|
348951
|
7.5 |
HIGH
|
keyvan1
|
eimagepro
|
Multiple SQL injection vulnerabilities in EImagePro allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter to subList.asp, (2) SubjectID parameter to imageList.asp, or (…
|
NVD-CWE-Other
|
CVE-2006-2300
|
2017-07-20 10:31 |
2006-05-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348952
|
7.5 |
HIGH
|
ozzywork
|
galeri
|
SQL injection vulnerability in admin_default.asp in OzzyWork Galeri allows remote attackers to execute arbitrary SQL commands via the (1) Login or (2) password fields.
|
CWE-89
SQLインジェクション
|
CVE-2006-2301
|
2017-07-20 10:31 |
2006-05-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348953
|
7.5 |
HIGH
|
duware
|
dugallery
|
SQL injection vulnerability in admin_default.asp in DUGallery 2.x allows remote attackers to execute arbitrary SQL commands via the (1) Login or (2) password field.
|
NVD-CWE-Other
|
CVE-2006-2302
|
2017-07-20 10:31 |
2006-05-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348954
|
5.8 |
MEDIUM
|
jadu_limited
|
jadu_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in Jadu CMS allow remote attackers to inject arbitrary web script or HTML via the (1) forename, (2) surname, (3) reg_email, (4) email_conf, (5) com…
|
NVD-CWE-Other
|
CVE-2006-2305
|
2017-07-20 10:31 |
2006-05-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348955
|
9.3 |
HIGH
|
keyvan_janghorbani
|
epublisherpro
|
Cross-site scripting (XSS) vulnerability in moreinfo.asp in EPublisherPro allows remote attackers to inject arbitrary web script or HTML via the title parameter. NOTE: the provenance of this informa…
|
NVD-CWE-Other
|
CVE-2006-2306
|
2017-07-20 10:31 |
2006-05-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348956
|
6.4 |
MEDIUM
|
cisco
|
application_velocity_system_3110 application_velocity_system_3120
|
The transparent proxy feature of the Cisco Application Velocity System (AVS) 3110 5.0 and 4.0 and earlier, and 3120 5.0.0 and earlier, has a default configuration that allows remote attackers to prox…
|
NVD-CWE-Other
|
CVE-2006-2322
|
2017-07-20 10:31 |
2006-05-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348957
|
6.8 |
MEDIUM
|
onlyscript.info
|
online_universal_payment_system_script
|
Cross-site scripting (XSS) vulnerability in index.php in OnlyScript.info Online Universal Payment System Script allows remote attackers to inject arbitrary web script or HTML via the read parameter. …
|
NVD-CWE-Other
|
CVE-2006-2325
|
2017-07-20 10:31 |
2006-05-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348958
|
5.0 |
MEDIUM
|
onlyscript.info
|
online_universal_payment_system_script
|
Directory traversal vulnerability in index.php in OnlyScript.info Online Universal Payment System Script allows remote attackers to read arbitrary files via directory traversal sequences in the read …
|
NVD-CWE-Other
|
CVE-2006-2326
|
2017-07-20 10:31 |
2006-05-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348959
|
6.4 |
MEDIUM
|
evo-dev
|
evotopsites evotopsites_pro
|
SQL injection vulnerability in index.php in evoTopsites 2.x and evoTopsites Pro 2.x allows remote attackers to execute arbitrary SQL commands via the (1) cat_id and (2) id parameters.
|
NVD-CWE-Other
|
CVE-2006-2339
|
2017-07-20 10:31 |
2006-05-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348960
|
5.8 |
MEDIUM
|
lethal_penguin
|
passmasterflex passmasterflexplus
|
Cross-site scripting (XSS) vulnerability in PassMasterFlex and PassMasterFlexPlus (PassMasterFlex+) 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) username…
|
NVD-CWE-Other
|
CVE-2006-2340
|
2017-07-20 10:31 |
2006-05-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348961
|
7.5 |
HIGH
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 6.0.2 before FixPack 3 allows remote attackers to bypass authentication for the Welcome Page via a request to the default context root.
