|
355251
|
7.5 |
HIGH
|
hyper_estraier
|
hyper_estraier
|
This vulnerability is addressed in the following product release:
Hyper Estraier, Hyper Estraier, 1.3.3
|
NVD-CWE-Other
|
CVE-2006-3671
|
2011-03-8 11:39 |
2006-07-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355252
|
5.0 |
MEDIUM
|
hp
|
openvms
|
Unspecified vulnerability in [SYSEXE]SMPUTIL.EXE in HP OpenVMS 7.3-2 allows local users and "remote users" to cause a denial of service (crash).
|
NVD-CWE-Other
|
CVE-2006-3686
|
2011-03-8 11:39 |
2006-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355253
|
6.5 |
MEDIUM
|
citrix
|
metaframe metaframe_presentation_server presentation_server
|
Citrix MetaFrame up to XP 1.0 Feature 1, except when running on Windows Server 2003, installs a registry key with an insecure ACL, which allows remote authenticated users to gain privileges.
|
NVD-CWE-Other
|
CVE-2006-3779
|
2011-03-8 11:39 |
2006-07-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355254
|
7.5 |
HIGH
|
krusader
|
krusader
|
Krusader 1.50-beta1 up to 1.70.0 stores passwords for remote connections in cleartext in the bookmark file (krbookmarks.xml), which allows attackers to steal passwords by obtaining the file.
|
NVD-CWE-Other
|
CVE-2006-3816
|
2011-03-8 11:39 |
2006-07-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355255
|
5.1 |
MEDIUM
|
geodesicsolutions
|
geoauctions_enterprise
|
SQL injection vulnerability in index.php in GeodesicSolutions GeoAuctions Enterprise 1.0.6 allows remote attackers to execute arbitrary SQL commands via the d parameter.
|
NVD-CWE-Other
|
CVE-2006-3822
|
2011-03-8 11:39 |
2006-07-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355256
|
5.1 |
MEDIUM
|
geodesicsolutions
|
geoauctions_enterprise
|
Successful exploitation requires that the 'accumulative feedback' feature is turned on.
|
NVD-CWE-Other
|
CVE-2006-3822
|
2011-03-8 11:39 |
2006-07-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355257
|
4.3 |
MEDIUM
|
phpfaber
|
topsites
|
Cross-site scripting (XSS) vulnerability in index.php in phpFaber TopSites 2.0.9 allows remote attackers to inject arbitrary web script or HTML via the i_cat parameter. NOTE: the provenance of this …
|
NVD-CWE-Other
|
CVE-2006-3902
|
2011-03-8 11:39 |
2006-07-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355258
|
5.1 |
MEDIUM
|
intel
|
2200bg_proset_wireless 2915abg_proset_wireless
|
Unspecified vulnerability in the Centrino (1) w22n50.sys, (2) w22n51.sys, (3) w29n50.sys, and (4) w29n51.sys Microsoft Windows drivers for Intel 2200BG and 2915ABG PRO/Wireless Network Connection bef…
|
NVD-CWE-Other
|
CVE-2006-3992
|
2011-03-8 11:39 |
2006-08-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355259
|
5.1 |
MEDIUM
|
intel
|
2200bg_proset_wireless 2915abg_proset_wireless
|
Affected versions are only vulnerable with driver version 9.0.4.16
This vulnerability is addressed in the following product releases:
Intel, 2200BG PROSet/Wireless, 10.5
Intel, 2915ABG PROSet/Wire…
|
NVD-CWE-Other
|
CVE-2006-3992
|
2011-03-8 11:39 |
2006-08-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355260
|
10.0 |
HIGH
|
ibm
|
websphere_application_server
|
Unspecified vulnerability in IBM WebSphere Application Server before 6.0.2.11 has unknown impact and attack vectors because the "UserNameToken cache was improperly used."
|
NVD-CWE-noinfo
|
CVE-2006-3232
|
2011-03-8 11:38 |
2006-06-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355261
|
4.0 |
MEDIUM
|
twiki
|
twiki
|
TWiki 01-Dec-2000 up to 4.0.3 allows remote attackers to bypass the upload filter and execute arbitrary code via filenames with double extensions such as ".php.en", ".php.1", and other allowed extens…
|
NVD-CWE-Other
|
CVE-2006-3336
|
2011-03-8 11:38 |
2006-07-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355262
|
2.6 |
LOW
|
phpmaillist
|
phpmaillist
|
Cross-site scripting (XSS) vulnerability in maillist.php in PHPMailList 1.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the email parameter.
