|
289801
|
- |
|
ultimate_helpdesk
|
ultimate_helpdesk
|
Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
|
NVD-CWE-Other
|
CVE-2006-6381
|
2017-10-19 10:29 |
2006-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289802
|
- |
|
open_solution
|
quick.cart
|
Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrar…
|
NVD-CWE-Other
|
CVE-2006-6390
|
2017-10-19 10:29 |
2006-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289803
|
- |
|
blazevideo
|
hdtv_player
|
Stack-based buffer overflow in BlazeVideo HDTV Player 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via a long filename in a PLF playlist, a different product than CVE-…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-6396
|
2017-10-19 10:29 |
2006-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289804
|
- |
|
thinkedit
|
thinkedit
|
PHP remote file inclusion vulnerability in design/thinkedit/render.php in ThinkEdit 1.9.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a UR…
|
NVD-CWE-Other
|
CVE-2006-6426
|
2017-10-19 10:29 |
2006-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289805
|
- |
|
thinkedit
|
thinkedit
|
Successful exploitation requires that "register_globals" is enabled.
This vulnerability is addressed in the following product release:
ThinkEdit, ThinkEdit, 1.9.2
|
NVD-CWE-Other
|
CVE-2006-6426
|
2017-10-19 10:29 |
2006-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289806
|
- |
|
envolution
|
envolution
|
Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) para…
|
NVD-CWE-Other
|
CVE-2006-6445
|
2017-10-19 10:29 |
2006-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289807
|
- |
|
j-owamp
|
web_interface
|
PHP remote file inclusion vulnerability in JOWAMP_ShowPage.php in J-OWAMP Web Interface 2.1 allows remote authenticated users to execute arbitrary PHP code via a URL in the link parameter.
|
NVD-CWE-Other
|
CVE-2006-6453
|
2017-10-19 10:29 |
2006-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289808
|
- |
|
cm68_news
|
cm68_news
|
PHP remote file inclusion vulnerability in engine/oldnews.inc.php in CM68 News 12.02.06 allows remote attackers to execute arbitrary PHP code via a URL in the addpath parameter.
|
CWE-94
Code Injection
|
CVE-2006-6462
|
2017-10-19 10:29 |
2006-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289809
|
- |
|
ezhrs
|
hr_assist
|
SQL injection vulnerability in vdateUsr.asp in EzHRS HR Assist 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the Uname (UserName) parameter.
|
NVD-CWE-Other
|
CVE-2006-6524
|
2017-10-19 10:29 |
2006-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289810
|
- |
|
fantastic_news
|
fantastic_news
|
SQL injection vulnerability in news.php in Fantastic News 2.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2006-6542
|
2017-10-19 10:29 |
2006-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|