|
343871
|
- |
|
alkacon
|
opencms
|
Absolute path traversal vulnerability in downloadTrigger.jsp in Alkacon OpenCms before 6.2.2 allows remote authenticated users to download arbitrary files via an absolute pathname in the filePath par…
|
CWE-22
Path Traversal
|
CVE-2006-3934
|
2018-10-18 06:32 |
2006-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343872
|
- |
|
alkacon
|
opencms
|
This vulnerability is addressed in the following product release:
Alkacon, OpenCms, 6.2.2
|
CWE-22
Path Traversal
|
CVE-2006-3934
|
2018-10-18 06:32 |
2006-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343873
|
- |
|
alkacon
|
opencms
|
system/workplace/views/admin/admin-main.jsp in Alkacon OpenCms before 6.2.2 does not restrict access to administrator functions, which allows remote authenticated users to (1) send broadcast messages…
|
NVD-CWE-Other
|
CVE-2006-3935
|
2018-10-18 06:32 |
2006-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343874
|
- |
|
alkacon
|
opencms
|
system/workplace/editors/editor.jsp in Alkacon OpenCms before 6.2.2 allows remote authenticated users to read the source code of arbitrary JSP files by specifying the file in the resource parameter, …
|
NVD-CWE-Other
|
CVE-2006-3936
|
2018-10-18 06:32 |
2006-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343875
|
- |
|
xguestbook
|
xguestbook
|
post.php in x_atrix xGuestBook 1.02 allows remote attackers to obtain sensitive information via a request without the (1) user, (2) mail, (3) p, or (4) url parameter, which reveals the installation p…
|
NVD-CWE-Other
|
CVE-2006-3937
|
2018-10-18 06:32 |
2006-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343876
|
- |
|
dotclear
|
dotclear
|
DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.php in ecrire/tools/blogroll/; (4) syslog/index.php, (5) theme…
|
NVD-CWE-Other
|
CVE-2006-3938
|
2018-10-18 06:32 |
2006-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343877
|
- |
|
scriptscenter
|
ezupload_pro
|
ScriptsCenter ezUpload Pro 2.2.0 allows remote attackers to perform administrative activities without authentication in (1) filter.php, which permits changing the Extensions Mode file type; (2) acces…
|
NVD-CWE-Other
|
CVE-2006-3939
|
2018-10-18 06:32 |
2006-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343878
|
- |
|
phpbb_group
|
phpbb-auction
|
Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auction_room.php and (2) the u parameter in auction_store.…
|
NVD-CWE-Other
|
CVE-2006-3940
|
2018-10-18 06:32 |
2006-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343879
|
- |
|
microsoft
|
windows_2000 windows_2003_server windows_xp
|
The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that cont…
|
CWE-20
Improper Input Validation
|
CVE-2006-3942
|
2018-10-18 06:32 |
2006-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343880
|
- |
|
mambo
|
mambatstaff
|
PHP remote file inclusion vulnerability in components/com_mambatstaff/mambatstaff.php in the Mambatstaff 3.1b and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via…
|
CWE-94
Code Injection
|
CVE-2006-3947
|
2018-10-18 06:32 |
2006-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|