264331
|
- |
|
james_barnsley
|
jab_guest_book
|
Multiple cross-site scripting (XSS) vulnerabilities in pbguestbook.php in JAB Guest Book 20061205 allow remote attackers to inject arbitrary web script or HTML via the (1) topic or (2) message parame…
|
NVD-CWE-Other
|
CVE-2006-6372
|
2017-07-29 10:29 |
2006-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264332
|
- |
|
positive_software
|
h-sphere
|
The control panel for Positive Software H-Sphere before 2.5.0 RC3 creates log files in a user's directory with insecure permissions, which allows local users to append log data to arbitrary files via…
|
NVD-CWE-Other
|
CVE-2006-6382
|
2017-07-29 10:29 |
2006-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264333
|
- |
|
drupal
|
cvs_management_and_tracker
|
Cross-site scripting (XSS) vulnerability in the CVS management/tracker 4.7.x-1.0, 4.7.x-2.0, and 4.7.0 (before the 20060807 contribution release system) for Drupal allows remote attackers to inject a…
|
NVD-CWE-Other
|
CVE-2006-6386
|
2017-07-29 10:29 |
2006-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264334
|
- |
|
link_content_management_server
|
link_content_management_server
|
Multiple SQL injection vulnerabilities in LINK Content Management Server (CMS) allow remote attackers to execute arbitrary SQL commands via the (1) IDMeniGlavni parameter to navigacija.php, and the (…
|
NVD-CWE-Other
|
CVE-2006-6387
|
2017-07-29 10:29 |
2006-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264335
|
- |
|
link
|
content_management_server
|
Cross-site scripting (XSS) vulnerability in naprednaPretraga.php in LINK Content Management Server (CMS) allows remote attackers to inject arbitrary web script or HTML via the txtPretraga parameter. …
|
NVD-CWE-Other
|
CVE-2006-6388
|
2017-07-29 10:29 |
2006-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264336
|
- |
|
plx_web_studio
|
plx_pay
|
Directory traversal vulnerability in index.php in plx Web Studio (aka plxWebDev) plx Pay 3.2 and earlier allows remote attackers to include and execute arbitrary local files, or obtain user credentia…
|
NVD-CWE-Other
|
CVE-2006-6392
|
2017-07-29 10:29 |
2006-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264337
|
- |
|
jonas_gauffin
|
publicera
|
Cross-site scripting (XSS) vulnerability in Jonas Gauffin Publicera 1.0-rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the InputFilt…
|
NVD-CWE-Other
|
CVE-2006-6393
|
2017-07-29 10:29 |
2006-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264338
|
- |
|
jonas_gauffin
|
publicera
|
SQL injection vulnerability in certain database classes in Jonas Gauffin Publicera 1.0-rc2 and earlier might allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-6394
|
2017-07-29 10:29 |
2006-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264339
|
- |
|
mystats
|
mystats
|
mystats.php in MyStats 1.0.8 and earlier allows remote attackers to obtain the installation path via (1) details and (2) by array parameters, probably resulting in a path disclosure in an error messa…
|
NVD-CWE-Other
|
CVE-2006-6403
|
2017-07-29 10:29 |
2006-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264340
|
- |
|
phpleague_-_univert
|
phpleague
|
Multiple PHP remote file inclusion vulnerabilities in PhpLeague - Univert PhpLeague 0.81 allow remote attackers to execute arbitrary PHP code via a URL in the cheminmini parameter to (1) consult/mini…
|
NVD-CWE-Other
|
CVE-2006-6416
|
2017-07-29 10:29 |
2006-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|