|
313601
|
- |
|
noah_medling
|
rcblog
|
Noah Medling RCBlog 1.03 stores the data and config directories under the web root with insufficient access control, which allows remote attackers to view account names and MD5 password hashes.
|
NVD-CWE-Other
|
CVE-2006-0370
|
2024-02-14 10:17 |
2006-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313602
|
- |
|
noah_medling
|
rcblog
|
Directory traversal vulnerability in index.php in Noah Medling RCBlog 1.03 allows remote attackers to read arbitrary .txt files, possibly including one that stores the administrator's account name an…
|
NVD-CWE-Other
|
CVE-2006-0371
|
2024-02-14 10:17 |
2006-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313603
|
- |
|
mike_helton
|
aoblogger
|
Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag.
|
NVD-CWE-Other
|
CVE-2006-0310
|
2024-02-14 10:17 |
2006-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313604
|
- |
|
mike_helton
|
aoblogger
|
SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
NVD-CWE-Other
|
CVE-2006-0311
|
2024-02-14 10:17 |
2006-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313605
|
- |
|
mike_helton
|
aoblogger
|
create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1.
|
NVD-CWE-Other
|
CVE-2006-0312
|
2024-02-14 10:17 |
2006-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313606
|
- |
|
ca broadcom
|
unicenter_remote_control brightstor_mobile_backup brightstor_arcserve_backup_laptops_desktops business_protection_suite desktop_protection_suite server_protection_suite
|
The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1…
|
CWE-399
Resource Management Errors
|
CVE-2006-0306
|
2024-02-14 10:17 |
2006-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313607
|
- |
|
carnegie_mellon_university
|
snmptrapd
|
Format string vulnerability in the snmp_input function in snmptrapd in CMU SNMP utilities (cmu-snmp) allows remote attackers to execute arbitrary code by sending crafted SNMP messages to UDP port 162.
|
NVD-CWE-Other
|
CVE-2006-0250
|
2024-02-14 10:17 |
2006-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313608
|
- |
|
helm_hosting
|
helm_hosting_control_panel
|
Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress p…
|
NVD-CWE-Other
|
CVE-2006-0211
|
2024-02-14 10:17 |
2006-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313609
|
- |
|
postnuke_software_foundation john_lim the_cacti_group mantis moodle mediabeez
|
postnuke adodb cacti mantis moodle mediabeez
|
The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8…
|
CWE-89
SQL Injection
|
CVE-2006-0146
|
2024-02-14 10:17 |
2006-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313610
|
- |
|
dave_carrigan
|
auth_ldap
|
Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the …
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2006-0150
|
2024-02-14 10:17 |
2006-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|