|
314401
|
- |
|
pkr_internet
|
taskjitsu
|
The "change password forms" in Taskjitsu before 2.0.1 includes password hashes in hidden form fields, which allows remote attackers to obtain sensitive information from the (1) Category Editor and (2…
|
NVD-CWE-Other
|
CVE-2006-3398
|
2024-02-14 10:17 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314402
|
- |
|
siemens
|
speedstream_wireless_router
|
Siemens Speedstream Wireless Router 2624 allows local users to bypass authentication and access protected files by using the Universal Plug and Play UPnP/1.0 component.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-3344
|
2024-02-14 10:17 |
2006-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314403
|
- |
|
netsoft
|
smartnet
|
Cross-site scripting (XSS) vulnerability in search.jsp in Netsoft smartNet 2.0 allows remote attackers to inject arbitrary web script or HTML via the keyWord parameter.
|
NVD-CWE-Other
|
CVE-2006-3313
|
2024-02-14 10:17 |
2006-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314404
|
- |
|
namo
|
deepsearch
|
Cross-site scripting (XSS) vulnerability in mclient.cgi in Namo DeepSearch 4.5 allows remote attackers to inject arbitrary web script or HTML via the p parameter.
|
NVD-CWE-Other
|
CVE-2006-3264
|
2024-02-14 10:17 |
2006-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314405
|
- |
|
microsoft
|
windows_live_messenger
|
Heap-based buffer overflow in Windows Live Messenger 8.0 allows user-assisted attackers to execute arbitrary code via a crafted Contact List (.ctt) file, which triggers the overflow when it is import…
|
NVD-CWE-Other
|
CVE-2006-3250
|
2024-02-14 10:17 |
2006-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314406
|
- |
|
ultimate_php_board
|
ultimate_php_board
|
The installation of Ultimate PHP Board (UPB) 1.9.6 and earlier includes a default administrator login account and password, which allows remote attackers to gain privileges.
|
CWE-255
Credentials Management
|
CVE-2006-3203
|
2024-02-14 10:17 |
2006-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314407
|
- |
|
ultimate_php_board
|
ultimate_php_board
|
Ultimate PHP Board (UPB) 1.9.6 and earlier uses a cryptographically weak block cipher with a large key collision space, which allows remote attackers to determine a suitable decryption key given the …
|
NVD-CWE-Other
|
CVE-2006-3204
|
2024-02-14 10:17 |
2006-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314408
|
- |
|
ultimate_php_board
|
ultimate_php_board
|
Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to gain access via modified user_env, pass_env, power_env, and id_env parameters in a cookie, which comprise a persistent logon that…
|
NVD-CWE-Other
|
CVE-2006-3205
|
2024-02-14 10:17 |
2006-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314409
|
- |
|
ultimate_php_board
|
ultimate_php_board
|
Direct static code injection vulnerability in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote authenticated administrators to execute arbitrary PHP code via multiple unspecified "configurati…
|
NVD-CWE-Other
|
CVE-2006-3208
|
2024-02-14 10:17 |
2006-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314410
|
- |
|
viart
|
shop
|
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Free 2.5.5, and possibly other distributions including Light, Standard, and Enterprise, allow remote attackers to inject arbitrary we…
|
NVD-CWE-Other
|
CVE-2006-2979
|
2024-02-14 10:17 |
2006-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|