newsportal (TRanx rebuilded), allows remote attackers to inject arbitrary web script or HTML via un…
|
NVD-CWE-Other
|
CVE-2006-2556
|
2011-03-8 11:36 |
2006-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274545
|
- |
|
e107
|
e107
|
SQL injection vulnerability in e107 before 0.7.5 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-2590
|
2011-03-8 11:36 |
2006-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274546
|
- |
|
e107
|
e107
|
Unspecified vulnerability in e107 before 0.7.5 has unknown impact and remote attack vectors related to an "emailing exploit".
|
NVD-CWE-Other
|
CVE-2006-2591
|
2011-03-8 11:36 |
2006-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274547
|
- |
|
artmedic_webdesign
|
artmedic_newsletter
|
artmedic newsletter 4.1.2 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the email parameter to ne…
|
NVD-CWE-Other
|
CVE-2006-2609
|
2011-03-8 11:36 |
2006-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274548
|
- |
|
ibm
|
aix
|
Untrusted search path vulnerability in update_flash for IBM AIX 5.1, 5.2 and 5.3 allows local users to execute arbitrary commands via unknown vectors involving lsmcode and possibly other commands.
|
NVD-CWE-Other
|
CVE-2006-2647
|
2011-03-8 11:36 |
2006-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274549
|
- |
|
mono suse
|
xsp suse_open_enterprise_server suse_linux
|
Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE Linux 9.2 through 10.0, allows remote attackers to read arb…
|
NVD-CWE-Other
|
CVE-2006-2658
|
2011-03-8 11:36 |
2006-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274550
|
- |
|
albinator
|
albinator
|
Multiple PHP remote file inclusion vulnerabilities in (1) eday.php, (2) eshow.php, or (3) forgot.php in albinator 2.0.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in t…
|
NVD-CWE-Other
|
CVE-2006-2182
|
2011-03-8 11:35 |
2006-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|