|
NVD-CWE-Other
|
CVE-2006-2342
|
2017-07-20 10:31 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348962
|
5.8 |
MEDIUM
|
adventnet
|
manageengine_opmanager
|
Cross-site scripting (XSS) vulnerability in Search.do in ManageEngine OpManager 6.0 allows remote attackers to inject arbitrary web script or HTML via the searchTerm parameter. NOTE: the provenance …
|
NVD-CWE-Other
|
CVE-2006-2343
|
2017-07-20 10:31 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348963
|
6.4 |
MEDIUM
|
ajax_softwares
|
alipager
|
SQL injection vulnerability in inc/elementz.php in AliPAGER 1.5, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the ubild parameter.
|
NVD-CWE-Other
|
CVE-2006-2344
|
2017-07-20 10:31 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348964
|
4.3 |
MEDIUM
|
roostercode_ajax_softwares
|
alipager
|
Cross-site scripting (XSS) vulnerability in inc/elementz.php in AliPAGER 1.5 allows remote attackers to inject arbitrary web script or HTML via the ubild parameter. NOTE: the provenance of this info…
|
NVD-CWE-Other
|
CVE-2006-2345
|
2017-07-20 10:31 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348965
|
7.5 |
HIGH
|
inter7
|
vpopmail_\(vchkpw\)
|
vpopmail 5.4.14 and 5.4.15, with cleartext passwords enabled, allows remote attackers to authenticate to an account that does not have a cleartext password set by using a blank password to (1) SMTP A…
|
NVD-CWE-Other
|
CVE-2006-2346
|
2017-07-20 10:31 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348966
|
4.3 |
MEDIUM
|
ipswitch
|
whatsup_professional
|
Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via the (…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-2351
|
2017-07-20 10:31 |
2006-05-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348967
|
4.3 |
MEDIUM
|
ipswitch
|
whatsup_professional
|
Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via unkno…
|
NVD-CWE-Other
|
CVE-2006-2352
|
2017-07-20 10:31 |
2006-05-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348968
|
5.0 |
MEDIUM
|
ipswitch
|
whatsup_professional
|
NmConsole/DeviceSelection.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to redirect users to other websites via the (1) sCancelURL and possib…
|
CWE-264
認可・権限・アクセス制御
|
CVE-2006-2353
|
2017-07-20 10:31 |
2006-05-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348969
|
5.0 |
MEDIUM
|
ipswitch
|
whatsup_professional
|
NmConsole/Login.asp in Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium generates different error messages in a way that allows remote attackers to enumerate valid us…
|
NVD-CWE-Other
|
CVE-2006-2354
|
2017-07-20 10:31 |
2006-05-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348970
|
5.0 |
MEDIUM
|
ipswitch
|
whatsup_professional
|
Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium allows remote attackers to obtain full path information via 404 error messages. NOTE: the provenance of this informa…
|
NVD-CWE-Other
|
CVE-2006-2355
|
2017-07-20 10:31 |
2006-05-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348971
|
5.0 |
MEDIUM
|
ipswitch
|
whatsup_professional
|
Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain source code for scripts via a trailing dot in a request to NmConsole/Login.asp.
|
NVD-CWE-Other
|
CVE-2006-2357
|
2017-07-20 10:31 |
2006-05-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348972
|
4.3 |
MEDIUM
|
web-labs
|
web-labs_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in various scripts in Web-Labs CMS allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter and (2) unspecified f…
|
NVD-CWE-Other
|
CVE-2006-2358
|
2017-07-20 10:31 |
2006-05-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348973
|
5.8 |
MEDIUM
|
macromedia
|
coldfusion
|
Cross-site scripting (XSS) vulnerability in the validation feature in Macromedia ColdFusion 5 and earlier allows remote attackers to inject arbitrary web script or HTML via a "_required" field when t…
|
NVD-CWE-Other
|
CVE-2006-2364
|
2017-07-20 10:31 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348974
|
2.6 |
LOW
|
openobex
|
openobex
|
ircp_io.c in libopenobex for ircp 1.2, when ircp is run with the -r option, does not prompt the user when overwriting files, which allows user-assisted remote attackers to overwrite dangerous files v…
|
NVD-CWE-Other
|
CVE-2006-2366
|
2017-07-20 10:31 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348975
|
4.3 |
MEDIUM
|
clansys
|
clansys
|
Cross-site scripting (XSS) vulnerability in index.php in Clansys (aka Clanpage System) 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the func parameter in a search fu…
|
NVD-CWE-Other
|
CVE-2006-2367
|
2017-07-20 10:31 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348976
|
5.8 |
MEDIUM
|
clansys
|
clansys
|
Cross-site scripting (XSS) vulnerability in index.php in Clansys (aka Clanpage System) 1.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
NVD-CWE-Other
|
CVE-2006-2368
|
2017-07-20 10:31 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348977
|
5.8 |
MEDIUM
|
ozjournals
|
ozjournals
|
Cross-site scripting (XSS) vulnerability in OZJournals 1.2 allows remote attackers to inject arbitrary web script or HTML via the vname parameter in the comments functionality.
