|
280371
|
- |
|
dmxready
|
dmxready_secure_login_manager
|
Multiple cross-site scripting (XSS) vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified parameters to…
|
NVD-CWE-Other
|
CVE-2006-6815
|
2018-10-18 06:49 |
2006-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280372
|
- |
|
dmxready
|
dmxready_secure_login_manager
|
Multiple SQL injection vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) set_preferences.asp, (2) send_pa…
|
NVD-CWE-Other
|
CVE-2006-6816
|
2018-10-18 06:49 |
2006-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280373
|
- |
|
alstrasoft
|
webhost_directory
|
AlstraSoft Web Host Directory allows remote attackers to obtain sensitive information by requesting any invalid URI, which reveals the path in an error message, a different vulnerability than CVE-200…
|
NVD-CWE-Other
|
CVE-2006-6817
|
2018-10-18 06:49 |
2006-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280374
|
- |
|
alstrasoft
|
webhost_directory
|
AlstraSoft Web Host Directory allows remote attackers to bypass authentication and change the admin password via a direct request to admin/config.
|
NVD-CWE-Other
|
CVE-2006-6818
|
2018-10-18 06:49 |
2006-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280375
|
- |
|
alstrasoft
|
webhost_directory
|
AlstraSoft Web Host Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup database via a direct request for ad…
|
NVD-CWE-Other
|
CVE-2006-6819
|
2018-10-18 06:49 |
2006-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280376
|
- |
|
php_icalendar
|
php_icalendar
|
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) getdate para…
|
CWE-79
Cross-site Scripting
|
CVE-2006-6824
|
2018-10-18 06:49 |
2006-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280377
|
- |
|
neocrome
|
land_down_under
|
SQL injection vulnerability in Journal.inc.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the w parameter to journal.php.
|
NVD-CWE-Other
|
CVE-2006-6835
|
2018-10-18 06:49 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280378
|
- |
|
sergey_oblomov
|
iso_wincmd
|
Multiple stack-based buffer overflows in the (1) LoadTree, (2) ReadHeader, and (3) LoadXBOXTree functions in the ISO (iso_wincmd) plugin 1.7.3.3 and earlier for Total Commander allow user-assisted re…
|
NVD-CWE-Other
|
CVE-2006-6837
|
2018-10-18 06:49 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280379
|
- |
|
cmsmadesimple
|
cms_made_simple
|
Cross-site scripting (XSS) vulnerability in the optional user comment module in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the user comment form.
|
NVD-CWE-Other
|
CVE-2006-6844
|
2018-10-18 06:49 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280380
|
- |
|
cmsmadesimple
|
cms_made_simple
|
Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the cntnt01searchinput parameter in a Search action.
|
NVD-CWE-Other
|
CVE-2006-6845
|
2018-10-18 06:49 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|