|
NVD-CWE-Other
|
CVE-2006-3482
|
2011-03-8 11:38 |
2006-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355263
|
2.6 |
LOW
|
adaptive_technology_resource_centre
|
atutor
|
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) show_courses or (2) current_cat parameters to (a) …
|
NVD-CWE-Other
|
CVE-2006-3484
|
2011-03-8 11:38 |
2006-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355264
|
4.6 |
MEDIUM
|
apple
|
xsan mac_os_x mac_os_x_server
|
Buffer overflow in the Xsan Filesystem driver on Mac OS X 10.4.7 and OS X Server 10.4.7 allows local users with Xsan write access, to execute arbitrary code via unspecified vectors related to "proces…
|
NVD-CWE-Other
|
CVE-2006-3506
|
2011-03-8 11:38 |
2006-08-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355265
|
4.6 |
MEDIUM
|
apple
|
xsan mac_os_x mac_os_x_server
|
This vulnerability is addressed in the following product release:
Apple, Xsan, 1.4
|
NVD-CWE-Other
|
CVE-2006-3506
|
2011-03-8 11:38 |
2006-08-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355266
|
7.2 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Multiple stack-based buffer overflows in the AirPort wireless driver on Apple Mac OS X 10.3.9 and 10.4.7 allow physically proximate attackers to execute arbitrary code by injecting crafted frames int…
|
NVD-CWE-Other
|
CVE-2006-3507
|
2011-03-8 11:38 |
2006-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355267
|
7.2 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Heap-based buffer overflow in the AirPort wireless driver on Apple Mac OS X 10.4.7 allows physically proximate attackers to cause a denial of service (crash), gain privileges, and execute arbitrary c…
|
NVD-CWE-Other
|
CVE-2006-3508
|
2011-03-8 11:38 |
2006-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355268
|
7.2 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Integer overflow in the API for the AirPort wireless driver on Apple Mac OS X 10.4.7 might allow physically proximate attackers to cause a denial of service (crash) or execute arbitrary code in third…
|
NVD-CWE-Other
|
CVE-2006-3509
|
2011-03-8 11:38 |
2006-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355269
|
7.8 |
HIGH
|
nullsoft
|
shoutcast_server
|
Directory traversal vulnerability in Nullsoft SHOUTcast DSP before 1.9.6 filters directory traversal sequences before decoding, which allows remote attackers to read arbitrary files via encoded dot d…
|
NVD-CWE-Other
|
CVE-2006-3534
|
2011-03-8 11:38 |
2006-07-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355270
|
7.8 |
HIGH
|
nullsoft
|
shoutcast_server
|
This vulnerability is addressed in the following product releases:
Nullsoft, SHOUTcast DSP, 1.9.6
Nullsoft, SHOUTcast DSP, 1.9.7
|
NVD-CWE-Other
|
CVE-2006-3534
|
2011-03-8 11:38 |
2006-07-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355271
|
6.4 |
MEDIUM
|
ipswitch
|
ipswitch_collaboration_suite ipswitch_secure_server
|
Premium Anti-Spam in Ipswitch IMail Secure Server 2006 and Collaboration Suite 2006 Premium, when using a certain .dat file in the StarEngine /data directory from 20060630 or earlier, does not proper…
|
NVD-CWE-Other
|
CVE-2006-3552
|
2011-03-8 11:38 |
2006-07-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355272
|
7.5 |
HIGH
|
logicalware
|
mailmanager
|
Logicalware MailManager before 2.0.10 does not remove 0xc8 0x27 (0xc8 followed by a single-quote character) from the data stream to the server, which allows remote attackers to modify data and gain a…
|
NVD-CWE-Other
|
CVE-2006-2824
|
2011-03-8 11:37 |
2006-06-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355273
|
4.3 |
MEDIUM
|
techno_dreams
|
techno_dreams_guest_book
|
Cross-site scripting (XSS) vulnerability in Techno Dreams Guest Book allows remote attackers to inject arbitrary web script or HTML via certain comment fields in the "Sign Our GuestBook" page, probab…
|
NVD-CWE-Other
|
CVE-2006-2837
|
2011-03-8 11:37 |
2006-06-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355274
|
7.5 |
HIGH
|
particle_soft
|
particle_gallery
|
SQL injection vulnerability in viewimage.php in Particle Gallery 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the imageid parameter.