|
NVD-CWE-Other
|
CVE-2006-2390
|
2017-07-20 10:31 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348978
|
5.8 |
MEDIUM
|
phpodp
|
phpodp
|
Cross-site scripting (XSS) vulnerability in phpODP 1.5h allows remote attackers to inject arbitrary web script via the browse parameter.
|
NVD-CWE-Other
|
CVE-2006-2396
|
2017-07-20 10:31 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348979
|
7.5 |
HIGH
|
filezilla
|
filezilla
|
Buffer overflow in FileZilla before 2.2.23 allows remote attackers to execute arbitrary commands via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-2403
|
2017-07-20 10:31 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348980
|
7.5 |
HIGH
|
filezilla
|
filezilla
|
Failed exploit attempts will likely crash the application.
This vulnerability is addressed in the following product release:
FileZilla, FileZilla, 2.2.23
|
NVD-CWE-Other
|
CVE-2006-2403
|
2017-07-20 10:31 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348981
|
5.8 |
MEDIUM
|
flexchat
|
flexchat
|
Multiple cross-site scripting (XSS) vulnerabilities in FlexChat 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) CFTOKEN parameter in (a) ind…
|
NVD-CWE-Other
|
CVE-2006-2415
|
2017-07-20 10:31 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348982
|
4.3 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.x before 2.8.0.4 allows remote attackers to inject arbitrary web script or HTML via the theme parameter in unknown scripts. NOTE: the lan…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-2417
|
2017-07-20 10:31 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348983
|
4.3 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
Update to version 2.8.0.4.
http://www.phpmyadmin.net/home_page/downloads.php
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-2417
|
2017-07-20 10:31 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348984
|
6.8 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
Cross-site scripting (XSS) vulnerabilities in certain versions of phpMyAdmin before 2.8.0.4 allow remote attackers to inject arbitrary web script or HTML via the db parameter in unknown scripts.
|
NVD-CWE-Other
|
CVE-2006-2418
|
2017-07-20 10:31 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348985
|
6.8 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
Some releases of phpMyAdmin before 2.8.0.4 are affected (2.6.2 tested vulnerable).
This vulnerability is addressed in the following product release:
phpMyAdmin, phpMyAdmin, 2.8.0.4
|
NVD-CWE-Other
|
CVE-2006-2418
|
2017-07-20 10:31 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348986
|
4.3 |
MEDIUM
|
mozilla
|
bugzilla
|
Bugzilla 2.20rc1 through 2.20 and 2.21.1, when using RSS 1.0, allows remote attackers to conduct cross-site scripting (XSS) attacks via a title element with HTML encoded sequences such as ">", whi…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-2420
|
2017-07-20 10:31 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348987
|
4.3 |
MEDIUM
|
mozilla
|
bugzilla
|
Update to version 2.18.5 or 2.20.1.
