|
349351
|
4.3 |
MEDIUM
|
webcheck
|
webcheck
|
Cross-site scripting (XSS) vulnerability in webcheck before 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the (1) url, (2) title, or (3) author name in a crawled page, whic…
|
NVD-CWE-Other
|
CVE-2006-1321
|
2017-07-20 10:30 |
2006-03-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349352
|
4.3 |
MEDIUM
|
webcheck
|
webcheck
|
Versions before 1.0 are named "linbot" instead of "webcheck".
|
NVD-CWE-Other
|
CVE-2006-1321
|
2017-07-20 10:30 |
2006-03-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349353
|
5.0 |
MEDIUM
|
novell
|
netware_ftp_server netware
|
Novell Netware NWFTPD 5.06.05 allows remote attackers to cause a denial of service (ABEND) via an MDTM command that uses a long path for the target file, possibly due to a buffer overflow.
|
NVD-CWE-Other
|
CVE-2006-1322
|
2017-07-20 10:30 |
2006-03-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349354
|
6.8 |
MEDIUM
|
woltlab
|
burning_board
|
Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter w…
|
NVD-CWE-Other
|
CVE-2006-1324
|
2017-07-20 10:30 |
2006-03-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349355
|
6.8 |
MEDIUM
|
streber
|
streber
|
Cross-site scripting (XSS) vulnerability in Streber 0.055 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-1325
|
2017-07-20 10:30 |
2006-03-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349356
|
6.8 |
MEDIUM
|
streber
|
streber
|
The vulnerability has been fixed in version 0.055 (development release).
|
NVD-CWE-Other
|
CVE-2006-1325
|
2017-07-20 10:30 |
2006-03-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349357
|
5.0 |
MEDIUM
|
jabberstudio
|
jabberd
|
The SASL negotiation in Jabber Studio jabberd before 2.0s11 allows remote attackers to cause a denial of service ("c2s segfault") by sending a "response stanza before an auth stanza".
|
NVD-CWE-Other
|
CVE-2006-1329
|
2017-07-20 10:30 |
2006-03-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349358
|
6.8 |
MEDIUM
|
phpoutsourcing
|
noahs_classifieds
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) method or (2) list par…
|
NVD-CWE-Other
|
CVE-2006-1331
|
2017-07-20 10:30 |
2006-03-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349359
|
6.4 |
MEDIUM
|
phpoutsourcing
|
noahs_classifieds
|
Noah's Classifieds 1.3 and earlier allows remote attackers to obtain sensitive information via an invalid list parameter in the showdetails method to index.php, which reveals the path in an error mes…
|
NVD-CWE-Other
|
CVE-2006-1332
|
2017-07-20 10:30 |
2006-03-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349360
|
3.7 |
LOW
|
gnome
|
screensaver
|
gnome screensaver before 2.14, when running on an X server with AllowDeactivateGrabs and AllowClosedownGrabs enabled, allows attackers with physical access to cause the screensaver to crash and acces…
|
NVD-CWE-Other
|
CVE-2006-1335
|
2017-07-20 10:30 |
2006-03-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349361
|
3.7 |
LOW
|
gnome
|
screensaver
|
The vulnerability has reportedly been fixed in version 2.14.
|
NVD-CWE-Other
|
CVE-2006-1335
|
2017-07-20 10:30 |
2006-03-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349362
|
7.5 |
HIGH
|
mailenable
|
mailenable
|
Buffer overflow in the POP 3 (POP3) service in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edition before 1.21 allows remote attackers to execute arbitra…
|
CWE-119
バッファエラー
|
CVE-2006-1337
|
2017-07-20 10:30 |
2006-03-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349363
|
5.0 |
MEDIUM
|
mailenable
|
mailenable_enterprise mailenable_professional
|
Webmail in MailEnable Professional Edition before 1.73 and Enterprise Edition before 1.21 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors involving "inc…
|
CWE-399
リソース管理の問題
|
CVE-2006-1338
|
2017-07-20 10:30 |
2006-03-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349364
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic Server 6.1 SP7 and earlier allows remote attackers to read arbitrary files via unknown attack vectors related to a "default internal servlet" accessed through HTTP.
