|
349301
|
4.3 |
MEDIUM
|
datenbank_module
|
datenbank_module
|
This vulnerability may only affect Datenbank MOD 2.7 and earlier versions in a Woltlab Burning Board environment.
|
NVD-CWE-Other
|
CVE-2006-1097
|
2017-07-20 10:30 |
2006-03-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349302
|
5.0 |
MEDIUM
|
bmail
|
bmail
|
SQL injection vulnerability in bmail before Aardvark PR9.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving GBK character sets.
|
NVD-CWE-Other
|
CVE-2006-1118
|
2017-07-20 10:30 |
2006-03-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349303
|
6.4 |
MEDIUM
|
gallery_project
|
gallery
|
Gallery 2 up to 2.0.2 allows remote attackers to spoof their IP address via a modified X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is checked by Gallery before other more reliable sources of…
|
NVD-CWE-Other
|
CVE-2006-1126
|
2017-07-20 10:30 |
2006-03-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349304
|
4.3 |
MEDIUM
|
gallery_project
|
gallery
|
Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is not pr…
|
NVD-CWE-Other
|
CVE-2006-1127
|
2017-07-20 10:30 |
2006-03-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349305
|
6.4 |
MEDIUM
|
gallery_project
|
gallery
|
Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote attackers to access and delete files by specifying the session in a cooki…
|
NVD-CWE-Other
|
CVE-2006-1128
|
2017-07-20 10:30 |
2006-03-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349306
|
4.3 |
MEDIUM
|
bitweaver
|
bitweaver
|
Cross-site scripting (XSS) vulnerability in read.php in bitweaver CMS 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the comment_title parameter.
|
NVD-CWE-Other
|
CVE-2006-1131
|
2017-07-20 10:30 |
2006-03-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349307
|
4.3 |
MEDIUM
|
sblog
|
sblog
|
Multiple cross-site scripting (XSS) vulnerabilities in sBlog 0.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to search.php or (2) username parameter …
|
NVD-CWE-Other
|
CVE-2006-1135
|
2017-07-20 10:30 |
2006-03-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349308
|
7.5 |
HIGH
|
redblog
|
redblog
|
SQL injection vulnerability in rss.php in RedBLoG 0.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
|
NVD-CWE-Other
|
CVE-2006-1140
|
2017-07-20 10:30 |
2006-03-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349309
|
7.5 |
HIGH
|
inter7
|
qmailadmin
|
Buffer overflow in qmailadmin.c in QmailAdmin before 1.2.10 allows remote attackers to execute arbitrary code via a long PATH_INFO environment variable.
|
NVD-CWE-Other
|
CVE-2006-1141
|
2017-07-20 10:30 |
2006-03-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349310
|
5.0 |
MEDIUM
|
solido_systems
|
ravenous_web_server
|
Unspecified vulnerability in Ravenous Web Server before 0.7.1 allows remote attackers to access arbitrary rvplg files, with unknown impact.
|
NVD-CWE-Other
|
CVE-2006-1142
|
2017-07-20 10:30 |
2006-03-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349311
|
7.8 |
HIGH
|
teg
|
tenes_empanadas_graciela
|
Buffer overflow in Tenes Empanadas Graciela (TEG) 0.11.1, automatically appends an _ (underscore) to the end of duplicate nicknames, which allows remote attackers to cause a denial of service (applic…
|
NVD-CWE-Other
|
CVE-2006-1150
|
2017-07-20 10:30 |
2006-03-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349312
|
5.0 |
MEDIUM
|
m_phorum
|
m_phorum
|
PHP remote file inclusion vulnerability in index.php in M-Phorum 0.2 allows remote attackers to include arbitrary files via the go parameter. NOTE: the provenance of this information is unknown; the…
|
NVD-CWE-Other
|
CVE-2006-1152
|
2017-07-20 10:30 |
2006-03-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349313
|
4.3 |
MEDIUM
|
manas_tungare
|
site_membership_script
|
Cross-site scripting (XSS) vulnerability in manas tungare Site Membership Script before 8 March, 2006 allows remote attackers to inject arbitrary web script or HTML via the Error parameter in (1) log…
|
NVD-CWE-Other
|
CVE-2006-1155
|
2017-07-20 10:30 |
2006-03-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349314
|
5.0 |
MEDIUM
|
manas_tungare
|
site_membership_script
|
SQL injection vulnerability in manas tungare Site Membership Script before 8 March, 2006 allows remote attackers to execute arbitrary SQL commands via the Username parameter in login.asp.
