|
348901
|
7.5 |
HIGH
|
pentasoft_corp.
|
avactis_shopping_cart
|
Multiple SQL injection vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category_id parameter in (a) store_special_offer…
|
NVD-CWE-Other
|
CVE-2006-2164
|
2017-07-20 10:31 |
2006-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348902
|
2.6 |
LOW
|
pentasoft_corp.
|
avactis_shopping_cart
|
Multiple cross-site scripting (XSS) vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) category_id parameter in (a) s…
|
NVD-CWE-Other
|
CVE-2006-2165
|
2017-07-20 10:31 |
2006-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348903
|
5.0 |
MEDIUM
|
best_practical_solutions
|
request_tracker
|
RT: Request Tracker 3.5.HEAD allows remote attackers to obtain sensitive information via the Rows parameter in Dist/Display.html, which reveals the installation path in an error message.
|
NVD-CWE-Other
|
CVE-2006-2169
|
2017-07-20 10:31 |
2006-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348904
|
6.4 |
MEDIUM
|
argosoft
|
ftp_server
|
Buffer overflow in ArgoSoft FTP Server 1.4.3.6 allows remote attackers to execute arbitrary code via Unicode in the RNTO command, as demonstrated by the Infigo FTPStress Fuzzer.
|
NVD-CWE-Other
|
CVE-2006-2170
|
2017-07-20 10:31 |
2006-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348905
|
6.4 |
MEDIUM
|
jgaa
|
warftpd
|
Buffer overflow in WDM.exe in WarFTPD allows remote attackers to execute arbitrary code via unspecified arguments, as demonstrated by the Infigo FTPStress Fuzzer.
|
NVD-CWE-Other
|
CVE-2006-2171
|
2017-07-20 10:31 |
2006-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348906
|
6.4 |
MEDIUM
|
filezilla
|
filezilla_server
|
Buffer overflow in FileZilla FTP Server 2.2.22 allows remote authenticated attackers to cause a denial of service and possibly execute arbitrary code via a long (1) PORT or (2) PASS followed by the M…
|
NVD-CWE-Other
|
CVE-2006-2173
|
2017-07-20 10:31 |
2006-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348907
|
4.3 |
MEDIUM
|
virtual_hosting_control_system
|
virtual_hosting_control_system
|
Multiple cross-site scripting (XSS) vulnerabilities in admin/server_day_stats.php in Virtual Hosting Control System (VHCS) allow remote attackers to inject arbitrary web script or HTML via the (1) da…
|
NVD-CWE-Other
|
CVE-2006-2174
|
2017-07-20 10:31 |
2006-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348908
|
5.8 |
MEDIUM
|
php_design_x
|
php_linkliste
|
Multiple cross-site scripting (XSS) vulnerabilities in links.php in PHP Linkliste 1.0b allow remote attackers to inject arbitrary web script or HTML via the (1) new_input, (2) new_url, or (3) new_nam…
|
NVD-CWE-Other
|
CVE-2006-2176
|
2017-07-20 10:31 |
2006-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348909
|
5.8 |
MEDIUM
|
smartwin_technology
|
cyberoffice_warehouse_builder
|
Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to login.asp, (2) ProductIndex paramete…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-2178
|
2017-07-20 10:31 |
2006-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348910
|
7.5 |
HIGH
|
smartwin_technology
|
cyberoffice_warehouse_builder
|
Multiple SQL injection vulnerabilities in CyberBuild allow remote attackers to execute arbitrary SQL commands via the (1) SessionID parameter to login.asp or (2) ProductIndex parameter to browse0.htm.
|
NVD-CWE-Other
|
CVE-2006-2179
|
2017-07-20 10:31 |
2006-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348911
|
6.4 |
MEDIUM
|
kmint21_software
|
golden_ftp_server
|
Buffer overflow in Golden FTP Server Pro 2.70 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long argument to the (1) NLST or (2) APPE comma…
|
CWE-119
バッファエラー
|
CVE-2006-2180
|
2017-07-20 10:31 |
2006-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348912
|
4.3 |
MEDIUM
|
albinator
|
albinator
|
Multiple cross-site scripting (XSS) vulnerabilities in Albinator 2.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to dlisting.php or (2) prelo…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-2181
|
2017-07-20 10:31 |
2006-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348913
|
7.2 |
HIGH
|
truecrypt_foundation
|
truecrypt
|
Untrusted search path vulnerability in Truecrypt 4.1, when running suid root on Linux, allows local users to execute arbitrary commands and gain privileges via a modified PATH environment variable th…
|
NVD-CWE-Other
|
CVE-2006-2183
|
2017-07-20 10:31 |
2006-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348914
|
4.0 |
MEDIUM
|
novell
|
netware
|
PORTAL.NLM in Novell Netware 6.5 SP5 writes the username and password in cleartext to the abend.log log file when the groupOperationsMethod function fails, which allows context-dependent attackers to…
|
NVD-CWE-Other
|
CVE-2006-2185
|
2017-07-20 10:31 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348915
|
6.8 |
MEDIUM
|
horde
|
horde
|
Cross-site scripting (XSS) vulnerability in horde 3 (horde3) before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) templates/problem/problem.inc and (2) test.php.
