|
349151
|
4.3 |
MEDIUM
|
my_photo_scrapbook
|
my_photo_scrapbook
|
Cross-site scripting (XSS) vulnerability in display.asp in My Photo Scrapbook 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the key_m parameter.
|
NVD-CWE-Other
|
CVE-2006-2992
|
2017-07-20 10:31 |
2006-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349152
|
7.5 |
HIGH
|
my_photo_scrapbook
|
my_photo_scrapbook
|
Multiple SQL injection vulnerabilities in My Photo Scrapbook 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the key parameter in (1) Displayview.asp and (2) Details_Phot…
|
NVD-CWE-Other
|
CVE-2006-2993
|
2017-07-20 10:31 |
2006-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349153
|
4.3 |
MEDIUM
|
okscripts
|
quicklinks
|
Cross-site scripting (XSS) vulnerability in search.php in OkScripts QuickLinks 1.1 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
|
NVD-CWE-Other
|
CVE-2006-2999
|
2017-07-20 10:31 |
2006-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349154
|
4.3 |
MEDIUM
|
okscripts
|
okarticles
|
Cross-site scripting (XSS) vulnerability in search.php in OkScripts OkArticles 1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
|
NVD-CWE-Other
|
CVE-2006-3000
|
2017-07-20 10:31 |
2006-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349155
|
5.8 |
MEDIUM
|
okscripts
|
okmall
|
Cross-site scripting (XSS) vulnerability in search.php in OkScripts OkMall 1.0 allow remote attackers to inject arbitrary web script or HTML via the page parameter. NOTE: this might be resultant fro…
|
NVD-CWE-Other
|
CVE-2006-3001
|
2017-07-20 10:31 |
2006-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349156
|
5.8 |
MEDIUM
|
easy_ad-manager
|
easy_ad-manager
|
Cross-site scripting (XSS) vulnerability in details.php in Easy Ad-Manager allows remote attackers to inject arbitrary web script or HTML via the mbid parameter, which is reflected in an error messag…
|
NVD-CWE-Other
|
CVE-2006-3002
|
2017-07-20 10:31 |
2006-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349157
|
4.3 |
MEDIUM
|
easy_ad-manager
|
easy_ad-manager
|
details.php in Easy Ad-Manager allows remote attackers to obtain the full installation path via an invalid mbid parameter, which leaks the path in an error message. NOTE: this might be resultant fro…
|
NVD-CWE-Other
|
CVE-2006-3003
|
2017-07-20 10:31 |
2006-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349158
|
4.3 |
MEDIUM
|
scriptsez
|
ez_ringtone_manager
|
Multiple cross-site scripting (XSS) vulnerabilities in Ez Ringtone Manager allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in player.php and (2) keyword paramet…
|
NVD-CWE-Other
|
CVE-2006-3004
|
2017-07-20 10:31 |
2006-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349159
|
5.0 |
MEDIUM
|
gentoo
|
media-libs_jpeg linux
|
The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (memory exhaustion) v…
|
NVD-CWE-Other
|
CVE-2006-3005
|
2017-07-20 10:31 |
2006-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349160
|
4.3 |
MEDIUM
|
nullsoft
|
shoutcast_server
|
Multiple cross-site scripting (XSS) vulnerabilities in SHOUTcast 1.9.5 allow remote attackers to inject arbitrary HTML or web script via the DJ fields (1) Description, (2) URL, (3) Genre, (4) AIM, an…
|
NVD-CWE-Other
|
CVE-2006-3007
|
2017-07-20 10:31 |
2006-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349161
|
5.8 |
MEDIUM
|
aliacom
|
open_business_management
|
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to inject arbitrary HTML or web script via the (1) tf_lang, (2) tf_name, (3) tf_…
|
NVD-CWE-Other
|
CVE-2006-3009
|
2017-07-20 10:31 |
2006-06-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349162
|
7.5 |
HIGH
|
aliacom
|
open_business_management
|
Multiple SQL injection vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to execute arbitrary SQL commands via the (1) new_order and (2) order_dir parameters to (a) i…
|
NVD-CWE-Other
|
CVE-2006-3010
|
2017-07-20 10:31 |
2006-06-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349163
|
4.6 |
MEDIUM
|
php
|
php
|
