|
344031
|
- |
|
dream4
|
koobi_pro
|
Cross-site scripting (XSS) vulnerability in the showtopic module in Koobi Pro CMS 5.6 allows remote attackers to inject arbitrary web script or HTML via the toid parameter.
|
NVD-CWE-Other
|
CVE-2006-3620
|
2018-10-19 01:48 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344032
|
- |
|
dream4
|
koobi_pro
|
SQL injection vulnerability in the showtopic module in Koobi Pro CMS 5.6 allows remote attackers to execute arbitrary SQL commands via the toid parameter.
|
NVD-CWE-Other
|
CVE-2006-3621
|
2018-10-19 01:48 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344033
|
- |
|
dream4
|
koobi_pro
|
The showtopic module in Koobi Pro CMS 5.6 allows remote attackers to obtain sensitive information via a ' (single quote) in the p parameter, which displays the path in an error message. NOTE: it is …
|
NVD-CWE-Other
|
CVE-2006-3622
|
2018-10-19 01:48 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344034
|
- |
|
mcafee
|
epolicy_orchestrator_agent
|
Directory traversal vulnerability in Framework Service component in McAfee ePolicy Orchestrator agent 3.5.0.x and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the d…
|
NVD-CWE-Other
|
CVE-2006-3623
|
2018-10-19 01:48 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344035
|
- |
|
flv
|
flv_player
|
Multiple cross-site scripting (XSS) vulnerabilities in FLV Players 8 allow remote attackers to inject arbitrary web script or HTML via the url parameter to (1) player.php or (2) popup.php.
|
NVD-CWE-Other
|
CVE-2006-3624
|
2018-10-19 01:48 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344036
|
- |
|
flv
|
flv_player
|
FLV Players 8 allows remote attackers to obtain sensitive information via (1) a direct request to paginate.php or (2) an invalid p parameter to player.php, which reveal the path in an error message.
|
NVD-CWE-Other
|
CVE-2006-3625
|
2018-10-19 01:48 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344037
|
- |
|
wireshark
|
wireshark
|
Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0.10.11 to 0.99.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors.
|
CWE-399
Resource Management Errors
|
CVE-2006-3627
|
2018-10-19 01:48 |
2006-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344038
|
- |
|
wireshark
|
wireshark
|
This vulnerability is addressed in the following product release:
Wireshark, Ethereal, 0.99.2
|
CWE-399
Resource Management Errors
|
CVE-2006-3627
|
2018-10-19 01:48 |
2006-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344039
|
- |
|
ethereal_group wireshark
|
ethereal wireshark
|
Multiple format string vulnerabilities in Wireshark (aka Ethereal) 0.10.x to 0.99.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) ANSI MAP, (2) C…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2006-3628
|
2018-10-19 01:48 |
2006-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344040
|
- |
|
ethereal_group wireshark
|
ethereal wireshark
|
This vulnerability is addressed in the following product release:
Ethereal Group, Ethereal, 0.99.2
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2006-3628
|
2018-10-19 01:48 |
2006-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|