|
NVD-CWE-Other
|
CVE-2006-1156
|
2017-07-20 10:30 |
2006-03-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349315
|
5.1 |
MEDIUM
|
nodez
|
nodez
|
Directory traversal vulnerability in Nodez 4.6.1.1 and earlier allows remote attackers to read or include arbitrary PHP files via a .. (dot dot) in the op parameter, as demonstrated by inserting mal…
|
NVD-CWE-Other
|
CVE-2006-1162
|
2017-07-20 10:30 |
2006-03-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349316
|
6.8 |
MEDIUM
|
nodez
|
nodez
|
Cross-site scripting (XSS) vulnerability in Nodez 4.6.1.1 allows remote attackers to inject arbitrary web script or HTML via the op parameter. NOTE: it is possible that this issue is resultant from …
|
NVD-CWE-Other
|
CVE-2006-1163
|
2017-07-20 10:30 |
2006-03-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349317
|
4.3 |
MEDIUM
|
andreas_gohr
|
dokuwiki
|
Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors relating to…
|
NVD-CWE-Other
|
CVE-2006-1165
|
2017-07-20 10:30 |
2006-03-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349318
|
3.7 |
LOW
|
monotone
|
monotone
|
Monotone 0.25 and earlier, when a user creates a file in a directory called "mt", and when checking out that file on a case-insensitive file system such as Windows or Mac OS X, places the file into t…
|
NVD-CWE-Other
|
CVE-2006-1166
|
2017-07-20 10:30 |
2006-03-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349319
|
4.0 |
MEDIUM
|
weonlydo
|
weonlydo_sftp
|
The WeOnlyDo! SFTP (wodSFTP) ActiveX control is marked as safe for scripting, which allows remote attackers to read and write files in arbitrary locations by accessing the control from a web page.
|
NVD-CWE-Other
|
CVE-2006-1175
|
2017-07-20 10:30 |
2006-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349320
|
7.5 |
HIGH
|
ebay
|
enhanced_picture_services
|
Buffer overflow in eBay Enhanced Picture Services (aka EPUImageControl Class) in EUPWALcontrol.dll before 1.0.3.48, as used in Sell Your Item (SYI), Setup & Test eBay Enhanced Picture Services, Pictu…
|
NVD-CWE-Other
|
CVE-2006-1176
|
2017-07-20 10:30 |
2006-07-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349321
|
5.0 |
MEDIUM
|
tamarack_consulting
|
tamarack_mmsd
|
Tamarack MMSd before 7.992 allows remote attackers to cause a denial of service (crash) via malformed RFC1006 (OSI over TCP/IP) packets.
|
NVD-CWE-Other
|
CVE-2006-1178
|
2017-07-20 10:30 |
2006-07-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349322
|
4.3 |
MEDIUM
|
david_barrett
|
qwikiwiki
|
Multiple cross-site scripting (XSS) vulnerabilities in QwikiWiki 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) from and (2) help parameters to (a) index.php; (3) actio…
|
NVD-CWE-Other
|
CVE-2006-1196
|
2017-07-20 10:30 |
2006-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349323
|
4.3 |
MEDIUM
|
woltlab
|
burning_board
|
Cross-site scripting (XSS) vulnerability in misc.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the percent parameter. NOTE: this issue h…
|
NVD-CWE-Other
|
CVE-2006-1215
|
2017-07-20 10:30 |
2006-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349324
|
7.5 |
HIGH
|
hosting_controller
|
hosting_controller
|
SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provenance of this info…
|
NVD-CWE-Other
|
CVE-2006-1229
|
2017-07-20 10:30 |
2006-03-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349325
|
7.5 |
HIGH
|
hosting_controller
|
hosting_controller
|
This vulnerability may affect all versions of Hosting Controller previous to 6.1 Hotfix 2.9 as well.