The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe mode and open_basedir restrictions via a "php://" or other scheme in the third a…
|
CWE-264
認可・権限・アクセス制御
|
CVE-2006-3011
|
2017-07-20 10:31 |
2006-06-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349164
|
6.8 |
MEDIUM
|
planete_afrique
|
ws-album
|
Multiple cross-site scripting (XSS) vulnerabilities in FullPhoto.asp in WS-Album 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) image and (2) PublisedDate p…
|
NVD-CWE-Other
|
CVE-2006-3020
|
2017-07-20 10:31 |
2006-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349165
|
6.8 |
MEDIUM
|
blue-collar_productions
|
i-gallery
|
Multiple cross-site scripting (XSS) vulnerabilities in BlueCollar i-Gallery 4.1 PLUS and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) n and (2) d parameters in (a…
|
NVD-CWE-Other
|
CVE-2006-3021
|
2017-07-20 10:31 |
2006-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349166
|
6.8 |
MEDIUM
|
fipsasp
|
fipsgallery
|
Cross-site scripting (XSS) vulnerability in zoom.php in fipsGallery 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the path parameter.
|
NVD-CWE-Other
|
CVE-2006-3022
|
2017-07-20 10:31 |
2006-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349167
|
4.3 |
MEDIUM
|
uapplication
|
uphotogallery
|
Multiple cross-site scripting (XSS) vulnerabilities in thumbnails.asp in Uapplication Uphotogallery 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) s and (2)…
|
NVD-CWE-Other
|
CVE-2006-3023
|
2017-07-20 10:31 |
2006-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349168
|
4.3 |
MEDIUM
|
evgenius
|
evgenius_counter
|
Multiple cross-site scripting (XSS) vulnerabilities in EvGenius Counter 3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) monthly.php and (2)…
|
NVD-CWE-Other
|
CVE-2006-3024
|
2017-07-20 10:31 |
2006-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349169
|
4.3 |
MEDIUM
|
clicktech
|
clickgallery
|
Multiple cross-site scripting (XSS) vulnerabilities in ClickGallery 5.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in gallery.asp and (…
|
NVD-CWE-Other
|
CVE-2006-3026
|
2017-07-20 10:31 |
2006-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349170
|
4.3 |
MEDIUM
|
clicktech
|
clickcart
|
Cross-site scripting (XSS) vulnerability in default.asp in ClickTech Clickcart 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
|
NVD-CWE-Other
|
CVE-2006-3029
|
2017-07-20 10:31 |
2006-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349171
|
4.3 |
MEDIUM
|
dwzone
|
dwzone_shopping_cart
|
Multiple cross-site scripting (XSS) vulnerabilities in DwZone Shopping Cart 1.1.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ToCategory and (2) FromCategory…
|
NVD-CWE-Other
|
CVE-2006-3030
|
2017-07-20 10:31 |
2006-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349172
|
4.3 |
MEDIUM
|
fipsasp
|
fipscms
|
Multiple cross-site scripting (XSS) vulnerabilities in index.asp in fipsCMS 4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) w, (2) phcat, (3) dayid, and (4) …
|
NVD-CWE-Other
|
CVE-2006-3031
|
2017-07-20 10:31 |
2006-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349173
|
4.3 |
MEDIUM
|
pensacola_web_designs
|
xtreme_asp_photo_gallery
|
Multiple cross-site scripting (XSS) vulnerabilities in Xtreme ASP Photo Gallery 1.05 and earlier, and possibly 2.0 (trial), allow remote attackers to inject arbitrary web script or HTML via the (1) c…
|
NVD-CWE-Other
|
CVE-2006-3032
|
2017-07-20 10:31 |
2006-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349174
|
2.6 |
LOW
|
site_trade
|
st_admanager_lite
|
Multiple cross-site scripting (XSS) vulnerabilities in publish.php in ST AdManager Lite allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, (3) article, …
|
NVD-CWE-Other
|
CVE-2006-3037
|
2017-07-20 10:31 |
2006-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349175
|
2.6 |
LOW
|
cfxe-cms
|
cfxe-cms
|
Cross-site scripting (XSS) vulnerability in search.cfm in CreaFrameXe (CFXe) CMS 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the voltext_suche parameter.
