|
348801
|
6.8 |
MEDIUM
|
jax_scripts
|
jax_guestbook
|
Cross-site scripting (XSS) vulnerability in jax_guestbook.php in Jax Guestbook 3.1, 3.31, and 3.50 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
NVD-CWE-Other
|
CVE-2006-1913
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348802
|
5.0 |
MEDIUM
|
dbbs
|
dbbs
|
DbbS 2.0-alpha and earlier allows remote attackers to obtain sensitive information via an invalid (1) fcategoryid parameter to topics.php or (2) unavariabile, (3) GLOBALS, or (4) _SERVER[] parameters…
|
NVD-CWE-Other
|
CVE-2006-1914
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348803
|
6.8 |
MEDIUM
|
dbbs
|
dbbs
|
Multiple cross-site scripting (XSS) vulnerabilities in profile.php in DbbS 2.0-alpha and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ulocation or (2) uhobbies pa…
|
NVD-CWE-Other
|
CVE-2006-1916
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348804
|
6.4 |
MEDIUM
|
pmtool
|
pmtool
|
SQL injection vulnerability in index.php in PMTool 1.2.2 allows remote attackers to execute arbitrary SQL commands via the order parameter in the include files (1) user.inc.php, (2) customer.inc.php,…
|
NVD-CWE-Other
|
CVE-2006-1920
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348805
|
5.8 |
MEDIUM
|
linpha
|
linpha
|
Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) RSS/RSS.php and (2) possibly other vectors.
|
NVD-CWE-Other
|
CVE-2006-1923
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348806
|
6.4 |
MEDIUM
|
linpha
|
linpha
|
SQL injection vulnerability in functions/db_api.php in LinPHA 1.1.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
|
NVD-CWE-Other
|
CVE-2006-1924
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348807
|
5.0 |
MEDIUM
|
cisco
|
ios_xr
|
Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 or Cisco 12000 series routers, allows remote attackers to cause a denial of service (Line card crash…
|
NVD-CWE-Other
|
CVE-2006-1927
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348808
|
5.0 |
MEDIUM
|
cisco
|
ios_xr
|
Only systems that are running Cisco IOS XR and configured for MPLS are affected by this vulnerability.
|
NVD-CWE-Other
|
CVE-2006-1927
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348809
|
5.0 |
MEDIUM
|
cisco
|
ios_xr
|
Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 routers, allows remote attackers to cause a denial of service (Modular Services Cards (MSC) crash or…
|
NVD-CWE-Other
|
CVE-2006-1928
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348810
|
5.0 |
MEDIUM
|
i-rater
|
i-rater_platinum
|
PHP remote file inclusion vulnerability in include/common.php in I-Rater Platinum allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.
|
NVD-CWE-Other
|
CVE-2006-1929
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348811
|
2.6 |
LOW
|
smarter_scripts
|
intellilink_pro
|
Multiple cross-site scripting (XSS) vulnerabilities in Smarter Scripts IntelliLink Pro 5.06 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter in addl…
|
NVD-CWE-Other
|
CVE-2006-1943
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348812
|
2.6 |
LOW
|
sibsoft
|
communimail
|
Multiple cross-site scripting (XSS) vulnerabilities in SibSoft CommuniMail 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the list_id parameter in mailadmin.cgi…
|
NVD-CWE-Other
|
CVE-2006-1944
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348813
|
2.6 |
LOW
|
visale
|
visale
|
Multiple cross-site scripting (XSS) vulnerabilities in Visale 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the keyval parameter in pbpgst.cgi, (2) the catsubn…
|
NVD-CWE-Other
|
CVE-2006-1946
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348814
|
7.5 |
HIGH
|
nicplex
|
plexum
|
Multiple SQL injection vulnerabilities in plexum.php in NicPlex Plexum X5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pagesize, (2) maxrec, and (3) startpos param…
|
NVD-CWE-Other
|
CVE-2006-1947
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348815
|
7.5 |
HIGH
|
nicplex
|
plexcart
|
SQL injection vulnerability in plexcart.pl in NicPlex PlexCart X3 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.
