265121
|
- |
|
plume-cms
|
plume_cms
|
PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the _PX_config[manager_pat…
|
CWE-94
Code Injection
|
CVE-2006-0725
|
2017-07-20 10:30 |
2006-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265122
|
- |
|
cpg-nuke
|
dragonfly_cms
|
Cross-site scripting (XSS) vulnerability in linking.php in CPG-Nuke Dragonfly CMS 9.0.6.1 allows remote attackers to inject arbitrary web script or HTML via a URI that is generated when creating a li…
|
NVD-CWE-Other
|
CVE-2006-0726
|
2017-07-20 10:30 |
2006-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265123
|
- |
|
webspell
|
webspell
|
SQL injection vulnerability in search.php in webSPELL 4.01.00 and earlier allows remote attackers to inject arbitrary SQL commands via the title_op parameter.
|
NVD-CWE-Other
|
CVE-2006-0728
|
2017-07-20 10:30 |
2006-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265124
|
- |
|
timo_sirainen
|
dovecot
|
Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs"…
|
NVD-CWE-noinfo CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-0730
|
2017-07-20 10:30 |
2006-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265125
|
- |
|
valve_software
|
half-life_cstrike_dedicated_server
|
The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.6 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon ha…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-0734
|
2017-07-20 10:30 |
2006-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265126
|
- |
|
apache
|
log4net
|
Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2006-0743
|
2017-07-20 10:30 |
2006-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265127
|
- |
|
hivemail
|
hivemail
|
Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid parameter in addressbook.update.php, (2) the messag…
|
NVD-CWE-Other
|
CVE-2006-0757
|
2017-07-20 10:30 |
2006-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265128
|
- |
|
hivemail
|
hivemail
|
Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via a URL encoded expression in the query string in (1) i…
|
NVD-CWE-Other
|
CVE-2006-0758
|
2017-07-20 10:30 |
2006-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265129
|
- |
|
lighttpd
|
lighttpd
|
LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected ca…
|
NVD-CWE-Other
|
CVE-2006-0760
|
2017-07-20 10:30 |
2006-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265130
|
- |
|
hivemail
|
hivemail
|
Multiple SQL injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the contactgroupid parameter in addressbook.update.php, (2) the mes…
|
NVD-CWE-Other
|
CVE-2006-0759
|
2017-07-20 10:30 |
2006-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|