|
280341
|
- |
|
dreaxteam
|
xt-news
|
Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script or HTML via the id_news parameter to (1) add_comment.php or (2) show_news.php.
|
CWE-79
Cross-site Scripting
|
CVE-2006-6746
|
2018-10-18 06:49 |
2006-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280342
|
- |
|
dreaxteam
|
xt-news
|
SQL injection vulnerability in show_news.php in Xt-News 0.1 allows remote attackers to execute arbitrary SQL commands via the id_news parameter.
|
CWE-89
SQL Injection
|
CVE-2006-6747
|
2018-10-18 06:49 |
2006-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280343
|
- |
|
openser
|
openser
|
Buffer overflow in the parse_expression function in parse_config in OpenSER 1.1.0 allows attackers to have an unknown impact via a long str parameter.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-6749
|
2018-10-18 06:49 |
2006-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280344
|
- |
|
microsoft
|
windows_event_viewer
|
Event Viewer (eventvwr.exe) in Microsoft Windows does not properly display log data that contains '%' (percent) characters, which might make it impossible to use Event Viewer to determine the actual …
|
NVD-CWE-Other
|
CVE-2006-6753
|
2018-10-18 06:49 |
2006-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280345
|
- |
|
ixprim
|
ixprim_cms
|
Multiple SQL injection vulnerabilities in Ixprim 1.2 allow remote attackers to execute arbitrary SQL commands via the story_id parameter to ixm_ixpnews.php, and unspecified other vectors.
|
NVD-CWE-Other
|
CVE-2006-6754
|
2018-10-18 06:49 |
2006-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280346
|
- |
|
ixprim
|
ixprim_cms
|
Successful exploitation reportedly requires load_file privileges.
|
NVD-CWE-Other
|
CVE-2006-6754
|
2018-10-18 06:49 |
2006-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280347
|
- |
|
ixprim
|
ixprim_cms
|
Ixprim 1.2 allows remote attackers to obtain sensitive information via a direct request for kernel/plugins/fckeditor2/ixprim_api.php, which reveals the path in an error message.
|
NVD-CWE-Other
|
CVE-2006-6755
|
2018-10-18 06:49 |
2006-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280348
|
- |
|
ixprim
|
ixprim_cms
|
The code function in install.fct.php in Ixprim 1.2 produces a guessable value of the confidential IXP_CODE in mainfile.php, which might allow remote attackers to gain access to the administration pan…
|
NVD-CWE-Other
|
CVE-2006-6756
|
2018-10-18 06:49 |
2006-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280349
|
- |
|
keep_it_simple_guest_book
|
keep_it_simple_guest_book
|
Multiple PHP remote file inclusion vulnerabilities in the Keep It Simple Guest Book (KISGB) allow remote attackers to execute arbitrary PHP code via a URL in the (1) path_to_themes parameter in (a) a…
|
NVD-CWE-Other
|
CVE-2006-6763
|
2018-10-18 06:49 |
2006-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280350
|
- |
|
pwp_technologies
|
the_classified_ad_system
|
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in PWP Technologies The Classified Ad System allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) ma…
|
NVD-CWE-Other
|
CVE-2006-6768
|
2018-10-18 06:49 |
2006-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|