|
NVD-CWE-Other
|
CVE-2006-1949
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348816
|
4.3 |
MEDIUM
|
perlcoders_group
|
bannerfarm
|
Multiple cross-site scripting (XSS) vulnerabilities in banners.cgi in PerlCoders BannerFarm 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) aff and (2) cat p…
|
NVD-CWE-Other
|
CVE-2006-1950
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348817
|
5.0 |
MEDIUM
|
winagents
|
tftp_server
|
Directory traversal vulnerability in WinAgents TFTP Server for Windows 3.1 and earlier allows remote attackers to read arbitrary files via "..." (triple dot) sequences in a GET request.
|
NVD-CWE-Other
|
CVE-2006-1952
|
2017-07-20 10:31 |
2006-04-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348818
|
5.0 |
MEDIUM
|
winagents
|
tftp_server
|
According to the vendor, WinAgents TFTP server version 3.2 fixes this directory traversal vulnerability.
|
NVD-CWE-Other
|
CVE-2006-1952
|
2017-07-20 10:31 |
2006-04-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348819
|
5.8 |
MEDIUM
|
aasi_media
|
net_clubs_pro
|
Multiple cross-site scripting (XSS) vulnerabilities in aasi media Net Clubs Pro 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) onuser, (2) pass, (3) chatsys…
|
NVD-CWE-Other
|
CVE-2006-1965
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348820
|
2.6 |
LOW
|
kcscripts
|
kcscripts_calendar portal_pack
|
Cross-site scripting (XSS) vulnerability in calendar/Visitor.cgi in KCScripts Calendar, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrar…
|
NVD-CWE-Other
|
CVE-2006-1967
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348821
|
5.8 |
MEDIUM
|
kcscripts
|
kcscripts_news_publisher portal_pack
|
Cross-site scripting (XSS) vulnerability in news/NsVisitor.cgi in KCScripts News Publisher, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbi…
|
NVD-CWE-Other
|
CVE-2006-1968
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348822
|
2.6 |
LOW
|
kcscripts
|
portal_pack
|
Cross-site scripting (XSS) vulnerability in search/search.cgi in an unspecified KCScripts script, probably Search Engine or Site Search, distributed individually and as part of Portal Pack 6.0 and ea…
|
NVD-CWE-Other
|
CVE-2006-1969
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348823
|
4.3 |
MEDIUM
|
kcscripts
|
portal_pack
|
Cross-site scripting (XSS) vulnerability in classifieds/viewcat.cgi in KCScripts Classifieds, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject ar…
|
NVD-CWE-Other
|
CVE-2006-1970
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348824
|
5.0 |
MEDIUM
|
linksys
|
rt31p2
|
Multiple unspecified vulnerabilities in Linksys RT31P2 VoIP router allow remote attackers to cause a denial of service via malformed Session Initiation Protocol (SIP) messages.
|
NVD-CWE-Other
|
CVE-2006-1973
|
2017-07-20 10:31 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348825
|
2.6 |
LOW
|
w2b
|
online_banking
|
Cross-site scripting (XSS) vulnerability in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the (1) query string, (2) SID parameter, or (3) ilang parameter.
