|
350401
|
4.3 |
MEDIUM
|
fujitsu
|
serverview
|
This vulnerability is addressed in the following product releases:
Fujitsu, ServerView, 3.60L99
Fujitsu, ServerView, 4.20L11B
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-3579
|
2008-09-6 06:07 |
2006-07-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350402
|
7.2 |
HIGH
|
ubuntu
|
ubuntu_linux
|
passwd before 1:4.0.13 on Ubuntu 6.06 LTS leaves the root password blank instead of locking it when the administrator selects the "Go Back" option after the final "Installation complete" message and …
|
NVD-CWE-Other
|
CVE-2006-3597
|
2008-09-6 06:07 |
2006-07-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350403
|
2.6 |
LOW
|
cutephp
|
cutenews
|
Cross-site scripting (XSS) vulnerability in Index.PHP in CuteNews 1.4.5 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information i…
|
NVD-CWE-Other
|
CVE-2006-3661
|
2008-09-6 06:07 |
2006-07-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350404
|
10.0 |
HIGH
|
kde
|
kdebase
|
The KDE PAM configuration shipped with Fedora Core 5 causes KDM passwords to be cached, which allows attackers to login without a password by attempting to log in multiple times.
|
NVD-CWE-Other
|
CVE-2006-3742
|
2008-09-6 06:07 |
2006-09-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350405
|
6.8 |
MEDIUM
|
lucid_designs
|
lucid_calendar
|
Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea Lucid Calendar 0.22 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: the provenance …
|
NVD-CWE-Other
|
CVE-2006-3025
|
2008-09-6 06:06 |
2006-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350406
|
6.8 |
MEDIUM
|
lucid_designs
|
lucid_calendar
|
Lucid Designs, Lucid Calendar, 0.22 is unsupported. A new, supported version of this product will be released in the near future.
|
NVD-CWE-Other
|
CVE-2006-3025
|
2008-09-6 06:06 |
2006-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350407
|
4.3 |
MEDIUM
|
emailarchitect
|
email_server
|
Cross-site scripting (XSS) vulnerability in EmailArchitect Email Server 6.1 allows remote attackers to inject arbitrary Javascript via an HTML div tag with a carriage return between the onmouseover a…
|
NVD-CWE-Other
|
CVE-2006-3108
|
2008-09-6 06:06 |
2006-06-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350408
|
1.2 |
LOW
|
canonical
|
spread
|
spread uses a temporary file with a static filename based on the port number, which allows local users to cause a denial of service by creating the file during a race condition between unlink and bin…
|
NVD-CWE-Other
|
CVE-2006-3118
|
2008-09-6 06:06 |
2006-07-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350409
|
7.5 |
HIGH
|
mambo
|
mambo
|
SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.
|
NVD-CWE-Other
|
CVE-2006-3263
|
2008-09-6 06:06 |
2006-06-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350410
|
7.5 |
HIGH
|
mpg123
|
mpg123
|
Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not properly terminated before being used with the strnc…
|
NVD-CWE-Other
|
CVE-2006-3355
|
2008-09-6 06:06 |
2006-07-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350411
|
7.2 |
HIGH
|
ubuntu
|
ubuntu_linux
|
passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileg…
|
NVD-CWE-Other
|
CVE-2006-3378
|
2008-09-6 06:06 |
2006-07-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350412
|
5.0 |
MEDIUM
|
amule
|
amule
|
Multiple unspecified vulnerabilities in aMuleWeb for AMule before 2.1.2 allow remote attackers to read arbitrary image, HTML, or PHP files via unknown vectors, probably related to directory traversal.
|
NVD-CWE-Other
|
CVE-2006-2692
|
2008-09-6 06:05 |
2006-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350413
|
5.0 |
MEDIUM
|
amule
|
amule
|
Successful exploitation requires that the full pathname of the file is known.
