|
349251
|
4.3 |
MEDIUM
|
limbo_cms
|
limbo_cms
|
Cross-site scripting (XSS) vulnerability in webinsta Limbo 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the message field in the Contact Form.
|
NVD-CWE-Other
|
CVE-2006-0934
|
2017-07-20 10:30 |
2006-02-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349252
|
5.0 |
MEDIUM
|
unu_networks
|
mailgust
|
U.N.U. Mailgust 1.9 allows remote attackers to obtain sensitive information via a direct request to index.php with method=showfullcsv, which reveals the POP3 server configuration, including account n…
|
NVD-CWE-Other
|
CVE-2006-0937
|
2017-07-20 10:30 |
2006-02-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349253
|
7.5 |
HIGH
|
dci-designs
|
dci-taskeen
|
SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id or (2) action parameter to (a) basket.php, or (3) id or (4) page parameter to …
|
NVD-CWE-Other
|
CVE-2006-0939
|
2017-07-20 10:30 |
2006-03-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349254
|
4.3 |
MEDIUM
|
thomson
|
speedtouch
|
Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter to the LocalNetw…
|
NVD-CWE-Other
|
CVE-2006-0946
|
2017-07-20 10:30 |
2006-03-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349255
|
5.0 |
MEDIUM
|
raidenhttpd
|
raidenhttpd
|
RaidenHTTPD 1.1.47 allows remote attackers to obtain source code of script files, including PHP, via crafted requests involving (1) "." (dot), (2) space, and (3) "/" (slash) characters.
|
NVD-CWE-Other
|
CVE-2006-0949
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349256
|
5.0 |
MEDIUM
|
raidenhttpd
|
raidenhttpd
|
This vulnerability affects RaidenHTTPD, RaidenHTTPD version 1.1.47 and may affect all previous versions.
|
NVD-CWE-Other
|
CVE-2006-0949
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349257
|
5.0 |
MEDIUM
|
compex
|
netpassage_wpe54g
|
uConfig agent in Compex NetPassage WPE54G router allows remote attackers to cause a denial of service (unresposiveness) via crafted datagrams to UDP port 7778.
|
NVD-CWE-Other
|
CVE-2006-0960
|
2017-07-20 10:30 |
2006-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349258
|
4.3 |
MEDIUM
|
battleaxe_software
|
bttlxeforum
|
Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML via the err_txt parameter.
|
NVD-CWE-Other
|
CVE-2006-0974
|
2017-07-20 10:30 |
2006-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349259
|
4.3 |
MEDIUM
|
battleaxe_software
|
bttlxeforum
|
This vulnerability affects Battleaxe Software, bttlxeForum versions 2.0 and previous
|
NVD-CWE-Other
|
CVE-2006-0974
|
2017-07-20 10:30 |
2006-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349260
|
10.0 |
HIGH
|
nidelven_it
|
issue_dealer
|
Unspecified vulnerability in the local weblog publisher in Nidelven IT Issue Dealer before 0.9.96 has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2006-0979
|
2017-07-20 10:30 |
2006-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349261
|
10.0 |
HIGH
|
nidelven_it
|
issue_dealer
|
This vulnerability affects Nidelven IT, Issue Dealer versions 0.9.95 and previous.
|
NVD-CWE-Other
|
CVE-2006-0979
|
2017-07-20 10:30 |
2006-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349262
|
5.0 |
MEDIUM
|
emc_dantz
|
retrospect
|
EMC Dantz Retrospect 7 backup client 7.0.107, and other versions before 7.0.109, and 6.5 before 6.5.138 allows remote attackers to cause a denial of service (client termination and loss of backup ser…
|
NVD-CWE-Other
|
CVE-2006-0995
|
2017-07-20 10:30 |
2006-03-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349263
|
5.0 |
MEDIUM
|
emc_dantz
|
retrospect
|
This vulnerability affects EMC Dantz, Retrospect versions 7.0.x (all 7.0.x versions previous to 7.0.109) as well as versions 6.5.x (all 6.5.x versions previous to 6.5.138)
|
NVD-CWE-Other
|
CVE-2006-0995
|
2017-07-20 10:30 |
2006-03-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349264
|
5.0 |
MEDIUM
|
netgear
|
wgt624
|
The backup configuration option in NETGEAR WGT624 Wireless Firewall Router stores sensitive information in cleartext, which allows remote attackers to obtain passwords and gain privileges.
|
NVD-CWE-Other
|
CVE-2006-1003
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349265
|
4.3 |
MEDIUM
|
cactusoft
|
parodia
|
Cross-site scripting (XSS) vulnerability in agencyprofile.asp in Parodia 6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the AG_ID parameter. NOTE: the provenance …
|
NVD-CWE-Other
|
CVE-2006-1004
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349266
|
7.5 |
HIGH
|
sendcard
|
sendcard
|
Multiple SQL injection vulnerabilities in sendcard.php in sendcard before 3.3.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.
