|
348701
|
4.9 |
MEDIUM
|
sun
|
solaris
|
Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors involving (1) the /net mount point and (2) the "-hosts" map in a mount point.
|
NVD-CWE-Other
|
CVE-2006-3783
|
2017-07-20 10:32 |
2006-07-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348702
|
7.5 |
HIGH
|
twiki
|
twiki
|
Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via an HTTP POST request containing a parameter name starting …
|
NVD-CWE-Other
|
CVE-2006-3819
|
2017-07-20 10:32 |
2006-07-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348703
|
4.3 |
MEDIUM
|
gerrit_van_aaken
|
loudblog
|
Cross-site scripting (XSS) vulnerability in loudblog/index.php in Loudblog before 0.5 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
NVD-CWE-Other
|
CVE-2006-3820
|
2017-07-20 10:32 |
2006-07-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348704
|
2.1 |
LOW
|
sun
|
solaris
|
The IPv4 implementation in Sun Solaris 10 before 20060721 allows local users to select routes that differ from the routing table, possibly facilitating firewall bypass or unauthorized network communi…
|
NVD-CWE-Other
|
CVE-2006-3825
|
2017-07-20 10:32 |
2006-07-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348705
|
6.5 |
MEDIUM
|
pablo_software_solutions
|
quick_n_easy_ftp_server
|
Buffer overflow in Quick 'n Easy FTP Server 3.0 allows remote authenticated users to execute arbitrary commands via a long argument to the LIST command, a different issue than CVE-2006-2027.
|
NVD-CWE-Other
|
CVE-2006-3844
|
2017-07-20 10:32 |
2006-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348706
|
9.3 |
HIGH
|
rarlab
|
winrar
|
Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a LHA archive.
|
NVD-CWE-Other
|
CVE-2006-3845
|
2017-07-20 10:32 |
2006-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348707
|
7.5 |
HIGH
|
gillius_programming
|
game_networking_engine
|
Format string vulnerability in the flush_output function in ConsoleStreambuf.cpp in Game Network Engine (GNE) 0.70 and earlier allows remote attackers to cause a denial of service (crash) and possibl…
|
NVD-CWE-Other
|
CVE-2006-3908
|
2017-07-20 10:32 |
2006-07-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348708
|
5.0 |
MEDIUM
|
microsoft
|
ie
|
Internet Explorer 6 on Windows XP SP2, when Outlook is installed, allows remote attackers to cause a denial of service (crash) by calling the NewDefaultItem function of an OVCtl (OVCtl.OVCtl.1) Activ…
|
NVD-CWE-Other
|
CVE-2006-3910
|
2017-07-20 10:32 |
2006-07-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348709
|
4.3 |
MEDIUM
|
solucija
|
snews
|
Cross-site scripting (XSS) vulnerability in snews.php in sNews (aka Solucija News) 1.4 allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.
|
NVD-CWE-Other
|
CVE-2006-3916
|
2017-07-20 10:32 |
2006-07-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348710
|
7.5 |
HIGH
|
sd_studio
|
sd_studio_cms
|
SQL injection vulnerability in index.php in SD Studio CMS allows remote attackers to execute arbitrary SQL commands via the (1) news_id, (2) tid, and (3) page_id parameters.
|
NVD-CWE-Other
|
CVE-2006-3919
|
2017-07-20 10:32 |
2006-07-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348711
|
4.0 |
MEDIUM
|
sun
|
java_system_application_server java_system_web_server
|
Sun Java System Application Server (SJSAS) 7 through 8.1 and Web Server (SJSWS) 6.0 and 6.1 allows remote authenticated users to read files outside of the "document root directory" via a direct reque…
|
NVD-CWE-Other
|
CVE-2006-3921
|
2017-07-20 10:32 |
2006-07-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348712
|
6.4 |
MEDIUM
|
interactual_technologies
|
interactual_player
|
Stack-based buffer overflow in ITIRecorder.MicRecorder ActiveX control in iarecord.dll in InterActual Player before 2.6 allows remote attackers to execute arbitrary code via a long argument to the Fi…
|
NVD-CWE-Other
|
CVE-2006-3925
|
2017-07-20 10:32 |
2006-07-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348713
|
7.5 |
HIGH
|
php_pro_bid
|
php_pro_bid
|
Multiple SQL injection vulnerabilities in PhpProBid 5.24 allow remote attackers to execute arbitrary SQL commands via the (1) view or (2) start parameters to (a) viewfeedback.php or the (3) orderType…
|
NVD-CWE-Other
|
CVE-2006-3926
|
2017-07-20 10:32 |
2006-08-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348714
|
4.3 |
MEDIUM
|
php_pro_bid
|
php_pro_bid
|
Cross-site scripting (XSS) vulnerability in auctionsearch.php in PhpProBid 5.24 allows remote attackers to inject arbitrary web script or HTML via the advsrc parameter.
