|
348051
|
- |
|
neosys
|
neon_webmail
|
The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying…
|
NVD-CWE-Other
|
CVE-2006-4954
|
2017-07-20 10:33 |
2006-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348052
|
- |
|
neosys
|
neon_webmail
|
Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the (1) savefolder an…
|
NVD-CWE-Other
|
CVE-2006-4955
|
2017-07-20 10:33 |
2006-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348053
|
- |
|
neosys
|
neon_webmail
|
Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote attackers to inject arbitrary web script or HTML via the in_name parameter, as us…
|
NVD-CWE-Other
|
CVE-2006-4956
|
2017-07-20 10:33 |
2006-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348054
|
- |
|
ibm
|
inventory_scout
|
Unspecified vulnerability in IBM Inventory Scout for AIX 2.2.0.0 through 2.2.0.9 (invscoutClient_VPD_Survey) allows attackers to overwrite arbitrary files via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-5002
|
2017-07-20 10:33 |
2006-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348055
|
- |
|
ibm
|
aix
|
Unspecified vulnerability in the named8 command in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-5003
|
2017-07-20 10:33 |
2006-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348056
|
- |
|
buffalotech
|
terastation_hd-htgl_firmware
|
Cross-site request forgery (CSRF) vulnerability in the administrative interface for the TeraStation HD-HTGL firmware 2.05 beta 1 and earlier allows remote attackers to modify configurations or delete…
|
CWE-352
Origin Validation Error
|
CVE-2006-5175
|
2017-07-20 10:33 |
2006-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348057
|
- |
|
mole_group_ticket_booking_script
|
mole_group_ticket_booking_script
|
Multiple cross-site scripting (XSS) vulnerabilities in booking3.php in Mole Group Ticket Booking Script allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) address1, (…
|
NVD-CWE-Other
|
CVE-2006-3049
|
2017-07-20 10:32 |
2006-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348058
|
- |
|
myphp_guestbook
|
myphp_guestbook
|
Multiple cross-site scripting (XSS) vulnerabilities in myPHP Guestbook 1.x through 2.0.0-r1 and before 2.0.1 RC5 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2)…
|
NVD-CWE-Other
|
CVE-2006-3063
|
2017-07-20 10:32 |
2006-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348059
|
- |
|
ibm
|
db2_universal_database
|
Multiple unspecified vulnerabilities in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allow remote attackers to cause a denial of service (application crash) via a (1) "long column list" in t…
|
NVD-CWE-Other
|
CVE-2006-3067
|
2017-07-20 10:32 |
2006-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348060
|
- |
|
symantec
|
security_information_manager
|
M4 Macro Library in Symantec Security Information Manager before 4.0.2.29 HOTFIX 1 allows local users to execute arbitrary commands via crafted "rule definitions", which produces dangerous Java code …
|
NVD-CWE-Other
|
CVE-2006-3072
|
2017-07-20 10:32 |
2006-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|