|
343771
|
- |
|
imendio_planner
|
imendio_planner
|
Format string vulnerability in Imendio Planner 0.13 allows user-assisted attackers to execute arbitrary code via format string specifiers in a filename.
|
NVD-CWE-Other
|
CVE-2006-4070
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343772
|
- |
|
microsoft
|
windows_2003_server windows_xp
|
Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to ca…
|
NVD-CWE-Other
|
CVE-2006-4071
|
2018-10-18 06:33 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343773
|
- |
|
phpcc
|
phpcc
|
Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz phpCC Beta 4.2 allow remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter to (1) login.php, (2) reacti…
|
NVD-CWE-Other
|
CVE-2006-4073
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343774
|
- |
|
wim_fleischhauer
|
docpile_we
|
Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the INIT…
|
NVD-CWE-Other
|
CVE-2006-4075
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343775
|
- |
|
wim_fleischhauer
|
docpile_we
|
Successful exploitation requires that "register_globals" is enabled.
|
NVD-CWE-Other
|
CVE-2006-4075
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343776
|
- |
|
deluxebb
|
deluxebb
|
pm.php (aka the PM system) in DeluxeBB 1.08, and possibly earlier, allows remote attackers to bypass authentication by providing an arbitrary username in the membercookie cookie parameter.
|
NVD-CWE-Other
|
CVE-2006-4078
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343777
|
- |
|
deluxebb
|
deluxebb
|
Cross-site scripting (XSS) vulnerability in newpost.php in DeluxeBB 1.08, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the subject parameter (aka the topic…
|
NVD-CWE-Other
|
CVE-2006-4079
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343778
|
- |
|
deluxebb
|
deluxebb
|
DeluxeBB 1.08, and possibly earlier, uses cookies that include the MD5 hash of a password, which allows remote attackers to gain privileges by sniffing or cross-site scripting (XSS) and conduct passw…
|
NVD-CWE-Other
|
CVE-2006-4080
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343779
|
- |
|
barracuda_networks
|
barracuda_spam_firewall
|
preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote attackers to execute commands via shell metacharacters ("|" pipe symbol) in the file parameter. NOTE: t…
|
NVD-CWE-Other
|
CVE-2006-4081
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343780
|
- |
|
barracuda_networks
|
barracuda_spam_firewall
|
Barracuda Spam Firewall (BSF), possibly 3.3.03.053, contains a hardcoded password for the admin account for logins from 127.0.0.1 (localhost), which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2006-4082
|
2018-10-18 06:33 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|