|
355351
|
10.0 |
HIGH
|
mantis
|
mantis
|
Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectors. NOTE: the provenance of this information is unknown; the…
|
NVD-CWE-Other
|
CVE-2006-0665
|
2011-03-8 11:30 |
2006-02-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355352
|
4.6 |
MEDIUM
|
ibm
|
aix
|
lscfg in IBM AIX 5.2 and 5.3 allows local users to modify arbitrary files via a symlink attack.
|
NVD-CWE-Other
|
CVE-2006-0667
|
2011-03-8 11:30 |
2006-03-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355353
|
7.5 |
HIGH
|
musox
|
df_msanalysis
|
SQL injection vulnerability in mstrack.php in MusOX DF MSAnalysis (DFMSA), as used in some environments that use CPG-Nuke Dragonfly CMS, allows remote attackers to trigger path disclosure from a SQL …
|
NVD-CWE-Other
|
CVE-2006-0727
|
2011-03-8 11:30 |
2006-02-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355354
|
10.0 |
HIGH
|
noofs_team
|
network_object_oriented_file_system
|
Multiple unspecified vulnerabilities in the (1) Filesystem in USErspace (FUSE) client and (2) NOOFS daemon in in Network Object Oriented File System (NOOFS) before 0.9.0 have unspecified impact and a…
|
NVD-CWE-noinfo
|
CVE-2006-0751
|
2011-03-8 11:30 |
2006-02-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355355
|
5.0 |
MEDIUM
|
xerox
|
workcentre_232 workcentre_238 workcentre_245 workcentre_255 workcentre_265 workcentre_275
|
Unspecified vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote attackers t…
|
NVD-CWE-Other
|
CVE-2006-0828
|
2011-03-8 11:30 |
2006-02-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355356
|
5.0 |
MEDIUM
|
popfile
|
popfile
|
POPFile before 0.22.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving character sets within e-mail messages.
|
NVD-CWE-Other
|
CVE-2006-0876
|
2011-03-8 11:30 |
2006-02-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355357
|
7.5 |
HIGH
|
pam-mysql
|
pam-mysql
|
Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service …
|
CWE-119
バッファエラー
|
CVE-2006-0056
|
2011-03-8 11:29 |
2006-02-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355358
|
7.5 |
HIGH
|
vego
|
vego_links_builder
|
SQL injection vulnerability in login.php in VEGO Links Builder 2.00 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
NVD-CWE-Other
|
CVE-2006-0067
|
2011-03-8 11:29 |
2006-01-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355359
|
7.5 |
HIGH
|
primo_place
|
primo_cart
|
SQL injection vulnerability in Primo Cart 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) q parameter to search.php and (2) email parameter to user.php.
|
NVD-CWE-Other
|
CVE-2006-0068
|
2011-03-8 11:29 |
2006-01-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355360
|
2.1 |
LOW
|
richard_dawe
|
file_extattr
|
Off-by-one error in the getfattr function in File::ExtAttr before 0.03 allows attackers to trigger a buffer overflow via unspecified attack vectors.
|
NVD-CWE-Other
|
CVE-2006-0077
|
2011-03-8 11:29 |
2006-01-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355361
|
5.0 |
MEDIUM
|
rasmp
|
rasmp
|
Cross-site scripting vulnerability in index.php in raSMP 2.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the $_SERVER[HTTP_USER_AGENT] variable (User-Agent header…
|
NVD-CWE-Other
|
CVE-2006-0084
|
2011-03-8 11:29 |
2006-01-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355362
|
7.5 |
HIGH
|
nkads
|
nkads
|
SQL injection vulnerability in Nkads 1.0 alfa 3 allows remote attackers to execute arbitrary SQL commands via the (1) usuario_nkads_admin or (2) password_nkads_admin parameters.
