|
349051
|
5.1 |
MEDIUM
|
dgnews
|
dgnews
|
Successful exploitation requires access to the administration section.
|
NVD-CWE-Other
|
CVE-2006-2695
|
2017-07-20 10:31 |
2006-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349052
|
7.5 |
HIGH
|
geeklog
|
geeklog
|
SQL injection vulnerability in Geeklog 1.4.0sr2 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to story submission.
|
NVD-CWE-Other
|
CVE-2006-2701
|
2017-07-20 10:31 |
2006-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349053
|
5.0 |
MEDIUM
|
secure_elements
|
c5_enterprise_vulnerability_management
|
Secure Elements Class 5 AVR server and client (aka C5 EVM) before 2.8.1 send messages in cleartext, which allows remote attackers to read sensitive vulnerability information.
|
NVD-CWE-Other
|
CVE-2006-2704
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349054
|
5.0 |
MEDIUM
|
secure_elements
|
c5_enterprise_vulnerability_management
|
The vulnerabilities and security issues have been fixed in C5 EVM version 2.8.1.
|
NVD-CWE-Other
|
CVE-2006-2704
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349055
|
5.0 |
MEDIUM
|
secure_elements
|
c5_enterprise_vulnerability_management
|
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause an unspecified denial of service via a large number of forged client registration messages.
|
NVD-CWE-Other
|
CVE-2006-2705
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349056
|
5.0 |
MEDIUM
|
secure_elements
|
c5_enterprise_vulnerability_management
|
The vulnerabilities and security issues have been fixed in C5 EVM version 2.8.1.
|
NVD-CWE-Other
|
CVE-2006-2705
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349057
|
5.0 |
MEDIUM
|
secure_elements
|
class_5_enterprise_vulnerability_management
|
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause a denial of service via forged "session start" messages that cause AVR to connect to arbitrary hosts.
|
NVD-CWE-Other
|
CVE-2006-2706
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349058
|
5.0 |
MEDIUM
|
secure_elements
|
class_5_enterprise_vulnerability_management
|
The vulnerabilities and security issues have been fixed in C5 EVM version 2.8.1.
|
NVD-CWE-Other
|
CVE-2006-2706
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349059
|
5.0 |
MEDIUM
|
secure_elements
|
class_5_enterprise_vulnerability_management
|
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could allow remote attackers to distribute malicious updates to cli…
|
NVD-CWE-Other
|
CVE-2006-2707
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349060
|
5.0 |
MEDIUM
|
secure_elements
|
class_5_enterprise_vulnerability_management
|
The vulnerabilities and security issues have been fixed in C5 EVM version 2.8.1.
|
NVD-CWE-Other
|
CVE-2006-2707
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349061
|
5.0 |
MEDIUM
|
secure_elements
|
class_5_enterprise_vulnerability_management
|
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 allows remote attackers to read portions of process memory via a modified size for (1) EM_GET_CE_PARAMETER and (2) EM_SET_CE_PARAMETER mes…
|
NVD-CWE-Other
|
CVE-2006-2708
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349062
|
5.0 |
MEDIUM
|
secure_elements
|
class_5_enterprise_vulnerability_management
|
Upgrade to version 2.8.1
|
NVD-CWE-Other
|
CVE-2006-2708
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349063
|
5.0 |
MEDIUM
|
secure_elements
|
class_5_enterprise_vulnerability_management
|
Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 do not validate the source address of a message, which allows remote attackers to (1) execute arbitrary code on a client or (2) forge messages to…
|
NVD-CWE-Other
|
CVE-2006-2709
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349064
|
5.0 |
MEDIUM
|
secure_elements
|
class_5_enterprise_vulnerability_management
|
Upgrade to version 2.8.1
|
NVD-CWE-Other
|
CVE-2006-2709
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349065
|
5.0 |
MEDIUM
|
secure_elements
|
class_5_enterprise_vulnerability_management
|
Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 uses the same invariant RSA key for all installations, which allows remote attackers with the key to decrypt communications.
