|
289421
|
- |
|
phpnews
|
phpnews
|
Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code via the Include parameter to (1) Include/lib.inc.php3 and (2) Include/variables.…
|
NVD-CWE-Other
|
CVE-2006-7081
|
2017-10-11 10:31 |
2007-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289422
|
- |
|
phpwind
|
phpwind
|
SQL injection vulnerability in admin.php in PHPWind 5.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the AdminUser cookie.
|
NVD-CWE-Other
|
CVE-2006-7101
|
2017-10-11 10:31 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289423
|
- |
|
matthias_dietrich
|
phpburningportal_quiz-modul
|
Multiple PHP remote file inclusion vulnerabilities in phpBurningPortal quiz-modul 1.0.1, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the lang_path paramete…
|
CWE-94
Code Injection
|
CVE-2006-7102
|
2017-10-11 10:31 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289424
|
- |
|
powerphlogger
|
powerphlogger
|
PHP remote file inclusion vulnerability in config.inc.php3 in Power Phlogger 2.0.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rel_path parameter.
|
CWE-94
Code Injection
|
CVE-2006-7106
|
2017-10-11 10:31 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289425
|
- |
|
coalescent_systems
|
freepbx
|
PHP remote file inclusion vulnerability in upgrade.php in Coalescent Systems freePBX 2.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the amp_conf[AMPWEBROOT] parameter.
|
NVD-CWE-Other
|
CVE-2006-7107
|
2017-10-11 10:31 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289426
|
- |
|
andries_brouwer
|
util-linux
|
login in util-linux-2.12a skips pam_acct_mgmt and chauth_tok when authentication is skipped, such as when a Kerberos krlogin session has been established, which might allow users to bypass intended a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-7108
|
2017-10-11 10:31 |
2007-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289427
|
- |
|
maxdev
|
mdpro
|
Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demonstrated by uploading…
|
CWE-22
Path Traversal
|
CVE-2006-7112
|
2017-10-11 10:31 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289428
|
- |
|
kubix
|
kubix
|
SQL injection vulnerability in includes/functions.php in Kubix 0.7 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via the member_id parameter ($id var…
|
CWE-89
SQL Injection
|
CVE-2006-7116
|
2017-10-11 10:31 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289429
|
- |
|
kubix
|
kubix
|
Multiple directory traversal vulnerabilities in Kubix 0.7 and earlier allow remote attackers to (1) include and execute arbitrary local files via ".." sequences in the theme cookie to index.php, whic…
|
CWE-22
Path Traversal
|
CVE-2006-7117
|
2017-10-11 10:31 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289430
|
- |
|
phpgiggle
|
phpgiggle
|
PHP remote file inclusion vulnerability in kernel/system/startup.php in J. He PHPGiggle 12.08 and earlier, as distributed on comscripts.com, allows remote attackers to execute arbitrary PHP code via …
|
NVD-CWE-Other
|
CVE-2006-7119
|
2017-10-11 10:31 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|