|
349001
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
Multiple vulnerabilities in BEA WebLogic Server 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 leak sensitive information to remote attackers, including (1) DNS and IP addresses to address to …
|
NVD-CWE-Other
|
CVE-2006-2471
|
2017-07-20 10:31 |
2006-05-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349002
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
This vulnerability is addressed in the following product releases:
BEA Systems, Weblogic Server, 8.1 SP 5
BEA Systems, Weblogic Express, 8.1 SP 5
BEA Systems, Weblogic Server, 7.0 SP 7
BEA System…
|
NVD-CWE-Other
|
CVE-2006-2471
|
2017-07-20 10:31 |
2006-05-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349003
|
4.9 |
MEDIUM
|
bea
|
weblogic_server
|
Unspecified vulnerability in BEA WebLogic Server 9.1 and 9.0, 8.1 through SP5, 7.0 through SP6, and 6.1 through SP7 allows untrusted applications to obtain private server keys.
|
NVD-CWE-Other
|
CVE-2006-2472
|
2017-07-20 10:31 |
2006-05-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349004
|
4.9 |
MEDIUM
|
bea
|
weblogic_server
|
Hyperlink #907650 has patches for the following products:
WebLogic Server 9.1
WebLogic Server 9.0
This vulnerability is addressed in the following product releases:
BEA Systems, Weblogic Server, …
|
NVD-CWE-Other
|
CVE-2006-2472
|
2017-07-20 10:31 |
2006-05-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349005
|
6.8 |
MEDIUM
|
microchip_data_systems pentaware
|
ziptv_for_c\+\+_builder ziptv_for_delphi_7 pentasuite-pro pentazip
|
Heap-based buffer overflow in the TZipTV component in (1) ZipTV for Delphi 7 2006.1.26 and for C++ Builder 2006-1.16, (2) PentaZip 8.5.1.190 and PentaSuite-PRO 8.5.1.221, and possibly other products,…
|
CWE-119
バッファエラー
|
CVE-2006-2482
|
2017-07-20 10:31 |
2006-09-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349006
|
4.3 |
MEDIUM
|
spymac
|
spymac_web_os
|
Multiple cross-site scripting (XSS) vulnerabilities in Spymac WebOS (WOS) 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) del_folder, (2) nick, or (3) action parameters …
|
NVD-CWE-Other
|
CVE-2006-2488
|
2017-07-20 10:31 |
2006-05-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349007
|
6.4 |
MEDIUM
|
invision_power_services
|
invision_power_board
|
Invision Power Board (IPB) before 2.1.6 allows remote attackers to execute arbitrary PHP script via attack vectors involving (1) the post_icon variable in classes/post/class_post.php and (2) the df v…
|
NVD-CWE-Other
|
CVE-2006-2498
|
2017-07-20 10:31 |
2006-05-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349008
|
6.8 |
MEDIUM
|
sun
|
java_system_application_server java_system_web_server one_application_server one_web_server
|
Cross-site scripting (XSS) vulnerability in Sun ONE Web Server 6.0 SP9 and earlier, Java System Web Server 6.1 SP4 and earlier, Sun ONE Application Server 7 Platform and Standard Edition Update 6 and…
|
NVD-CWE-Other
|
CVE-2006-2501
|
2017-07-20 10:31 |
2006-05-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349009
|
6.8 |
MEDIUM
|
sun
|
java_system_application_server java_system_web_server one_application_server one_web_server
|
This vulnerability is addressed in the following product releases:
Sun, ONE Web Server, 6.0 SP10 or later
Sun, Java System Web Server, 6.1 SP5 or later
Sun, ONE Application Server, 7.0 Platform Up…
|
NVD-CWE-Other
|
CVE-2006-2501
|
2017-07-20 10:31 |
2006-05-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349010
|
5.1 |
MEDIUM
|
cyrus
|
imapd
|
Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute arbitrary code via a long USER command.