This vulnerability is addressed in the following product release:
aMule, aMule, 2.1.2
|
NVD-CWE-Other
|
CVE-2006-2692
|
2008-09-6 06:05 |
2006-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350414
|
5.0 |
MEDIUM
|
jetty
|
jetty
|
Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the same issue as CVE-2…
|
CWE-22
パス・トラバーサル
|
CVE-2006-2758
|
2008-09-6 06:05 |
2006-06-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350415
|
5.0 |
MEDIUM
|
jetty
|
jetty
|
jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary script source code via a capital P in the .jsp extension, and probably other mixed case manipulations.
|
NVD-CWE-Other
|
CVE-2006-2759
|
2008-09-6 06:05 |
2006-06-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350416
|
6.8 |
MEDIUM
|
xiti
|
xiti_tracking_script
|
Multiple cross-site scripting (XSS) vulnerabilities in XiTi Tracking Script 6 and 7 RC allow remote attackers to inject arbitrary web script or HTML via (1) the xtref parameter in xiti.js and (2) an …
|
NVD-CWE-Other
|
CVE-2006-2795
|
2008-09-6 06:05 |
2006-06-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350417
|
5.0 |
MEDIUM
|
jelsoft
|
vbulletin
|
SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter.
|
NVD-CWE-Other
|
CVE-2006-2805
|
2008-09-6 06:05 |
2006-06-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350418
|
4.3 |
MEDIUM
|
visiongate
|
visiongate_portal_system
|
Cross-site scripting (XSS) vulnerability in Print.PHP in VisionGate Portal System allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: The provenance of t…
|
NVD-CWE-Other
|
CVE-2006-2846
|
2008-09-6 06:05 |
2006-06-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350419
|
4.3 |
MEDIUM
|
skoom
|
i.list
|
Cross-site scripting (XSS) vulnerability in i.List 1.5 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the banurl parameter to add.php. NOTE: the provenance of th…
|
NVD-CWE-Other
|
CVE-2006-2957
|
2008-09-6 06:05 |
2006-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350420
|
7.5 |
HIGH
|
arantius
|
vice_stats
|
SQL injection vulnerability in vs_search.php in Arantius Vice Stats before 1.0.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors, a different issue than CVE-2006-2972.
|
NVD-CWE-Other
|
CVE-2006-2981
|
2008-09-6 06:05 |
2006-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350421
|
5.8 |
MEDIUM
|
vizra
|
vizra
|
Cross-site scripting (XSS) vulnerability in a_login.php in Vizra allows remote attackers to inject arbitrary web script or HTML via the message parameter.
|
NVD-CWE-Other
|
CVE-2006-2365
|
2008-09-6 06:04 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350422
|
2.6 |
LOW
|
unclassified_newsboard
|
unclassified_newsboard
|
Directory traversal vulnerability in bb_lib/abbc.css.php in Unclassified NewsBoard (UNB) 1.5.3-d and possibly earlier versions, when register_globals is enabled, allows remote attackers to include ar…
|
NVD-CWE-Other
|
CVE-2006-2406
|
2008-09-6 06:04 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350423
|
5.0 |
MEDIUM
|
pioneers
|
pioneers_meta-server
|
Pioneers meta-server before 0.9.55, when the server-console is not installed, allows remote attackers to cause a denial of service (crash) via certain requests from an older gnocatan client to create…
|
NVD-CWE-Other
|
CVE-2006-2441
|
2008-09-6 06:04 |
2006-05-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350424
|
5.0 |
MEDIUM
|
pioneers
|
pioneers_meta-server
|
Successful exploitation requires that the server-console is not installed.
