|
344881
|
- |
|
sun
|
java_system_access_manager
|
Unspecified vulnerability in Sun Java System Access Manager 7.0 allows local users logged in as "root" to bypass authentication and gain top-level administrator privileges via the amadmin CLI tool.
|
NVD-CWE-Other
|
CVE-2006-0531
|
2017-10-11 10:30 |
2006-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344882
|
- |
|
kinesphere_corporation
|
exchange_pop3
|
Buffer overflow in the POP3 server in Kinesphere Corporation eXchange before 5.0.060125 allows remote attackers to execute arbitrary code via a long RCPT TO argument.
|
NVD-CWE-Other
|
CVE-2006-0537
|
2017-10-11 10:30 |
2006-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344883
|
- |
|
fckeditor
|
fckeditor
|
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the fi…
|
NVD-CWE-Other
|
CVE-2006-0658
|
2017-10-11 10:30 |
2006-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344884
|
- |
|
fckeditor
|
fckeditor
|
Per: http://cwe.mitre.org/data/definitions/184.html
'CWE-184: Incomplete Blacklist'
|
NVD-CWE-Other
|
CVE-2006-0658
|
2017-10-11 10:30 |
2006-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344885
|
- |
|
sun
|
solaris
|
Unspecified vulnerability in in.rexecd in Solaris 10 allows local users to gain privileges on Kerberos systems via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-0769
|
2017-10-11 10:30 |
2006-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344886
|
- |
|
php
|
php
|
Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large numb…
|
CWE-79
Cross-site Scripting
|
CVE-2006-0996
|
2017-10-11 10:30 |
2006-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344887
|
- |
|
fscripts
|
fantastic_news
|
PHP remote file inclusion vulnerability in archive.php in Fantastic News 2.1.2 allows remote attackers to include arbitrary files via the CONFIG[script_path] variable. NOTE: 2.1.4 was also reported …
|
CWE-94
Code Injection
|
CVE-2006-1154
|
2017-10-11 10:30 |
2006-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344888
|
- |
|
hp
|
hp-ux
|
Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all direct…
|
NVD-CWE-Other
|
CVE-2006-1248
|
2017-10-11 10:30 |
2006-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344889
|
- |
|
light_weight_calendar
|
light_weight_calendar
|
Eval injection vulnerability in cal.php in Light Weight Calendar (LWC) 1.0 allows remote attackers to execute arbitrary PHP code via the date parameter to index.php.
|
NVD-CWE-Other
|
CVE-2006-1252
|
2017-10-11 10:30 |
2006-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344890
|
- |
|
php_icalendar
|
php_icalendar
|
publish.ical.php in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier does not require authentication for write access to the calendars directory, which allows remote attackers to upload and exec…
|
NVD-CWE-Other
|
CVE-2006-1291
|
2017-10-11 10:30 |
2006-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|