|
NVD-CWE-Other
|
CVE-2006-2502
|
2017-07-20 10:31 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349011
|
6.5 |
MEDIUM
|
hitachi
|
eur_print_service eur_print_service_for_ilf eur_professional eur_viewer
|
SQL injection vulnerability in Hitachi EUR Professional Edition, EUR Viewer, EUR Print Service, and EUR Print Service for ILF allows remote authenticated users to execute arbitrary SQL commands via u…
|
NVD-CWE-Other
|
CVE-2006-2512
|
2017-07-20 10:31 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349012
|
6.5 |
MEDIUM
|
hitachi
|
eur_print_service eur_print_service_for_ilf eur_professional eur_viewer
|
This vulnerability is addressed in the following product releases:
Hitachi, EUR Viewer, 05-06-/A
Hitachi, EUR Professional, 05-06-/A
Hitachi, EUR Print Service, 05-06-/A
|
NVD-CWE-Other
|
CVE-2006-2512
|
2017-07-20 10:31 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349013
|
7.5 |
HIGH
|
sun
|
java_system_directory_server
|
Unspecified vulnerability in the installation process in Sun Java System Directory Server 5.2 causes wrong user data to be written to a file created by the installation, which allows remote attackers…
|
NVD-CWE-Other
|
CVE-2006-2513
|
2017-07-20 10:31 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349014
|
7.5 |
HIGH
|
coppermine
|
coppermine_photo_gallery
|
Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arbitrary files via a filename with multiple file extensions.
|
NVD-CWE-Other
|
CVE-2006-2514
|
2017-07-20 10:31 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349015
|
7.5 |
HIGH
|
coppermine
|
coppermine_photo_gallery
|
Product is vulnerable when running on Apache with mod_mime installed.
This vulnerability is addressed in the following product release:
Coppermine, Photo Gallery, 1.4.6
|
NVD-CWE-Other
|
CVE-2006-2514
|
2017-07-20 10:31 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349016
|
7.5 |
HIGH
|
fujitsu
|
myweb_portal_office
|
SQL injection vulnerability in MyWeb Portal Office, Standard Edition, Public Edition, Medical Edition, Citizen Edition, School Edition, and Light Edition allows remote attackers to execute arbitrary …
|
NVD-CWE-Other
|
CVE-2006-2517
|
2017-07-20 10:31 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349017
|
7.5 |
HIGH
|
dayfox_designs
|
dayfox_blog
|
Dayfox Blog 2.0 and earlier stores user credentials in edit/slog_users.txt under the web document root with insufficient access control, which allows remote attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2006-2522
|
2017-07-20 10:31 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349018
|
6.8 |
MEDIUM
|
usebb
|
usebb
|
Cross-site scripting (XSS) vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors when processing the user date format.
|
NVD-CWE-Other
|
CVE-2006-2524
|
2017-07-20 10:31 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349019
|
6.4 |
MEDIUM
|
usebb
|
usebb
|
SQL injection vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to execute arbitrary SQL commands via the member list search module.
|
NVD-CWE-Other
|
CVE-2006-2525
|
2017-07-20 10:31 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349020
|
6.4 |
MEDIUM
|
smartisoft
|
phpbazar
|
PHP remote file inclusion vulnerability in classified_right.php in phpBazar 2.1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the language_dir parameter.
|
NVD-CWE-Other
|
CVE-2006-2528
|
2017-07-20 10:31 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349021
|
7.5 |
HIGH
|
horizontal_shooter_bor openbor senile_team
|
horizontal_shooter_bor openbor beats_of_rage
|
Multiple format string vulnerabilities in (a) OpenBOR 2.0046 and earlier, (b) Beats of Rage (BOR) 1.0029 and earlier, and (c) Horizontal Shooter BOR (HOR) 2.0000 and earlier allow remote attackers to…
|
NVD-CWE-Other
|
CVE-2006-2537
|
2017-07-20 10:31 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349022
|
3.5 |
LOW
|
sybase
|
easerver
|
Sybase EAServer 5.0 for HP-UX Itanium, 5.2 for IBM AIX, HP-UX PA-RISC, Linux x86, and Sun Solaris SPARC, and 5.3 for Sun Solaris SPARC does not properly protect passwords when they are being entered …
|
NVD-CWE-Other
|
CVE-2006-2539
|
2017-07-20 10:31 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349023
|
2.1 |
LOW
|
ti_kan
|
xmcd
|
xmcdconfig in xmcd for Debian GNU/Linux 2.6-17.1 creates /var/lib/cddb and /var/lib/xmcd/discog with world writable permissions, which allows local users to cause a denial of service (disk consumptio…
|
NVD-CWE-Other
|
CVE-2006-2542
|
2017-07-20 10:31 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349024
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
A recommended admin password reset mechanism for BEA WebLogic Server 8.1, when followed before October 10, 2005, causes the administrator password to be stored in cleartext in the domain directory, w…
|
NVD-CWE-Other
|
CVE-2006-2546
|
2017-07-20 10:31 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349025
|
2.1 |
LOW
|
php
|
php
|
The cURL library (libcurl) in PHP 4.4.2 and 5.1.4 allows attackers to bypass safe mode and read files via a file:// request containing null characters.
