|
349501
|
5.0 |
MEDIUM
|
kgb
|
archiver
|
Directory traversal vulnerability in KGB Archiver before 1.1.5.22 allows remote attackers to overwrite arbitrary files wile decompressing an archive, possibly due to directory traversal sequences in …
|
NVD-CWE-Other
|
CVE-2006-1611
|
2017-07-20 10:30 |
2006-04-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349502
|
5.0 |
MEDIUM
|
kgb
|
archiver
|
This vulnerability affects all versions of KGB, Archiver before 1.1.5.22
|
NVD-CWE-Other
|
CVE-2006-1611
|
2017-07-20 10:30 |
2006-04-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349503
|
10.0 |
HIGH
|
clamav
|
clamav
|
Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute arbitrary code. NOTE: as of 20060410, it is unclear whethe…
|
CWE-134
書式文字列の問題
|
CVE-2006-1615
|
2017-07-20 10:30 |
2006-04-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349504
|
7.5 |
HIGH
|
advanced_poll
|
advanced_poll
|
Multiple SQL injection vulnerabilities in Advanced Poll 2.02 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to comments.php or (2) poll_id parameter to page.php.
|
NVD-CWE-Other
|
CVE-2006-1616
|
2017-07-20 10:30 |
2006-04-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349505
|
4.3 |
MEDIUM
|
advanced_poll
|
advanced_poll
|
Multiple cross-site scripting (XSS) vulnerabilities in Advanced Poll 2.02 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to comments.php or (2) poll_id paramet…
|
NVD-CWE-Other
|
CVE-2006-1617
|
2017-07-20 10:30 |
2006-04-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349506
|
5.0 |
MEDIUM
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 4.0.1 through 4.0.3 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a large header.
|
NVD-CWE-Other
|
CVE-2006-1619
|
2017-07-20 10:30 |
2006-04-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349507
|
4.6 |
MEDIUM
|
adobe
|
livecycle_form_manager
|
Adobe LiveCycle Workflow 7.01 and LiveCycle Forum Manager 7.01 allows users to authenticate and perform privileged actions when their account is marked "OBSOLETE" but the account is also active, with…
|
NVD-CWE-Other
|
CVE-2006-1628
|
2017-07-20 10:30 |
2006-04-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349508
|
5.0 |
MEDIUM
|
clam_anti-virus
|
clamav
|
The cli_bitset_set function in libclamav/others.c in Clam AntiVirus (ClamAV) before 0.88.1 allows remote attackers to cause a denial of service via unspecified vectors that trigger an "invalid memory…
|
NVD-CWE-Other
|
CVE-2006-1630
|
2017-07-20 10:30 |
2006-04-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349509
|
5.0 |
MEDIUM
|
cisco
|
content_services_switch_11500
|
Unspecified vulnerability in the HTTP compression functionality in Cisco CSS 11500 Series Content Services switches allows remote attackers to cause a denial of service (device reload) via (1) "valid…
|
NVD-CWE-Other
|
CVE-2006-1631
|
2017-07-20 10:30 |
2006-04-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349510
|
4.3 |
MEDIUM
|
lucidcms
|
lucidcms
|
Cross-site scripting (XSS) vulnerability in index.php in LucidCMS 2.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the command parameter.
|
NVD-CWE-Other
|
CVE-2006-1634
|
2017-07-20 10:30 |
2006-04-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349511
|
5.0 |
MEDIUM
|
lucidcms
|
lucidcms
|
LucidCMS 2.0.0 RC4 allows remote attackers to obtain sensitive information via a direct request to /lucid_phplib/translator.php, which reveals the path in an error message.