|
CWE-89
SQLインジェクション
|
CVE-2006-1006
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349267
|
4.6 |
MEDIUM
|
m4_project
|
enigma-suite
|
M4 Project enigma-suite before 0.73.3 (Windows) has a default password of "nominal" for the "enigma-client" account, which allows local users to gain access.
|
NVD-CWE-Other
|
CVE-2006-1009
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349268
|
6.4 |
MEDIUM
|
crossfire
|
crossfire
|
Buffer overflow in socket/request.c in CrossFire before 1.9.0, when oldsocketmode is enabled, allows remote attackers to cause a denial of service (segmentation fault) and possibly execute code by se…
|
NVD-CWE-Other
|
CVE-2006-1010
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349269
|
6.4 |
MEDIUM
|
crossfire
|
crossfire
|
This vulnerability affects CrossFire versions 1.8.0 and previous.
|
NVD-CWE-Other
|
CVE-2006-1010
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349270
|
2.1 |
LOW
|
peters_software
|
lettermerger
|
LetterMerger 1.2 stores user information in Access database files with insecure permissions, which allows local users to obtain sensitive information. NOTE: the provenance of this information is unk…
|
NVD-CWE-Other
|
CVE-2006-1011
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349271
|
7.5 |
HIGH
|
wordpress
|
wordpress
|
SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execute arbitrary SQL commands via the User-Agent field in an HTTP header for a comm…
|
NVD-CWE-Other
|
CVE-2006-1012
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349272
|
4.3 |
MEDIUM
|
ukiweb
|
ukiboard
|
Cross-site scripting (XSS) vulnerability in fce.php in UKiBoard 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a BBCode url tag when using the show_post function. NOTE: the…
|
NVD-CWE-Other
|
CVE-2006-1019
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349273
|
7.5 |
HIGH
|
addsoft
|
storebot
|
SQL injection vulnerability in MgrLogin.asp in Addsoft StoreBot 2005 Professional allows remote attackers to execute arbitrary SQL commands via the Pwd parameter. NOTE: the provenance of this inform…
|
NVD-CWE-Other
|
CVE-2006-1024
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349274
|
7.5 |
HIGH
|
addsoft
|
storebot
|
This vulnerability affects all versions of AddSoft, StoreBot 2005 Professional Edition.
|
NVD-CWE-Other
|
CVE-2006-1024
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349275
|
6.8 |
MEDIUM
|
addsoft
|
storebot
|
Cross-site scripting (XSS) vulnerability in manage.asp in Addsoft StoreBot 2002 Standard allows remote attackers to inject arbitrary web script or HTML via the ShipMethod parameter. NOTE: the proven…
|
NVD-CWE-Other
|
CVE-2006-1025
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349276
|
7.5 |
HIGH
|
jfacets
|
jfacets
|
JFacets before 0.2 allows remote attackers to gain privileges as any account via a GET request with a modified account profileID.
|
NVD-CWE-Other
|
CVE-2006-1026
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349277
|
7.5 |
HIGH
|
jfacets
|
jfacets
|
This vulnerability affects JFacets versions prior to 0.2.
|
NVD-CWE-Other
|
CVE-2006-1026
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349278
|
5.0 |
MEDIUM
|
joomla
|
joomla
|
Unspecified vulnerability in mod_templatechooser in Joomla! 1.0.7 allows remote attackers to obtain sensitive information via an unspecified attack vector that reveals the path.
|
NVD-CWE-Other
|
CVE-2006-1030
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349279
|
7.5 |
HIGH
|
igenus
|
igenus_webmail
|
config/config_inc.php in iGENUS Webmail 2.02 and earlier allows remote attackers to include arbitrary local files via the SG_HOME parameter.
|
CWE-94
コード・インジェクション
|
CVE-2006-1031
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349280
|
4.3 |
MEDIUM
|
cpg-nuke
|
dragonfly_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) uname, (2) error, (3) profile or (4) the user…
|
NVD-CWE-Other
|
CVE-2006-1033
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349281
|
10.0 |
HIGH
|
van_dyke_technologies
|
securecrt securefx
|
Buffer overflow in SecureCRT 5.0.4 and earlier and SecureFX 3.0.4 and earlier allows remote attackers to have an unknown impact when a Unicode string is converted to a "narrow" string.
|
NVD-CWE-Other
|
CVE-2006-1038
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349282
|
5.0 |
MEDIUM
|
monopd
|
monopd
|
server.cpp in Monopd 0.9.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a string containing a large number of characters that are escaped when Monopd produces…
|
NVD-CWE-Other
|
CVE-2006-1046
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349283
|
5.0 |
MEDIUM
|
joomla
|
joomla
|
Joomla! 1.0.7 and earlier allows attackers to bypass intended access restrictions and gain certain privileges via certain attack vectors related to the (1) Weblink, (2) Polls, (3) Newsfeeds, (4) Webl…
|
NVD-CWE-Other
|
CVE-2006-1048
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349284
|
5.0 |
MEDIUM
|
joomla
|
joomla
|
This vulnerability affects Joomla! versions 1.0.7 and previous.