|
NVD-CWE-Other
|
CVE-2006-3927
|
2017-07-20 10:32 |
2006-08-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348715
|
5.1 |
MEDIUM
|
gonafish
|
linkscaffe
|
SQL injection vulnerability in links.php in Gonafish LinksCaffe 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the provenance of this information is unkno…
|
NVD-CWE-Other
|
CVE-2006-3932
|
2017-07-20 10:32 |
2006-08-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348716
|
5.1 |
MEDIUM
|
gonafish
|
linkscaffe
|
Successful exploitation via the "cat" parameter requires that "magic_quotes_gpc" is disabled.
|
NVD-CWE-Other
|
CVE-2006-3932
|
2017-07-20 10:32 |
2006-08-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348717
|
7.5 |
HIGH
|
sun
|
n1_grid_engine
|
Unspecified vulnerability in the daemons for Sun N1 Grid Engine 5.3 and N1 Grid Engine 6.0 allows local users to cause a denial of service (grid service shutdown) and possibly execute arbitrary code …
|
NVD-CWE-noinfo
|
CVE-2006-3941
|
2017-07-20 10:32 |
2006-08-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348718
|
2.6 |
LOW
|
microsoft
|
ie
|
Stack-based buffer overflow in NDFXArtEffects in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via long (1) RGBExtraColor, (2) RGBForeCo…
|
NVD-CWE-Other
|
CVE-2006-3943
|
2017-07-20 10:32 |
2006-08-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348719
|
5.0 |
MEDIUM
|
microsoft
|
ie
|
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via a (1) Forms.ListBox.1 or (2) Forms.ListBox.1 object with the ListWidth property set to…
|
NVD-CWE-Other
|
CVE-2006-3944
|
2017-07-20 10:32 |
2006-08-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348720
|
7.5 |
HIGH
|
apple
|
safari mac_os_x
|
WebCore in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted HTML that triggers a "memory mana…
|
CWE-119
バッファエラー
|
CVE-2006-3946
|
2017-07-20 10:32 |
2006-08-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348721
|
7.5 |
HIGH
|
x-scripts
|
x-statistics
|
SQL injection vulnerability in x-statistics.php in X-Scripts X-Statistics 1.20 allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.
|
NVD-CWE-Other
|
CVE-2006-3950
|
2017-07-20 10:32 |
2006-08-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348722
|
7.5 |
HIGH
|
efs_software
|
efs_ftp_server
|
Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrary code via a long argument to the PASS command. NOTE: the provenance of this i…
|
NVD-CWE-Other
|
CVE-2006-3952
|
2017-07-20 10:32 |
2006-08-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348723
|
7.5 |
HIGH
|
x-scripts
|
x-statistics
|
SQL injection vulnerability in protect.php in X-Scripts X-Protection 1.10, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passw…
|
NVD-CWE-Other
|
CVE-2006-3959
|
2017-07-20 10:32 |
2006-08-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348724
|
5.0 |
MEDIUM
|
sun
|
solaris
|
The crypto provider in Sun Solaris 10 3/05 HW2 without patch 121236-01, when running on Sun Fire T2000 platforms, incorrectly verifies a DSA signature, which might prevent applications from detecting…
|
NVD-CWE-Other
|
CVE-2006-3968
|
2017-07-20 10:32 |
2006-08-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348725
|
6.8 |
MEDIUM
|
scott_weedon
|
ajax_chat
|
Cross-site scripting (XSS) vulnerability in visitor/livesupport/chat.php in Scott Weedon Ajax Chat, possibly 0.1, allows remote attackers to inject arbitrary web script or HTML via the userid paramet…
|
NVD-CWE-Other
|
CVE-2006-3971
|
2017-07-20 10:32 |
2006-08-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348726
|
5.0 |
MEDIUM
|
scott_weedon
|
ajax_chat
|
Directory traversal vulnerability in includes/operator_chattranscript.php in Scott Weedon Ajax Chat, possibly 0.1, allows remote attackers to read arbitrary files via a .. (dot dot) in the chatid par…
|
NVD-CWE-Other
|
CVE-2006-3972
|
2017-07-20 10:32 |
2006-08-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348727
|
7.2 |
HIGH
|
macromedia
|
coldfusion
|
The AdminAPI of ColdFusion MX 7 allows attackers to bypass authentication by using "programmatic access" to the adminAPI instead of the ColdFusion Administrator.