|
NVD-CWE-Other
|
CVE-2006-2195
|
2017-07-20 10:31 |
2006-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348916
|
6.8 |
MEDIUM
|
horde
|
horde
|
This vulnerability is addressed in the following product release:
Horde, Horde, 3.1.1
|
NVD-CWE-Other
|
CVE-2006-2195
|
2017-07-20 10:31 |
2006-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348917
|
4.6 |
MEDIUM
|
jochen_friedrich
|
pinball
|
Unspecified vulnerability in pinball 0.3.1 allows local users to gain privileges via unknown attack vectors that cause pinball to load plugins from an attacker-controlled directory while operating at…
|
NVD-CWE-Other
|
CVE-2006-2196
|
2017-07-20 10:31 |
2006-06-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348918
|
6.4 |
MEDIUM
|
kerio
|
kerio_mailserver
|
Unspecified vulnerability in Kerio MailServer before 6.1.4 has unknown impact and remote attack vectors related to a "possible bypass of attachment filter."
|
NVD-CWE-Other
|
CVE-2006-2203
|
2017-07-20 10:31 |
2006-05-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348919
|
10.0 |
HIGH
|
ultravnc
|
ultravnc
|
The MS-Logon authentication scheme in UltraVNC (aka Ultr@VNC) 1.0.1 uses weak encryption (XOR) for challenge/response, which allows remote attackers to gain privileges by sniffing and decrypting pass…
|
NVD-CWE-Other
|
CVE-2006-2206
|
2017-07-20 10:31 |
2006-05-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348920
|
6.4 |
MEDIUM
|
php_arena
|
pacheckbook
|
Multiple SQL injection vulnerabilities in index.php in PHP Arena paCheckBook 1.1 allow remote attackers to execute arbitrary SQL commands via (1) the transtype parameter in an add action or (2) entry…
|
NVD-CWE-Other
|
CVE-2006-2209
|
2017-07-20 10:31 |
2006-05-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348921
|
5.0 |
MEDIUM
|
hostapd
|
hostapd
|
Hostapd 0.3.7-2 allows remote attackers to cause a denial of service (segmentation fault) via an unspecified value in the key_data_length field of an EAPoL frame.
|
NVD-CWE-Other
|
CVE-2006-2213
|
2017-07-20 10:31 |
2006-05-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348922
|
7.5 |
HIGH
|
4images
|
image_gallery_management_system
|
Multiple SQL injection vulnerabilities in 4images 1.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sessionid parameter in (1) top.php and (2) member.php. NOTE: this…
|
NVD-CWE-Other
|
CVE-2006-2214
|
2017-07-20 10:31 |
2006-05-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348923
|
7.5 |
HIGH
|
apple
|
quicktime
|
Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted BMP file that triggers the overflow in the ReadBMP function. NOTE: this issue…
|
CWE-119
バッファエラー
|
CVE-2006-2238
|
2017-07-20 10:31 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348924
|
7.5 |
HIGH
|
apple
|
quicktime
|
This vulnerability is addressed in the following product release:
Apple, QuickTime, 7.1 for Mac OS X (latest update)
|
CWE-119
バッファエラー
|
CVE-2006-2238
|
2017-07-20 10:31 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348925
|
7.5 |
HIGH
|
tuomas_airaksinen
|
newsadmin
|
SQL injection vulnerability in readarticle.php in Newsadmin 1.1 allows remote attackers to execute arbitrary SQL commands via the nid parameter.
