264301
|
- |
|
thomas_lange debian
|
fully_automated_installation debian_linux
|
The save_log_local function in Fully Automatic Installation (FAI) 2.10.1, and possibly 3.1.2, when verbose mode is enabled, stores the root password hash in /var/log/fai/current/fai.log, whose file p…
|
NVD-CWE-Other
|
CVE-2006-6614
|
2017-07-29 10:29 |
2006-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264302
|
- |
|
w00t_gallery
|
w00t_gallery
|
index.php in w00t Gallery 1.4.0 allows remote authenticated users with privileges for one installation to gain access to other installations on the same web server, aka "multi-gallery admin session s…
|
NVD-CWE-Other
|
CVE-2006-6616
|
2017-07-29 10:29 |
2006-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264303
|
- |
|
mambo
|
extcalthai_module
|
Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote attackers to execute arbitrary PHP code via a URL in (1) the …
|
NVD-CWE-Other
|
CVE-2006-6634
|
2017-07-29 10:29 |
2006-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264304
|
- |
|
ibm
|
websphere_application_server
|
Unspecified vulnerability in the Utility Classes for IBM WebSphere Application Server (WAS) before 5.1.1.13 and 6.x before 6.0.2.17 has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2006-6636
|
2017-07-29 10:29 |
2006-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264305
|
- |
|
chetcpasswd
|
chetcpasswd
|
Pedro Lineu Orso chetcpasswd 2.3.3 does not have a rate limit for client requests, which might allow remote attackers to determine passwords via a dictionary attack.
|
CWE-399
Resource Management Errors
|
CVE-2006-6681
|
2017-07-29 10:29 |
2006-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264306
|
- |
|
atmail
|
atmail_webadmin
|
Cross-site scripting (XSS) vulnerability in the Webadmin in @Mail before 4.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "unescaped data in the da…
|
NVD-CWE-Other
|
CVE-2006-6704
|
2017-07-29 10:29 |
2006-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264307
|
- |
|
atmail
|
atmail_webadmin
|
This vulnerability is addressed in the following product release:
@Mail, @Mail Webadmin, 4.6
|
NVD-CWE-Other
|
CVE-2006-6704
|
2017-07-29 10:29 |
2006-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264308
|
- |
|
mginternet
|
property_site_manager
|
Cross-site scripting (XSS) vulnerability in listings.asp in MGinternet Property Site Manager allows remote attackers to inject arbitrary web script or HTML via the s parameter.
|
NVD-CWE-Other
|
CVE-2006-6708
|
2017-07-29 10:29 |
2006-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264309
|
- |
|
mginternet
|
property_site_manager
|
Multiple SQL injection vulnerabilities in MGinternet Property Site Manager allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) detail.asp; the (2) l, (3) typ, or (…
|
NVD-CWE-Other
|
CVE-2006-6709
|
2017-07-29 10:29 |
2006-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264310
|
- |
|
a-blog
|
a-blog
|
Cross-site scripting (XSS) vulnerability in a-blog 1.51 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2006-6729
|
2017-07-29 10:29 |
2006-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|