|
NVD-CWE-Other
|
CVE-2006-2563
|
2017-07-20 10:31 |
2006-05-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349026
|
5.1 |
MEDIUM
|
dian_gemilang
|
dgbook
|
SQL injection vulnerability in index.php in DGBook 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) homepage, (4) addres…
|
NVD-CWE-Other
|
CVE-2006-2573
|
2017-07-20 10:31 |
2006-05-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349027
|
5.1 |
MEDIUM
|
dian_gemilang
|
dgbook
|
Successful exploitation requires that "magic_quotes_gpc" is disabled.
|
NVD-CWE-Other
|
CVE-2006-2573
|
2017-07-20 10:31 |
2006-05-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349028
|
5.1 |
MEDIUM
|
esyndicat
|
esyndicat_directory
|
admin/cron.php in eSyndicat Directory 1.2, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files and possibly execute arbitrary PHP cod…
|
NVD-CWE-Other
|
CVE-2006-2578
|
2017-07-20 10:31 |
2006-05-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349029
|
4.3 |
MEDIUM
|
rwiki
|
rwiki
|
Cross-site scripting (XSS) vulnerability in Wiki content in RWiki 2.1.0pre1 through 2.1.0 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-2581
|
2017-07-20 10:31 |
2006-05-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349030
|
7.5 |
HIGH
|
rwiki
|
rwiki
|
The editing form in RWiki 2.1.0pre1 through 2.1.0 allows remote attackers to execute arbitrary Ruby code via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-2582
|
2017-07-20 10:31 |
2006-05-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349031
|
6.4 |
MEDIUM
|
greg_donald
|
destiney_links_script
|
SQL injection vulnerability in Destiney Links Script 2.1.2 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the provenance of this information is unknown; the de…
|
NVD-CWE-Other
|
CVE-2006-2585
|
2017-07-20 10:31 |
2006-05-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349032
|
5.8 |
MEDIUM
|
iplogger
|
iplogger
|
Cross-site scripting (XSS) vulnerability in IpLogger 1.7 and earlier allows remote attackers to inject arbitrary HTML or web script via the HTTP_REFERER header in an HTTP request.
|
NVD-CWE-Other
|
CVE-2006-2586
|
2017-07-20 10:31 |
2006-05-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349033
|
7.5 |
HIGH
|
dschat
|
dschat
|
Unspecified vulnerability in DSChat 1.0 allows remote attackers to execute arbitrary PHP code via the Nickname field, which is not sanitized before creating a file in a user directory. NOTE: the pro…
|
NVD-CWE-Other
|
CVE-2006-2592
|
2017-07-20 10:31 |
2006-05-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349034
|
4.3 |
MEDIUM
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in includes/Sanitizer.php in the variable handler in MediaWiki 1.6.x before r14349 allows remote attackers to inject arbitrary Javascript via unspecified vect…
|
NVD-CWE-Other
|
CVE-2006-2611
|
2017-07-20 10:31 |
2006-05-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349035
|
4.6 |
MEDIUM
|
sun
|
n1_system_manager
|
Sun N1 System Manager 1.1 for Solaris 10 before patch 121161-01 records system passwords in the world-readable scripts (1) /cr/hd_jobs_db.sh, (2) /cr/hd_plan_checkin.sh, and (3) /cr/oracle_plan_check…
|
NVD-CWE-Other
|
CVE-2006-2614
|
2017-07-20 10:31 |
2006-05-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349036
|
4.0 |
MEDIUM
|
linux
|
linux_kernel
|
Race condition in Linux kernel 2.6.15 to 2.6.17, when running on SMP platforms, allows local users to cause a denial of service (crash) by creating and exiting a large number of tasks, then accessing…
|
NVD-CWE-Other
|
CVE-2006-2629
|
2017-07-20 10:31 |
2006-05-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349037
|
6.8 |
MEDIUM
|
cosmicphp
|
cosmicshoppingcart
|
Multiple cross-site scripting (XSS) vulnerabilities in (a) search.php, (b) search_cat.php, (c) search_price.php, and (d) product_details.php in the cosmicshop directory for CosmicShoppingCart allow r…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-2649
|
2017-07-20 10:31 |
2006-05-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349038
|
7.5 |
HIGH
|
cosmicphp
|
cosmicshoppingcart
|
SQL injection vulnerability in cosmicshop/search.php in CosmicShoppingCart allows remote attackers to execute arbitrary SQL commands via the max parameter.
