|
355301
|
6.4 |
MEDIUM
|
e107
|
e107
|
SQL injection vulnerability in e107 before 0.7.5 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-2590
|
2011-03-8 11:36 |
2006-05-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355302
|
5.0 |
MEDIUM
|
e107
|
e107
|
Unspecified vulnerability in e107 before 0.7.5 has unknown impact and remote attack vectors related to an "emailing exploit".
|
NVD-CWE-Other
|
CVE-2006-2591
|
2011-03-8 11:36 |
2006-05-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355303
|
5.1 |
MEDIUM
|
artmedic_webdesign
|
artmedic_newsletter
|
artmedic newsletter 4.1.2 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the email parameter to ne…
|
NVD-CWE-Other
|
CVE-2006-2609
|
2011-03-8 11:36 |
2006-05-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355304
|
7.2 |
HIGH
|
ibm
|
aix
|
Untrusted search path vulnerability in update_flash for IBM AIX 5.1, 5.2 and 5.3 allows local users to execute arbitrary commands via unknown vectors involving lsmcode and possibly other commands.
|
NVD-CWE-Other
|
CVE-2006-2647
|
2011-03-8 11:36 |
2006-05-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355305
|
5.0 |
MEDIUM
|
mono suse
|
xsp suse_open_enterprise_server suse_linux
|
Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE Linux 9.2 through 10.0, allows remote attackers to read arb…
|
NVD-CWE-Other
|
CVE-2006-2658
|
2011-03-8 11:36 |
2006-09-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355306
|
6.4 |
MEDIUM
|
albinator
|
albinator
|
Multiple PHP remote file inclusion vulnerabilities in (1) eday.php, (2) eshow.php, or (3) forgot.php in albinator 2.0.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in t…
|
NVD-CWE-Other
|
CVE-2006-2182
|
2011-03-8 11:35 |
2006-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355307
|
4.3 |
MEDIUM
|
chadha_software_technologies
|
phpkb_knowledge_base
|
Cross-site scripting (XSS) vulnerability in search.php in PHPKB Knowledge Base allows remote attackers to inject arbitrary web script or HTML via the searchkeyword parameter. NOTE: the issue was ori…
|
NVD-CWE-Other
|
CVE-2006-2184
|
2011-03-8 11:35 |
2006-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355308
|
6.8 |
MEDIUM
|
timobraun
|
dynamic_galerie
|
Cross-site scripting (XSS) vulnerability in Dynamic Galerie 1.0 allows remote attackers to inject arbitrary web script or HTML via the pfad parameter in (1) index.php and (2) galerie.php. NOTE: this…
|
NVD-CWE-Other
|
CVE-2006-2294
|
2011-03-8 11:35 |
2006-05-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355309
|
5.0 |
MEDIUM
|
new_atlanta_communications
|
bluedragon_server bluedragon_server_jx
|
BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to cause a denial of service (hang) via a request for a .cfm file whose name contains an MS-DOS device name such as (1) c…
|
NVD-CWE-Other
|
CVE-2006-2310
|
2011-03-8 11:35 |
2006-06-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355310
|
5.0 |
MEDIUM
|
new_atlanta_communications
|
bluedragon_server bluedragon_server_jx
|
This vulnerability is addressed in the following product release:
New Atlanta Communications, BlueDragon Server, 6.2.1.309
|
NVD-CWE-Other
|
CVE-2006-2310
|
2011-03-8 11:35 |
2006-06-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355311
|
2.6 |
LOW
|
new_atlanta_communications
|
bluedragon_server bluedragon_server_jx
|
Cross-site scripting (XSS) vulnerability in BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to inject arbitrary web script or HTML via the filename in a request to a (1)…
|
NVD-CWE-Other
|
CVE-2006-2311
|
2011-03-8 11:35 |
2006-06-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355312
|
2.6 |
LOW
|
updi_network_enterprise
|
at1_event_publisher
|
Cross-site scripting (XSS) vulnerability in tablepublisher.cgi in UPDI Network Enterprise @1 Table Publisher 2006-03-23 allows remote attackers to inject arbitrary web script or HTML via the Title of…
|
NVD-CWE-Other
|
CVE-2006-1795
|
2011-03-8 11:34 |
2006-04-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355313
|
6.4 |
MEDIUM
|
digium
|
asterisk
|
Integer signedness error in format_jpeg.c in Asterisk 1.2.6 and earlier allows remote attackers to execute arbitrary code via a length value that passes a length check as a negative number, but trigg…
|
NVD-CWE-Other
|
CVE-2006-1827
|
2011-03-8 11:34 |
2006-04-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355314
|
4.3 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
Cross-site scripting (XSS) vulnerability in the Your_Account module in PHP-Nuke 7.8 might allows remote attackers to inject arbitrary HTML and web script via the ublock parameter, which is saved in t…
|
NVD-CWE-Other
|
CVE-2006-1846
|
2011-03-8 11:34 |
2006-04-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355315
|
6.4 |
MEDIUM
|
sweetphp
|
totalcalendar
|
PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.