|
NVD-CWE-Other
|
CVE-2006-2710
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349066
|
5.0 |
MEDIUM
|
secure_elements
|
class_5_enterprise_vulnerability_management
|
Upgrade to 2.8.1
|
NVD-CWE-Other
|
CVE-2006-2710
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349067
|
5.0 |
MEDIUM
|
secure_elements
|
class_5_enterprise_vulnerability_management
|
Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key for each message session, which allows remote attackers to o…
|
NVD-CWE-Other
|
CVE-2006-2711
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349068
|
5.0 |
MEDIUM
|
secure_elements
|
class_5_enterprise_vulnerability_management
|
Upgrade to 2.8.1
|
NVD-CWE-Other
|
CVE-2006-2711
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349069
|
5.0 |
MEDIUM
|
secure_elements
|
class_5_enterprise_vulnerability_management
|
Secure Elements Class 5 AVR (aka C5 EVM) client and server before 2.8.1 do not verify the integrity of a message digest, which allows remote attackers to modify and replay messages.
|
NVD-CWE-Other
|
CVE-2006-2712
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349070
|
5.0 |
MEDIUM
|
secure_elements
|
class_5_enterprise_vulnerability_management
|
Upgrade to version 2.8.1
|
NVD-CWE-Other
|
CVE-2006-2712
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349071
|
5.0 |
MEDIUM
|
secure_elements
|
c5_enterprise_vulnerability_management
|
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 generates predictable CEIDs, which allows remote attackers to determine the CEID of a protected asset, which can be used in other attacks …
|
NVD-CWE-Other
|
CVE-2006-2713
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349072
|
5.0 |
MEDIUM
|
secure_elements
|
c5_enterprise_vulnerability_management
|
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 does not validate the CEID of an incoming message, which allows remote attackers to send messages to a protected asset without knowing the…
|
NVD-CWE-Other
|
CVE-2006-2714
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349073
|
7.5 |
HIGH
|
secure_elements
|
c5_enterprise_vulnerability_management
|
The Administration Console in Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 does not enforce access control, which allows remote attackers to gain access to servers via the console.
|
NVD-CWE-Other
|
CVE-2006-2715
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349074
|
7.5 |
HIGH
|
secure_elements
|
c5_enterprise_vulnerability_management
|
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 uses a hard-coded user ID and password, which allows remote attackers to gain access to the server.
|
NVD-CWE-Other
|
CVE-2006-2716
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349075
|
4.0 |
MEDIUM
|
secure_elements
|
c5_enterprise_vulnerability_management
|
Unspecified vulnerability in Secure Elements Class 5 AVR client and server (aka C5 EVM) before 2.8.1 allows authenticated attackers to overwrite arbitrary files (1) on a server during an update or (2…
|
NVD-CWE-Other
|
CVE-2006-2717
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349076
|
7.5 |
HIGH
|
out_of_the_trees_web_design
|
selectapix
|
SQL injection vulnerability in view_album.php in SelectaPix 1.4 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: the provenance of this information is unknown; th…
|
NVD-CWE-Other
|
CVE-2006-2722
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349077
|
6.8 |
MEDIUM
|
punbb
|
punbb
|
Cross-site scripting (XSS) vulnerability in PunBB 1.2.11 allows remote authenticated administrators to inject arbitrary HTML or web script to other administrators via the "Admin note" feature, a diff…
|
NVD-CWE-Other
|
CVE-2006-2724
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349078
|
2.6 |
LOW
|
jan_chmelik
|
photoalbum_bandw
|
Cross-site scripting (XSS) vulnerability in superalbum/index.php in Photoalbum B&W 1.3 allows remote attackers to inject arbitrary web script or HTML via the gal parameter. NOTE: the provenance of t…
|
NVD-CWE-Other
|
CVE-2006-2729
|
2017-07-20 10:31 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349079
|
5.0 |
MEDIUM
|
eitsop
|
my_web_server
|
Eitsop My Web Server 1.0 allows remote attackers to cause a denial of service (application crash) via a long GET request. NOTE: CVE analysis suggests that this is a different product, and therefore …
|
NVD-CWE-Other
|
CVE-2006-2756
|
2017-07-20 10:31 |
2006-06-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349080
|
7.5 |
HIGH
|
warpspeed
|
4nforum
|
SQL injection vulnerability in modules.php in 4nNukeWare 4nForum 0.91 allows remote attackers to execute arbitrary SQL commands via the tid parameter.
