|
344381
|
- |
|
particle_soft
|
particle_links
|
SQL injection vulnerability in index.php in Partial Links 1.2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter.
|
NVD-CWE-Other
|
CVE-2006-2904
|
2018-10-19 01:43 |
2006-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344382
|
- |
|
particle_soft
|
particle_links
|
Partial Links 1.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) page_footer.php and (2) page_header.php, which displays the path in an error message.
|
NVD-CWE-Other
|
CVE-2006-2905
|
2018-10-19 01:43 |
2006-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344383
|
- |
|
mybulletinboard
|
mybulletinboard
|
The domecode function in inc/functions_post.php in MyBulletinBoard (MyBB) 1.1.2, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the username field, which is us…
|
NVD-CWE-Other
|
CVE-2006-2908
|
2018-10-19 01:43 |
2006-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344384
|
- |
|
picozip
|
picozip
|
Stack-based buffer overflow in the info tip shell extension (zipinfo.dll) in PicoZip 4.01 allows remote attackers to execute arbitrary code via a long filename in an (1) ACE, (2) RAR, or (3) ZIP arch…
|
NVD-CWE-Other
|
CVE-2006-2909
|
2018-10-19 01:43 |
2006-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344385
|
- |
|
hotwebscripts
|
cms_mundo
|
SQL injection vulnerability in controlpanel/index.php in CMS Mundo before 1.0 build 008 allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
NVD-CWE-Other
|
CVE-2006-2911
|
2018-10-19 01:43 |
2006-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344386
|
- |
|
out_of_the_trees_web_design
|
selectapix
|
Multiple SQL injection vulnerabilities in SelectaPix 1.31 allow remote attackers to execute arbitrary SQL commands via the (1) albumID parameter to (a) view_album.php or (b) index.php, (2) imageID pa…
|
NVD-CWE-Other
|
CVE-2006-2912
|
2018-10-19 01:43 |
2006-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344387
|
- |
|
deluxebb
|
deluxebb
|
PHP remote file inclusion vulnerability in DeluxeBB 1.06 allows remote attackers to execute arbitrary code via a URL in the templatefolder parameter to (1) postreply.php, (2) posting.php, (3) and pm/…
|
NVD-CWE-Other
|
CVE-2006-2914
|
2018-10-19 01:43 |
2006-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344388
|
- |
|
deluxebb
|
deluxebb
|
Multiple SQL injection vulnerabilities in DeluxeBB 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) hideemail, (2) languagex, (3) xthetimeoffset, and (4) xthetimeformat param…
|
NVD-CWE-Other
|
CVE-2006-2915
|
2018-10-19 01:43 |
2006-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344389
|
- |
|
lanap_botdetect
|
captcha_asp.net
|
The Lanap BotDetect APS.NET CAPTCHA component before 1.5.4.0 stores the UUID and hash for a CAPTCHA in the ViewState of a page, which makes it easier for remote attackers to conduct automated attacks…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-2918
|
2018-10-19 01:43 |
2006-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344390
|
- |
|
microsoft
|
netmeeting
|
Unspecified vulnerability in Microsoft NetMeeting 3.01 allows remote attackers to cause a denial of service (crash or CPU consumption) and possibly execute arbitrary code via crafted inputs that trig…
|
NVD-CWE-Other
|
CVE-2006-2919
|
2018-10-19 01:43 |
2006-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|