|
NVD-CWE-Other
|
CVE-2006-1229
|
2017-07-20 10:30 |
2006-03-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349326
|
4.3 |
MEDIUM
|
countersoft
|
gemini
|
Cross-site scripting (XSS) vulnerability in issue/createissue.aspx in Gemini 2.0 allows remote attackers to inject arbitrary web script or HTML via the rtcDescription$RadEditor1 field. NOTE: the pro…
|
NVD-CWE-Other
|
CVE-2006-1239
|
2017-07-20 10:30 |
2006-03-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349327
|
7.2 |
HIGH
|
ibm
|
aix
|
Unspecified vulnerability in mklvcopy in BOS.RTE.LVM in IBM AIX 5.3 allows local users to execute arbitrary commands when mklvcopy calls external commands, possibly due to an untrusted search path vu…
|
NVD-CWE-noinfo
|
CVE-2006-1246
|
2017-07-20 10:30 |
2006-03-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349328
|
5.0 |
MEDIUM
|
sa-exim
|
sa-exim
|
Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, …
|
CWE-94
コード・インジェクション
|
CVE-2006-1251
|
2017-07-20 10:30 |
2006-03-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349329
|
10.0 |
HIGH
|
borderware
|
mxtreme
|
Unspecified vulnerability in BorderWare MXtreme 5.0 and 6.0 allows remote attackers to have an unknown impact via unknown attack vectors. NOTE: the provenance of this information is unknown; the deta…
|
NVD-CWE-noinfo
|
CVE-2006-1254
|
2017-07-20 10:30 |
2006-03-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349330
|
10.0 |
HIGH
|
mercur
|
mercur_messaging
|
Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code vi…
|
NVD-CWE-Other
|
CVE-2006-1255
|
2017-07-20 10:30 |
2006-03-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349331
|
4.3 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.1 allows remote attackers to inject arbitrary web script or HTML via the set_theme parameter.
|
NVD-CWE-Other
|
CVE-2006-1258
|
2017-07-20 10:30 |
2006-03-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349332
|
4.3 |
MEDIUM
|
aspportal
|
aspportal
|
Multiple cross-site scripting (XSS) vulnerabilities in ASPPortal 3.00 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-1261
|
2017-07-20 10:30 |
2006-03-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349333
|
7.5 |
HIGH
|
aspportal
|
aspportal
|
Multiple SQL injection vulnerabilities in ASPPortal 3.00 have unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2006-1262
|
2017-07-20 10:30 |
2006-03-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349334
|
4.3 |
MEDIUM
|
virtual_communication_services
|
vpmi_enterprise
|
Cross-site scripting (XSS) vulnerability in Service_Requests.asp in VPMi Enterprise 3.3 allows remote attackers to inject arbitrary web script or HTML via the Request_Name_Display parameter.
|
NVD-CWE-Other
|
CVE-2006-1266
|
2017-07-20 10:30 |
2006-03-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349335
|
6.2 |
MEDIUM
|
rahul_dhesi
|
zoo
|
Buffer overflow in the parse function in parse.c in zoo 2.10 might allow local users to execute arbitrary code via long filename command line arguments, which are not properly handled during archive …
|
NVD-CWE-Other
|
CVE-2006-1269
|
2017-07-20 10:30 |
2006-03-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349336
|
3.5 |
LOW
|
inprotect
|
inprotect
|
Multiple cross-site scripting (XSS) vulnerabilities in zones.php in Inprotect 0.21 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Description field. NOTE: the …
|
NVD-CWE-Other
|
CVE-2006-1270
|
2017-07-20 10:30 |
2006-03-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349337
|
3.5 |
LOW
|
inprotect
|
inprotect
|
A remote attacker must have "Manage Zones and Server" permissions on Inprotect to exploit this vulnerability.
|
NVD-CWE-Other
|
CVE-2006-1270
|
2017-07-20 10:30 |
2006-03-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349338
|
5.0 |
MEDIUM
|
ggz_gaming_zone
|
ggz_gaming_zone
|
GGZ Gaming Zone 0.0.12 allows remote attackers to cause a denial of service (client disconnect) via inputs that produce malformed XML, including (1) trailing ' (apostrophe) character on the ID attrib…
|
CWE-399
リソース管理の問題
|
CVE-2006-1275
|
2017-07-20 10:30 |
2006-03-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349339
|
10.0 |
HIGH
|
himpfen_consulting
|
php_simplenews
|
admin.php in Himpfen Consulting Company PHP SimpleNEWS 1.0.0 allows remote attackers to bypass authentication by setting the admin parameter in a cookie.
