|
348751
|
4.3 |
MEDIUM
|
drupal
|
bibliography_module
|
Cross-site scripting (XSS) vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote attackers to inject arbitrary web s…
|
NVD-CWE-Other
|
CVE-2006-4109
|
2017-07-20 10:32 |
2006-08-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348752
|
5.4 |
MEDIUM
|
sun
|
solaris
|
The squeue_drain function in Sun Solaris 10, possibly only when run on CMT processors, allows remote attackers to cause a denial of service ("bad trap" and system panic) by opening and closing a larg…
|
NVD-CWE-Other
|
CVE-2006-4117
|
2017-07-20 10:32 |
2006-08-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348753
|
5.4 |
MEDIUM
|
sun
|
solaris
|
It is reportedly unlikely that this affects systems not using CMT processors.
|
NVD-CWE-Other
|
CVE-2006-4117
|
2017-07-20 10:32 |
2006-08-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348754
|
5.1 |
MEDIUM
|
chaossoft
|
geheimchaos
|
SQL injection vulnerability in gc.php in GeheimChaos 0.5 and earlier allows remote attackers to execute arbitrary SQL commands via the Temp_entered_password parameter. NOTE: the provenance of this i…
|
NVD-CWE-Other
|
CVE-2006-4119
|
2017-07-20 10:32 |
2006-08-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348755
|
5.1 |
MEDIUM
|
chaossoft
|
geheimchaos
|
Successful exploitation requires that "magic_quotes_gpc" is disabled.
|
NVD-CWE-Other
|
CVE-2006-4119
|
2017-07-20 10:32 |
2006-08-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348756
|
5.1 |
MEDIUM
|
drupal
|
drupal recipe_module
|
Cross-site scripting (XSS) vulnerability in the Recipe module (recipe.module) before 1.54 for Drupal 4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vec…
|
NVD-CWE-Other
|
CVE-2006-4120
|
2017-07-20 10:32 |
2006-08-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348757
|
5.1 |
MEDIUM
|
drupal
|
drupal recipe_module
|
If you do not use the Recipe Module, or use Recipe Module version 1.54 or later, you are not affected by this vulnerability.
This vulnerability has been addressed in the latest patch for:
Drupal, D…
|
NVD-CWE-Other
|
CVE-2006-4120
|
2017-07-20 10:32 |
2006-08-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348758
|
5.4 |
MEDIUM
|
sun
|
solaris
|
Race condition in Sun Solaris 10 allows attackers to cause a denial of service (system panic) via unspecified vectors related to ifconfig and either netstat or SNMP queries.
|
NVD-CWE-Other
|
CVE-2006-4139
|
2017-07-20 10:32 |
2006-08-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348759
|
6.8 |
MEDIUM
|
netcommons
|
netcommons
|
Cross-site scripting (XSS) vulnerability in NetCommons 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-4165
|
2017-07-20 10:32 |
2006-08-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348760
|
6.8 |
MEDIUM
|
netcommons
|
netcommons
|
This vulnerability is addressed in the following product release:
NetCommons, NetCommons, 1.0.9
|
NVD-CWE-Other
|
CVE-2006-4165
|
2017-07-20 10:32 |
2006-08-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348761
|
5.1 |
MEDIUM
|
boonex
|
dolphin
|
Multiple PHP remote file inclusion vulnerabilities in Dolphin 5.1 allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) index.php, (2) aemodule.php, (3) brow…
|
NVD-CWE-Other
|
CVE-2006-4189
|
2017-07-20 10:32 |
2006-08-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348762
|
6.8 |
MEDIUM
|
soft3304
|
04webserver
|
Cross-site scripting (XSS) vulnerability in Soft3304 04WebServer 1.83 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly sanitized before it…
|
NVD-CWE-Other
|
CVE-2006-4199
|
2017-07-20 10:32 |
2006-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348763
|
6.8 |
MEDIUM
|
soft3304
|
04webserver
|
This vulnerability is addressed in the following product release:
Soft3304, 04WebServer, 1.84
|
NVD-CWE-Other
|
CVE-2006-4199
|
2017-07-20 10:32 |
2006-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348764
|
7.5 |
HIGH
|
soft3304
|
04webserver
|
Unspecified vulnerability in 04WebServer 1.83 and earlier allows remote attackers to bypass user authentication via unspecified vectors related to request processing.