|
NVD-CWE-Other
|
CVE-2006-2650
|
2017-07-20 10:31 |
2006-05-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349039
|
6.4 |
MEDIUM
|
freebsd
|
freebsd
|
Directory traversal vulnerability in smbfs smbfs on FreeBSD 4.10 up to 6.1 allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences. NOTE: this is similar …
|
NVD-CWE-Other
|
CVE-2006-2654
|
2017-07-20 10:31 |
2006-06-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349040
|
6.4 |
MEDIUM
|
freebsd
|
freebsd
|
The build process for ypserv in FreeBSD 5.3 up to 6.1 accidentally disables access restrictions when using the /var/yp/securenets file, which allows remote attackers to bypass intended access restric…
|
NVD-CWE-Other
|
CVE-2006-2655
|
2017-07-20 10:31 |
2006-06-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349041
|
5.0 |
MEDIUM
|
sitescape
|
sitescape_forum
|
Dispatch.cgi/_user/uservCard/ in SiteScape Forum 7.2 and possibly earlier generates different responses in a way that allows remote attackers to enumerate valid usernames.
|
NVD-CWE-Other
|
CVE-2006-2676
|
2017-07-20 10:31 |
2006-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349042
|
5.0 |
MEDIUM
|
sitescape
|
sitescape_forum
|
SiteScape Forum 7.2 and possibly earlier stores the avf.rc configuraiton file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive path info…
|
NVD-CWE-Other
|
CVE-2006-2677
|
2017-07-20 10:31 |
2006-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349043
|
7.2 |
HIGH
|
cisco
|
vpn_client
|
Unspecified vulnerability in the VPN Client for Windows Graphical User Interface (GUI) (aka the VPN client dialer) in Cisco VPN Client for Windows 4.8.00.* and earlier, except for 4.7.00.0533, allows…
|
NVD-CWE-noinfo
|
CVE-2006-2679
|
2017-07-20 10:31 |
2006-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349044
|
6.8 |
MEDIUM
|
socketmail
|
socketmail
|
PHP remote file inclusion vulnerability in SocketMail Lite and Pro 2.2.6 and earlier, when register_globals and magic_quotes are enabled, allows remote attackers to execute arbitrary PHP code via a U…
|
CWE-94
コード・インジェクション
|
CVE-2006-2681
|
2017-07-20 10:31 |
2006-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349045
|
4.9 |
MEDIUM
|
agtc_websolutions
|
php-agtc_membership_system
|
Cross-site scripting (XSS) vulnerability in adduser.php in PHP-AGTC Membership System 1.1a and earlier allows remote attackers to inject arbitrary web script or HTML via the email address (useremail …
|
NVD-CWE-Other
|
CVE-2006-2687
|
2017-07-20 10:31 |
2006-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349046
|
6.4 |
MEDIUM
|
achievo
|
achievo
|
SQL injection vulnerability in the employees node (class.employee.inc) in Achievo 1.1.0 and earlier and 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the atkselector p…
|
NVD-CWE-Other
|
CVE-2006-2688
|
2017-07-20 10:31 |
2006-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349047
|
6.8 |
MEDIUM
|
eva-web
|
eva-web
|
Multiple cross-site scripting (XSS) vulnerabilities in EVA-Web 2.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) debut_image parameter in (a) article-album.p…
|
NVD-CWE-Other
|
CVE-2006-2689
|
2017-07-20 10:31 |
2006-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349048
|
5.0 |
MEDIUM
|
amule
|
amule
|
Unspecified "information leakage" vulnerabilities in aMuleWeb for AMule before 2.1.2 allow remote attackers to access arbitrary images, including dynamically generated images, via unknown vectors.
|
NVD-CWE-Other
|
CVE-2006-2691
|
2017-07-20 10:31 |
2006-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349049
|
5.0 |
MEDIUM
|
amule
|
amule
|
Successful exploitation requires that the full pathname of the file is known.
This vulnerability is addressed in the following product release:
aMule, aMule, 2.1.2
|
NVD-CWE-Other
|
CVE-2006-2691
|
2017-07-20 10:31 |
2006-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349050
|
5.1 |
MEDIUM
|
dgnews
|
dgnews
|
admin/upprocess.php in DGNews 1.5 and earlier allows remote attackers to execute arbitrary code by uploading scripts with arbitrary extensions to the img directory.
|
NVD-CWE-Other
|
CVE-2006-2695
|
2017-07-20 10:31 |
2006-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|