264281
|
- |
|
simplemachines
|
smf
|
Successful exploitation requires privileges to add a new board.
|
CWE-89
SQL Injection
|
CVE-2006-4564
|
2017-07-20 10:33 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264282
|
- |
|
the_address_book
|
the_address_book
|
Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote attackers to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4) passwordNew, (5) id…
|
NVD-CWE-Other
|
CVE-2006-4575
|
2017-07-20 10:33 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264283
|
- |
|
the_address_book
|
the_address_book
|
Cross-site scripting (XSS) vulnerability in The Address Book 1.04e allows remote attackers to inject arbitrary web script or HTML by uploading the HTML file with a GIF or JPG extension, which is rend…
|
NVD-CWE-Other
|
CVE-2006-4576
|
2017-07-20 10:33 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264284
|
- |
|
the_address_book
|
the_address_book
|
Multiple cross-site scripting (XSS) vulnerabilities in The Address Book 1.04e allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) email, (2) websites, and (…
|
NVD-CWE-Other
|
CVE-2006-4577
|
2017-07-20 10:33 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264285
|
- |
|
the_address_book
|
the_address_book
|
export.php in The Address Book 1.04e writes username and password hash information into a publicly accessible file when dumping the MySQL database contents, which allows remote attackers to obtain se…
|
NVD-CWE-Other
|
CVE-2006-4578
|
2017-07-20 10:33 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264286
|
- |
|
the_address_book
|
the_address_book
|
Directory traversal vulnerability in users.php in The Address Book 1.04e allows remote attackers to include arbitrary files via a .. (dot dot) in the language parameter.
|
NVD-CWE-Other
|
CVE-2006-4579
|
2017-07-20 10:33 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264287
|
- |
|
the_address_book
|
the_address_book
|
register.php in The Address Book 1.04e allows remote attackers to bypass the "Allow User Self-Registration" setting and create arbitrary users by setting the mode parameter to "confirm".
|
NVD-CWE-Other
|
CVE-2006-4580
|
2017-07-20 10:33 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264288
|
- |
|
the_address_book
|
the_address_book
|
Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote attackers to upload arbitrary PHP scripts.
|
NVD-CWE-Other
|
CVE-2006-4581
|
2017-07-20 10:33 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264289
|
- |
|
the_address_book
|
the_address_book
|
Cross-site request forgery (CSRF) vulnerability in The Address Book 1.04e allows remote attackers to perform unauthorized actions as other users via unspecified vectors, as demonstrated by deleting a…
|
NVD-CWE-Other
|
CVE-2006-4582
|
2017-07-20 10:33 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264290
|
- |
|
jetstat.com
|
js_asp_faq_manager
|
SQL injection vulnerability in admin/default.asp in Jetstat.com JS ASP Faq Manager 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the uid parameter, a different vector…
|
NVD-CWE-Other
|
CVE-2006-4590
|
2017-07-20 10:33 |
2006-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|