This vulnerability is addressed in the following product release:
Pioneers, Pioneers, 0.9.49
|
NVD-CWE-Other
|
CVE-2006-2441
|
2008-09-6 06:04 |
2006-05-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350425
|
4.6 |
MEDIUM
|
knowledgetree
|
knowledgetree
|
The Debian package of knowledgetree 2.0.7 creates environment.php with world-readable permissions, which allows local users to obtain sensitive information such as the username and password for the K…
|
NVD-CWE-Other
|
CVE-2006-2443
|
2008-09-6 06:04 |
2006-05-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350426
|
5.0 |
MEDIUM
|
out_of_the_trees_web_design
|
selectapix
|
view_album.php in SelectaPix 1.31 and earlier allows remote attackers to obtain the installation path via a certain request, which displays the path in an error message, possibly due to an invalid or…
|
NVD-CWE-Other
|
CVE-2006-2463
|
2008-09-6 06:04 |
2006-05-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350427
|
7.5 |
HIGH
|
s9y
|
serendipity
|
config.php in S9Y Serendipity 1.0 beta 2 allows remote attackers to inject arbitrary PHP code by editing values that are stored in config.php and later executed. NOTE: the provenance of this informa…
|
NVD-CWE-Other
|
CVE-2006-1910
|
2008-09-6 06:03 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350428
|
5.0 |
MEDIUM
|
dbbs
|
dbbs
|
SQL injection vulnerability in topics.php in DbbS 2.0-alpha and earlier allows remote attackers to execute arbitrary SQL commands via the fcategoryid parameter.
|
NVD-CWE-Other
|
CVE-2006-1915
|
2008-09-6 06:03 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350429
|
4.0 |
MEDIUM
|
ibm
|
lotus_notes
|
The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Boo…
|
NVD-CWE-Other
|
CVE-2006-1948
|
2008-09-6 06:03 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350430
|
7.5 |
HIGH
|
mybulletinboard
|
mybulletinboard
|
SQL injection vulnerability in index.php in MyBB (MyBulletinBoard) before 1.04 allows remote attackers to execute arbitrary SQL commands via the referrer parameter.
|
NVD-CWE-Other
|
CVE-2006-1974
|
2008-09-6 06:03 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350431
|
2.6 |
LOW
|
stadtaus.com
|
php-gastebuch
|
Cross-site scripting (XSS) vulnerability in guestbook_newentry.php in PHP-Gastebuch 1.61 allows remote attackers to inject arbitrary web script or HTML via the Kommentar field.
|
NVD-CWE-Other
|
CVE-2006-1975
|
2008-09-6 06:03 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350432
|
2.6 |
LOW
|
geekforgod.net
|
prayer_request_board
|
Cross-site scripting (XSS) vulnerability in addRequest.php in Prayer Request Board (PRB) Beta 1 before 20060320 allows remote attackers to inject arbitrary web script or HTML via the Request field.
|
NVD-CWE-Other
|
CVE-2006-1976
|
2008-09-6 06:03 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350433
|
7.5 |
HIGH
|
php_thumbnail_autoindex
|
php_thumbnail_autoindex
|
PHP remote file inclusion vulnerability in Thumbnail AutoIndex before 2.0 allows remote attackers to execute arbitrary PHP code via (1) README.html or (2) HEADER.html.
|
NVD-CWE-Other
|
CVE-2006-2098
|
2008-09-6 06:03 |
2006-04-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350434
|
5.0 |
MEDIUM
|
jupiter_cms
|
jupiter_cms
|
Directory traversal vulnerability in index.php in Jupiter CMS 1.1.4 and 1.1.5 allows remote attackers to read arbitrary files via ".." sequences terminated by a %00 (null) character in the n paramete…
|
NVD-CWE-Other
|
CVE-2006-2105
|
2008-09-6 06:03 |
2006-04-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350435
|
6.4 |
MEDIUM
|
duware
|
duclassified
|
SQL injection vulnerability in detail.asp in DUclassified allows remote attackers to execute arbitrary SQL commands via the iPro parameter. NOTE: the provenance of this information is unknown; the d…
|
NVD-CWE-Other
|
CVE-2006-2132
|
2008-09-6 06:03 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350436
|
7.5 |
HIGH
|
invision_power_services
|
invision_power_board
|
SQL injection vulnerability in index.php in Invision Power Board allows remote attackers to execute arbitrary SQL commands via the pid parameter in a reputation action. NOTE: the provenance of this …
|
NVD-CWE-Other
|
CVE-2006-2217
|
2008-09-6 06:03 |
2006-05-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350437
|
5.0 |
MEDIUM
|
internet_key_exchange
|
internet_key_exchange
|
The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in the Shoichi Sakane KAME Project racoon, as used by NetBSD 1.6, 2.x before 20060119, certain FreeBSD releases, and possibly…
|
NVD-CWE-Other
|
CVE-2006-1646
|
2008-09-6 06:02 |
2006-04-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350438
|
7.2 |
HIGH
|
vserver
|
util-vserver
|
vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is invalid and non-numeric, which might cause local users to inadvertently execute dangerous commands as r…
|
NVD-CWE-Other
|
CVE-2006-1656
|
2008-09-6 06:02 |
2006-04-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350439
|
2.6 |
LOW
|
phpwebgallery
|
phpwebgallery
|
Cross-site scripting (XSS) vulnerability in search.php in PHPWebGallery 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vulnerability than CVE-2…
|
NVD-CWE-Other
|
CVE-2006-1674
|
2008-09-6 06:02 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350440
|
7.5 |
HIGH
|
aweb
|
scripts_seller
|
Buy.php in Aweb Scripts Seller uses predictable cookies for authentication based on the time and the script number, which allows remote attackers to bypass authentication.
