264661
|
- |
|
the_address_book the_address_book_reloaded
|
the_address_book the_address_book_reloaded
|
Multiple SQL injection vulnerabilities in the authentication process in katzlbt (a) The Address Book 1.04e and earlier and (b) The Address Book Reloaded before 2.0-rc4 allow remote attackers to execu…
|
NVD-CWE-Other
|
CVE-2006-4056
|
2017-07-20 10:32 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264662
|
- |
|
cakefoundation
|
cakephp
|
Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 4…
|
CWE-79
Cross-site Scripting
|
CVE-2006-4067
|
2017-07-20 10:32 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264663
|
- |
|
mywebland
|
myevent
|
PHP remote file inclusion vulnerability in viewevent.php in myWebland myEvent 1.x allows remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter, a different vector tha…
|
NVD-CWE-Other
|
CVE-2006-4083
|
2017-07-20 10:32 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264664
|
- |
|
olaf_noehring
|
the_search_engine_project
|
PHP remote file inclusion vulnerability in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tsep_config[absPath]…
|
NVD-CWE-Other
|
CVE-2006-4085
|
2017-07-20 10:32 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264665
|
- |
|
mojoscripts
|
mojogallery
|
Cross-site scripting (XSS) vulnerability in admin.cgi in mojoscripts.com mojoGallery allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: the provenance o…
|
NVD-CWE-Other
|
CVE-2006-4087
|
2017-07-20 10:32 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264666
|
- |
|
cisco
|
secure_access_control_server
|
Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary …
|
NVD-CWE-Other
|
CVE-2006-4098
|
2017-07-20 10:32 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264667
|
- |
|
businessobjects
|
crystal_enterprise
|
Business Objects Crystal Enterprise 9 and 10 generates predictable session identifiers, which allows remote attackers to hijack sessions of other users via WCSID cookie values.
|
NVD-CWE-Other
|
CVE-2006-4099
|
2017-07-20 10:32 |
2006-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264668
|
- |
|
mojoscripts
|
mojogallery
|
Cross-site scripting (XSS) vulnerability in admin.cgi in mojoscripts.com mojoGallery allows remote attackers to inject arbitrary web script or HTML via "password input."
|
NVD-CWE-Other
|
CVE-2006-4104
|
2017-07-20 10:32 |
2006-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264669
|
- |
|
drupal
|
job_search
|
SQL injection vulnerability in the Job Search module (job.module) 4.6 before revision 1.3.2.1 in Drupal allows remote attackers to execute arbitrary SQL commands via a job or resume search.
|
NVD-CWE-Other
|
CVE-2006-4107
|
2017-07-20 10:32 |
2006-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264670
|
- |
|
drupal
|
bibliography_module
|
SQL injection vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote attackers to execute arbitrary SQL commands via …
|
NVD-CWE-Other
|
CVE-2006-4108
|
2017-07-20 10:32 |
2006-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|