|
349401
|
4.3 |
MEDIUM
|
toast_forums
|
toast_forums
|
Multiple cross-site scripting (XSS) vulnerabilities in toast.asp in Toast Forums 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) author, (2) subject, (3) mes…
|
NVD-CWE-Other
|
CVE-2006-1414
|
2017-07-20 10:30 |
2006-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349402
|
4.3 |
MEDIUM
|
dotnetbb
|
dotnetbb_forums
|
Cross-site scripting (XSS) vulnerability in iforget.aspx in dotNetBB 2.42EC SP 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the em parameter.
|
NVD-CWE-Other
|
CVE-2006-1415
|
2017-07-20 10:30 |
2006-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349403
|
4.3 |
MEDIUM
|
xigla
|
absolute_faq_manager_.net
|
Cross-site scripting (XSS) vulnerability in afmsearch.aspx in Absolute FAQ Manager .NET 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module pa…
|
NVD-CWE-Other
|
CVE-2006-1416
|
2017-07-20 10:30 |
2006-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349404
|
4.3 |
MEDIUM
|
caloris_planitia_technologies
|
web_quiz_pro
|
Multiple cross-site scripting (XSS) vulnerabilities in Caloris Planitia Online Quiz System (aka Web Quiz pro), possibly 1.0, allow remote attackers to inject arbitrary web script or HTML via the (1) …
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-1417
|
2017-07-20 10:30 |
2006-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349405
|
2.6 |
LOW
|
caloris_planitia_technologies
|
e-school_management_system
|
Cross-site scripting (XSS) vulnerability in default.asp in Caloris Planitia E-School Management System 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg param…
|
NVD-CWE-Other
|
CVE-2006-1418
|
2017-07-20 10:30 |
2006-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349406
|
2.6 |
LOW
|
caloris_planitia_technologies
|
e-school_management_system
|
A new version of School Management System was released on May 28, 2006.
|
NVD-CWE-Other
|
CVE-2006-1418
|
2017-07-20 10:30 |
2006-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349407
|
4.3 |
MEDIUM
|
web-app.org
|
webapp
|
Multiple cross-site scripting (XSS) vulnerabilities in WebAPP 0.9.9.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) id, (3) num, (4) board, (5) c…
|
NVD-CWE-Other
|
CVE-2006-1427
|
2017-07-20 10:30 |
2006-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349408
|
4.3 |
MEDIUM
|
coinsoft_technologies
|
phpcoin
|
Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the fs parameter to (1) mod.php or (2) mod_print.php.
|
NVD-CWE-Other
|
CVE-2006-1428
|
2017-07-20 10:30 |
2006-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349409
|
4.3 |
MEDIUM
|
fusionzone
|
classifiedzone
|
Cross-site scripting (XSS) vulnerability in accountlogon.cfm in classifiedZONE 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the rtn parameter.
|
NVD-CWE-Other
|
CVE-2006-1429
|
2017-07-20 10:30 |
2006-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349410
|
4.3 |
MEDIUM
|
controlzx
|
hms
|
Multiple cross-site scripting (XSS) vulnerabilities in CONTROLzx HMS (formerly DRZES) 3.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dedicatedPlanID param…
|
NVD-CWE-Other
|
CVE-2006-1430
|
2017-07-20 10:30 |
2006-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349411
|
4.3 |
MEDIUM
|
fusionzone
|
couponzone
|
Cross-site scripting (XSS) vulnerability in local.cfm in fusionZONE couponZONE 4.2 allows remote attackers to inject arbitrary web script or HTML via URL-encoded (1) srchfor and (2) srchby parameters.
|
NVD-CWE-Other
|
CVE-2006-1431
|
2017-07-20 10:30 |
2006-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349412
|
5.0 |
MEDIUM
|
fusionzone
|
couponzone
|
fusionZONE couponZONE 4.2 allows remote attackers to obtain the full path of the web server, and other sensitive information, via invalid values, as demonstrated using manipulations associated with S…
|
NVD-CWE-Other
|
CVE-2006-1432
|
2017-07-20 10:30 |
2006-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349413
|
5.0 |
MEDIUM
|
annuaire
|
directory
|
Annuaire (Directory) 1.0 allows remote attackers to obtain sensitive information via a direct request to include/lang-en.php, which reveals the full installation path.
