|
279891
|
- |
|
dreamcost
|
hostadmin
|
PHP remote file inclusion vulnerability in index.php in DreamCost HostAdmin allows remote attackers to include arbitrary files via the $path variable, which is not initialized before use.
|
NVD-CWE-Other
|
CVE-2006-0791
|
2018-10-19 01:29 |
2006-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279892
|
- |
|
thomastsoi
|
quirex
|
Absolute path traversal vulnerability in convert.cgi in Quirex 2.0.2 and earlier allows remote attackers to read arbitrary files, and possibly execute arbitrary code, via the (1) quiz_head, (2) quiz_…
|
CWE-22
Path Traversal
|
CVE-2006-0795
|
2018-10-19 01:29 |
2006-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279893
|
- |
|
francisco_burzi
|
php-nuke
|
The CAPTCHA functionality in php-Nuke 6.0 through 7.9 uses fixed challenge/response pairs that only vary once per day based on the User Agent (HTTP_USER_AGENT), which allows remote attackers to bypas…
|
NVD-CWE-Other
|
CVE-2006-0805
|
2018-10-19 01:29 |
2006-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279894
|
- |
|
john_lim
|
adodb
|
Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page par…
|
CWE-79
Cross-site Scripting
|
CVE-2006-0806
|
2018-10-19 01:29 |
2006-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279895
|
- |
|
njstar
|
chinese_word_processor japanese_word_processor
|
Stack-based buffer overflow in NJStar Chinese and Japanese Word Processor 4.x and 5.x before 5.10 allows user-assisted attackers to execute arbitrary code via font names in NJStar (.njx) documents.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-0807
|
2018-10-19 01:29 |
2006-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279896
|
- |
|
visnetic
|
visnetic_antivirus_plug-in_for_mail_server
|
The VisNetic AntiVirus Plug-in (DKAVUpSch.exe) for Mail Server 4.6.0.4, 4.6.1.1, and possibly other versions before 4.6.1.2, does not drop privileges before executing other programs, which allows loc…
|
NVD-CWE-Other
|
CVE-2006-0812
|
2018-10-19 01:29 |
2006-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279897
|
- |
|
winace
|
winace
|
Heap-based buffer overflow in WinACE 2.60 allows user-assisted attackers to execute arbitrary code via a large header block in an ARJ archive.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-0813
|
2018-10-19 01:29 |
2006-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279898
|
- |
|
lighttpd
|
lighttpd
|
response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via requests that contain trailing (1) "." (dot) and (2) space…
|
NVD-CWE-Other
|
CVE-2006-0814
|
2018-10-19 01:29 |
2006-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279899
|
- |
|
networkactiv
|
networkactiv_web_server
|
NetworkActiv Web Server 3.5.15 allows remote attackers to read script source code via a crafted URL with a "/" (forward slash) after the file extension.
|
NVD-CWE-Other
|
CVE-2006-0815
|
2018-10-19 01:29 |
2006-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279900
|
- |
|
orionserver
|
orion_application_server
|
Orion Application Server before 2.0.7, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the extension of a URL.
|
NVD-CWE-Other
|
CVE-2006-0816
|
2018-10-19 01:29 |
2006-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|