|
NVD-CWE-Other
|
CVE-2006-1922
|
2011-03-8 11:34 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355316
|
4.3 |
MEDIUM
|
community_architect
|
community_architect_guestbook
|
Cross-site scripting (XSS) vulnerability in cgi-bin/guest in Community Architect Guestbook allows remote attackers to inject arbitrary web script or HTML by signing the guestbook, which is displayed …
|
NVD-CWE-Other
|
CVE-2006-2003
|
2011-03-8 11:34 |
2006-04-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355317
|
5.0 |
MEDIUM
|
vihor
|
vihordesign
|
Directory traversal vulnerability in index.php in ViHor Design allows remote attackers to read arbitrary files via the page parameter.
|
NVD-CWE-Other
|
CVE-2006-1497
|
2011-03-8 11:33 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355318
|
5.0 |
MEDIUM
|
basic_analysis_and_security_engine
|
base
|
base_maintenance.php in Basic Analysis and Security Engine (BASE) before 1.2.4 (melissa), when running in standalone mode, allows remote attackers to bypass authentication, possibly by setting the st…
|
NVD-CWE-Other
|
CVE-2006-1505
|
2011-03-8 11:33 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355319
|
5.0 |
MEDIUM
|
basic_analysis_and_security_engine
|
base
|
Succesful exploitation requires that the product is running in standalone mode.
|
NVD-CWE-Other
|
CVE-2006-1505
|
2011-03-8 11:33 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355320
|
7.2 |
HIGH
|
sun
|
grid_engine n1_grid_engine
|
Unspecified vulnerability in rsh in Sun Microsystems Sun Grid Engine 5.3 before 20060327 and N1 Grid Engine 6.0 before 20060327 allows local users to gain root privileges.
|
NVD-CWE-Other
|
CVE-2006-1506
|
2011-03-8 11:33 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355321
|
7.2 |
HIGH
|
sun
|
grid_engine n1_grid_engine
|
This vulnerability affects Sun Microsystems, Sun Grid Engine 5.3 before 20060327 & N1 Grid Engine 6.0 before 20060327.
|
NVD-CWE-Other
|
CVE-2006-1506
|
2011-03-8 11:33 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355322
|
7.5 |
HIGH
|
abcmidi
|
abcmidi
|
Multiple buffer overflows in the abcmidi-yaps translator in abcmidi 20050101, and other versions, allow remote attackers to execute arbitrary code via crafted ABC music files that trigger the overflo…
|
NVD-CWE-Other
|
CVE-2006-1514
|
2011-03-8 11:33 |
2006-04-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355323
|
7.5 |
HIGH
|
typespeed
|
typespeed
|
Buffer overflow in the addnewword function in typespeed 0.4.4 and earlier might allow remote attackers to execute arbitrary code via unknown vectors.
|
NVD-CWE-Other
|
CVE-2006-1515
|
2011-03-8 11:33 |
2006-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355324
|
6.8 |
MEDIUM
|
php
|
php_script_index
|
Cross-site scripting (XSS) vulnerability in search.php in PHP Script Index allows remote attackers to inject arbitrary web script or HTML via the search parameter.