|
NVD-CWE-Other
|
CVE-2006-1980
|
2017-07-20 10:31 |
2006-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348826
|
2.1 |
LOW
|
apple
|
mac_os_x mac_os_x_server
|
Unspecified vulnerability in Java InputMethods on Mac OS X 10.4.5 may cause InputMethods to send input events for secure fields to the wrong text field, which might reveal the password to others who …
|
NVD-CWE-Other
|
CVE-2006-1981
|
2017-07-20 10:31 |
2006-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348827
|
6.4 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
Multiple heap-based buffer overflows in Mac OS X 10.4.6 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) PredictorVSetField function for…
|
CWE-119
バッファエラー
|
CVE-2006-1983
|
2017-07-20 10:31 |
2006-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348828
|
5.0 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
Unspecified vulnerability in the _cg_TIFFSetField function in Mac OS X 10.4.6 and earlier, as used in applications that use ImageIO or AppKit, allows remote attackers to cause a denial of service (ap…
|
NVD-CWE-noinfo
|
CVE-2006-1984
|
2017-07-20 10:31 |
2006-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348829
|
5.1 |
MEDIUM
|
apple
|
safari mac_os_x mac_os_x_server
|
Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to execute arbitrary code via a crafted archive (such a…
|
CWE-119
バッファエラー
|
CVE-2006-1985
|
2017-07-20 10:31 |
2006-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348830
|
7.5 |
HIGH
|
apple
|
safari
|
Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via a large CELLSPACING attribute in a TABLE tag, which triggers an error in KWQListIteratorImpl::KWQ…
|
NVD-CWE-Other
|
CVE-2006-1986
|
2017-07-20 10:31 |
2006-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348831
|
7.5 |
HIGH
|
apple
|
safari
|
Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via an invalid FRAME tag, possibly due to (1) multiple SCROLLING attributes with no values, or (2) a …
|
NVD-CWE-Other
|
CVE-2006-1987
|
2017-07-20 10:31 |
2006-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348832
|
5.0 |
MEDIUM
|
apple
|
safari
|
The WebTextRenderer(WebInternal) _CG_drawRun:style:geometry: function in Apple Safari 2.0.3 allows remote attackers to cause a denial of service (application crash) via an HTML LI tag with a large VA…
|
NVD-CWE-Other
|
CVE-2006-1988
|
2017-07-20 10:31 |
2006-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348833
|
5.1 |
MEDIUM
|
clam_anti-virus
|
clamav
|
Buffer overflow in the get_database function in the HTTP client in Freshclam in ClamAV 0.80 to 0.88.1 might allow remote web servers to execute arbitrary code via long HTTP headers.
|
NVD-CWE-Other
|
CVE-2006-1989
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348834
|
5.1 |
MEDIUM
|
clam_anti-virus
|
clamav
|
This vulnerability is addressed in the following product release:
Clam Anti-Virus, ClamAV, 0.88.2
|
NVD-CWE-Other
|
CVE-2006-1989
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348835
|
6.4 |
MEDIUM
|
php
|
php
|
The substr_compare function in string.c in PHP 5.1.2 allows context-dependent attackers to cause a denial of service (memory access violation) via an out-of-bounds offset argument.
|
CWE-399
リソース管理の問題
|
CVE-2006-1991
|
2017-07-20 10:31 |
2006-04-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348836
|
7.5 |
HIGH
|
dforum
|
dforum
|
PHP remote file inclusion vulnerability in dForum 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DFORUM_PATH parameter to (1) about.php, (2) admin.php, (3) anm…
|
NVD-CWE-Other
|
CVE-2006-1994
|
2017-07-20 10:31 |
2006-04-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348837
|
2.1 |
LOW
|
sybase
|
pylon_anywhere
|
Unspecified vulnerability in Sybase Pylon Anywhere groupware synchronization server before 7.0 allows local users to obtain sensitive information such as email and PIM data of another user via unknow…
|
NVD-CWE-noinfo
|
CVE-2006-1997
|
2017-07-20 10:31 |
2006-04-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348838
|
4.3 |
MEDIUM
|
logmethods
|
logmethods
|
Cross-site scripting (XSS) vulnerability in /lms/a2z.jsp in logMethods 0.9 allows remote attackers to inject arbitrary web script or HTML via the kwd parameter.
|
NVD-CWE-Other
|
CVE-2006-2000
|
2017-07-20 10:31 |
2006-04-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348839
|
5.0 |
MEDIUM
|
ivan_zahariev
|
izarc
|
Multiple directory traversal vulnerabilities in IZArc Archiver 3.5 beta 3 allow remote attackers to write arbitrary files via a ..\ (dot dot backslash) in a (1) .rar, (2) .tar, (3) .zip, (4) .jar, or…
|
NVD-CWE-Other
|
CVE-2006-2006
|
2017-07-20 10:31 |
2006-04-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348840
|
7.5 |
HIGH
|
winny
|
winny
|
Heap-based buffer overflow in Winny 2.0 b7.1 and earlier allows remote attackers to execute arbitrary code via long strings to certain commands sent to the file transfer port.
