265021
|
- |
|
hogstorps
|
hogstorp_guestbook
|
admin/radera/tabort.asp in Hogstorps hogstorp guestbook 2.0 does not verify user credentials, which allows remote attackers to delete arbitrary posts via a modified delID parameter.
|
NVD-CWE-Other
|
CVE-2006-2771
|
2017-07-20 10:31 |
2006-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265022
|
- |
|
hogstorps
|
hogstorp_guestbook
|
Cross-site scripting (XSS) vulnerability in add.asp in Hogstorps hogstorp guestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, and (3) headline pa…
|
NVD-CWE-Other
|
CVE-2006-2772
|
2017-07-20 10:31 |
2006-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265023
|
- |
|
hogstorps
|
hogstorp_guestbook
|
admin/redigera/redigera2.asp in Hogstorps hogstorp Guestbook 2.0 does not verify user credentials, which allows remote attackers to edit arbitrary posts via unspecified vectors. NOTE: the provenance…
|
NVD-CWE-Other
|
CVE-2006-2773
|
2017-07-20 10:31 |
2006-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265024
|
- |
|
sun
|
storage_automated_diagnostic_environment
|
A package component in Sun Storage Automated Diagnostic Environment (StorADE) 2.4 uses world-writable permissions for certain critical files and directories, which allows local users to gain privileg…
|
NVD-CWE-Other
|
CVE-2006-2790
|
2017-07-20 10:31 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265025
|
- |
|
sun
|
storage_automated_diagnostic_environment
|
This vulnerability is addressed in the following product release:
Sun, Storage Automated Diagnostic Environment, 2.4 (for Solaris 8, 9 and 10) with patch 117654-60 or later.
|
NVD-CWE-Other
|
CVE-2006-2790
|
2017-07-20 10:31 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265026
|
- |
|
new-place
|
captivate
|
Cross-site scripting (XSS) vulnerability in gallery.php in Captivate 1.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter, which is reflected in an error message.
|
CWE-79
Cross-site Scripting
|
CVE-2006-2796
|
2017-07-20 10:31 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265027
|
- |
|
toenda_software_development
|
toendacms
|
Cross-site scripting (XSS) vulnerability in content_footer.php in toendaCMS 0.7.0 allows remote attackers to inject arbitrary web scripts or HTML via the print_url variable. NOTE: the provenance of …
|
NVD-CWE-Other
|
CVE-2006-2799
|
2017-07-20 10:31 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265028
|
- |
|
toenda_software_development
|
toendacms
|
Successful exploitation requires that the user is running a browser that has not URL-encoded the request (e.g. Internet Explorer).
|
NVD-CWE-Other
|
CVE-2006-2799
|
2017-07-20 10:31 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265029
|
- |
|
unak
|
unak_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in Unak CMS 1.5 RC2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) u_a or (2) u_s parameters. NOTE: this mi…
|
CWE-79
Cross-site Scripting
|
CVE-2006-2800
|
2017-07-20 10:31 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265030
|
- |
|
unak
|
unak_cms
|
Multiple SQL injection vulnerabilities in Unak CMS 1.5 RC2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) u_a or (2) u_s parameters.
|
NVD-CWE-Other
|
CVE-2006-2801
|
2017-07-20 10:31 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|