|
NVD-CWE-Other
|
CVE-2006-0085
|
2011-03-8 11:29 |
2006-01-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355363
|
5.0 |
MEDIUM
|
next_generation_image_gallery
|
next_generation_image_gallery
|
Cross-site scripting vulnerability in index.php in Next Generation Image Gallery 0.0.1 Lite Edition allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
NVD-CWE-Other
|
CVE-2006-0086
|
2011-03-8 11:29 |
2006-01-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355364
|
5.0 |
MEDIUM
|
esri
|
arcpad
|
Buffer overflow in ESRI ArcPad 7.0.0.156 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .amp file with a COORDSYS tag with a long s…
|
NVD-CWE-Other
|
CVE-2006-0089
|
2011-03-8 11:29 |
2006-01-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355365
|
5.0 |
MEDIUM
|
idv_directory_viewer
|
idv_directory_viewer
|
Directory traversal vulnerability in index.php in IDV Directory Viewer before 2005.1 allows remote attackers to view arbitrary directory contents via a .. (dot dot) in the dir parameter.
|
NVD-CWE-Other
|
CVE-2006-0090
|
2011-03-8 11:29 |
2006-01-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355366
|
4.3 |
MEDIUM
|
ecardmax.com
|
atcard_me_php
|
Cross-site scripting (XSS) vulnerability in index.php in @Card ME PHP allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
|
NVD-CWE-Other
|
CVE-2006-0093
|
2011-03-8 11:29 |
2006-01-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355367
|
5.0 |
MEDIUM
|
modular_merchant
|
shopping_cart
|
Cross-site scripting vulnerability in category.php in Modular Merchant Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
|
NVD-CWE-Other
|
CVE-2006-0109
|
2011-03-8 11:29 |
2006-01-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355368
|
4.3 |
MEDIUM
|
enhanced_simple_php_gallery
|
enhanced_simple_php_gallery
|
Cross-site scripting (XSS) vulnerability in index.php in Enhanced Simple PHP Gallery 1.7 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.
|
NVD-CWE-Other
|
CVE-2006-0112
|
2011-03-8 11:29 |
2006-01-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355369
|
4.3 |
MEDIUM
|
aquifer_cms
|
aquifer_cms
|
Cross-site scripting (XSS) vulnerability in Public/Index.asp in Aquifer CMS allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter.
|
NVD-CWE-Other
|
CVE-2006-0122
|
2011-03-8 11:29 |
2006-01-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355370
|
4.3 |
MEDIUM
|
aquifer_cms
|
aquifer_cms
|
Vendor provided solution:
"Liquid Development has identified this vulnerability in all shipping versions of AquiferCMS and coded a software fix. The fix will be included in all releases of Aquifer…
|
NVD-CWE-Other
|
CVE-2006-0122
|
2011-03-8 11:29 |
2006-01-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355371
|
5.0 |
MEDIUM
|
appserv_open_project
|
appserv
|
Unspecified vulnerability in appserv/main.php in AppServ 2.4.5 allows remote attackers to include arbitrary files via the appserv_root parameter. NOTE: the provenance of this information is unknown;…
|
NVD-CWE-Other
|
CVE-2006-0125
|
2011-03-8 11:29 |
2006-01-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355372
|
4.6 |
MEDIUM
|
rxvt-unicode
|
rxvt-unicode
|
rxvt-unicode before 6.3, on certain platforms that use openpty and non-Unix pty devices such as Linux and most BSD platforms, does not maintain the intended permissions of tty devices, which allows l…
|
NVD-CWE-Other
|
CVE-2006-0126
|
2011-03-8 11:29 |
2006-01-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355373
|
4.0 |
MEDIUM
|
rockliffe
|
mailsite
|
Directory traversal vulnerability in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote authenticated users to rename the folders of other users via a .. (dot dot) in the RENAME com…
|
NVD-CWE-Other
|
CVE-2006-0127
|
2011-03-8 11:29 |
2006-01-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355374
|
5.0 |
MEDIUM
|
rockliffe
|
mailsite
|
Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier generates different responses depending on whether or not a username is valid, which allows remot…
|
NVD-CWE-Other
|
CVE-2006-0129
|
2011-03-8 11:29 |
2006-01-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355375
|
7.5 |
HIGH
|
cyberdoc
|
sitesuite_cms
|
SQL injection vulnerability in index.php in CyberDoc SiteSuite CMS allows remote attackers to execute arbitrary SQL commands via the page parameter.