|
NVD-CWE-Other
|
CVE-2006-2007
|
2017-07-20 10:31 |
2006-04-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348841
|
7.5 |
HIGH
|
web-provence
|
sl_site
|
SQL injection vulnerability in page.php in SL_site 1.0 allows remote attackers to execute arbitrary SQL commands via the id_page parameter. NOTE: this issue could be used to produce resultant XSS fro…
|
NVD-CWE-Other
|
CVE-2006-2013
|
2017-07-20 10:31 |
2006-04-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348842
|
5.0 |
MEDIUM
|
web-provence
|
sl_site
|
Directory traversal vulnerability in gallerie.php in SL_site 1.0 allows remote attackers to list images in arbitrary directories via ".." sequences in the rep parameter, which is used to construct a …
|
NVD-CWE-Other
|
CVE-2006-2014
|
2017-07-20 10:31 |
2006-04-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348843
|
2.6 |
LOW
|
web-provence
|
sl_site
|
Cross-site scripting (XSS) vulnerability in SL_site 1.0 allows remote attackers to inject arbitrary web script or HTML via the recherche parameter in recherche.php. NOTE: other XSS vectors, as repor…
|
NVD-CWE-Other
|
CVE-2006-2015
|
2017-07-20 10:31 |
2006-04-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348844
|
5.0 |
MEDIUM
|
dnsmasq
|
dnsmasq
|
Dnsmasq 2.29 allows remote attackers to cause a denial of service (application crash) via a DHCP client broadcast reply request.
|
NVD-CWE-Other
|
CVE-2006-2017
|
2017-07-20 10:31 |
2006-04-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348845
|
5.0 |
MEDIUM
|
dnsmasq
|
dnsmasq
|
This vulnerability is addressed in the following product release:
version 2.30
|
NVD-CWE-Other
|
CVE-2006-2017
|
2017-07-20 10:31 |
2006-04-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348846
|
2.6 |
LOW
|
phpmyadmin
|
phpmyadmin
|
Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin 2.8.0.3, 2.8.0.2, 2.8.1-dev, and 2.9.0-dev allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
|
NVD-CWE-Other
|
CVE-2006-2031
|
2017-07-20 10:31 |
2006-04-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348847
|
7.5 |
HIGH
|
amplecom
|
ampleshop
|
Multiple SQL injection vulnerabilities in ampleShop 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) RecordID parameter in (a) Customeraddresses_RecordAction.cfm a…
|
NVD-CWE-Other
|
CVE-2006-2038
|
2017-07-20 10:31 |
2006-04-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348848
|
7.5 |
HIGH
|
ubertec
|
help_center_live
|
Multiple SQL injection vulnerabilities in the osTicket module in Help Center Live before 2.1.0 allow remote attackers to execute arbitrary SQL commands via unknown vectors.
|
NVD-CWE-Other
|
CVE-2006-2039
|
2017-07-20 10:31 |
2006-04-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348849
|
5.0 |
MEDIUM
|
phpwebgallery
|
phpwebgallery
|
PhpWebGallery before 1.6.0RC1 allows remote attackers to obtain arbitrary pictures via a request to picture.php without specifying the cat parameter. NOTE: the provenance of this information is unkn…
|
NVD-CWE-Other
|
CVE-2006-2041
|
2017-07-20 10:31 |
2006-04-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348850
|
7.5 |
HIGH
|
adobe
|
dreamweaver
|
Adobe Dreamweaver 8 before 8.0.2 and MX 2004 can generate code that allows SQL injection attacks in the (1) ColdFusion, (2) PHP mySQL, (3) ASP, (4) ASP.NET, and (5) JSP server models.
|
NVD-CWE-Other
|
CVE-2006-2042
|
2017-07-20 10:31 |
2006-05-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|