|
NVD-CWE-Other
|
CVE-2006-3979
|
2017-07-20 10:32 |
2006-08-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348728
|
7.5 |
HIGH
|
mambo
|
mambo_gallery_manager
|
PHP remote file inclusion vulnerability in about.mgm.php in Mambo Gallery Manager (MGM) 0.95r2 and earlier for Mambo 4.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConf…
|
NVD-CWE-Other
|
CVE-2006-3981
|
2017-07-20 10:32 |
2006-08-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348729
|
4.3 |
MEDIUM
|
drupal
|
drupal
|
Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: …
|
NVD-CWE-Other
|
CVE-2006-4002
|
2017-07-20 10:32 |
2006-08-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348730
|
4.3 |
MEDIUM
|
drupal
|
drupal
|
This vulnerability is addressed in the following product releases:
Drupal, Drupal, 4.6.9
Drupal, Drupal, 4.7.3
|
NVD-CWE-Other
|
CVE-2006-4002
|
2017-07-20 10:32 |
2006-08-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348731
|
5.0 |
MEDIUM
|
bomberclone
|
bomberclone
|
BomberClone 0.11.6 and earlier allows remote attackers to cause a denial of service (daemon crash) via (1) a certain malformed PKGF_ackreq packet, which triggers a crash in the rscache_add() function…
|
NVD-CWE-Other
|
CVE-2006-4005
|
2017-07-20 10:32 |
2006-08-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348732
|
5.0 |
MEDIUM
|
bomberclone
|
bomberclone
|
The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_pkg function (packets.c) to use this data size whe…
|
CWE-200
情報漏えい
|
CVE-2006-4006
|
2017-07-20 10:32 |
2006-08-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348733
|
7.6 |
HIGH
|
symantec
|
brightmail_antispam
|
Multiple directory traversal vulnerabilities in Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allow remote attackers to read and o…
|
CWE-22
パス・トラバーサル
|
CVE-2006-4013
|
2017-07-20 10:32 |
2006-08-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348734
|
5.0 |
MEDIUM
|
cisco
|
callmanager_express
|
Unspecified vulnerability in Cisco IOS CallManager Express (CME) allows remote attackers to gain sensitive information (user names) from the Session Initiation Protocol (SIP) user directory via certa…
|
NVD-CWE-Other
|
CVE-2006-4032
|
2017-07-20 10:32 |
2006-08-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348735
|
5.0 |
MEDIUM
|
cisco
|
callmanager_express
|
Cisco's recommended best practice of implementing the VoIP infrastructure and data devices on separate VLANs would prevent malicious users from launching such attacks against the VoIP network.
|
NVD-CWE-Other
|
CVE-2006-4032
|
2017-07-20 10:32 |
2006-08-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348736
|
7.5 |
HIGH
|
counterchaos
|
counterchaos
|
SQL injection vulnerability in counterchaos.php in CounterChaos 0.48c and earlier allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header.
|
NVD-CWE-Other
|
CVE-2006-4035
|
2017-07-20 10:32 |
2006-08-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348737
|
7.5 |
HIGH
|
pike
|
pike
|
SQL injection vulnerability in Pike before 7.6.86, when using a Postgres database server, allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors.
