|
345861
|
- |
|
advanced_poll
|
advanced_poll
|
Successful exploitation requires that magic_quotes_gpc is set to off.
|
NVD-CWE-Other
|
CVE-2006-2130
|
2017-07-20 10:31 |
2006-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345862
|
- |
|
advanced_poll
|
advanced_poll
|
include/class_poll.php in Advanced Poll 2.0.4 uses the HTTP_X_FORWARDED_FOR (X-Forwarded-For HTTP header) to identify the IP address of a client, which makes it easier for remote attackers to spoof t…
|
NVD-CWE-Other
|
CVE-2006-2131
|
2017-07-20 10:31 |
2006-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345863
|
- |
|
boonex
|
barracuda
|
SQL injection vulnerability in index.php in BoonEx Barracuda 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) link_dir_target and (2) link_id_target parameter, po…
|
NVD-CWE-Other
|
CVE-2006-2133
|
2017-07-20 10:31 |
2006-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345864
|
- |
|
ruperts_news
|
ruperts_news
|
SQL injection vulnerability in login.php in Ruperts News allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
NVD-CWE-Other
|
CVE-2006-2135
|
2017-07-20 10:31 |
2006-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345865
|
- |
|
ruperts_news
|
ruperts_news
|
Successful exploitation requires that magic_quotes_gpc is set to off.
|
NVD-CWE-Other
|
CVE-2006-2135
|
2017-07-20 10:31 |
2006-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345866
|
- |
|
aznews
|
aznews
|
SQL injection vulnerability in news.php in AZNEWS allows remote attackers to execute arbitrary SQL commands via the ID parameter.
|
NVD-CWE-Other
|
CVE-2006-2136
|
2017-07-20 10:31 |
2006-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345867
|
- |
|
aznews
|
aznews
|
Other versions of this product may also be affected by this vulnerability.
|
NVD-CWE-Other
|
CVE-2006-2136
|
2017-07-20 10:31 |
2006-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345868
|
- |
|
wilsonncareabusinesses
|
php_newsfeed
|
Multiple SQL injection vulnerabilities in PHP Newsfeed 20040723 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to (a) deltables.php, (2) select, (3) header, (4) u…
|
NVD-CWE-Other
|
CVE-2006-2139
|
2017-07-20 10:31 |
2006-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345869
|
- |
|
orbitscripts
|
orbithyip
|
Multiple cross-site scripting (XSS) vulnerabilities in OrbitHYIP 2.0 and earlier allow remote attackers to inject arbitrary web script via the (1) referral parameter to signup.php or (2) id parameter…
|
NVD-CWE-Other
|
CVE-2006-2140
|
2017-07-20 10:31 |
2006-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345870
|
- |
|
collaborative_portal_server_project
|
collaborative_portal_server
|
Cross-site scripting (XSS) vulnerability in popup_image in Collaborative Portal Server (CPS) 3.4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the pos argument.
|
NVD-CWE-Other
|
CVE-2006-2141
|
2017-07-20 10:31 |
2006-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|