267441
|
- |
|
mozilla
|
bugzilla
|
Bugzilla 2.20rc1 through 2.20 and 2.21.1, when using RSS 1.0, allows remote attackers to conduct cross-site scripting (XSS) attacks via a title element with HTML encoded sequences such as ">", whi…
|
CWE-79
Cross-site Scripting
|
CVE-2006-2420
|
2017-07-20 10:31 |
2006-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267442
|
- |
|
mozilla
|
bugzilla
|
Update to version 2.18.5 or 2.20.1.
|
CWE-79
Cross-site Scripting
|
CVE-2006-2420
|
2017-07-20 10:31 |
2006-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267443
|
- |
|
pragma_systems
|
fortressssh
|
Stack-based buffer overflow in Pragma FortressSSH 4.0.7.20 allows remote attackers to execute arbitrary code via long SSH_MSG_KEXINIT messages, which may cause an overflow when being logged. NOTE: t…
|
NVD-CWE-Other
|
CVE-2006-2421
|
2017-07-20 10:31 |
2006-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267444
|
- |
|
coinsoft_technologies
|
phpcoin
|
phpCOIN 1.2.3 and earlier stores messages based upon e-mail addresses, which allows remote authenticated users to read messages for other users by adding the sender's e-mail address as an "additional…
|
NVD-CWE-Other
|
CVE-2006-2422
|
2017-07-20 10:31 |
2006-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267445
|
- |
|
coinsoft_technologies
|
phpcoin
|
Apply patch :
http://forums.phpcoin.com/index.php?showtopic=5941
|
NVD-CWE-Other
|
CVE-2006-2422
|
2017-07-20 10:31 |
2006-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267446
|
- |
|
caucho_technology
|
resin
|
Directory traversal vulnerability in the viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to read arbitrary files under other web r…
|
NVD-CWE-Other
|
CVE-2006-2438
|
2017-07-20 10:31 |
2006-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267447
|
- |
|
caucho_technology
|
resin
|
This vulnerability is addressed in the following product release:
Caucho Technology, Resin, 3.0.19
|
NVD-CWE-Other
|
CVE-2006-2438
|
2017-07-20 10:31 |
2006-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267448
|
- |
|
bea
|
weblogic_server
|
BEA WebLogic Server before 8.1 Service Pack 4 does not properly set the Quality of Service in certain circumstances, which prevents some transmissions from being encrypted via SSL, and allows remote …
|
NVD-CWE-Other
|
CVE-2006-2461
|
2017-07-20 10:31 |
2006-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267449
|
- |
|
bea
|
weblogic_server
|
BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service Pack 6, may send sensitive data over non-secure channels when using JTA transactions, which allows remote attackers to read potent…
|
NVD-CWE-Other
|
CVE-2006-2462
|
2017-07-20 10:31 |
2006-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267450
|
- |
|
bea
|
weblogic_server
|
stopWebLogic.sh in BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service Pack 6 displays the administrator password to stdout when executed, which allows local users to obtain the pass…
|
NVD-CWE-Other
|
CVE-2006-2464
|
2017-07-20 10:31 |
2006-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|