|
NVD-CWE-Other
|
CVE-2006-1276
|
2017-07-20 10:30 |
2006-03-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349340
|
5.0 |
MEDIUM
|
sherzod_ruzmetov
|
cgi_session
|
CGI::Session 4.03-1 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by (1) Driver::File, (2) Driver::db_file, and possibly (3) Driver::sqlite.
|
NVD-CWE-Other
|
CVE-2006-1279
|
2017-07-20 10:30 |
2006-03-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349341
|
7.5 |
HIGH
|
sherzod_ruzmetov
|
cgi_session
|
CGI::Session 4.03-1 does not set proper permissions on temporary files created in (1) Driver::File and (2) Driver::db_file, which allows local users to obtain privileged information, such as session …
|
NVD-CWE-Other
|
CVE-2006-1280
|
2017-07-20 10:30 |
2006-03-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349342
|
7.2 |
HIGH
|
freebsd
|
freebsd
|
opiepasswd in One-Time Passwords in Everything (OPIE) in FreeBSD 4.10-RELEASE-p22 through 6.1-STABLE before 20060322 uses the getlogin function to determine the invoking user account, which might all…
|
NVD-CWE-Other
|
CVE-2006-1283
|
2017-07-20 10:30 |
2006-03-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349343
|
2.1 |
LOW
|
symantec
|
ghost_solutions_suite norton_ghost
|
Buffer overflow in the login dialog in dbisqlc.exe in SQLAnywhere for Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, might allow local users to read certain sensiti…
|
NVD-CWE-Other
|
CVE-2006-1286
|
2017-07-20 10:30 |
2006-03-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349344
|
2.1 |
LOW
|
symantec
|
ghost_solutions_suite norton_ghost
|
Update to Symantec Ghost 8.3 that is shipped as a part of Symantec Ghost Solutions Suite 1.1.
|
NVD-CWE-Other
|
CVE-2006-1286
|
2017-07-20 10:30 |
2006-03-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349345
|
7.5 |
HIGH
|
invision_power_services
|
invision_power_board
|
Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060105 allow remote attackers to execute arbitrary SQL commands via cookies, related to (1) arrays of id/…
|
NVD-CWE-Other
|
CVE-2006-1288
|
2017-07-20 10:30 |
2006-03-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349346
|
4.3 |
MEDIUM
|
spip
|
spip
|
Cross-site scripting (XSS) vulnerability in recherche.php3 in SPIP 1.8.2-g allows remote attackers to inject arbitrary web script or HTML via the recherche parameter.
|
NVD-CWE-Other
|
CVE-2006-1295
|
2017-07-20 10:30 |
2006-03-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349347
|
7.5 |
HIGH
|
beagle-project
|
beagle
|
Untrusted search path vulnerability in Beagle 0.2.2.1 might allow local users to gain privileges via a malicious beagle-info program in the current working directory, or possibly directories specifie…
|
NVD-CWE-Other
|
CVE-2006-1296
|
2017-07-20 10:30 |
2006-03-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349348
|
6.2 |
MEDIUM
|
runit
|
runit
|
chpst in runit 1.3.3-1 for Debian GNU/Linux, when compiled on little endian i386 machines against dietlibc, does not properly handle when multiple groups are specified in the -u option, which causes …
|
NVD-CWE-Other
|
CVE-2006-1319
|
2017-07-20 10:30 |
2006-03-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349349
|
6.2 |
MEDIUM
|
runit
|
runit
|
This vulnerability may be relevant only to Debian GNU/Linux implementations on little endian i386 machines.
|
NVD-CWE-Other
|
CVE-2006-1319
|
2017-07-20 10:30 |
2006-03-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349350
|
7.5 |
HIGH
|
rssh
|
rssh
|
util.c in rssh 2.3.0 in Debian GNU/Linux does not use braces to make a block, which causes a check for CVS to always succeed and allows rsync and rdist to bypass intended access restrictions in rssh.…
|
NVD-CWE-Other
|
CVE-2006-1320
|
2017-07-20 10:30 |
2006-03-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|