|
CWE-89
SQLインジェクション
|
CVE-2006-2760
|
2017-07-20 10:31 |
2006-06-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349081
|
6.4 |
MEDIUM
|
hitachi
|
hitsenser3
|
SQL injection vulnerability in Hitachi HITSENSER3 HITSENSER3/PRP, HITSENSER3/PUP, HITSENSER3/STP, and HITSENSER3/EUP allows remote attackers to execute arbitrary SQL commands via unknown attack vecto…
|
NVD-CWE-Other
|
CVE-2006-2761
|
2017-07-20 10:31 |
2006-06-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349082
|
4.3 |
MEDIUM
|
xander_ladage
|
guestbookxl
|
Cross-site scripting (XSS) vulnerability in GuestbookXL 1.3 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in an IMG tag in a comment field to (1) guestwrite.php …
|
NVD-CWE-Other
|
CVE-2006-2764
|
2017-07-20 10:31 |
2006-06-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349083
|
2.6 |
LOW
|
interlink_advantage
|
interlink_advantage
|
Cross-site scripting (XSS) vulnerability in news_information.php in Interlink Advantage allows remote attackers to inject arbitrary web script or HTML via the flag parameter.
|
NVD-CWE-Other
|
CVE-2006-2765
|
2017-07-20 10:31 |
2006-06-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349084
|
6.4 |
MEDIUM
|
hogstorps
|
hogstorp_guestbook
|
admin/radera/tabort.asp in Hogstorps hogstorp guestbook 2.0 does not verify user credentials, which allows remote attackers to delete arbitrary posts via a modified delID parameter.
|
NVD-CWE-Other
|
CVE-2006-2771
|
2017-07-20 10:31 |
2006-06-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349085
|
6.8 |
MEDIUM
|
hogstorps
|
hogstorp_guestbook
|
Cross-site scripting (XSS) vulnerability in add.asp in Hogstorps hogstorp guestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, and (3) headline pa…
|
NVD-CWE-Other
|
CVE-2006-2772
|
2017-07-20 10:31 |
2006-06-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349086
|
6.4 |
MEDIUM
|
hogstorps
|
hogstorp_guestbook
|
admin/redigera/redigera2.asp in Hogstorps hogstorp Guestbook 2.0 does not verify user credentials, which allows remote attackers to edit arbitrary posts via unspecified vectors. NOTE: the provenance…
|
NVD-CWE-Other
|
CVE-2006-2773
|
2017-07-20 10:31 |
2006-06-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349087
|
7.2 |
HIGH
|
sun
|
storage_automated_diagnostic_environment
|
A package component in Sun Storage Automated Diagnostic Environment (StorADE) 2.4 uses world-writable permissions for certain critical files and directories, which allows local users to gain privileg…
|
NVD-CWE-Other
|
CVE-2006-2790
|
2017-07-20 10:31 |
2006-06-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349088
|
7.2 |
HIGH
|
sun
|
storage_automated_diagnostic_environment
|
This vulnerability is addressed in the following product release:
Sun, Storage Automated Diagnostic Environment, 2.4 (for Solaris 8, 9 and 10) with patch 117654-60 or later.
|
NVD-CWE-Other
|
CVE-2006-2790
|
2017-07-20 10:31 |
2006-06-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349089
|
6.8 |
MEDIUM
|
new-place
|
captivate
|
Cross-site scripting (XSS) vulnerability in gallery.php in Captivate 1.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter, which is reflected in an error message.