|
NVD-CWE-Other
|
CVE-2006-1700
|
2008-09-6 06:02 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350441
|
4.6 |
MEDIUM
|
joey_hess
|
bsdgames
|
Buffer overflow in pl_main.c in sail in BSDgames before 2.17-7 allows local users to execute arbitrary code via a long player name that is used in a scanf function call.
|
NVD-CWE-Other
|
CVE-2006-1744
|
2008-09-6 06:02 |
2006-04-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350442
|
7.2 |
HIGH
|
debian
|
debian_linux
|
debconf in Debian GNU/Linux, when configuring mnogosearch in the mnogosearch-common 3.2.31-1 package, uses the world-readable config.dat file instead of the restricted passwords.dat for storing the c…
|
NVD-CWE-Other
|
CVE-2006-1772
|
2008-09-6 06:02 |
2006-04-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350443
|
4.3 |
MEDIUM
|
phpbb_group
|
phpbb
|
Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.19 allow remote attackers to inject arbitrary web script or HTML via the (1) Site Description field in (a) admin_board.php, the (2) Gr…
|
NVD-CWE-Other
|
CVE-2006-1775
|
2008-09-6 06:02 |
2006-04-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350444
|
10.0 |
HIGH
|
mailenable
|
mailenable_enterprise mailenable_professional mailenable_standard
|
Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edition before 1.22 has unknown attack vectors and impact rel…
|
NVD-CWE-Other
|
CVE-2006-1792
|
2008-09-6 06:02 |
2006-04-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350445
|
7.6 |
HIGH
|
runcms
|
runcms
|
Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) class.forumposts.php and (2) forumpollrenderer.php. N…
|
NVD-CWE-Other
|
CVE-2006-1793
|
2008-09-6 06:02 |
2006-04-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350446
|
7.6 |
HIGH
|
runcms
|
runcms
|
Succesful exploitation requires that register_globals = On & allow_url_fopen = On
|
NVD-CWE-Other
|
CVE-2006-1793
|
2008-09-6 06:02 |
2006-04-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350447
|
6.8 |
MEDIUM
|
wordpress
|
wordpress
|
Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other versions before 2.0.1, allows remote attackers to inj…
|
NVD-CWE-Other
|
CVE-2006-1796
|
2008-09-6 06:02 |
2006-04-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350448
|
6.8 |
MEDIUM
|
wordpress
|
wordpress
|
The vulnerability manifests itself only when viewed by IE.
This vulnerability is addressed in the following product release:
Wordpress 2.0.1-1
|
NVD-CWE-Other
|
CVE-2006-1796
|
2008-09-6 06:02 |
2006-04-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350449
|
7.5 |
HIGH
|
datenbank_module woltlab
|
datenbank_module burning_board
|
SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) dat…
|
NVD-CWE-Other
|
CVE-2006-1094
|
2008-09-6 06:01 |
2006-03-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350450
|
7.5 |
HIGH
|
logit
|
logit
|
PHP remote file include vulnerability in logIT 1.3 and 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter. NOTE: the provenance of this information is unknown; t…
|
NVD-CWE-Other
|
CVE-2006-1099
|
2008-09-6 06:01 |
2006-03-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|