|
CWE-89
SQLインジェクション
|
CVE-2006-2239
|
2017-07-20 10:31 |
2006-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348926
|
5.0 |
MEDIUM
|
fujitsu
|
netshelter_fw netshelter_fw-l netshelter_fw-m netshelter_fw-p
|
Unspecified vulnerability in the (1) web cache or (2) web proxy in Fujitsu NetShelter/FW allows remote attackers to cause a denial of service (device unresponsiveness) via certain DNS packets, as dem…
|
NVD-CWE-Other
|
CVE-2006-2240
|
2017-07-20 10:31 |
2006-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348927
|
5.0 |
MEDIUM
|
fujitsu
|
netshelter_fw netshelter_fw-l netshelter_fw-m netshelter_fw-p
|
All Fujitsu NetShelter/FW models E12Lxx and E11Lxx are affected except E11L27 and E12L31. The listing of affected models is broad, but the following list is a list of exceptions:
NetShelter/FW E1…
|
NVD-CWE-Other
|
CVE-2006-2240
|
2017-07-20 10:31 |
2006-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348928
|
5.8 |
MEDIUM
|
web4future
|
news_portal
|
Multiple cross-site scripting (XSS) vulnerabilities in Web4Future News Portal allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) comentarii.php or (2) view.php.…
|
NVD-CWE-Other
|
CVE-2006-2243
|
2017-07-20 10:31 |
2006-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348929
|
6.4 |
MEDIUM
|
web4future
|
news_portal
|
Multiple SQL injection vulnerabilities in Web4Future News Portal allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) comentarii.php or (2) view.php.
|
NVD-CWE-Other
|
CVE-2006-2244
|
2017-07-20 10:31 |
2006-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348930
|
6.8 |
MEDIUM
|
phpbb_group
|
phpbb-auction
|
PHP remote file inclusion vulnerability in auction\auction_common.php in Auction mod 1.3m for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
|
CWE-94
コード・インジェクション
|
CVE-2006-2245
|
2017-07-20 10:31 |
2006-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348931
|
5.0 |
MEDIUM
|
northern_solutions
|
xeneo_web_server
|
Xeneo Web Server 2.2.22.0 allows remote attackers to obtain the source code of script files via crafted requests containing dot, space, and slash characters in the file extension.
|
NVD-CWE-Other
|
CVE-2006-2248
|
2017-07-20 10:31 |
2006-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348932
|
6.4 |
MEDIUM
|
invision_power_services
|
invision_community_blog
|
SQL injection vulnerability in the do_mmod function in mod.php in Invision Community Blog (ICB) 1.1.2 final through 1.2 allows remote attackers with moderator privileges to execute arbitrary SQL comm…
|
NVD-CWE-Other
|
CVE-2006-2251
|
2017-07-20 10:31 |
2006-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348933
|
5.0 |
MEDIUM
|
intervations
|
filecopa
|
Buffer overflow in filecpnt.exe in FileCOPA 1.01 allows remote attackers to cause a denial of service (application crash) via a username with a large number of newline characters.
|
NVD-CWE-Other
|
CVE-2006-2254
|
2017-07-20 10:31 |
2006-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348934
|
7.5 |
HIGH
|
creative_software
|
community_portal
|
Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to (a) ArticleView.php, (…
|
NVD-CWE-Other
|
CVE-2006-2255
|
2017-07-20 10:31 |
2006-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348935
|
5.8 |
MEDIUM
|
faktorystudios
|
easyevent
|
Cross-site scripting (XSS) vulnerability in index.php in easyEvent 1.2 allows remote attackers to inject arbitrary web script or HTML via the curr_year parameter.
|
NVD-CWE-Other
|
CVE-2006-2257
|
2017-07-20 10:31 |
2006-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348936
|
2.6 |
LOW
|
maxxcode
|
maxxschedule
|
Cross-site scripting (XSS) vulnerability in Logon.asp in MaxxSchedule 1.0 allows remote attackers to inject arbitrary web script or HTML via the Error parameter.
|
NVD-CWE-Other
|
CVE-2006-2258
|
2017-07-20 10:31 |
2006-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348937
|
7.5 |
HIGH
|
maxxcode
|
maxxschedule
|
SQL injection vulnerability in Logon.asp in MaxxSchedule 1.0 allows remote attackers to execute arbitrary SQL commands via the txtLogon parameter.
