265161
|
- |
|
xerox
|
workcentre_232 workcentre_238 workcentre_245 workcentre_255 workcentre_265 workcentre_275
|
Cross-site scripting vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote at…
|
NVD-CWE-Other
|
CVE-2006-0827
|
2017-07-20 10:30 |
2006-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265162
|
- |
|
boonex
|
barracuda_directory
|
Multiple cross-site scripting (XSS) vulnerabilities in Barracuda Directory 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) Add URL and (2) Suggest…
|
NVD-CWE-Other
|
CVE-2006-0833
|
2017-07-20 10:30 |
2006-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265163
|
- |
|
mitridat
|
web_calendar_pro
|
SQL injection vulnerability in dropbase.php in MitriDAT Web Calendar Pro allows remote attackers to modify internal SQL queries and cause a denial of service (inaccessible database) via the tabls par…
|
NVD-CWE-Other
|
CVE-2006-0835
|
2017-07-20 10:30 |
2006-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265164
|
- |
|
calacode
|
atmail_webmail_system
|
Cross-site scripting (XSS) vulnerability in Calacode @Mail 4.3 allows remote attackers to inject arbitrary web script or HTML via a modified javascript: string in the SRC attribute of an IMG element …
|
CWE-79
Cross-site Scripting
|
CVE-2006-0842
|
2017-07-20 10:30 |
2006-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265165
|
- |
|
calacode
|
atmail_webmail_system
|
Successful exploitation of this issue requires a victim user has @Mail configured to display images in email messages.
|
CWE-79
Cross-site Scripting
|
CVE-2006-0842
|
2017-07-20 10:30 |
2006-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265166
|
- |
|
leif_m._wright
|
web_blog
|
Leif M. Wright's Blog 3.5 stores the config file and other txt files under the web root with insufficient access control, which allows remote attackers to read the administrator's password.
|
NVD-CWE-Other
|
CVE-2006-0843
|
2017-07-20 10:30 |
2006-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265167
|
- |
|
leif_m._wright
|
web_blog
|
Leif M. Wright's Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, probably by setting the …
|
NVD-CWE-Other
|
CVE-2006-0844
|
2017-07-20 10:30 |
2006-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265168
|
- |
|
leif_m._wright
|
web_blog
|
Leif M. Wright's Blog 3.5 allows remote authenticated users with administrative privileges to execute arbitrary programs, including shell commands, by configuring the sendmail path to a malicious pat…
|
NVD-CWE-Other
|
CVE-2006-0845
|
2017-07-20 10:30 |
2006-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265169
|
- |
|
leif_m._wright
|
web_blog
|
Multiple cross-site scripting (XSS) vulnerabilities in Leif M. Wright's Blog 3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Referer and (2) User-Agent HTTP headers, whi…
|
NVD-CWE-Other
|
CVE-2006-0846
|
2017-07-20 10:30 |
2006-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265170
|
- |
|
cherrypy
|
cherrypy
|
Directory traversal vulnerability in the staticfilter component in CherryPy before 2.1.1 allows remote attackers to read arbitrary files via ".." sequences in unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-0847
|
2017-07-20 10:30 |
2006-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|