264471
|
- |
|
planerd.net
|
p-news
|
Unrestricted file upload vulnerability in P-News 2.0 allows remote attackers to upload and execute arbitrary files via an avatar file. NOTE: the provenance of this information is unknown; the details…
|
CWE-20
Improper Input Validation
|
CVE-2006-7113
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264472
|
- |
|
planerd.net
|
p-news
|
P-News 2.0 stores db/user.txt under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and password hashes via a d…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-7114
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264473
|
- |
|
linksys
|
spa921
|
The HTTP server in Linksys SPA-921 VoIP Desktop Phone allows remote attackers to cause a denial of service (reboot) via (1) a long URL, or a long (2) username or (3) password during Basic Authenticat…
|
NVD-CWE-Other
|
CVE-2006-7121
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264474
|
- |
|
noah_spurrier
|
upload_tool_for_php
|
Unrestricted file upload vulnerability in main_user.php in Upload Tool for PHP 1.0 allows remote attackers to upload and execute arbitrary files with executable extensions such as .php. NOTE: the pr…
|
NVD-CWE-Other
|
CVE-2006-7134
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264475
|
- |
|
noah_spurrier
|
upload_tool_for_php
|
Successful exploitation requires valid user credentials.
|
NVD-CWE-Other
|
CVE-2006-7134
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264476
|
- |
|
php_poll_creator
|
php_poll_creator
|
PHP remote file inclusion vulnerability in lib/functions.inc.php in PHP Poll Creator (phpPC) 1.04 allows remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter, a di…
|
NVD-CWE-Other
|
CVE-2006-7135
|
2017-07-29 10:29 |
2007-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264477
|
- |
|
novell
|
bordermanager
|
Novell BorderManager 3.8 SP4 generates the same ISAKMP cookies for the same source IP and port number during the same day, which allows remote attackers to conduct denial of service and replay attack…
|
NVD-CWE-Other
|
CVE-2006-7155
|
2017-07-29 10:29 |
2007-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264478
|
- |
|
novell
|
bordermanager
|
This vulnerability is addressed in the following vendor document:
https://secure-support.novell.com/KanisaPlatform/Publishing/201/3003139_f.SAL_Public.html
|
NVD-CWE-Other
|
CVE-2006-7155
|
2017-07-29 10:29 |
2007-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264479
|
- |
|
koan_software
|
mega_mall
|
Multiple SQL injection vulnerabilities in Koan Software Mega Mall allow remote attackers to execute arbitrary SQL commands via the (1) t, (2) productId, (3) sk, (4) x, or (5) so parameter to (a) prod…
|
CWE-89
SQL Injection
|
CVE-2006-7170
|
2017-07-29 10:29 |
2007-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264480
|
- |
|
koan_software
|
mega_mall
|
product_review.php in Koan Software Mega Mall allows remote attackers to obtain the installation path via a request with an empty value of the x[] parameter.
|
CWE-20
Improper Input Validation
|
CVE-2006-7171
|
2017-07-29 10:29 |
2007-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|