|
CWE-89
SQLインジェクション
|
CVE-2006-2259
|
2017-07-20 10:31 |
2006-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348938
|
4.3 |
MEDIUM
|
drupal
|
drupal
|
Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-2260
|
2017-07-20 10:31 |
2006-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348939
|
6.5 |
MEDIUM
|
ocean12_technologies
|
calendar_manager_pro
|
Multiple SQL injection vulnerabilities in Ocean12 Calendar Manager Pro 1.00 allow remote attackers to execute arbitrary SQL commands via the (1) date parameter to admin/main.asp, (2) SearchFor parame…
|
NVD-CWE-Other
|
CVE-2006-2264
|
2017-07-20 10:31 |
2006-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348940
|
2.6 |
LOW
|
ocean12_technologies
|
calendar_manager_pro
|
Cross-site scripting vulnerability in admin/main.asp in Ocean12 Calendar Manager Pro 1.00 allows remote attackers to inject arbitrary web script or HTML via the date parameter. NOTE: the provenance …
|
NVD-CWE-Other
|
CVE-2006-2265
|
2017-07-20 10:31 |
2006-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348941
|
7.5 |
HIGH
|
chirpy
|
chirpy
|
SQL injection vulnerability in Chirpy! 0.1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
|
NVD-CWE-Other
|
CVE-2006-2266
|
2017-07-20 10:31 |
2006-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348942
|
6.8 |
MEDIUM
|
dokeos
|
dokeos dokeos_community_release
|
Multiple PHP remote file inclusion vulnerabilities in claro_init_global.inc.php in Dokeos 1.6.3 and earlier, and Dokeos community release 2.0.3, allow remote attackers to execute arbitrary PHP code v…
|
CWE-94
コード・インジェクション
|
CVE-2006-2286
|
2017-07-20 10:31 |
2006-05-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348943
|
6.8 |
MEDIUM
|
www.goel.ch
|
2005-comments-script
|
Multiple cross-site scripting (XSS) vulnerabilities in kommentar.php in 2005-Comments-Script allow remote attackers to inject arbitrary web script or HTML via the (1) id, (2) email, and (3) url param…
|
NVD-CWE-Other
|
CVE-2006-2290
|
2017-07-20 10:31 |
2006-05-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348944
|
5.8 |
MEDIUM
|
inhouse_associates
|
ia-calendar
|
Cross-site scripting (XSS) vulnerability in calendar_new.asp in IA-Calendar allows remote attackers to inject arbitrary web script or HTML via the TypeName1 parameter. NOTE: the provenance of this i…
|
NVD-CWE-Other
|
CVE-2006-2291
|
2017-07-20 10:31 |
2006-05-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348945
|
6.4 |
MEDIUM
|
inhouse_associates
|
ia-calendar
|
Multiple SQL injection vulnerabilities in IA-Calendar allow remote attackers to execute arbitrary SQL commands via the (1) type parameter in (a) calendar_new.asp and (b) default.asp, and (2) ID param…
|
NVD-CWE-Other
|
CVE-2006-2292
|
2017-07-20 10:31 |
2006-05-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348946
|
6.4 |
MEDIUM
|
expinion.net
|
multicalendars
|
SQL injection vulnerability in all_calendars.asp in MultiCalendars 3.0 allows remote attackers to execute arbitrary SQL commands via the calsids parameter. NOTE: the provenance of this information i…
|
NVD-CWE-Other
|
CVE-2006-2293
|
2017-07-20 10:31 |
2006-05-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348947
|
7.5 |
HIGH
|
timobraun
|
dynamic_galerie
|
Directory traversal vulnerability in Dynamic Galerie 1.0 allows remote attackers to access arbitrary files via an absolute path in the pfad parameter to (1) index.php and (2) galerie.php.
|
NVD-CWE-Other
|
CVE-2006-2295
|
2017-07-20 10:31 |
2006-05-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348948
|
6.4 |
MEDIUM
|
keyvan1.com
|
edirectorypro
|
SQL injection vulnerability in search_result.asp in EDirectoryPro 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the keyword parameter. NOTE: the provenance of this in…
|
NVD-CWE-Other
|
CVE-2006-2296
|
2017-07-20 10:31 |
2006-05-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348949
|
5.0 |
MEDIUM
|
internet_key_exchange
|
internet_key_exchange
|
The Internet Key Exchange version 1 (IKEv1) implementation in the libike library in Solaris 9 and 10 allows remote attackers to cause a denial of service (in.iked daemon crash) via crafted IKE packet…
|
NVD-CWE-Other
|
CVE-2006-2298
|
2017-07-20 10:31 |
2006-05-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348950
|
5.0 |
MEDIUM
|
internet_key_exchange
|
internet_key_exchange
|
Sun has released patches to address the vulnerability.
|
NVD-CWE-Other
|
CVE-2006-2298
|
2017-07-20 10:31 |
2006-05-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|