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-2796
|
2017-07-20 10:31 |
2006-06-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349090
|
6.8 |
MEDIUM
|
toenda_software_development
|
toendacms
|
Cross-site scripting (XSS) vulnerability in content_footer.php in toendaCMS 0.7.0 allows remote attackers to inject arbitrary web scripts or HTML via the print_url variable. NOTE: the provenance of …
|
NVD-CWE-Other
|
CVE-2006-2799
|
2017-07-20 10:31 |
2006-06-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349091
|
6.8 |
MEDIUM
|
toenda_software_development
|
toendacms
|
Successful exploitation requires that the user is running a browser that has not URL-encoded the request (e.g. Internet Explorer).
|
NVD-CWE-Other
|
CVE-2006-2799
|
2017-07-20 10:31 |
2006-06-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349092
|
6.8 |
MEDIUM
|
unak
|
unak_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in Unak CMS 1.5 RC2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) u_a or (2) u_s parameters. NOTE: this mi…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-2800
|
2017-07-20 10:31 |
2006-06-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349093
|
7.5 |
HIGH
|
unak
|
unak_cms
|
Multiple SQL injection vulnerabilities in Unak CMS 1.5 RC2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) u_a or (2) u_s parameters.
|
NVD-CWE-Other
|
CVE-2006-2801
|
2017-07-20 10:31 |
2006-06-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349094
|
6.8 |
MEDIUM
|
goss
|
icm
|
Cross-site scripting (XSS) vulnerability in index.cfm in Goss Intelligent Content Management (iCM) 7.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword param…
|
NVD-CWE-Other
|
CVE-2006-2804
|
2017-07-20 10:31 |
2006-06-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349095
|
7.5 |
HIGH
|
tekno.portal
|
tekno.portal
|
SQL injection vulnerability in bolum.php in tekno.Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the detai…
|
NVD-CWE-Other
|
CVE-2006-2817
|
2017-07-20 10:31 |
2006-06-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349096
|
5.1 |
MEDIUM
|
cpanel
|
cpanel
|
cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts that share physical directories, which might allow a local user to byp…
|
NVD-CWE-Other
|
CVE-2006-2825
|
2017-07-20 10:31 |
2006-06-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349097
|
7.5 |
HIGH
|
phplib_team
|
phplib
|
SQL injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a allows remote attackers to execute arbitrary SQL commands via the id variable, which is set by a client through a …
|
NVD-CWE-Other
|
CVE-2006-2826
|
2017-07-20 10:31 |
2006-06-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349098
|
6.8 |
MEDIUM
|
tibco
|
hawk hawk_monitoring_agent runtime_agent
|
Buffer overflow in Hawk Monitoring Agent (HMA) for TIBCO Hawk before 4.6.1 and TIBCO Runtime Agent (TRA) before 5.4 allows authenticated users to execute arbitrary code via the configuration for tibh…
|
NVD-CWE-Other
|
CVE-2006-2829
|
2017-07-20 10:31 |
2006-06-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349099
|
7.5 |
HIGH
|
tibco
|
hawk rendezvous runtime_agent
|
Buffer overflow in TIBCO Rendezvous before 7.5.1, TIBCO Runtime Agent (TRA) before 5.4, and Hawk before 4.6.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code …
|
NVD-CWE-Other
|
CVE-2006-2830
|
2017-07-20 10:31 |
2006-06-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349100
|
7.5 |
HIGH
|
pineapple_technologies
|
lore
|
SQL injection vulnerability in comment.php in Pineapple Technologies Lore 1.5.6 and earlier allows remote attackers to execute arbitrary SQL commands via the article_id parameter.
|
NVD-CWE-Other
|
CVE-2006-2836
|
2017-07-20 10:31 |
2006-06-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|