|
NVD-CWE-Other
|
CVE-2006-0158
|
2011-03-8 11:29 |
2006-01-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355376
|
5.0 |
MEDIUM
|
php-nuke
|
news_module pool_module
|
Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an I…
|
NVD-CWE-Other
|
CVE-2006-0185
|
2011-03-8 11:29 |
2006-01-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355377
|
5.0 |
MEDIUM
|
paypal
|
php_toolkit
|
Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50, and possibly earlier versions, allows remote attackers to enter false payment entries into the log file via HTTP POST …
|
NVD-CWE-Other
|
CVE-2006-0201
|
2011-03-8 11:29 |
2006-01-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355378
|
3.6 |
LOW
|
paypal
|
php_toolkit
|
Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50 and possibly earlier has (1) world-readable permissions for ipn/logs/ipn_success.txt, which allows local users to view …
|
NVD-CWE-Other
|
CVE-2006-0202
|
2011-03-8 11:29 |
2006-01-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355379
|
7.5 |
HIGH
|
pdfdirectory
|
pdfdirectory
|
Multiple SQL injection vulnerabilities in PDFdirectory before 1.0 allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors involving (1) util.php, (2) userpref.php, (…
|
NVD-CWE-Other
|
CVE-2006-0313
|
2011-03-8 11:29 |
2006-01-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355380
|
7.5 |
HIGH
|
pdfdirectory
|
pdfdirectory
|
PDFdirectory before 1.0 stores sensitive data in plaintext, which allows remote attackers to obtain arbitrary users' passwords by direct queries to the database, possibly via one of the SQL injection…
|
NVD-CWE-Other
|
CVE-2006-0314
|
2011-03-8 11:29 |
2006-01-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355381
|
5.0 |
MEDIUM
|
sun
|
java_system_web_proxy_server
|
Multiple unspecified vulnerabilities in Sun Java System Web Proxy Server 3.6 SP7 and earlier allow remote attackers to cause a denial of service (unresponsive service) via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-4806
|
2011-03-8 11:29 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355382
|
10.0 |
HIGH
|
hp
|
http_server
|
Buffer overflow in the HP HTTP Server 5.0 through 5.95 of the HP Web-enabled Management Software allows remote attackers to execute arbitrary code via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-4823
|
2011-03-8 11:29 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355383
|
4.3 |
MEDIUM
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source code and other sens…
|
NVD-CWE-Other
|
CVE-2005-4833
|
2011-03-8 11:29 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355384
|
5.0 |
MEDIUM
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server (WAS) 5.0.2.5 through 5.1.1.3 allows remote attackers to obtain JSP source code and other sensitive information, related to incorrect request processing by the web co…
|
NVD-CWE-Other
|
CVE-2005-4834
|
2011-03-8 11:29 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355385
|
7.8 |
HIGH
|
hitachi
|
groupmax_mail_smtp
|
Hitachi Groupmax Mail SMTP 06-50 through 06-52-/A and 07-00 through 07-20 allows remote attackers to cause a denial of service (service stop) via an e-mail message with an "invalid format."
|
NVD-CWE-Other
|
CVE-2005-4324
|
2011-03-8 11:28 |
2005-12-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355386
|
4.3 |
MEDIUM
|
university_of_arizona
|
webglimpse
|
Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the ID parameter.
|
NVD-CWE-Other
|
CVE-2005-4328
|
2011-03-8 11:28 |
2005-12-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355387
|
7.5 |
HIGH
|
php_arena
|
pafiledb
|
SQL injection vulnerability in pafiledb.php in PHP Arena paFileDB Extreme Edition RC 5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) newsid and (2) id parameter.
|
NVD-CWE-Other
|
CVE-2005-4329
|
2011-03-8 11:28 |
2005-12-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355388
|
7.5 |
HIGH
|
-
|
-
|
SQL injection vulnerability in browse.ihtml in iHTML Merchant Mall allows remote attackers to execute arbitrary SQL commands via the (1) id, (2) store, and (3) step parameters.
