|
348981
|
- |
|
roxio
|
toast
|
Race condition in Deja Vu, as used in Roxio Toast Titanium 7 and possibly other products, allows local users to execute arbitrary code via temporary files, including dejavu_manual.rb, which are execu…
|
CWE-362
Race Condition
|
CVE-2006-4801
|
2011-03-8 11:42 |
2006-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348982
|
- |
|
iodine
|
iodine
|
Unspecified vulnerability in IP over DNS is now easy (iodine) before 0.3.2 has unknown impact and attack vectors, related to "potential security problems."
|
NVD-CWE-Other
|
CVE-2006-4831
|
2011-03-8 11:42 |
2006-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348983
|
- |
|
iodine
|
iodine
|
This vulnerability is addressed in the following product release:
Iodine, Iodine, 0.3.2
|
NVD-CWE-Other
|
CVE-2006-4831
|
2011-03-8 11:42 |
2006-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348984
|
- |
|
joomla
|
joomla
|
Unspecified vulnerability in com_content in Joomla! before 1.0.11, when $mosConfig_hideEmail is set, allows attackers to perform the emailform and emailsend tasks.
|
NVD-CWE-Other
|
CVE-2006-4473
|
2011-03-8 11:41 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348985
|
- |
|
joomla
|
joomla
|
Joomla! before 1.0.11 does not limit access to the Admin Popups functionality, which has unknown impact and attack vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-4475
|
2011-03-8 11:41 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348986
|
- |
|
joomla
|
joomla
|
Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to "Injection Flaws," allow attackers to have an unknown impact via (1) globals.php, which uses include_once() instead of requir…
|
CWE-94 CWE-264
Code Injection Permissions, Privileges, and Access Controls
|
CVE-2006-4476
|
2011-03-8 11:41 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348987
|
- |
|
ibm
|
aix
|
Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code with root privileges via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-4522
|
2011-03-8 11:41 |
2006-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348988
|
- |
|
vtiger
|
vtiger_crm
|
Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 4.2.4, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) description parameter in unspe…
|
NVD-CWE-Other
|
CVE-2006-4587
|
2011-03-8 11:41 |
2006-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348989
|
- |
|
vtiger
|
vtiger_crm
|
vtiger CRM 4.2.4, and possibly earlier, allows remote attackers to bypass authentication and access administrative modules via a direct request to index.php with a modified module parameter, as demon…
|
NVD-CWE-Other
|
CVE-2006-4588
|
2011-03-8 11:41 |
2006-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348990
|
- |
|
bare_concept_media
|
pheap_cms
|
PHP remote file inclusion vulnerability in settings.php in Pheap 1.2, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the lpref parameter. NOTE: the provenan…
|
NVD-CWE-Other
|
CVE-2006-4621
|
2011-03-8 11:41 |
2006-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|