|
299661
|
- |
|
stefan_frech
|
online-bookmarks
|
SQL injection vulnerability in the login function in auth.inc in Stefan Frech online-bookmarks 0.6.12 allows remote attackers to execute arbitrary SQL commands via the (1) username and possibly the (…
|
NVD-CWE-Other
|
CVE-2006-6358
|
2017-07-29 10:29 |
2006-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299662
|
- |
|
stefan_frech
|
online-bookmarks
|
Cross-site scripting (XSS) vulnerability in Stefan Frech online-bookmarks 0.6.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2006-6359
|
2017-07-29 10:29 |
2006-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299663
|
- |
|
bitflux
|
upload_progress_meter
|
Heap-based buffer overflow in the uploadprogress_php_rfc1867_file function in uploadprogress.c in Bitflux Upload Progress Meter before 8276 allows remote attackers to cause a denial of service (crash…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-6361
|
2017-07-29 10:29 |
2006-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299664
|
- |
|
cerberus
|
helpdesk
|
Cross-site scripting (XSS) vulnerability in includes/elements/spellcheck/spellwin.php in Cerberus Helpdesk 0.97.3, 2.0 through 2.7, 3.2.1, and 3.3 allows remote attackers to inject arbitrary web scri…
|
NVD-CWE-Other
|
CVE-2006-6366
|
2017-07-29 10:29 |
2006-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299665
|
- |
|
duware
|
dudownload dunews dupaypal
|
Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) iFile or (2) action parameter…
|
CWE-89
SQL Injection
|
CVE-2006-6367
|
2017-07-29 10:29 |
2006-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299666
|
- |
|
james_barnsley
|
jab_guest_book
|
Multiple cross-site scripting (XSS) vulnerabilities in pbguestbook.php in JAB Guest Book 20061205 allow remote attackers to inject arbitrary web script or HTML via the (1) topic or (2) message parame…
|
NVD-CWE-Other
|
CVE-2006-6372
|
2017-07-29 10:29 |
2006-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299667
|
- |
|
positive_software
|
h-sphere
|
The control panel for Positive Software H-Sphere before 2.5.0 RC3 creates log files in a user's directory with insecure permissions, which allows local users to append log data to arbitrary files via…
|
NVD-CWE-Other
|
CVE-2006-6382
|
2017-07-29 10:29 |
2006-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299668
|
- |
|
drupal
|
cvs_management_and_tracker
|
Cross-site scripting (XSS) vulnerability in the CVS management/tracker 4.7.x-1.0, 4.7.x-2.0, and 4.7.0 (before the 20060807 contribution release system) for Drupal allows remote attackers to inject a…
|
NVD-CWE-Other
|
CVE-2006-6386
|
2017-07-29 10:29 |
2006-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299669
|
- |
|
link_content_management_server
|
link_content_management_server
|
Multiple SQL injection vulnerabilities in LINK Content Management Server (CMS) allow remote attackers to execute arbitrary SQL commands via the (1) IDMeniGlavni parameter to navigacija.php, and the (…
|
NVD-CWE-Other
|
CVE-2006-6387
|
2017-07-29 10:29 |
2006-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299670
|
- |
|
link
|
content_management_server
|
Cross-site scripting (XSS) vulnerability in naprednaPretraga.php in LINK Content Management Server (CMS) allows remote attackers to inject arbitrary web script or HTML via the txtPretraga parameter. …
|
NVD-CWE-Other
|
CVE-2006-6388
|
2017-07-29 10:29 |
2006-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|