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-2420
|
2017-07-20 10:31 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348988
|
7.5 |
HIGH
|
pragma_systems
|
fortressssh
|
Stack-based buffer overflow in Pragma FortressSSH 4.0.7.20 allows remote attackers to execute arbitrary code via long SSH_MSG_KEXINIT messages, which may cause an overflow when being logged. NOTE: t…
|
NVD-CWE-Other
|
CVE-2006-2421
|
2017-07-20 10:31 |
2006-05-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348989
|
5.0 |
MEDIUM
|
coinsoft_technologies
|
phpcoin
|
phpCOIN 1.2.3 and earlier stores messages based upon e-mail addresses, which allows remote authenticated users to read messages for other users by adding the sender's e-mail address as an "additional…
|
NVD-CWE-Other
|
CVE-2006-2422
|
2017-07-20 10:31 |
2006-05-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348990
|
5.0 |
MEDIUM
|
coinsoft_technologies
|
phpcoin
|
Apply patch :
http://forums.phpcoin.com/index.php?showtopic=5941
|
NVD-CWE-Other
|
CVE-2006-2422
|
2017-07-20 10:31 |
2006-05-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348991
|
5.0 |
MEDIUM
|
caucho_technology
|
resin
|
Directory traversal vulnerability in the viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to read arbitrary files under other web r…
|
NVD-CWE-Other
|
CVE-2006-2438
|
2017-07-20 10:31 |
2006-05-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348992
|
5.0 |
MEDIUM
|
caucho_technology
|
resin
|
This vulnerability is addressed in the following product release:
Caucho Technology, Resin, 3.0.19
|
NVD-CWE-Other
|
CVE-2006-2438
|
2017-07-20 10:31 |
2006-05-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348993
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic Server before 8.1 Service Pack 4 does not properly set the Quality of Service in certain circumstances, which prevents some transmissions from being encrypted via SSL, and allows remote …
|
NVD-CWE-Other
|
CVE-2006-2461
|
2017-07-20 10:31 |
2006-05-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348994
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service Pack 6, may send sensitive data over non-secure channels when using JTA transactions, which allows remote attackers to read potent…
|
NVD-CWE-Other
|
CVE-2006-2462
|
2017-07-20 10:31 |
2006-05-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348995
|
4.6 |
MEDIUM
|
bea
|
weblogic_server
|
stopWebLogic.sh in BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service Pack 6 displays the administrator password to stdout when executed, which allows local users to obtain the pass…
|
NVD-CWE-Other
|
CVE-2006-2464
|
2017-07-20 10:31 |
2006-05-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348996
|
2.6 |
LOW
|
bea
|
weblogic_server
|
BEA WebLogic Server 8.1 up to SP4 and 7.0 up to SP6 allows remote attackers to obtain the source code of JSP pages during certain circumstances related to a "timing window" when a compilation error o…
|
NVD-CWE-Other
|
CVE-2006-2466
|
2017-07-20 10:31 |
2006-05-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348997
|
4.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic Server 8.1 up to SP4, 7.0 up to SP6, and 6.1 up to SP7 displays the internal IP address of the WebLogic server in the WebLogic Server Administration Console, which allows remote authenti…
|
NVD-CWE-Other
|
CVE-2006-2467
|
2017-07-20 10:31 |
2006-05-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348998
|
4.0 |
MEDIUM
|
bea
|
weblogic_server
|
The WebLogic Server Administration Console in BEA WebLogic Server 8.1 up to SP4 and 7.0 up to SP6 displays the domain name in the Console login form, which allows remote attackers to obtain sensitive…
|
NVD-CWE-Other
|
CVE-2006-2468
|
2017-07-20 10:31 |
2006-05-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348999
|
7.5 |
HIGH
|
bea
|
weblogic_server
|
The HTTP handlers in BEA WebLogic Server 9.0, 8.1 up to SP5, 7.0 up to SP6, and 6.1 up to SP7 stores the username and password in cleartext in the WebLogic Server log when access to a web application…
|
NVD-CWE-Other
|
CVE-2006-2469
|
2017-07-20 10:31 |
2006-05-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349000
|
7.5 |
HIGH
|
bea
|
weblogic_server
|
Unspecified vulnerability in the WebLogic Server Administration Console for BEA WebLogic Server 9.0 prevents the console from setting custom JDBC security policies correctly, which could allow attack…
|
NVD-CWE-Other
|
CVE-2006-2470
|
2017-07-20 10:31 |
2006-05-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|