|
NVD-CWE-Other
|
CVE-2006-1351
|
2017-07-20 10:30 |
2006-03-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349365
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and WebLogic Server 6.1 SP7 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via …
|
NVD-CWE-Other
|
CVE-2006-1352
|
2017-07-20 10:30 |
2006-03-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349366
|
5.1 |
MEDIUM
|
andrew_hsu
|
libvc rolo
|
Stack-based buffer overflow in the count_vcards function in LibVC 3, as used in Rolo, allows user-assisted attackers to execute arbitrary code via a vCard file (e.g. contacts.vcf) containing a long l…
|
NVD-CWE-Other
|
CVE-2006-1356
|
2017-07-20 10:30 |
2006-03-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349367
|
4.3 |
MEDIUM
|
oswiki
|
oswiki
|
Cross-site scripting (XSS) vulnerability in OSWiki before 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the username field to (1) list.rhtml or (2) show.rhtml.
|
NVD-CWE-Other
|
CVE-2006-1361
|
2017-07-20 10:30 |
2006-03-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349368
|
4.3 |
MEDIUM
|
oswiki
|
oswiki
|
This vulnerability is addressed in the following product release:
OSWiki, OSWiki, 0.3.1
|
NVD-CWE-Other
|
CVE-2006-1361
|
2017-07-20 10:30 |
2006-03-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349369
|
6.8 |
MEDIUM
|
invision_power_services
|
invision_power_board
|
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.5 and earlier before 20060308 allows remote attackers to inject arbitrary web script or HTML via a Private Message (PM) in c…
|
NVD-CWE-Other
|
CVE-2006-1369
|
2017-07-20 10:30 |
2006-03-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349370
|
6.8 |
MEDIUM
|
invision_power_services
|
invision_power_board
|
Update to version 2.1.5 (2006-03-08 or later).
|
NVD-CWE-Other
|
CVE-2006-1369
|
2017-07-20 10:30 |
2006-03-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349371
|
9.3 |
HIGH
|
realnetworks
|
realone_player realplayer
|
Buffer overflow in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne Player v1, RealPlayer 8, and RealPlayer Enterprise before 20060322 allows re…
|
NVD-CWE-Other
|
CVE-2006-1370
|
2017-07-20 10:30 |
2006-03-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349372
|
9.3 |
HIGH
|
realnetworks
|
realone_player realplayer
|
This vulnerability affects all versions of RealNetworks, RealPlayer from 10.5 v6.0.12.1040 through 10.5 v6.0.12.1348.
|
NVD-CWE-Other
|
CVE-2006-1370
|
2017-07-20 10:30 |
2006-03-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349373
|
5.0 |
MEDIUM
|
benson_it_solutions
|
1webcalendar
|
Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) EventID parameter in viewEvent.cfm, (2) NewsID parameter in…
|
NVD-CWE-Other
|
CVE-2006-1372
|
2017-07-20 10:30 |
2006-03-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349374
|
7.5 |
HIGH
|
brain_book_software
|
adman
|
SQL injection vulnerability in viewStatement.php in AdMan 1.0.20051221 and earlier allows remote attackers to execute arbitrary SQL commands via the transactions_offset parameter.
|
NVD-CWE-Other
|
CVE-2006-1374
|
2017-07-20 10:30 |
2006-03-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349375
|
5.0 |
MEDIUM
|
brain_book_software
|
adman
|
AdMan 1.0.20051221 and earlier allows remote attackers to obtain the full path via (1) a blank campaignId parameter to editCampaign.php and (2) a blank schemeId parameter to viewPricingScheme.php.