|
NVD-CWE-Other
|
CVE-2006-2862
|
2011-03-8 11:37 |
2006-06-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355275
|
6.8 |
MEDIUM
|
deltascripts
|
php_pro_publish
|
Cross-site scripting (XSS) vulnerability in cat.php in PHP Pro Publish 2.0 allows remote attackers to inject arbitrary web script or HTML via the catname parameter. NOTE: the provenance of this info…
|
NVD-CWE-Other
|
CVE-2006-2876
|
2011-03-8 11:37 |
2006-06-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355276
|
5.5 |
MEDIUM
|
qbik
|
wingate
|
Directory traversal vulnerability in the IMAP server in WinGate 6.1.2.1094 and 6.1.3.1096, and possibly other versions before 6.1.4 Build 1099, allows remote authenticated users to read email of othe…
|
NVD-CWE-Other
|
CVE-2006-2917
|
2011-03-8 11:37 |
2006-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355277
|
5.0 |
MEDIUM
|
dmx_forum
|
dmx_forum
|
Dmx Forum 2.1a stores _includes/bd.inc under the web root with insufficient access control, which allows remote attackers to obtain database username and password information.
|
NVD-CWE-Other
|
CVE-2006-2946
|
2011-03-8 11:37 |
2006-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355278
|
4.3 |
MEDIUM
|
skoom
|
i.list
|
Multiple cross-site scripting (XSS) vulnerabilities in i.List 1.5 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) searchword parameter to search.php or (2) …
|
NVD-CWE-Other
|
CVE-2006-2956
|
2011-03-8 11:37 |
2006-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355279
|
7.5 |
HIGH
|
enterprise_payroll_systems
|
enterprise_payroll_systems
|
PHP remote file inclusion vulnerability in Enterprise Timesheet and Payroll Systems (EPS) 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolutepath parameter…
|
NVD-CWE-Other
|
CVE-2006-2983
|
2011-03-8 11:37 |
2006-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355280
|
5.8 |
MEDIUM
|
myscrapbook
|
myscrapbook
|
Multiple cross-site scripting (XSS) vulnerabilities in addwords.php in MyScrapbook 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) comment param…
|
NVD-CWE-Other
|
CVE-2006-3035
|
2011-03-8 11:37 |
2006-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355281
|
6.5 |
MEDIUM
|
subtext
|
subtext
|
Unspecified vulnerability in the admin login feature in Subtext 1.5, in a multiblog setup, allows remote administrators of one blog to login to another blog.
|
NVD-CWE-Other
|
CVE-2006-3046
|
2011-03-8 11:37 |
2006-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355282
|
6.8 |
MEDIUM
|
cescripts
|
event_registration_2checkout event_registration_corporate event_registration_paypal event_registration_rsvp
|
Cross-site scripting (XSS) vulnerability in Event Registration allows remote attackers to inject arbitrary web script or HTML via the (1) event_id parameter to view-event-details.php or (2) select_ev…
|
NVD-CWE-Other
|
CVE-2006-3052
|
2011-03-8 11:37 |
2006-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355283
|
4.3 |
MEDIUM
|
cescripts
|
car_classifieds
|
Cross-site scripting (XSS) vulnerability in index.php in Car Classifieds allows remote attackers to inject arbitrary web script or HTML via the make_id parameter. NOTE: the provenance of this inform…
|
NVD-CWE-Other
|
CVE-2006-3088
|
2011-03-8 11:37 |
2006-06-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355284
|
7.5 |
HIGH
|
brian_wotring
|
osiris
|
Format string vulnerability in Brian Wotring Osiris before 4.2.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified attack ve…
|
NVD-CWE-Other
|
CVE-2006-3120
|
2011-03-8 11:37 |
2006-08-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355285
|
7.5 |
HIGH
|
julian_pawlowski
|
capi4hylafax
|
c2faxrecv in capi4hylafax 01.02.03 allows remote attackers to execute arbitrary commands via null (\0) and shell metacharacters in the TSI string, as demonstrated by a fax from an anonymous number.
|
NVD-CWE-Other
|
CVE-2006-3126
|
2011-03-8 11:37 |
2006-09-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355286
|
4.3 |
MEDIUM
|
php
|
directory_listing_script
|
Cross-site scripting (XSS) vulnerability in index.php in Directory Listing Script allows remote attackers to inject arbitrary web script or HTML via the dir parameter.
