|
346161
|
- |
|
neosys
|
neon_webmail
|
The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail folders, specified by the folderid and tofolderid…
|
NVD-CWE-Other
|
CVE-2006-4952
|
2017-07-20 10:33 |
2006-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346162
|
- |
|
neosys
|
neon_webmail
|
Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary SQL commands via the (1) adr_sortkey and (2) adr_sortkey_desc parameters in the…
|
NVD-CWE-Other
|
CVE-2006-4953
|
2017-07-20 10:33 |
2006-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346163
|
- |
|
neosys
|
neon_webmail
|
The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying…
|
NVD-CWE-Other
|
CVE-2006-4954
|
2017-07-20 10:33 |
2006-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346164
|
- |
|
neosys
|
neon_webmail
|
Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the (1) savefolder an…
|
NVD-CWE-Other
|
CVE-2006-4955
|
2017-07-20 10:33 |
2006-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346165
|
- |
|
neosys
|
neon_webmail
|
Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote attackers to inject arbitrary web script or HTML via the in_name parameter, as us…
|
NVD-CWE-Other
|
CVE-2006-4956
|
2017-07-20 10:33 |
2006-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346166
|
- |
|
ibm
|
inventory_scout
|
Unspecified vulnerability in IBM Inventory Scout for AIX 2.2.0.0 through 2.2.0.9 (invscoutClient_VPD_Survey) allows attackers to overwrite arbitrary files via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-5002
|
2017-07-20 10:33 |
2006-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346167
|
- |
|
ibm
|
aix
|
Unspecified vulnerability in the named8 command in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-5003
|
2017-07-20 10:33 |
2006-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346168
|
- |
|
buffalotech
|
terastation_hd-htgl_firmware
|
Cross-site request forgery (CSRF) vulnerability in the administrative interface for the TeraStation HD-HTGL firmware 2.05 beta 1 and earlier allows remote attackers to modify configurations or delete…
|
CWE-352
Origin Validation Error
|
CVE-2006-5175
|
2017-07-20 10:33 |
2006-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346169
|
- |
|
mole_group_ticket_booking_script
|
mole_group_ticket_booking_script
|
Multiple cross-site scripting (XSS) vulnerabilities in booking3.php in Mole Group Ticket Booking Script allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) address1, (…
|
NVD-CWE-Other
|
CVE-2006-3049
|
2017-07-20 10:32 |
2006-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346170
|
- |
|
myphp_guestbook
|
myphp_guestbook
|
Multiple cross-site scripting (XSS) vulnerabilities in myPHP Guestbook 1.x through 2.0.0-r1 and before 2.0.1 RC5 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2)…
|
NVD-CWE-Other
|
CVE-2006-3063
|
2017-07-20 10:32 |
2006-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|