|
NVD-CWE-Other
|
CVE-2006-4041
|
2017-07-20 10:32 |
2006-08-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348738
|
7.5 |
HIGH
|
pike
|
pike
|
This vulnerability is addressed in the following product release:
Pike, Pike, 7.6.86
|
NVD-CWE-Other
|
CVE-2006-4041
|
2017-07-20 10:32 |
2006-08-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348739
|
7.5 |
HIGH
|
brad_fears
|
phpcodecabinet
|
PHP remote file inclusion vulnerability in Beautifier/Core.php in Brad Fears phpCodeCabinet 0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the BEAUT_PATH parameter.
|
NVD-CWE-Other
|
CVE-2006-4044
|
2017-07-20 10:32 |
2006-08-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348740
|
7.5 |
HIGH
|
netious_cms
|
netious_cms
|
SQL injection vulnerability in index.php in Netious CMS 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information…
|
NVD-CWE-Other
|
CVE-2006-4047
|
2017-07-20 10:32 |
2006-08-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348741
|
7.5 |
HIGH
|
netious_cms
|
netious_cms
|
Netious CMS 0.4 initializes session IDs based on the client IP address, which allows remote attackers to gain access to the administration section when originating from the same IP address as the adm…
|
NVD-CWE-Other
|
CVE-2006-4048
|
2017-07-20 10:32 |
2006-08-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348742
|
2.1 |
LOW
|
sun
|
ray_server_software
|
Unspecified vulnerability in the utxconfig utility in Sun Ray Server Software 3.x allows local users to create or overwrite arbitrary files via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-4049
|
2017-07-20 10:32 |
2006-08-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348743
|
7.5 |
HIGH
|
the_address_book the_address_book_reloaded
|
the_address_book the_address_book_reloaded
|
Multiple SQL injection vulnerabilities in the authentication process in katzlbt (a) The Address Book 1.04e and earlier and (b) The Address Book Reloaded before 2.0-rc4 allow remote attackers to execu…
|
NVD-CWE-Other
|
CVE-2006-4056
|
2017-07-20 10:32 |
2006-08-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348744
|
4.3 |
MEDIUM
|
cakefoundation
|
cakephp
|
Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 4…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-4067
|
2017-07-20 10:32 |
2006-08-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348745
|
7.5 |
HIGH
|
mywebland
|
myevent
|
PHP remote file inclusion vulnerability in viewevent.php in myWebland myEvent 1.x allows remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter, a different vector tha…
|
NVD-CWE-Other
|
CVE-2006-4083
|
2017-07-20 10:32 |
2006-08-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348746
|
7.5 |
HIGH
|
olaf_noehring
|
the_search_engine_project
|
PHP remote file inclusion vulnerability in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tsep_config[absPath]…
|
NVD-CWE-Other
|
CVE-2006-4085
|
2017-07-20 10:32 |
2006-08-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348747
|
4.3 |
MEDIUM
|
mojoscripts
|
mojogallery
|
Cross-site scripting (XSS) vulnerability in admin.cgi in mojoscripts.com mojoGallery allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: the provenance o…
|
NVD-CWE-Other
|
CVE-2006-4087
|
2017-07-20 10:32 |
2006-08-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348748
|
4.3 |
MEDIUM
|
mojoscripts
|
mojogallery
|
Cross-site scripting (XSS) vulnerability in admin.cgi in mojoscripts.com mojoGallery allows remote attackers to inject arbitrary web script or HTML via "password input."
|
NVD-CWE-Other
|
CVE-2006-4104
|
2017-07-20 10:32 |
2006-08-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348749
|
7.5 |
HIGH
|
drupal
|
job_search
|
SQL injection vulnerability in the Job Search module (job.module) 4.6 before revision 1.3.2.1 in Drupal allows remote attackers to execute arbitrary SQL commands via a job or resume search.
|
NVD-CWE-Other
|
CVE-2006-4107
|
2017-07-20 10:32 |
2006-08-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348750
|
7.5 |
HIGH
|
drupal
|
bibliography_module
|
SQL injection vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote attackers to execute arbitrary SQL commands via …
|
NVD-CWE-Other
|
CVE-2006-4108
|
2017-07-20 10:32 |
2006-08-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|