|
NVD-CWE-Other
|
CVE-2006-4200
|
2017-07-20 10:32 |
2006-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348765
|
7.5 |
HIGH
|
soft3304
|
04webserver
|
This vulnerability is addressed in the following product release:
Soft3304, 04WebServer, 1.84
|
NVD-CWE-Other
|
CVE-2006-4200
|
2017-07-20 10:32 |
2006-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348766
|
7.5 |
HIGH
|
hp
|
openview_storage_data_protector
|
Unspecified vulnerability in the backup agent and Cell Manager in HP OpenView Storage Data Protector 5.1 and 5.5 before 20060810 allows remote attackers to execute arbitrary code on an agent via unsp…
|
NVD-CWE-Other
|
CVE-2006-4201
|
2017-07-20 10:32 |
2006-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348767
|
7.5 |
HIGH
|
hp
|
openview_storage_data_protector
|
A patch is available for affected versions.
|
NVD-CWE-Other
|
CVE-2006-4201
|
2017-07-20 10:32 |
2006-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348768
|
4.3 |
MEDIUM
|
b0zz_and_chris_vincent
|
owl_intranet_engine
|
Cross-site scripting (XSS) vulnerability in b0zz and Chris Vincent Owl Intranet Engine 0.90 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-4211
|
2017-07-20 10:32 |
2006-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348769
|
4.3 |
MEDIUM
|
b0zz_and_chris_vincent
|
owl_intranet_engine
|
Upgrade to Owl Intranet Engine version 0.91
|
NVD-CWE-Other
|
CVE-2006-4211
|
2017-07-20 10:32 |
2006-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348770
|
7.5 |
HIGH
|
b0zz_and_chris_vincent
|
owl_intranet_engine
|
SQL injection vulnerability in b0zz and Chris Vincent Owl Intranet Engine 0.90 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-4212
|
2017-07-20 10:32 |
2006-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348771
|
7.5 |
HIGH
|
zen_cart
|
zen_cart
|
Multiple SQL injection vulnerabilities in Zen Cart 1.3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) GPC data to the ipn_get_stored_session function in ipn_main_han…
|
CWE-89
SQLインジェクション
|
CVE-2006-4214
|
2017-07-20 10:32 |
2006-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348772
|
5.1 |
MEDIUM
|
zen_cart
|
zen_cart
|
PHP remote file inclusion vulnerability in index.php in Zen Cart 1.3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the autoLoad…
|
CWE-94
コード・インジェクション
|
CVE-2006-4215
|
2017-07-20 10:32 |
2006-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348773
|
7.5 |
HIGH
|
webinsta
|
webinsta_cms
|
PHP remote file inclusion vulnerability in modules/usersonline/users.php in WEBInsta CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the module_dir parameter, a different…
|
NVD-CWE-Other
|
CVE-2006-4217
|
2017-07-20 10:32 |
2006-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348774
|
7.5 |
HIGH
|
zen_cart
|
zen_cart
|
Directory traversal vulnerability in Zen Cart 1.3.0.2 and earlier allows remote attackers to include and possibly execute arbitrary local files via directory traversal sequences in the typefilter par…
|
NVD-CWE-Other
|
CVE-2006-4218
|
2017-07-20 10:32 |
2006-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348775
|
1.2 |
LOW
|
globus
|
globus_toolkit
|
Race condition in the grid-proxy-init tool in Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allows local users to steal credential data by replacing the proxy credentials file in between fil…
|
NVD-CWE-Other
|
CVE-2006-4232
|
2017-07-20 10:32 |
2006-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348776
|
3.6 |
LOW
|
globus
|
globus_toolkit
|
Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allow local users to obtain sensitive information (proxy certificates) and overwrite arbitrary files via a symlink attack on temporary files in …
|
NVD-CWE-Other
|
CVE-2006-4233
|
2017-07-20 10:32 |
2006-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348777
|
7.5 |
HIGH
|
sony
|
sonicstage_mastering_studio
|
Buffer overflow in the import project functionality in Sony SonicStage Mastering Studio 1.1.00 through 2.2.01 allows remote attackers to execute arbitrary code via a crafted SMP file.
