264641
|
- |
|
scott_weedon
|
ajax_chat
|
Cross-site scripting (XSS) vulnerability in visitor/livesupport/chat.php in Scott Weedon Ajax Chat, possibly 0.1, allows remote attackers to inject arbitrary web script or HTML via the userid paramet…
|
NVD-CWE-Other
|
CVE-2006-3971
|
2017-07-20 10:32 |
2006-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264642
|
- |
|
scott_weedon
|
ajax_chat
|
Directory traversal vulnerability in includes/operator_chattranscript.php in Scott Weedon Ajax Chat, possibly 0.1, allows remote attackers to read arbitrary files via a .. (dot dot) in the chatid par…
|
NVD-CWE-Other
|
CVE-2006-3972
|
2017-07-20 10:32 |
2006-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264643
|
- |
|
3com
|
3cr860-95
|
Cross-site scripting (XSS) vulnerability in cgi-bin/admin in 3Com OfficeConnect Secure Router with firmware 1.04-168 allows remote attackers to inject arbitrary web script or HTML via the tk paramete…
|
NVD-CWE-Other
|
CVE-2006-3974
|
2017-07-20 10:32 |
2007-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264644
|
- |
|
adobe
|
coldfusion
|
Unspecified vulnerability in a Verity third party library, as used on Adobe ColdFusion MX 7 through MX 7.0.2 and possibly other products, allows local users to execute arbitrary code via unknown atta…
|
NVD-CWE-Other
|
CVE-2006-3978
|
2017-07-20 10:32 |
2006-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264645
|
- |
|
macromedia
|
coldfusion
|
The AdminAPI of ColdFusion MX 7 allows attackers to bypass authentication by using "programmatic access" to the adminAPI instead of the ColdFusion Administrator.
|
NVD-CWE-Other
|
CVE-2006-3979
|
2017-07-20 10:32 |
2006-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264646
|
- |
|
mambo
|
mambo_gallery_manager
|
PHP remote file inclusion vulnerability in about.mgm.php in Mambo Gallery Manager (MGM) 0.95r2 and earlier for Mambo 4.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConf…
|
NVD-CWE-Other
|
CVE-2006-3981
|
2017-07-20 10:32 |
2006-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264647
|
- |
|
drupal
|
drupal
|
Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: …
|
NVD-CWE-Other
|
CVE-2006-4002
|
2017-07-20 10:32 |
2006-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264648
|
- |
|
drupal
|
drupal
|
This vulnerability is addressed in the following product releases:
Drupal, Drupal, 4.6.9
Drupal, Drupal, 4.7.3
|
NVD-CWE-Other
|
CVE-2006-4002
|
2017-07-20 10:32 |
2006-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264649
|
- |
|
bomberclone
|
bomberclone
|
BomberClone 0.11.6 and earlier allows remote attackers to cause a denial of service (daemon crash) via (1) a certain malformed PKGF_ackreq packet, which triggers a crash in the rscache_add() function…
|
NVD-CWE-Other
|
CVE-2006-4005
|
2017-07-20 10:32 |
2006-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264650
|
- |
|
bomberclone
|
bomberclone
|
The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_pkg function (packets.c) to use this data size whe…
|
CWE-200
Information Exposure
|
CVE-2006-4006
|
2017-07-20 10:32 |
2006-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|