|
NVD-CWE-Other
|
CVE-2006-1635
|
2017-07-20 10:30 |
2006-04-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349512
|
2.6 |
LOW
|
interact
|
interact
|
Cross-site scripting (XSS) vulnerability in Interact 2.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) the search_terms parameter to (a) search.php, and (2) the first_name,…
|
NVD-CWE-Other
|
CVE-2006-1642
|
2017-07-20 10:30 |
2006-04-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349513
|
7.5 |
HIGH
|
interact
|
interact
|
SQL injection vulnerability in login.php in Interact 2.1.1 allows remote attackers to execute arbitrary SQL commands via the user_name parameter. NOTE: the provenance of this information is unknown;…
|
NVD-CWE-Other
|
CVE-2006-1643
|
2017-07-20 10:30 |
2006-04-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349514
|
5.0 |
MEDIUM
|
interact
|
interact
|
login.php in Interact 2.1.1 generates different responses depending on whether or not a username is valid, which allows remote attackers to determine valid usernames. NOTE: the provenance of this in…
|
NVD-CWE-Other
|
CVE-2006-1644
|
2017-07-20 10:30 |
2006-04-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349515
|
6.8 |
MEDIUM
|
sk_soft
|
skforum
|
Multiple cross-site scripting (XSS) vulnerabilities in SKForum 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) areaID parameter in area.View.action, (2) time…
|
NVD-CWE-Other
|
CVE-2006-1661
|
2017-07-20 10:30 |
2006-04-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349516
|
2.6 |
LOW
|
jelsoft
|
vbug_tracker
|
Cross-site scripting (XSS) vulnerability in vbugs.php in Dark_Wizard vBug Tracker 3.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter.
|
NVD-CWE-Other
|
CVE-2006-1673
|
2017-07-20 10:30 |
2006-04-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349517
|
4.3 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.8.0.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors in unspecified scripts in the themes…
|
NVD-CWE-Other
|
CVE-2006-1678
|
2017-07-20 10:30 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349518
|
4.3 |
MEDIUM
|
talentsoft
|
web\+_shop
|
Cross-site scripting (XSS) vulnerability in webplus.exe in TalentSoft Web+Shop 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the deptname parameter, possibly invo…
|
NVD-CWE-Other
|
CVE-2006-1682
|
2017-07-20 10:30 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349519
|
7.5 |
HIGH
|
apt
|
apt-webshop-system
|
Multiple SQL injection vulnerabilities in modules.php in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allow remote attackers to execute arbitrary SQL commands via the (1) group, (2) seite, an…
|
NVD-CWE-Other
|
CVE-2006-1685
|
2017-07-20 10:30 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349520
|
6.8 |
MEDIUM
|
manic_web
|
mwnewsletter
|
Cross-site scripting (XSS) vulnerability in subscribe.php in MWNewsletter 1.0.0b allows remote attackers to inject arbitrary web script or HTML via the user_name parameter.
|
NVD-CWE-Other
|
CVE-2006-1690
|
2017-07-20 10:30 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349521
|
7.5 |
HIGH
|
manic_web
|
mwnewsletter
|
SQL injection vulnerability in MWNewsletter 1.0.0b allows remote attackers to execute arbitrary SQL commands via the user_name parameter to unsubscribe.php.
|
NVD-CWE-Other
|
CVE-2006-1691
|
2017-07-20 10:30 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349522
|
5.0 |
MEDIUM
|
globalscape
|
secure_ftp_server
|
Unspecified vulnerability in GlobalSCAPE Secure FTP Server before 3.1.4 Build 01.10.2006 allows attackers to cause a denial of service (application crash) via a "custom command" with a long argument.
|
NVD-CWE-Other
|
CVE-2006-1693
|
2017-07-20 10:30 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349523
|
5.0 |
MEDIUM
|
globalscape
|
secure_ftp_server
|
This issue is addressed in Secure FTP Server 3.1.4 Build 01.10.2006.
