266821
|
- |
|
keith_reichley
|
dotwidget_for_articles
|
Multiple PHP remote file inclusion vulnerabilities in DotWidget For Articles (dotwidgeta) 0.2 allow remote attackers to execute arbitrary code via a URL in the (1) file_path parameter to (a) index.ph…
|
NVD-CWE-Other
|
CVE-2006-7052
|
2017-07-29 10:29 |
2007-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266822
|
- |
|
arkoon
|
fast360
|
Unspecified vulnerability in Arkoon FAST360 UTM appliances 3.0 through 3.0/29, 3.1, 3.2, and 3.3 allows remote attackers to bypass keyword filtering in the FAST HTTP module, and signatures in the IDP…
|
NVD-CWE-Other
|
CVE-2006-7053
|
2017-07-29 10:29 |
2007-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266823
|
- |
|
arkoon
|
fast360
|
The DNS module in Arkoon FAST360 UTM appliances 3.0 up to 3.0/29, 3.1 through 3.3, and 4.0 allows remote attackers to cause a denial of service (reboot) via a malformed DNS message, as demonstrated b…
|
NVD-CWE-Other
|
CVE-2006-7054
|
2017-07-29 10:29 |
2007-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266824
|
- |
|
scriptsez.net
|
e-dating_system
|
Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net E-Dating System allow remote attackers to inject arbitrary web script or HTML via encoded entities (') in IMG tags to (1) …
|
CWE-79
Cross-site Scripting
|
CVE-2006-7059
|
2017-07-29 10:29 |
2007-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266825
|
- |
|
kmail
|
kmail
|
calendar.php in Kamgaing Email System (kmail) 2.3 and earlier allows remote attackers to obtain the full path of the server via an invalid d parameter, which leaks the path in an error message.
|
NVD-CWE-Other
|
CVE-2006-7062
|
2017-07-29 10:29 |
2007-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266826
|
- |
|
invision_power_services
|
invision_power_board
|
Cross-site scripting (XSS) vulnerability in forum/admin.php for Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML as the administrator via th…
|
NVD-CWE-Other
|
CVE-2006-7064
|
2017-07-29 10:29 |
2007-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266827
|
- |
|
invision_power_services
|
invision_power_board
|
Given complete CIA triad impact because remote attackers can inject arbitrary web script or HTML as the administrator.
|
NVD-CWE-Other
|
CVE-2006-7064
|
2017-07-29 10:29 |
2007-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266828
|
- |
|
opentools
|
attachment_mod
|
Cross-site scripting (XSS) vulnerability in Opentools Attachment Mod before 2.4.5 allows remote attackers to inject arbitrary web script or HTML in Internet Explorer via unknown vectors related to th…
|
NVD-CWE-Other
|
CVE-2006-7073
|
2017-07-29 10:29 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266829
|
- |
|
smartsitecms
|
smartsitecms
|
admin.php in SmartSiteCMS 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the userName cookie.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2006-7074
|
2017-07-29 10:29 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266830
|
- |
|
aqualung
|
aqualung
|
Buffer overflow in the meta_read_flac function in meta_decoder.c for Aqualung 0.9beta5 and earlier, and CVS 0.193.2 and earlier, allows user-assisted attackers to execute arbitrary code via a long Vo…
|
NVD-CWE-Other
|
CVE-2006-7075
|
2017-07-29 10:29 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|