|
NVD-CWE-Other
|
CVE-2006-1433
|
2017-07-20 10:30 |
2006-04-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349414
|
6.8 |
MEDIUM
|
annuaire
|
directory
|
Cross-site scripting (XSS) vulnerability in inscription.php in Annuaire (Directory) 1.0 allows remote attackers to inject arbitrary web script or HTML via the Comment Field (COMMENTAIRE parameter).
|
NVD-CWE-Other
|
CVE-2006-1434
|
2017-07-20 10:30 |
2006-04-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349415
|
6.8 |
MEDIUM
|
accounting_receiving_and_inventory_administration
|
aria
|
Cross-site scripting (XSS) vulnerability in genmessage.php in Accounting Receiving and Inventory Administration (ARIA) 0.99-6 allows remote attackers to inject arbitrary web script or HTML via the Me…
|
NVD-CWE-Other
|
CVE-2006-1435
|
2017-07-20 10:30 |
2006-04-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349416
|
6.8 |
MEDIUM
|
andy_grayndler
|
andys_php_knowledgebase
|
Multiple cross-site scripting (XSS) vulnerabilities in Andy's PHP Knowledgebase (aphpkb) 0.57 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword_list parameter to (a) i…
|
NVD-CWE-Other
|
CVE-2006-1438
|
2017-07-20 10:30 |
2006-04-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349417
|
2.1 |
LOW
|
apple
|
mac_os_x
|
NSSecureTextField in AppKit in Apple Mac OS X 10.4.6 does not re-enable secure event input under certain circumstances, which could allow other applications in the window session to monitor input cha…
|
CWE-200
情報漏えい
|
CVE-2006-1439
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349418
|
2.1 |
LOW
|
apple
|
mac_os_x
|
This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)
|
CWE-200
情報漏えい
|
CVE-2006-1439
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349419
|
2.1 |
LOW
|
apple
|
mac_os_x
|
BOM in Apple Mac OS X 10.3.9 and 10.4.6 allows attackers to overwrite arbitrary files via an archive that contains symbolic links.
|
NVD-CWE-Other
|
CVE-2006-1440
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349420
|
2.1 |
LOW
|
apple
|
mac_os_x
|
This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)
|
NVD-CWE-Other
|
CVE-2006-1440
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349421
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
Integer overflow in CFNetwork in Apple Mac OS X 10.4.6 allows remote attackers to execute arbitrary code via crafted chunked transfer encoding.
|
NVD-CWE-Other
|
CVE-2006-1441
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349422
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)
|
NVD-CWE-Other
|
CVE-2006-1441
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349423
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if the client application has not directly requested it, which allows attackers to execute arbitrary …
|
NVD-CWE-Other
|
CVE-2006-1442
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349424
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)
|
NVD-CWE-Other
|
CVE-2006-1442
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349425
|
6.5 |
MEDIUM
|
apple
|
mac_os_x
|
Integer underflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 allows context-dependent attackers to execute arbitrary code via unspecified vectors involving conversions from string to file …
|
NVD-CWE-Other
|
CVE-2006-1443
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349426
|
6.5 |
MEDIUM
|
apple
|
mac_os_x
|
This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)
|
NVD-CWE-Other
|
CVE-2006-1443
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349427
|
2.1 |
LOW
|
apple
|
mac_os_x
|
CoreGraphics in Apple Mac OS X 10.4.6, when "Enable access for assistive devices" is on, allows an application to bypass restrictions for secure event input and read certain events from other applica…
|
NVD-CWE-Other
|
CVE-2006-1444
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349428
|
2.1 |
LOW
|
apple
|
mac_os_x
|
Successful exploitation requires that "Enable access for assistive devices" is on.
This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)
|
NVD-CWE-Other
|
CVE-2006-1444
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349429
|
6.5 |
MEDIUM
|
apple
|
mac_os_x
|
Buffer overflow in the FTP server (FTPServer) in Apple Mac OS X 10.3.9 and 10.4.6 allows remote authenticated users to execute arbitrary code via vectors related to "FTP server path name handling."
