|
279861
|
- |
|
drupal
|
drupal
|
CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.
|
NVD-CWE-Other
|
CVE-2006-1225
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279862
|
- |
|
drupal
|
drupal
|
Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-1226
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279863
|
- |
|
drupal
|
drupal
|
Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8, when menu.module is used to create a menu item, does not implement access control for the page that is referenced, which might allow remote attackers…
|
NVD-CWE-Other
|
CVE-2006-1227
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279864
|
- |
|
drupal
|
drupal
|
Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.
|
CWE-287
Improper Authentication
|
CVE-2006-1228
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279865
|
- |
|
drupal
|
drupal
|
This vulnerability affects Drupal versions 4.6.x before 4.6.6, as well as versions 4.5.x before 4.5.8
|
CWE-287
Improper Authentication
|
CVE-2006-1228
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279866
|
- |
|
belchior_foundry
|
vcard
|
Multiple cross-site scripting (XSS) vulnerabilities in create.php in vCard 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) card_id, (2) uploaded, (3) card_fontsize, or (…
|
CWE-79
Cross-site Scripting
|
CVE-2006-1230
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279867
|
- |
|
julian_pawlowski
|
capi4hylafax
|
CAPI4HylaFAX 1.3, when compiled with GENERATE_DEBUGSFFDATAFILE set, allows local users to modify arbitrary files via a symlink attack on the c2faxrecv_dbgdatafile.sff temporary file.
|
NVD-CWE-Other
|
CVE-2006-1231
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279868
|
- |
|
dsportal
|
dsdownload
|
Multiple SQL injection vulnerabilities in DSDownload 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) key and (2) category parameters to (a) s…
|
NVD-CWE-Other
|
CVE-2006-1232
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279869
|
- |
|
dsportal
|
dsdownload
|
"magic_quotes_gpc" parameter must be disabled in order for this vulnerability to be exploited. This vulnerability may affect DSPortal, DSDownload versions previous to 1.0 as well.
|
NVD-CWE-Other
|
CVE-2006-1232
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279870
|
- |
|
mikael_software
|
wmnews
|
Multiple cross-site scripting (XSS) vulnerabilities in WMNews allow remote attackers to inject arbitrary web script or HTML via the (1) ArtCat parameter to wmview.php, (2) ctrrowcol parameter to foot…
|
NVD-CWE-Other
|
CVE-2006-1233
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|