|
NVD-CWE-Other
|
CVE-2006-4235
|
2017-07-20 10:32 |
2006-08-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348778
|
7.5 |
HIGH
|
sony
|
sonicstage_mastering_studio
|
This vulnerability is addressed in the following product releases:
Sony, SonicStage Mastering Studio, 1.2.04
Sony, SonicStage Mastering Studio, 1.4.04
Sony, SonicStage Mastering Studio, 2.2.04
|
NVD-CWE-Other
|
CVE-2006-4235
|
2017-07-20 10:32 |
2006-08-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348779
|
7.5 |
HIGH
|
fusionphp
|
fusion_news
|
PHP remote file inclusion vulnerability in index.php in Fusion News 3.7 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter.
|
NVD-CWE-Other
|
CVE-2006-4240
|
2017-07-20 10:32 |
2006-08-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348780
|
3.6 |
LOW
|
usermin
|
usermin
|
Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell parameter, which results in changing root's she…
|
NVD-CWE-Other
|
CVE-2006-4246
|
2017-07-20 10:32 |
2006-09-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348781
|
3.6 |
LOW
|
usermin
|
usermin
|
This vulnerability is addressed in the following product release:
Webmin, Usermin, 1.220
|
NVD-CWE-Other
|
CVE-2006-4246
|
2017-07-20 10:32 |
2006-09-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348782
|
7.5 |
HIGH
|
ibm
|
aix
|
Unspecified vulnerability in setlocale in IBM AIX 5.1.0 through 5.3.0 allows local users to gain privileges via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-4254
|
2017-07-20 10:32 |
2006-08-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348783
|
7.5 |
HIGH
|
ibm
|
aix
|
IBM has released an advisory and interim fixes to address this issue.
|
NVD-CWE-Other
|
CVE-2006-4254
|
2017-07-20 10:32 |
2006-08-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348784
|
4.0 |
MEDIUM
|
john_hanna
|
anti-spam_smtp_proxy_server
|
Absolute path traversal vulnerability in the get functionality in Anti-Spam SMTP Proxy (ASSP) allows remote authenticated users to read arbitrary files via (1) C:\ (Windows drive letter), (2) UNC, an…
|
NVD-CWE-Other
|
CVE-2006-4258
|
2017-07-20 10:32 |
2006-08-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348785
|
2.6 |
LOW
|
jake_olefsky
|
fotopholder
|
Cross-site scripting (XSS) vulnerability in index.php in Fotopholder 1.8 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: this might be resultant from a d…
|
NVD-CWE-Other
|
CVE-2006-4259
|
2017-07-20 10:32 |
2006-08-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348786
|
5.0 |
MEDIUM
|
jake_olefsky
|
fotopholder
|
Directory traversal vulnerability in index.php in Fotopholder 1.8 allows remote attackers to read arbitrary directories or files via a .. (dot dot) in the path parameter.
