|
313781
|
- |
|
simplog
|
simplog
|
Directory traversal vulnerability in index.php in Daverave Simplog 1.0.2 and earlier allows remote attackers to include or read arbitrary .txt files via the (1) act and (2) blogid parameters.
|
NVD-CWE-Other
|
CVE-2006-1073
|
2024-02-14 10:17 |
2006-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313782
|
- |
|
intensive_point
|
iuser_ecommerce
|
Multiple unspecified vulnerabilities in Intensive Point iUser Ecommerce before 2.2 have unspecified vectors and impact, as addressed by "Urgent secure fixes". NOTE: this might be a duplicate of CVE-…
|
NVD-CWE-noinfo
|
CVE-2006-0874
|
2024-02-14 10:17 |
2006-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313783
|
- |
|
bluecoat
|
sgos
|
Blue Coat Proxy Security Gateway OS (SGOS) 4.1.2.1 does not enforce CONNECT rules when using Deep Content Inspection, which allows remote attackers to bypass connection filters.
|
NVD-CWE-Other
|
CVE-2006-0578
|
2024-02-14 10:17 |
2006-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313784
|
- |
|
gallery_project
|
gallery
|
Unspecified vulnerability in util.php in Gallery before 1.5.2-pl2 allows remote authenticated users with trick an owner into modifying stored album data and possibly executing arbitrary code via unsp…
|
NVD-CWE-Other
|
CVE-2006-0587
|
2024-02-14 10:17 |
2006-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313785
|
- |
|
noah_medling
|
rcblog
|
Noah Medling RCBlog 1.03 stores the data and config directories under the web root with insufficient access control, which allows remote attackers to view account names and MD5 password hashes.
|
NVD-CWE-Other
|
CVE-2006-0370
|
2024-02-14 10:17 |
2006-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313786
|
- |
|
noah_medling
|
rcblog
|
Directory traversal vulnerability in index.php in Noah Medling RCBlog 1.03 allows remote attackers to read arbitrary .txt files, possibly including one that stores the administrator's account name an…
|
NVD-CWE-Other
|
CVE-2006-0371
|
2024-02-14 10:17 |
2006-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313787
|
- |
|
mike_helton
|
aoblogger
|
Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag.
|
NVD-CWE-Other
|
CVE-2006-0310
|
2024-02-14 10:17 |
2006-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313788
|
- |
|
mike_helton
|
aoblogger
|
SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
NVD-CWE-Other
|
CVE-2006-0311
|
2024-02-14 10:17 |
2006-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313789
|
- |
|
mike_helton
|
aoblogger
|
create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1.
|
NVD-CWE-Other
|
CVE-2006-0312
|
2024-02-14 10:17 |
2006-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313790
|
- |
|
ca broadcom
|
unicenter_remote_control brightstor_mobile_backup brightstor_arcserve_backup_laptops_desktops business_protection_suite desktop_protection_suite server_protection_suite
|
The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1…
|
CWE-399
Resource Management Errors
|
CVE-2006-0306
|
2024-02-14 10:17 |
2006-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|