|
NVD-CWE-Other
|
CVE-2006-3043
|
2017-07-20 10:31 |
2006-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349176
|
2.6 |
LOW
|
logisphere
|
logisphere
|
Cross-site scripting (XSS) vulnerability in LogiSphere 1.6.0 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected in an error page.
|
NVD-CWE-Other
|
CVE-2006-3044
|
2017-07-20 10:31 |
2006-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349177
|
7.5 |
HIGH
|
metamail_corporation
|
metamail
|
Buffer overflow in Metamail 2.7-50 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via e-mail messages with a long boundary attribute, a di…
|
NVD-CWE-Other
|
CVE-2006-0709
|
2017-07-20 10:30 |
2006-02-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349178
|
7.5 |
HIGH
|
isode
|
m-vault_server
|
Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code via a crafted LDAP request, as demonstrated by ProtoVer Sample LDAP.
|
CWE-119
バッファエラー
|
CVE-2006-0710
|
2017-07-20 10:30 |
2006-02-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349179
|
5.0 |
MEDIUM
|
neomail
|
neomail
|
The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured w…
|
NVD-CWE-Other
|
CVE-2006-0711
|
2017-07-20 10:30 |
2006-02-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349180
|
5.0 |
MEDIUM
|
squishdot
|
squishdot
|
mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, which allows remote attackers to bypass spam filters by injecting SMTP headers, pro…
|
NVD-CWE-Other
|
CVE-2006-0712
|
2017-07-20 10:30 |
2006-02-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349181
|
5.0 |
MEDIUM
|
ibm
|
tivoli_directory_server
|
IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.
|
NVD-CWE-Other
|
CVE-2006-0717
|
2017-07-20 10:30 |
2006-02-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349182
|
2.6 |
LOW
|
reamday_enterprises
|
magic_news_lite
|
PHP remote file inclusion vulnerability in preview.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in …
|
CWE-94
コード・インジェクション
|
CVE-2006-0723
|
2017-07-20 10:30 |
2006-02-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349183
|
2.6 |
LOW
|
reamday_enterprises
|
magic_news_lite
|
profile.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modi…
|
NVD-CWE-Other
|
CVE-2006-0724
|
2017-07-20 10:30 |
2006-02-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349184
|
6.8 |
MEDIUM
|
plume-cms
|
plume_cms
|
PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the _PX_config[manager_pat…
|
CWE-94
コード・インジェクション
|
CVE-2006-0725
|
2017-07-20 10:30 |
2006-02-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349185
|
4.3 |
MEDIUM
|
cpg-nuke
|
dragonfly_cms
|
Cross-site scripting (XSS) vulnerability in linking.php in CPG-Nuke Dragonfly CMS 9.0.6.1 allows remote attackers to inject arbitrary web script or HTML via a URI that is generated when creating a li…
|
NVD-CWE-Other
|
CVE-2006-0726
|
2017-07-20 10:30 |
2006-02-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349186
|
7.5 |
HIGH
|
webspell
|
webspell
|
SQL injection vulnerability in search.php in webSPELL 4.01.00 and earlier allows remote attackers to inject arbitrary SQL commands via the title_op parameter.
|
NVD-CWE-Other
|
CVE-2006-0728
|
2017-07-20 10:30 |
2006-02-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349187
|
5.0 |
MEDIUM
|
timo_sirainen
|
dovecot
|
Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs"…
|
NVD-CWE-noinfo CWE-119
バッファエラー
|
CVE-2006-0730
|
2017-07-20 10:30 |
2006-02-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349188
|
4.0 |
MEDIUM
|
valve_software
|
half-life_cstrike_dedicated_server
|
The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.6 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon ha…
|
CWE-119
バッファエラー
|
CVE-2006-0734
|
2017-07-20 10:30 |
2006-02-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349189
|
5.0 |
MEDIUM
|
apache
|
log4net
|
Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.