|
NVD-CWE-Other
|
CVE-2006-4260
|
2017-07-20 10:32 |
2006-08-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348787
|
7.5 |
HIGH
|
tutti_nova
|
tutti_nova
|
Multiple PHP remote file inclusion vulnerabilities in Tutti Nova 1.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to (1) include/novalib/class…
|
NVD-CWE-Other
|
CVE-2006-4277
|
2017-07-20 10:32 |
2006-08-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348788
|
7.5 |
HIGH
|
arthur_konze_webdesign
|
akocomment
|
PHP remote file inclusion vulnerability in akocomments.php in AkoComment 1.1 module (com_akocomment) for Mambo 4.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_abs…
|
NVD-CWE-Other
|
CVE-2006-4281
|
2017-07-20 10:32 |
2006-08-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348789
|
10.0 |
HIGH
|
sony
|
vaio_media_server
|
Buffer overflow in Sony VAIO Media Server 2.x, 3.x, 4.x, and 5.x before 20060626 allows remote attackers to execute arbitrary code via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-4289
|
2017-07-20 10:32 |
2006-08-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348790
|
5.0 |
MEDIUM
|
sony
|
vaio_media_server
|
Directory traversal vulnerability in Sony VAIO Media Server 2.x, 3.x, 4.x, and 5.x before 20060626 allows remote attackers to gain sensitive information via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-4290
|
2017-07-20 10:32 |
2006-08-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348791
|
5.0 |
MEDIUM
|
niels_provos
|
honeyd
|
Unspecified vulnerability in Niels Provos Honeyd before 1.5b allows remote attackers to cause a denial of service (application crash) via certain Address Resolution Protocol (ARP) packets.
|
NVD-CWE-Other
|
CVE-2006-4292
|
2017-07-20 10:32 |
2006-08-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348792
|
5.0 |
MEDIUM
|
oscommerce
|
oscommerce
|
Multiple directory traversal vulnerabilities in cache.php in osCommerce before 2.2 Milestone 2 060817 allow remote attackers to determine existence of arbitrary files and disclose the installation pa…
|
NVD-CWE-Other
|
CVE-2006-4298
|
2017-07-20 10:32 |
2006-08-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348793
|
4.3 |
MEDIUM
|
tiki
|
tikiwiki_cms\/groupware
|
Cross-site scripting (XSS) vulnerability in tiki-searchindex.php in TikiWiki 1.9.4 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter. NOTE: the provenance of…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-4299
|
2017-07-20 10:32 |
2006-08-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348794
|
2.6 |
LOW
|
sun
|
solaris
|
Race condition in (1) libnsl and (2) TLI/XTI API routines in Sun Solaris 10 allows remote attackers to cause a denial of service ("tight loop" and CPU consumption for listener applications) via unkno…
|
NVD-CWE-Other
|
CVE-2006-4303
|
2017-07-20 10:32 |
2006-08-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348795
|
10.0 |
HIGH
|
freebsd netbsd openbsd
|
freebsd netbsd openbsd
|
Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 allows remote attackers to cause a denial of servi…
|
NVD-CWE-Other
|
CVE-2006-4304
|
2017-07-20 10:32 |
2006-08-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348796
|
7.5 |
HIGH
|
mywebland
|
myevent
|
Multiple SQL injection vulnerabilities in myEvent 1.x allow remote attackers to inject arbitrary SQL commands via the event_id parameter to (1) addevent.php or (2) del.php or (3) event_desc parameter…
|
NVD-CWE-Other
|
CVE-2006-1907
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348797
|
2.6 |
LOW
|
mywebland
|
myevent
|
Cross-site scripting vulnerability in addevent.php in myEvent 1.x allows remote attackers to inject arbitrary web script or HTML via the event_desc parameter. NOTE: the provenance of this informatio…
|
NVD-CWE-Other
|
CVE-2006-1908
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348798
|
5.0 |
MEDIUM
|
coppermine
|
coppermine_photo_gallery
|
Directory traversal vulnerability in index.php in Coppermine 1.4.4 allows remote attackers to read arbitrary files via a .//./ (modified dot dot slash) in the file parameter, which causes a regular e…
|
NVD-CWE-Other
|
CVE-2006-1909
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348799
|
4.3 |
MEDIUM
|
mybulletinboard
|
mybulletinboard
|
Cross-site scripting (XSS) vulnerability in MyBB (MyBulletinBoard) 1.1 allows remote attackers to inject arbitrary web script or HTML via the attachment content disposition in an HTML attachment.
|
NVD-CWE-Other
|
CVE-2006-1911
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348800
|
4.3 |
MEDIUM
|
mybulletinboard
|
mybulletinboard
|
This vulnerability is addressed in the following product release:
MyBB, MyBB, 1.1.1
|
NVD-CWE-Other
|
CVE-2006-1911
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|