266771
|
- |
|
ibm
|
websphere_application_server
|
Unspecified vulnerability in the Utility Classes for IBM WebSphere Application Server (WAS) before 5.1.1.13 and 6.x before 6.0.2.17 has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2006-6636
|
2017-07-29 10:29 |
2006-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266772
|
- |
|
chetcpasswd
|
chetcpasswd
|
Pedro Lineu Orso chetcpasswd 2.3.3 does not have a rate limit for client requests, which might allow remote attackers to determine passwords via a dictionary attack.
|
CWE-399
Resource Management Errors
|
CVE-2006-6681
|
2017-07-29 10:29 |
2006-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266773
|
- |
|
atmail
|
atmail_webadmin
|
Cross-site scripting (XSS) vulnerability in the Webadmin in @Mail before 4.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "unescaped data in the da…
|
NVD-CWE-Other
|
CVE-2006-6704
|
2017-07-29 10:29 |
2006-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266774
|
- |
|
atmail
|
atmail_webadmin
|
This vulnerability is addressed in the following product release:
@Mail, @Mail Webadmin, 4.6
|
NVD-CWE-Other
|
CVE-2006-6704
|
2017-07-29 10:29 |
2006-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266775
|
- |
|
mginternet
|
property_site_manager
|
Cross-site scripting (XSS) vulnerability in listings.asp in MGinternet Property Site Manager allows remote attackers to inject arbitrary web script or HTML via the s parameter.
|
NVD-CWE-Other
|
CVE-2006-6708
|
2017-07-29 10:29 |
2006-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266776
|
- |
|
mginternet
|
property_site_manager
|
Multiple SQL injection vulnerabilities in MGinternet Property Site Manager allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) detail.asp; the (2) l, (3) typ, or (…
|
NVD-CWE-Other
|
CVE-2006-6709
|
2017-07-29 10:29 |
2006-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266777
|
- |
|
a-blog
|
a-blog
|
Cross-site scripting (XSS) vulnerability in a-blog 1.51 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2006-6729
|
2017-07-29 10:29 |
2006-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266778
|
- |
|
a-blog
|
a-blog
|
This vulnerability is addressed in the following product release:
A-blog, A-blog, 1.52
|
CWE-79
Cross-site Scripting
|
CVE-2006-6729
|
2017-07-29 10:29 |
2006-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266779
|
- |
|
phpprofiles
|
phpprofiles
|
phpProfiles before 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc…
|
NVD-CWE-Other
|
CVE-2006-6743
|
2017-07-29 10:29 |
2006-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266780
|
- |
|
dxmsoft
|
xm_easy_personal_ftp_server
|
Format string vulnerability in XM Easy Personal FTP Server 5.2.1 allows remote attackers to cause a denial of service (application crash) via format string specifiers in the USER command or certain o…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2006-6751
|
2017-07-29 10:29 |
2006-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|