266841
|
- |
|
debian
|
apache
|
The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local use…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-7098
|
2017-07-29 10:29 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266842
|
- |
|
mambo
|
mostlyce
|
PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a component for Mambo 4.5.4, allows remote attackers to execute ar…
|
CWE-94
Code Injection
|
CVE-2006-7104
|
2017-07-29 10:29 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266843
|
- |
|
drupal
|
imce_module
|
Unrestricted file upload vulnerability in IMCE before 1.6, a Drupal module, allows remote authenticated users to upload arbitrary PHP code via a filename with a double extension such as .php.gif.
|
NVD-CWE-Other
|
CVE-2006-7109
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266844
|
- |
|
drupal
|
imce_module
|
Directory traversal vulnerability in the delete function in IMCE before 1.6, a Drupal module, allows remote authenticated users to delete arbitrary files via ".." sequences.
|
NVD-CWE-Other
|
CVE-2006-7110
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266845
|
- |
|
futomis_cgi_cafe
|
kmail_cgi
|
Unspecified vulnerability in Futomi's CGI Cafe KMail CGI 1.0.3 and earlier allows remote attackers to bypass authentication and obtain unauthorized email access via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-7111
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266846
|
- |
|
planerd.net
|
p-news
|
Unrestricted file upload vulnerability in P-News 2.0 allows remote attackers to upload and execute arbitrary files via an avatar file. NOTE: the provenance of this information is unknown; the details…
|
CWE-20
Improper Input Validation
|
CVE-2006-7113
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266847
|
- |
|
planerd.net
|
p-news
|
P-News 2.0 stores db/user.txt under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and password hashes via a d…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-7114
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266848
|
- |
|
linksys
|
spa921
|
The HTTP server in Linksys SPA-921 VoIP Desktop Phone allows remote attackers to cause a denial of service (reboot) via (1) a long URL, or a long (2) username or (3) password during Basic Authenticat…
|
NVD-CWE-Other
|
CVE-2006-7121
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266849
|
- |
|
noah_spurrier
|
upload_tool_for_php
|
Unrestricted file upload vulnerability in main_user.php in Upload Tool for PHP 1.0 allows remote attackers to upload and execute arbitrary files with executable extensions such as .php. NOTE: the pr…
|
NVD-CWE-Other
|
CVE-2006-7134
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266850
|
- |
|
noah_spurrier
|
upload_tool_for_php
|
Successful exploitation requires valid user credentials.
|
NVD-CWE-Other
|
CVE-2006-7134
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|