|
345821
|
- |
|
ansilove
|
ansilove
|
Unspecified vulnerability in the loaders (load_*.php) in Ansilove before 1.03 allows remote attackers to read arbitrary files via unspecified vectors involving "converting files accessible by the web…
|
NVD-CWE-Other
|
CVE-2006-0694
|
2017-07-20 10:29 |
2006-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345822
|
- |
|
ansilove
|
ansilove
|
Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them dire…
|
NVD-CWE-Other
|
CVE-2006-0695
|
2017-07-20 10:29 |
2006-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345823
|
- |
|
zen_cart
|
zen_cart
|
SQL injection vulnerability in Zen Cart before 1.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-0696
|
2017-07-20 10:29 |
2006-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345824
|
- |
|
zen_cart
|
zen_cart
|
Unspecified vulnerabilities in Zen Cart before 1.2.7 allow remote attackers to cause unknown impact via unspecified vectors related to "other attempted exploits" other than SQL injection.
|
NVD-CWE-Other
|
CVE-2006-0698
|
2017-07-20 10:29 |
2006-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345825
|
- |
|
david_barrett
|
qwikiwiki
|
Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter.
|
NVD-CWE-Other
|
CVE-2006-0699
|
2017-07-20 10:29 |
2006-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345826
|
- |
|
imagevue
|
imagevue
|
imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-0700
|
2017-07-20 10:29 |
2006-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345827
|
- |
|
imagevue
|
imagevue
|
readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters.
|
NVD-CWE-Other
|
CVE-2006-0701
|
2017-07-20 10:29 |
2006-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345828
|
- |
|
imagevue
|
imagevue
|
admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter. NOTE: due to the lack of details, the…
|
NVD-CWE-Other
|
CVE-2006-0702
|
2017-07-20 10:29 |
2006-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345829
|
- |
|
ie
|
ie_integrator
|
iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the in…
|
NVD-CWE-Other
|
CVE-2006-0704
|
2017-07-20 10:29 |
2006-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345830
|
- |
|
pyblosxom
|
pyblosxom
|
PyBlosxom before 1.3.2, when running on certain webservers, allows remote attackers to read arbitrary files via an HTTP request with multiple leading / (slash) characters, which is accessed using the…
|
CWE-200
Information Exposure
|
CVE-2006-0707
|
2017-07-20 10:29 |
2006-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|