|
NVD-CWE-Other
|
CVE-2006-1048
|
2017-07-20 10:30 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349285
|
7.5 |
HIGH
|
akarru
|
social_bookmarking_engine
|
SQL injection vulnerability in Akarru Social BookMarking Engine before 0.4.3.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors, possibly involving the username pa…
|
NVD-CWE-Other
|
CVE-2006-1051
|
2017-07-20 10:30 |
2006-03-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349286
|
7.5 |
HIGH
|
xzgv
|
xzgv
|
Heap-based buffer overflow in zgv before 5.8 and xzgv before 0.8 might allow user-assisted attackers to execute arbitrary code via a JPEG image with more than 3 output components, such as a CMYK or Y…
|
CWE-119
バッファエラー
|
CVE-2006-1060
|
2017-07-20 10:30 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349287
|
7.5 |
HIGH
|
daniel_stenberg
|
curl
|
Heap-based buffer overflow in cURL and libcURL 7.15.0 through 7.15.2 allows remote attackers to execute arbitrary commands via a TFTP URL (tftp://) with a valid hostname and a long path.
|
NVD-CWE-Other
|
CVE-2006-1061
|
2017-07-20 10:30 |
2006-03-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349288
|
7.5 |
HIGH
|
daniel_stenberg
|
curl
|
Update to version 7.15.3.
|
NVD-CWE-Other
|
CVE-2006-1061
|
2017-07-20 10:30 |
2006-03-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349289
|
5.0 |
MEDIUM
|
lurker
|
lurker
|
Unspecified vulnerability in lurker.cgi for Lurker 2.0 and earlier allows attackers to read arbitrary files via unknown vectors.
|
NVD-CWE-Other
|
CVE-2006-1062
|
2017-07-20 10:30 |
2006-03-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349290
|
5.0 |
MEDIUM
|
lurker
|
lurker
|
This vulnerability affects all versions of Lurker from 0.1a through 0.2
|
NVD-CWE-Other
|
CVE-2006-1062
|
2017-07-20 10:30 |
2006-03-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349291
|
5.0 |
MEDIUM
|
lurker
|
lurker
|
Unspecified vulnerability in Lurker 2.0 and earlier allows remote attackers to create or overwrite files in any writable directory that is named "mbox".
|
NVD-CWE-Other
|
CVE-2006-1063
|
2017-07-20 10:30 |
2006-03-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349292
|
5.0 |
MEDIUM
|
lurker
|
lurker
|
This vulnarability affects all verions of Lurker from 0.1a through 0.2
|
NVD-CWE-Other
|
CVE-2006-1063
|
2017-07-20 10:30 |
2006-03-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349293
|
2.6 |
LOW
|
lurker
|
lurker
|
Multiple cross-site scripting (XSS) vulnerabilities in Lurker 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-1064
|
2017-07-20 10:30 |
2006-03-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349294
|
2.6 |
LOW
|
lurker
|
lurker
|
This vulnerability affects all verions of Lurker from 0.1a through 2.0
|
NVD-CWE-Other
|
CVE-2006-1064
|
2017-07-20 10:30 |
2006-03-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349295
|
4.3 |
MEDIUM
|
punbb
|
punbb
|
Cross-site scripting (XSS) vulnerability in header.php in PunBB 1.2.10 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly handled when the PHP_SELF vari…
|
NVD-CWE-Other
|
CVE-2006-1089
|
2017-07-20 10:30 |
2006-03-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349296
|
7.8 |
HIGH
|
punbb
|
punbb
|
register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations.
|
NVD-CWE-Other
|
CVE-2006-1090
|
2017-07-20 10:30 |
2006-03-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349297
|
7.8 |
HIGH
|
punbb
|
punbb
|
This vulnerability affects PunBB version 1.2.10, and may affect all previous versions.
|
NVD-CWE-Other
|
CVE-2006-1090
|
2017-07-20 10:30 |
2006-03-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349298
|
7.8 |
HIGH
|
kaspersky_lab
|
kaspersky_anti-virus
|
Kaspersky Antivirus 5.0.5 and 5.5.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-1091
|
2017-07-20 10:30 |
2006-03-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349299
|
7.2 |
HIGH
|
apache
|
mod_python
|
Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie.
|
CWE-22
パス・トラバーサル
|
CVE-2006-1095
|
2017-07-20 10:30 |
2006-03-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349300
|
4.3 |
MEDIUM
|
datenbank_module
|
datenbank_module
|
Multiple cross-site scripting (XSS) vulnerabilities in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allow remote attackers to inject arbitrary web script or HTML via the fileid parameter t…
|
NVD-CWE-Other
|
CVE-2006-1097
|
2017-07-20 10:30 |
2006-03-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|