|
CWE-134
書式文字列の問題
|
CVE-2006-0743
|
2017-07-20 10:30 |
2006-03-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349190
|
7.5 |
HIGH
|
hivemail
|
hivemail
|
Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid parameter in addressbook.update.php, (2) the messag…
|
NVD-CWE-Other
|
CVE-2006-0757
|
2017-07-20 10:30 |
2006-02-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349191
|
4.3 |
MEDIUM
|
hivemail
|
hivemail
|
Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via a URL encoded expression in the query string in (1) i…
|
NVD-CWE-Other
|
CVE-2006-0758
|
2017-07-20 10:30 |
2006-02-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349192
|
7.5 |
HIGH
|
hivemail
|
hivemail
|
Multiple SQL injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the contactgroupid parameter in addressbook.update.php, (2) the mes…
|
NVD-CWE-Other
|
CVE-2006-0759
|
2017-07-20 10:30 |
2006-02-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349193
|
2.6 |
LOW
|
lighttpd
|
lighttpd
|
LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected ca…
|
NVD-CWE-Other
|
CVE-2006-0760
|
2017-07-20 10:30 |
2006-02-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349194
|
4.3 |
MEDIUM
|
cpanel
|
cpanel
|
Cross-site scripting (XSS) vulnerability in dowebmailforward.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via a URL encoded value in the fwd parameter.
|
NVD-CWE-Other
|
CVE-2006-0763
|
2017-07-20 10:30 |
2006-02-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349195
|
5.1 |
MEDIUM
|
cisco
|
anomaly_guard_module guard traffic_anomaly_detector_module
|
The Authentication, Authorization, and Accounting (AAA) capability in versions 5.0(1) and 5.0(3) of the software used by multiple Cisco Anomaly Detection and Mitigation products, when running with an…
|
NVD-CWE-Other
|
CVE-2006-0764
|
2017-07-20 10:30 |
2006-02-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349196
|
5.0 |
MEDIUM
|
nathan_neulinger
|
cgiwrap
|
CGIWrap before 3.10 allows remote attackers to obtain sensitive information via unknown attack vectors that cause errors in scripts that reveal system information.
|
NVD-CWE-Other
|
CVE-2006-0767
|
2017-07-20 10:30 |
2006-02-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349197
|
2.6 |
LOW
|
mybulletinboard
|
mybulletinboard
|
Cross-site scripting (XSS) vulnerability in calendar.php in MyBulletinBoard (MyBB) 1.0.4 allows remote attackers to inject arbitrary web script or HTML via a URL that is not sanitized before being re…
|
NVD-CWE-Other
|
CVE-2006-0770
|
2017-07-20 10:30 |
2006-02-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349198
|
7.5 |
HIGH
|
hitachi
|
business_logic
|
SQL injection vulnerability in Hitachi Business Logic - Container 02-03 through 03-00-/B on Windows, and 03-00 through 03-00-/B on Linux, allows remote attackers to execute arbitrary SQL commands via…
|
CWE-89
SQLインジェクション
|
CVE-2006-0772
|
2017-07-20 10:30 |
2006-02-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349199
|
4.3 |
MEDIUM
|
hitachi
|
business_logic
|
Cross-site scripting (XSS) vulnerability in Hitachi Business Logic - Container 02-03 through 03-00-/B on Windows, and 03-00 through 03-00-/B on Linux, allows remote attackers to inject arbitrary web …
|
NVD-CWE-Other
|
CVE-2006-0773
|
2017-07-20 10:30 |
2006-02-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349200
|
7.5 |
HIGH
|
ridder_roeland
|
birthsys
|
Multiple SQL injection vulnerabilities in show.php in BirthSys 3.1 allow remote attackers to execute arbitrary SQL commands via the $month variable. NOTE: a vector regarding the $date parameter and …
|
NVD-CWE-Other
|
CVE-2006-0775
|
2017-07-20 10:30 |
2006-02-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|