|
315251
|
- |
|
seyeon
|
flexwatch_network_camera
|
Directory traversal vulnerability in FlexWATCH Network Camera 3.0 and earlier allows remote attackers to bypass access restrictions for (1) admin/aindex.asp or (2) admin/aindex.html via a .. (dot dot…
|
NVD-CWE-Other
|
CVE-2006-3604
|
2024-02-14 10:17 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315252
|
- |
|
bosdev
|
bosclassifieds_classified_ads
|
Multiple PHP remote file inclusion vulnerabilities in BosClassifieds Classified Ads allow remote attackers to execute arbitrary PHP code via a URL in the insPath parameter to (1) index.php, (2) recen…
|
NVD-CWE-Other
|
CVE-2006-3527
|
2024-02-14 10:17 |
2006-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315253
|
- |
|
webdesignhq
|
sitebuilder-fx
|
PHP remote file inclusion vulnerability in top.php in SiteBuilder-FX 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter.
|
CWE-94
Code Injection
|
CVE-2006-3395
|
2024-02-14 10:17 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315254
|
- |
|
pkr_internet
|
taskjitsu
|
Multiple cross-site scripting (XSS) vulnerabilities in Taskjitsu before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters, including the (1) titl…
|
NVD-CWE-Other
|
CVE-2006-3397
|
2024-02-14 10:17 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315255
|
- |
|
pkr_internet
|
taskjitsu
|
The "change password forms" in Taskjitsu before 2.0.1 includes password hashes in hidden form fields, which allows remote attackers to obtain sensitive information from the (1) Category Editor and (2…
|
NVD-CWE-Other
|
CVE-2006-3398
|
2024-02-14 10:17 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315256
|
- |
|
siemens
|
speedstream_wireless_router
|
Siemens Speedstream Wireless Router 2624 allows local users to bypass authentication and access protected files by using the Universal Plug and Play UPnP/1.0 component.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-3344
|
2024-02-14 10:17 |
2006-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315257
|
- |
|
netsoft
|
smartnet
|
Cross-site scripting (XSS) vulnerability in search.jsp in Netsoft smartNet 2.0 allows remote attackers to inject arbitrary web script or HTML via the keyWord parameter.
|
NVD-CWE-Other
|
CVE-2006-3313
|
2024-02-14 10:17 |
2006-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315258
|
- |
|
namo
|
deepsearch
|
Cross-site scripting (XSS) vulnerability in mclient.cgi in Namo DeepSearch 4.5 allows remote attackers to inject arbitrary web script or HTML via the p parameter.
|
NVD-CWE-Other
|
CVE-2006-3264
|
2024-02-14 10:17 |
2006-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315259
|
- |
|
microsoft
|
windows_live_messenger
|
Heap-based buffer overflow in Windows Live Messenger 8.0 allows user-assisted attackers to execute arbitrary code via a crafted Contact List (.ctt) file, which triggers the overflow when it is import…
|
NVD-CWE-Other
|
CVE-2006-3250
|
2024-02-14 10:17 |
2006-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315260
|
- |
|
ultimate_php_board
|
ultimate_php_board
|
The installation of Ultimate PHP Board (UPB) 1.9.6 and earlier includes a default administrator login account and password, which allows remote attackers to gain privileges.
|
CWE-255
Credentials Management
|
CVE-2006-3203
|
2024-02-14 10:17 |
2006-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|