264371
|
- |
|
usermin webmin
|
usermin webmin
|
This vulnerability is addressed in the following product releases:
Webmin, Webmin, 1.296
Usermin, Usermin, 1.226
|
CWE-79
Cross-site Scripting
|
CVE-2006-4542
|
2017-07-20 10:33 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264372
|
- |
|
retro64
|
cr64loader_activex_control
|
Buffer overflow in the Retro64 / Miniclip CR64Loader ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors involving an HTML document that references the CLSID of …
|
NVD-CWE-Other
|
CVE-2006-4555
|
2017-07-20 10:33 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264373
|
- |
|
phpnuke
|
myheadlines
|
Cross-site scripting (XSS) vulnerability in the MyHeadlines before 4.3.2 module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the myh_op parameter to modules.php.
|
NVD-CWE-Other
|
CVE-2006-4563
|
2017-07-20 10:33 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264374
|
- |
|
simplemachines
|
smf
|
SQL injection vulnerability in Sources/ManageBoards.php in Simple Machines Forum 1.1 RC3 allows remote attackers to execute arbitrary SQL commands via the cur_cat parameter.
|
CWE-89
SQL Injection
|
CVE-2006-4564
|
2017-07-20 10:33 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264375
|
- |
|
simplemachines
|
smf
|
Successful exploitation requires privileges to add a new board.
|
CWE-89
SQL Injection
|
CVE-2006-4564
|
2017-07-20 10:33 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264376
|
- |
|
the_address_book
|
the_address_book
|
Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote attackers to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4) passwordNew, (5) id…
|
NVD-CWE-Other
|
CVE-2006-4575
|
2017-07-20 10:33 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264377
|
- |
|
the_address_book
|
the_address_book
|
Cross-site scripting (XSS) vulnerability in The Address Book 1.04e allows remote attackers to inject arbitrary web script or HTML by uploading the HTML file with a GIF or JPG extension, which is rend…
|
NVD-CWE-Other
|
CVE-2006-4576
|
2017-07-20 10:33 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264378
|
- |
|
the_address_book
|
the_address_book
|
Multiple cross-site scripting (XSS) vulnerabilities in The Address Book 1.04e allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) email, (2) websites, and (…
|
NVD-CWE-Other
|
CVE-2006-4577
|
2017-07-20 10:33 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264379
|
- |
|
the_address_book
|
the_address_book
|
export.php in The Address Book 1.04e writes username and password hash information into a publicly accessible file when dumping the MySQL database contents, which allows remote attackers to obtain se…
|
NVD-CWE-Other
|
CVE-2006-4578
|
2017-07-20 10:33 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264380
|
- |
|
the_address_book
|
the_address_book
|
Directory traversal vulnerability in users.php in The Address Book 1.04e allows remote attackers to include arbitrary files via a .. (dot dot) in the language parameter.
|
NVD-CWE-Other
|
CVE-2006-4579
|
2017-07-20 10:33 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|