|
NVD-CWE-Other
|
CVE-2006-1445
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349430
|
6.5 |
MEDIUM
|
apple
|
mac_os_x
|
This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)
|
NVD-CWE-Other
|
CVE-2006-1445
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349431
|
5.0 |
MEDIUM
|
apple
|
mac_os_x
|
Keychain in Apple Mac OS X 10.3.9 and 10.4.6 might allow an application to bypass a locked Keychain by first obtaining a reference to the Keychain when it is unlocked, then reusing that reference aft…
|
NVD-CWE-Other
|
CVE-2006-1446
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349432
|
5.0 |
MEDIUM
|
apple
|
mac_os_x
|
This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)
|
NVD-CWE-Other
|
CVE-2006-1446
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349433
|
5.0 |
MEDIUM
|
apple
|
mac_os_x
|
LaunchServices in Apple Mac OS X 10.4.6 allows remote attackers to cause Safari to launch unsafe content via long file name extensions, which prevents Download Validation from determining which appli…
|
NVD-CWE-Other
|
CVE-2006-1447
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349434
|
5.0 |
MEDIUM
|
apple
|
mac_os_x
|
This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)
|
NVD-CWE-Other
|
CVE-2006-1447
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349435
|
6.5 |
MEDIUM
|
apple
|
mac_os_x
|
Finder in Apple Mac OS X 10.3.9 and 10.4.6 allows user-assisted attackers to execute arbitrary code by tricking a user into launching an Internet Location item that appears to use a safe URL scheme, …
|
NVD-CWE-Other
|
CVE-2006-1448
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349436
|
6.5 |
MEDIUM
|
apple
|
mac_os_x
|
This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)
|
NVD-CWE-Other
|
CVE-2006-1448
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349437
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
Integer overflow in Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted MacMIME encapsulated attachment.
|
NVD-CWE-Other
|
CVE-2006-1449
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349438
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)
|
NVD-CWE-Other
|
CVE-2006-1449
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349439
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via an enriched text e-mail message with "invalid color information" that causes Mail to allocate and initia…
|
NVD-CWE-Other
|
CVE-2006-1450
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349440
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)
|
NVD-CWE-Other
|
CVE-2006-1450
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349441
|
7.2 |
HIGH
|
apple
|
mac_os_x
|
MySQL Manager in Apple Mac OS X 10.3.9 and 10.4.6, when setting up a new MySQL database server, does not use the "New MySQL root password" that is provided, which causes the MySQL root password to be…
|
NVD-CWE-Other
|
CVE-2006-1451
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349442
|
7.2 |
HIGH
|
apple
|
mac_os_x
|
This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)
|
NVD-CWE-Other
|
CVE-2006-1451
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349443
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Stack-based buffer overflow in Preview in Apple Mac OS 10.4 up to 10.4.6 allows local users to execute arbitrary code via a deep directory hierarchy.
|
NVD-CWE-Other
|
CVE-2006-1452
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349444
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)
|
NVD-CWE-Other
|
CVE-2006-1452
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349445
|
7.8 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to cause a denial of service (crash and connection interruption) via a QuickTime movie with a missing track, whi…
|
NVD-CWE-Other
|
CVE-2006-1455
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349446
|
7.5 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Buffer overflow in QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted RTSP request, which is not properly handled during me…
|
NVD-CWE-Other
|
CVE-2006-1456
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349447
|
2.6 |
LOW
|
apple
|
mac_os_x mac_os_x_server
|
Safari on Apple Mac OS X 10.4.6, when "Open `safe' files after downloading" is enabled, will automatically expand archives, which could allow remote attackers to overwrite arbitrary files via an arch…
|
NVD-CWE-Other
|
CVE-2006-1457
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349448
|
5.1 |
MEDIUM
|
apple
|
quicktime
|
Integer overflow in Apple QuickTime Player before 7.1 allows remote attackers to execute arbitrary code via a crafted JPEG image.
|
CWE-189
数値処理の問題
|
CVE-2006-1458
|
2017-07-20 10:30 |
2006-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349449
|
4.0 |
MEDIUM
|
apple
|
xcode mac_os_x
|
Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service.
|
NVD-CWE-Other
|
CVE-2006-1466
|
2017-07-20 10:30 |
2006-05-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349450
|
5.0 |
MEDIUM
|
apple
|
mac_os_x
|
Unspecified vulnerability in Apple File Protocol (AFP) server in Apple Mac OS X 10.4 up to 10.4.6 includes the names of restricted files and folders within search results, which might allow remote at…
|
NVD-CWE-noinfo
|
CVE-2006-1468
|
2017-07-20 10:30 |
2006-06-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|