|
NVD-CWE-Other
|
CVE-2006-1558
|
2011-03-8 11:33 |
2006-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355325
|
7.5 |
HIGH
|
php
|
php_script_index
|
SQL injection vulnerability in PHP Script Index allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provenance of this information is unknown; the details ar…
|
NVD-CWE-Other
|
CVE-2006-1559
|
2011-03-8 11:33 |
2006-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355326
|
10.0 |
HIGH
|
exponent
|
exponent_cms
|
Unspecified vulnerability in Exponent CMS before 0.96.5 RC 1 has unknown impact and remote attack vectors related to variables that are not "typecasted."
|
NVD-CWE-Other
|
CVE-2006-1604
|
2011-03-8 11:33 |
2006-04-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355327
|
7.5 |
HIGH
|
exponent
|
exponent_cms
|
Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows remote attackers to execute arbitrary code via unknown vectors involving "parsed PHP."
|
NVD-CWE-Other
|
CVE-2006-1605
|
2011-03-8 11:33 |
2006-04-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355328
|
5.0 |
MEDIUM
|
exponent
|
exponent_cms
|
Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows "directory disclosure" with unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-1606
|
2011-03-8 11:33 |
2006-04-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355329
|
4.3 |
MEDIUM
|
apt
|
apt-webshop-system
|
Cross-site scripting (XSS) vulnerability in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to inject arbitrary web script or HTML via the message parameter, probably inv…
|
NVD-CWE-Other
|
CVE-2006-1687
|
2011-03-8 11:33 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355330
|
7.5 |
HIGH
|
manic_web
|
mwnewsletter
|
Multiple SQL injection vulnerabilities in MWNewsletter 1.0.0b allow remote attackers to execute arbitrary SQL commands via the (1) user_email parameter to (a) unsubscribe.php or (b) subscribe.php; or…
|
NVD-CWE-Other
|
CVE-2006-1692
|
2011-03-8 11:33 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355331
|
2.6 |
LOW
|
bitweaver
|
bitweaver
|
Cross-site scripting (XSS) vulnerability in login.php in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: the provenance of this informatio…
|
NVD-CWE-Other
|
CVE-2006-1745
|
2011-03-8 11:33 |
2006-04-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355332
|
7.8 |
HIGH
|
hosting_controller
|
hosting_controller
|
Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as user name and pass…
|
NVD-CWE-Other
|
CVE-2006-1764
|
2011-03-8 11:33 |
2006-04-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355333
|
6.4 |
MEDIUM
|
ibm
|
websphere_application_server
|
Unspecified vulnerability in IBM WebSphere 5.0.2.10 through 5.0.2.15 and 5.1.1.4 through 5.1.1.9 allows remote attackers to obtain sensitive information via unknown attack vectors, which causes JSP s…
|
NVD-CWE-Other
|
CVE-2006-1093
|
2011-03-8 11:32 |
2006-03-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355334
|
5.0 |
MEDIUM
|
novell
|
bordermanager
|
Unspecified vulnerability in the HTTP proxy in Novell BorderManager 3.8 and earlier allows remote attackers to cause a denial of service (CPU consumption and ABEND) via unknown attack vectors related…
|
NVD-CWE-Other
|
CVE-2006-1218
|
2011-03-8 11:32 |
2006-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355335
|
10.0 |
HIGH
|
amax_information_technologies
|
winmail
|
Unspecified vulnerability in the Webmail module in Winmail before 4.3 has unknown impact and unknown remote attack vectors.
|
NVD-CWE-Other
|
CVE-2006-1250
|
2011-03-8 11:32 |
2006-03-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355336
|
7.8 |
HIGH
|
funkwerk
|
x2300
|
The Internet Key Exchange implementation in Funkwerk X2300 7.2.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by t…
|
NVD-CWE-Other
|
CVE-2006-1268
|
2011-03-8 11:32 |
2006-03-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355337
|
4.6 |
MEDIUM
|
symantec
|
ghost_solutions_suite norton_ghost
|
The installation of SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, includes a default administrator login account and password, which allows local us…
|
NVD-CWE-Other
|
CVE-2006-1284
|
2011-03-8 11:32 |
2006-03-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355338
|
3.2 |
LOW
|
symantec
|
ghost_solutions_suite norton_ghost
|
SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, gives read and write permissions to all users for database shared memory sections, which allows local …
|
NVD-CWE-Other
|
CVE-2006-1285
|
2011-03-8 11:32 |
2006-03-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355339
|
3.2 |
LOW
|
symantec
|
ghost_solutions_suite norton_ghost
|
Update to Symantec Ghost 8.3 that is shipped as a part of Symantec Ghost Solutions Suite 1.1.