|
NVD-CWE-Other
|
CVE-2006-2419
|
2011-03-8 11:36 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355287
|
4.3 |
MEDIUM
|
php
|
directory_listing_script
|
The vulnerability has been confirmed in the latest available version of this product. Other versions may also be affected.
|
NVD-CWE-Other
|
CVE-2006-2419
|
2011-03-8 11:36 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355288
|
10.0 |
HIGH
|
ibm
|
websphere_application_server
|
Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and remote attack vectors related to "HTTP request handlers".
|
NVD-CWE-noinfo
|
CVE-2006-2429
|
2011-03-8 11:36 |
2006-05-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355289
|
10.0 |
HIGH
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2006-2430
|
2011-03-8 11:36 |
2006-05-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355290
|
7.5 |
HIGH
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 5.0.2 (or any earlier cumulative fix) and 5.1.1 (or any earlier cumulative fix) allows EJB access on Solaris systems via a crafted LTPA token.
|
NVD-CWE-Other
|
CVE-2006-2432
|
2011-03-8 11:36 |
2006-05-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355291
|
10.0 |
HIGH
|
ibm
|
websphere_application_server
|
Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and attack vectors related to the "administrative console".
|
NVD-CWE-noinfo
|
CVE-2006-2433
|
2011-03-8 11:36 |
2006-05-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355292
|
5.0 |
MEDIUM
|
ibm
|
websphere_application_server
|
Unspecified vulnerability in WebSphere 5.1.1 (or any earlier cumulative fix) Common Configuration Mode + CommonArchive and J2EE Models might allow attackers to obtain sensitive information via the tr…
|
NVD-CWE-Other
|
CVE-2006-2434
|
2011-03-8 11:36 |
2006-05-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355293
|
6.4 |
MEDIUM
|
ibm
|
websphere_application_server
|
Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earlier, has unknown impact and attack vectors related to "Inserting certain script tags in urls [that] …
|
NVD-CWE-noinfo
|
CVE-2006-2435
|
2011-03-8 11:36 |
2006-05-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355294
|
7.5 |
HIGH
|
ibm
|
websphere_application_server
|
WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords in plaintext in the FFDC logs when a login to WebSphere fails, which allows attackers to gain privil…
|
NVD-CWE-Other
|
CVE-2006-2436
|
2011-03-8 11:36 |
2006-05-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355295
|
5.0 |
MEDIUM
|
caucho_technology
|
resin
|
The viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to obtain the source code for file under the web root via the file parameter.
|
NVD-CWE-Other
|
CVE-2006-2437
|
2011-03-8 11:36 |
2006-05-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355296
|
4.6 |
MEDIUM
|
kphone
|
kphone
|
kphone 4.2 creates .qt/kphonerc with world-readable permissions, which allows local users to read usernames and SIP passwords.
|
NVD-CWE-Other
|
CVE-2006-2442
|
2011-03-8 11:36 |
2006-05-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355297
|
7.5 |
HIGH
|
s9y
|
serendipity
|
Cross-site request forgery (CSRF) vulnerability in the Entry Manager in Serendipity before 1.0-beta3 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag.
|
NVD-CWE-Other
|
CVE-2006-2495
|
2011-03-8 11:36 |
2006-05-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355298
|
5.0 |
MEDIUM
|
fckeditor
|
fckeditor
|
editor/filemanager/upload/php/upload.php in FCKeditor before 2.3 Beta, when the upload feature is enabled, does not verify the Type parameter, which allows remote attackers to upload arbitrary file t…
|
NVD-CWE-Other
|
CVE-2006-2529
|
2011-03-8 11:36 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355299
|
5.1 |
MEDIUM
|
xtreme_scripts
|
xtreme_topsites
|
Multiple SQL injection vulnerabilities in Xtreme Topsites 1.1, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchthis parameter in lostid.php …
|
NVD-CWE-Other
|
CVE-2006-2544
|
2011-03-8 11:36 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355300
|
5.8 |
MEDIUM
|
florian_amrhein
|
newsportal
|
Cross-site scripting (XSS) vulnerability in Florian Amrhein NewsPortal before 0.37, and possibly TR Newsportal (TRanx rebuilded), allows remote attackers to inject arbitrary web script or HTML via un…
|
NVD-CWE-Other
|
CVE-2006-2556
|
2011-03-8 11:36 |
2006-05-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|