|
NVD-CWE-Other
|
CVE-2006-1693
|
2017-07-20 10:30 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349524
|
1.2 |
LOW
|
fbida
|
fbida
|
The fbgs script in the fbi package 2.01-1.4, when the TMPDIR environment variable is not defined, allows local users to overwrite arbitrary files via a symlink attack on temporary files in /var/tmp/f…
|
NVD-CWE-Other
|
CVE-2006-1695
|
2017-07-20 10:30 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349525
|
4.3 |
MEDIUM
|
gallery_project
|
gallery
|
Cross-site scripting (XSS) vulnerability in Gallery before 1.5.3 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-1696
|
2017-07-20 10:30 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349526
|
4.3 |
MEDIUM
|
matt_wright
|
matt_wright_guestbook
|
Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) url, (2) city, (3) state, or (4) country parameters…
|
NVD-CWE-Other
|
CVE-2006-1698
|
2017-07-20 10:30 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349527
|
2.6 |
LOW
|
aweb
|
banner_generator
|
Cross-site scripting (XSS) vulnerability in index.php in Aweb Banner Generator 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the banner parameter in view mode.
|
NVD-CWE-Other
|
CVE-2006-1699
|
2017-07-20 10:30 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349528
|
7.5 |
HIGH
|
kansok_communications
|
shopweezle
|
Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (…
|
NVD-CWE-Other
|
CVE-2006-1706
|
2017-07-20 10:30 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349529
|
5.0 |
MEDIUM
|
kansok_communications
|
shopweezle
|
index.php in Shopweezle 2.0 allows remote attackers to include arbitrary local files via the url parameter.
|
NVD-CWE-Other
|
CVE-2006-1707
|
2017-07-20 10:30 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349530
|
6.8 |
MEDIUM
|
interaktiv
|
interaktiv.shop
|
Cross-site scripting (XSS) vulnerability in shop_main.cgi in interaktiv.shop 5 allows remote attackers to inject arbitrary web script or HTML via the (1) pn and (2) sbeg parameters.
|
NVD-CWE-Other
|
CVE-2006-1709
|
2017-07-20 10:30 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349531
|
5.0 |
MEDIUM
|
plone
|
plone
|
Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify po…
|
NVD-CWE-Other
|
CVE-2006-1711
|
2017-07-20 10:30 |
2006-04-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349532
|
6.8 |
MEDIUM
|
suche
|
shopxs
|
Cross-site scripting (XSS) vulnerability in suche.htm in ShopXS 4.0 allows remote attackers to inject arbitrary web script or HTML via the Suchstring1 (aka search) parameter.
|
NVD-CWE-Other
|
CVE-2006-1722
|
2017-07-20 10:30 |
2006-04-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349533
|
7.5 |
HIGH
|
jbook
|
jbook
|
Multiple SQL injection vulnerabilities in form.php in JBook 1.4 allow remote attackers to execute arbitrary SQL commands via the (1) nom or (2) mail parameters. NOTE: the provenance of this informat…
|
NVD-CWE-Other
|
CVE-2006-1743
|
2017-07-20 10:30 |
2006-04-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349534
|
5.0 |
MEDIUM
|
tincan
|
phplist
|
Directory traversal vulnerability in PHPList 2.10.2 and earlier allows remote attackers to include arbitrary local files via the (1) GLOBALS[database_module] or (2) GLOBALS[language_module] parameter…
|
CWE-22
パス・トラバーサル
|
CVE-2006-1746
|
2017-07-20 10:30 |
2006-04-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349535
|
2.6 |
LOW
|
jmb_software
|
autogallery
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Autogallery 0.41 allow remote attackers to inject arbitrary web script or HTML via the (1) pic or (2) show parameters.
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-1750
|
2017-07-20 10:30 |
2006-04-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349536
|
7.5 |
HIGH
|
michiel_van_baak
|
mvblog
|
Multiple SQL injection vulnerabilities in MvBlog before 1.6 allow remote attackers to execute arbitrary SQL commands via unknown vectors.
|
CWE-89
SQLインジェクション
|
CVE-2006-1751
|
2017-07-20 10:30 |
2006-04-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349537
|
2.6 |
LOW
|
michiel_van_baak
|
mvblog
|
Multiple cross-site scripting (XSS) vulnerabilities in the backend in MvBlog before 1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) body fields in a comment.