|
NVD-CWE-Other
|
CVE-2006-1285
|
2011-03-8 11:32 |
2006-03-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355340
|
5.8 |
MEDIUM
|
invision_power_services
|
invision_power_board
|
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060130 allows remote attackers to steal cookies and probably conduct other activities when the victim i…
|
NVD-CWE-Other
|
CVE-2006-1287
|
2011-03-8 11:32 |
2006-03-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355341
|
5.0 |
MEDIUM
|
oreka
|
oreka
|
Oreka before 0.5 allows remote attackers to cause a denial of service (application crash) via a "certain RTP sequence."
|
NVD-CWE-Other
|
CVE-2006-0912
|
2011-03-8 11:31 |
2006-02-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355342
|
7.5 |
HIGH
|
mozilla
|
bugzilla
|
Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which allows remote attackers to trigger a SQL error.
|
NVD-CWE-Other
|
CVE-2006-0915
|
2011-03-8 11:31 |
2006-02-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355343
|
4.0 |
MEDIUM
|
argosoft
|
argosoft_mail_server
|
Directory traversal vulnerability in Webmail in ArGoSoft Mail Server Pro 1.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the UIDL parameter.
|
NVD-CWE-Other
|
CVE-2006-0930
|
2011-03-8 11:31 |
2006-02-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355344
|
7.5 |
HIGH
|
thomson
|
speedtouch
|
Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the "31" parameter in a NewUser function, which is not filtere…
|
NVD-CWE-Other
|
CVE-2006-0947
|
2011-03-8 11:31 |
2006-03-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355345
|
7.2 |
HIGH
|
eset_software
|
nod32_antivirus
|
The GUI (nod32.exe) in NOD32 2.5 runs with SYSTEM privileges when the scheduler runs a scheduled on-demand scan, which allows local users to execute arbitrary code during a scheduled scan via unspeci…
|
NVD-CWE-Other
|
CVE-2006-0951
|
2011-03-8 11:31 |
2006-04-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355346
|
1.7 |
LOW
|
nufw
|
nufw_firewall
|
nuauth in NuFW before 1.0.21 does not properly handle blocking TLS sockets, which allows remote authenticated users to cause a denial of service (service hang) by flooding packets at the authenticati…
|
NVD-CWE-Other
|
CVE-2006-0956
|
2011-03-8 11:31 |
2006-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355347
|
1.7 |
LOW
|
nufw
|
nufw_firewall
|
This vulnerability affects NuFW, NuFW Firewall versions 1.0.20 and previous.
|
NVD-CWE-Other
|
CVE-2006-0956
|
2011-03-8 11:31 |
2006-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355348
|
7.5 |
HIGH
|
phprpc
|
phprpc
|
Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, exoops, and possibly other programs, allows remote attackers to execute arbitrary…
|
NVD-CWE-Other
|
CVE-2006-1032
|
2011-03-8 11:31 |
2006-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355349
|
10.0 |
HIGH
|
geeklog
|
geeklog
|
Unspecified vulnerability in the session handling for Geeklog 1.4.x before 1.4.0sr2, 1.3.11 before 1.3.11sr5, 1.3.9 before 1.3.9sr5, and possibly earlier versions allows attackers to gain privileges …
|
NVD-CWE-Other
|
CVE-2006-1069
|
2011-03-8 11:31 |
2006-03-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355350
|
5.0 |
MEDIUM
|
hp
|
systems_insight_manager
|
Directory traversal vulnerability in HP Systems Insight Manager 4.2 through 5.0 SP3 for Windows allows remote attackers to access arbitrary files via unspecified vectors, a different vulnerability th…
|
NVD-CWE-Other
|
CVE-2006-0656
|
2011-03-8 11:30 |
2006-02-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|