|
NVD-CWE-Other
|
CVE-2006-1375
|
2017-07-20 10:30 |
2006-03-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349376
|
2.1 |
LOW
|
debian
|
debian_linux
|
The installation of Debian GNU/Linux 3.1r1 from the network install CD creates /var/log/debian-installer/cdebconf with world writable permissions, which allows local users to cause a denial of servic…
|
NVD-CWE-Other
|
CVE-2006-1376
|
2017-07-20 10:30 |
2006-03-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349377
|
4.0 |
MEDIUM
|
pablo_software_solutions
|
baby_ftp_server
|
Directory traversal vulnerability in Baby FTP Server (BabyFTP) 1.24 allows remote authenticated users to determine existence of files outside the intended document root via unspecified manipulations,…
|
NVD-CWE-Other
|
CVE-2006-1383
|
2017-07-20 10:30 |
2006-03-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349378
|
4.3 |
MEDIUM
|
ibm
|
tivoli_business_systems_manager
|
Cross-site scripting (XSS) vulnerability in apwc_win_main.jsp in the web console in IBM Tivoli Business Systems Manager (TBSM) before 3.1.0.1 allows remote attackers to inject arbitrary web script or…
|
NVD-CWE-Other
|
CVE-2006-1384
|
2017-07-20 10:30 |
2006-03-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349379
|
7.5 |
HIGH
|
twiki
|
twiki
|
The (1) rdiff and (2) preview scripts in TWiki 4.0 and 4.0.1 ignore access control settings, which allows remote attackers to read restricted areas and access restricted content in TWiki topics.
|
NVD-CWE-Other
|
CVE-2006-1386
|
2017-07-20 10:30 |
2006-03-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349380
|
4.0 |
MEDIUM
|
twiki
|
twiki
|
TWiki 4.0, 4.0.1, and 20010901 through 20040904 allows remote authenticated users with edit rights to cause a denial of service (infinite recursion leading to CPU and memory consumption) via INCLUDE …
|
NVD-CWE-Other
|
CVE-2006-1387
|
2017-07-20 10:30 |
2006-03-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349381
|
4.3 |
MEDIUM
|
university_of_washington
|
pubcookie
|
Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in the login server in University of Washington Pubcookie 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote a…
|
NVD-CWE-Other
|
CVE-2006-1392
|
2017-07-20 10:30 |
2006-03-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349382
|
4.3 |
MEDIUM
|
university_of_washington
|
pubcookie
|
Multiple cross-site scripting (XSS) vulnerabilities in the mod_pubcookie Apache application server module in University of Washington Pubcookie 1.x, 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 be…
|
NVD-CWE-Other
|
CVE-2006-1393
|
2017-07-20 10:30 |
2006-03-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349383
|
7.5 |
HIGH
|
cholod
|
mysql_based_message_board
|
SQL injection vulnerability in mb.cgi in Cholod MySQL Based Message Board allows remote attackers to execute arbitrary SQL commands via unspecified vectors in a showmessage action, possibly the usern…
|
NVD-CWE-Other
|
CVE-2006-1395
|
2017-07-20 10:30 |
2006-03-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349384
|
4.3 |
MEDIUM
|
cholod
|
mysql_based_message_board
|
Multiple cross-site scripting (XSS) vulnerabilities in Cholod MySQL Based Message Board allow remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of thi…
|
NVD-CWE-Other
|
CVE-2006-1396
|
2017-07-20 10:30 |
2006-03-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349385
|
4.3 |
MEDIUM
|
php_lite
|
meeting_reserve
|
Cross-site scripting (XSS) vulnerability in searchresult.php in Meeting Reserve 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the search_term parameter. NOTE: the prove…
|
NVD-CWE-Other
|
CVE-2006-1399
|
2017-07-20 10:30 |
2006-03-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349386
|
4.3 |
MEDIUM
|
metisware
|
instructor
|
Cross-site scripting (XSS) vulnerability in MyTasks/PersonalTaskEdit.asp in Metisware Instructor 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the Task parameter.
