|
346021
|
- |
|
kailash_nadh
|
boastmachine
|
Cross-site request forgery (CSRF) vulnerability in bmc/admin.php in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote attackers to perform unauthorized actions as an adminis…
|
NVD-CWE-Other
|
CVE-2006-3829
|
2018-10-18 06:31 |
2006-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346022
|
- |
|
kailash_nadh
|
boastmachine
|
The Backup selection in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier uses predicable filenames for database backups and stores the files under the web root with insufficient access c…
|
NVD-CWE-Other
|
CVE-2006-3831
|
2018-10-18 06:31 |
2006-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346023
|
- |
|
gerrit_van_aaken
|
loudblog
|
SQL injection vulnerability in index.php in Gerrit van Aaken Loudblog 0.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2006-3832
|
2018-10-18 06:31 |
2006-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346024
|
- |
|
ej3
|
topo
|
index.php in EJ3 TOPo 2.2.178 allows remote attackers to overwrite existing entries and establish new passwords for the overwritten entries via a URL with a modified entry ID.
|
NVD-CWE-Other
|
CVE-2006-3833
|
2018-10-18 06:31 |
2006-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346025
|
- |
|
ej3
|
topo
|
EJ3 TOPo 2.2.178 includes the password in cleartext in the ID field to index.php, which allows context-dependent attackers to obtain entry passwords via log files, referrers, or other vectors.
|
NVD-CWE-Other
|
CVE-2006-3834
|
2018-10-18 06:31 |
2006-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346026
|
- |
|
unidomedia
|
chameleon_le
|
Directory traversal vulnerability in index.php in UNIDOmedia Chameleon LE 1.203 and earlier, and possibly Chameleon PRO, allows remote attackers to read arbitrary files via the rmid parameter.
|
NVD-CWE-Other
|
CVE-2006-3836
|
2018-10-18 06:31 |
2006-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346027
|
- |
|
professional_home_page_tools
|
professional_home_page_tools_guestbook
|
delcookie.php in Professional Home Page Tools Guestbook changes the expiration date of a cookie instead of deleting the cookie's value, which makes it easier for attackers to steal the cookie and obt…
|
NVD-CWE-Other
|
CVE-2006-3837
|
2018-10-18 06:31 |
2006-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346028
|
- |
|
owasp
|
webscarab
|
Cross-site scripting (XSS) vulnerability in WebScarab before 20060718-1904, when used with Microsoft Internet Explorer 6 SP2 or Konqueror 3.5.3, allows remote attackers to inject arbitrary web script…
|
NVD-CWE-Other
|
CVE-2006-3841
|
2018-10-18 06:31 |
2006-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346029
|
- |
|
eiqnetworks
|
enterprise_security_analyzer
|
Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in products including (a) Sidewinder, (b) iPolicy Security Manager, (c) Astaro Report Man…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-3838
|
2018-10-18 06:31 |
2006-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346030
|
- |
|
iss
|
blackice_pc_protection blackice_server_protection proventia_desktop realsecure_desktop realsecure_network realsecure_server_sensor proventia_a_series_xpu proventia_g_series_xpu
|
The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and Desktop, BlackICE PC and Server Protection 3.6, a…
|
CWE-399
Resource Management Errors
|
CVE-2006-3840
|
2018-10-18 06:31 |
2006-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|