|
NVD-CWE-Other
|
CVE-2006-1752
|
2017-07-20 10:30 |
2006-04-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349538
|
3.6 |
LOW
|
debian
|
debian_linux
|
A cron job in fcheck before 2.7.59 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
|
NVD-CWE-Other
|
CVE-2006-1753
|
2017-07-20 10:30 |
2006-04-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349539
|
3.6 |
LOW
|
debian
|
debian_linux
|
This vulnerability is addressed in the following product releases:
Fcheck, 2.7.59-7sarge1
Fcheck, 2.7.59-8
|
NVD-CWE-Other
|
CVE-2006-1753
|
2017-07-20 10:30 |
2006-04-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349540
|
4.3 |
MEDIUM
|
jetphotosoft.com
|
jetphoto
|
Multiple cross-site scripting (XSS) vulnerabilities in JetPhoto allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) Classic.view/thumbnail.php, (2) Classic.vie…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-1760
|
2017-07-20 10:30 |
2006-04-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349541
|
6.4 |
MEDIUM
|
papoo
|
papoo
|
Multiple SQL injection vulnerabilities in Papoo 2.1.5, and 3 beta1 and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) getlang and (2) reporeid parameter in (a) index.ph…
|
NVD-CWE-Other
|
CVE-2006-1766
|
2017-07-20 10:30 |
2006-04-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349542
|
6.4 |
MEDIUM
|
phpkit
|
phpkit
|
SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands via the contentid parameter, possibly involving content/news…
|
NVD-CWE-Other
|
CVE-2006-1773
|
2017-07-20 10:30 |
2006-04-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349543
|
7.6 |
HIGH
|
mambo
|
mambo
|
SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function …
|
NVD-CWE-Other
|
CVE-2006-1794
|
2017-07-20 10:30 |
2006-04-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349544
|
7.6 |
HIGH
|
mambo
|
mambo
|
Successful exploitation requires that "magic_quotes_gpc" is disabled.
|
NVD-CWE-Other
|
CVE-2006-1794
|
2017-07-20 10:30 |
2006-04-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349545
|
4.9 |
MEDIUM
|
netbsd
|
netbsd
|
The kernel in NetBSD-current before September 28, 2005 allows local users to cause a denial of service (system crash) by using the SIOCGIFALIAS ioctl to gather information on a non-existent alias of …
|
NVD-CWE-Other
|
CVE-2006-1797
|
2017-07-20 10:30 |
2006-04-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349546
|
7.5 |
HIGH
|
simplemedia
|
simplebbs
|
Directory traversal vulnerability in posts.php in SimpleBBS 1.0.6 through 1.1 allows remote attackers to include and execute arbitrary files via ".." sequences in the language cookie, as demonstrated…
|
NVD-CWE-Other
|
CVE-2006-1800
|
2017-07-20 10:30 |
2006-04-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349547
|
2.1 |
LOW
|
netbsd
|
netbsd
|
NetBSD 1.6, 2.0, 2.1 and 3.0 allows local users to cause a denial of service (memory exhaustion) by using the sysctl system call to lock a large buffer into physical memory.
|
NVD-CWE-Other
|
CVE-2006-1814
|
2017-07-20 10:30 |
2006-04-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349548
|
2.6 |
LOW
|
tritanium_scripts
|
tritanium_bulletin_board
|
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) newuser_realname …
|
NVD-CWE-Other
|
CVE-2006-1815
|
2017-07-20 10:30 |
2006-04-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349549
|
6.8 |
MEDIUM
|
phplinks
|
phplinks
|
Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.
|
NVD-CWE-Other
|
CVE-2006-1825
|
2017-07-20 10:30 |
2006-04-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349550
|
4.0 |
MEDIUM
|
sybase
|
easerver
|
EAServer Manager in Sybase EAServer 5.2 and 5.3 allows remote authenticated users, possibly guests, to obtain password credentials of arbitrary users via unspecified vectors involving (1) connection …
|
NVD-CWE-Other
|
CVE-2006-1829
|
2017-07-20 10:30 |
2006-04-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|