|
NVD-CWE-Other
|
CVE-2006-1400
|
2017-07-20 10:30 |
2006-03-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349387
|
4.3 |
MEDIUM
|
php_lite
|
calendar_express
|
Multiple cross-site scripting (XSS) vulnerabilities in search.php in Calendar Express 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) allwords or (2) oneword parameter. …
|
NVD-CWE-Other
|
CVE-2006-1401
|
2017-07-20 10:30 |
2006-03-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349388
|
7.5 |
HIGH
|
csdoom
|
csdoom
|
Buffer overflow in client/server Doom (csDoom) 0.7 and earlier allows remote attackers to (1) cause a denial of service via a long nickname or teamname to the SV_SetupUserInfo function or (2) execute…
|
NVD-CWE-Other
|
CVE-2006-1402
|
2017-07-20 10:30 |
2006-03-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349389
|
7.8 |
HIGH
|
csdoom
|
csdoom_2005
|
Format string vulnerability in the PrintString function in c_console.cpp in client/server Doom (csDoom) 0.7 and earlier allows remote attackers to cause a denial of service and possibly execute arbit…
|
NVD-CWE-Other
|
CVE-2006-1403
|
2017-07-20 10:30 |
2006-03-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349390
|
7.8 |
HIGH
|
csdoom
|
csdoom_2005
|
<a href="http://cwe.mitre.org/data/definitions/134.html">CWE-134: Use of Externally-Controlled Format String</a>
|
NVD-CWE-Other
|
CVE-2006-1403
|
2017-07-20 10:30 |
2006-03-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349391
|
5.8 |
MEDIUM
|
industrial_imagination
|
blankol
|
Multiple cross-site scripting (XSS) vulnerabilities in bol.cgi in BlankOL 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) file or (2) function parameter.
|
NVD-CWE-Other
|
CVE-2006-1404
|
2017-07-20 10:30 |
2006-03-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349392
|
5.8 |
MEDIUM
|
sheer_vision_technologies
|
sscms
|
Cross-site scripting (XSS) vulnerability in search.aspx in SweetSuite.NET Content Management System (ssCMS) 2.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the ke…
|
NVD-CWE-Other
|
CVE-2006-1405
|
2017-07-20 10:30 |
2006-03-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349393
|
4.3 |
MEDIUM
|
uniforum
|
uniforum
|
Multiple cross-site scripting (XSS) vulnerabilities in wbadmlog.aspx in uniForum 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtuser or (2) txtpassword p…
|
NVD-CWE-Other
|
CVE-2006-1406
|
2017-07-20 10:30 |
2006-03-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349394
|
5.8 |
MEDIUM
|
webhost_automation
|
helm_web_hosting_control_panel
|
Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parame…
|
NVD-CWE-Other
|
CVE-2006-1407
|
2017-07-20 10:30 |
2006-03-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349395
|
5.8 |
MEDIUM
|
webhost_automation
|
helm_web_hosting_control_panel
|
These issues are reportedly fixed by the vendor. Version 3.2.10-stable will contain these fixes when it is released. Contact the vendor for further information on obtaining fixes.
|
NVD-CWE-Other
|
CVE-2006-1407
|
2017-07-20 10:30 |
2006-03-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349396
|
5.0 |
MEDIUM
|
vavoom
|
vavoom
|
Vavoom 1.19.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via (1) a packet with no data or (2) a large packet, which prevents Vavoom from discarding the packet fr…
|
NVD-CWE-Other
|
CVE-2006-1408
|
2017-07-20 10:30 |
2006-03-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349397
|
5.0 |
MEDIUM
|
vavoom
|
vavoom
|
Buffer overflow in Vavoom 1.19.1 and earlier allows remote attackers to cause a denial of service (application crash) via an invalid comprLength value in a compressed packet.
|
NVD-CWE-Other
|
CVE-2006-1409
|
2017-07-20 10:30 |
2006-03-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349398
|
4.3 |
MEDIUM
|
xigla
|
absolute_live_support_xe
|
Multiple cross-site scripting (XSS) vulnerabilities in XIGLA Absolute Live Support XE 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Screen name or (2) Sess…
|
NVD-CWE-Other
|
CVE-2006-1410
|
2017-07-20 10:30 |
2006-03-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349399
|
4.3 |
MEDIUM
|
xigla
|
absolute_image_gallery_xe
|
Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the shownew parameter in gallery.asp and (…
|
NVD-CWE-Other
|
CVE-2006-1411
|
2017-07-20 10:30 |
2006-03-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349400
|
4.3 |
MEDIUM
|
htmljunction
|
ezhomepagepro
|
Multiple cross-site scripting (XSS) vulnerabilities in EZHomepagePro 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) adid or (2) aname parameter in (a) commo…
|
NVD-CWE-Other
|
CVE-2006-1413
|
2017-07-20 10:30 |
2006-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|