|
NVD-CWE-Other
|
CVE-2005-4330
|
2011-03-8 11:28 |
2005-12-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355389
|
7.5 |
HIGH
|
ihtml_merchant
|
ihtml_merchant
|
SQL injection vulnerability in merchant.ihtml in iHTML Merchant Version 2 Pro allows remote attackers to execute arbitrary SQL commands via the (1) step, (2) id, and (3) pid parameters.
|
NVD-CWE-Other
|
CVE-2005-4331
|
2011-03-8 11:28 |
2005-12-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355390
|
4.3 |
MEDIUM
|
courseforum
|
projectforum
|
Cross-site scripting (XSS) vulnerability in ProjectForum 4.7.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) fwd parameter in admin/adminsignin.html and (2) o…
|
NVD-CWE-Other
|
CVE-2005-4336
|
2011-03-8 11:28 |
2005-12-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355391
|
7.5 |
HIGH
|
macromedia
|
coldfusion
|
ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager is disabled, which might allow remote attackers to …
|
NVD-CWE-Other
|
CVE-2005-4342
|
2011-03-8 11:28 |
2005-12-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355392
|
5.0 |
MEDIUM
|
macromedia
|
coldfusion
|
Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary files and send mail via a crafted Subject field, which is not properly handled b…
|
NVD-CWE-Other
|
CVE-2005-4343
|
2011-03-8 11:28 |
2005-12-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355393
|
2.1 |
LOW
|
macromedia
|
coldfusion
|
Adobe (formerly Macromedia) ColdFusion MX 7.0 does not honor when the CFOBJECT /CreateObject(Java) setting is disabled, which allows local users to create an object despite the specified configuratio…
|
NVD-CWE-Other
|
CVE-2005-4344
|
2011-03-8 11:28 |
2005-12-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355394
|
7.2 |
HIGH
|
macromedia
|
coldfusion
|
Adobe (formerly Macromedia) ColdFusion MX 7.0 exposes the password hash of the Administrator in an API call, which allows local developers to obtain the hash and gain privileges.
|
NVD-CWE-Other
|
CVE-2005-4345
|
2011-03-8 11:28 |
2005-12-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355395
|
7.8 |
HIGH
|
sun
|
wbem_services
|
Unspecified vulnerability in WBEM Services A.01.x before A.01.05.12 and A.02.x before A.02.00.08 on HP-UX B.11.00 through B.11.23 allows remote attackers to cause an unspecified denial of service via…
|
NVD-CWE-Other
|
CVE-2005-4350
|
2011-03-8 11:28 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355396
|
7.5 |
HIGH
|
toenda_software_development
|
toendacms
|
SQL injection vulnerability in index.php in toendaCMS 0.6.2.1, when configured to use a SQL database, allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2005-4353
|
2011-03-8 11:28 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355397
|
4.3 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the query parameter.
|
NVD-CWE-Other
|
CVE-2005-4354
|
2011-03-8 11:28 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355398
|
4.3 |
MEDIUM
|
xmpie
|
ustore
|
Multiple cross-site scripting (XSS) vulnerabilities in UStore allow remote attackers to inject arbitrary web script or HTML via the (1) Cat parameter in default.asp and the (2) accessdenied parameter…
|
NVD-CWE-Other
|
CVE-2005-4355
|
2011-03-8 11:28 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355399
|
7.5 |
HIGH
|
xmpie
|
ustore
|
SQL injection vulnerability in UStore allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields. NOTE: the provenance of this information is unknown; the…
|
NVD-CWE-Other
|
CVE-2005-4356
|
2011-03-8 11:28 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355400
|
6.4 |
MEDIUM
|
oodie
|
odfaq
|
SQL injection vulnerability in includes/core.inc.php in ODFaq 2.1.0 allows remote attackers to execute arbitrary SQL commands via the (1) cat and (2) srcText parameters to faq.php.
|
NVD-CWE-Other
|
CVE-2005-4359
|
2011-03-8 11:28 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|