|
279571
|
- |
|
modxcms
|
modxcms
|
Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the id parameter.
|
NVD-CWE-Other
|
CVE-2006-1821
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279572
|
- |
|
modxcms
|
modxcms
|
To address this issue, the vendor has released a patch available at the following location:
http://modxcms.com/forums/index.php/topic,3982.0.html
|
NVD-CWE-Other
|
CVE-2006-1821
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279573
|
- |
|
farsinews
|
farsinews
|
Cross-site scripting (XSS) vulnerability in search.php in FarsiNews 2.5.3 Pro and earlier allows remote attackers to inject arbitrary web script or HTML via the selected_search_arch parameter.
|
NVD-CWE-Other
|
CVE-2006-1822
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279574
|
- |
|
farsinews
|
farsinews
|
Directory traversal vulnerability in FarsiNews 2.5.3 Pro and earlier allows remote attackers to obtain the installation path via ".." sequences in the archive parameter to index.php, which leaks the …
|
NVD-CWE-Other
|
CVE-2006-1823
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279575
|
- |
|
phpguestbook
|
phpguestbook
|
Multiple cross-site scripting (XSS) vulnerabilities in PhpGuestbook.php in PhpGuestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Website, and (3) Commen…
|
NVD-CWE-Other
|
CVE-2006-1824
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279576
|
- |
|
snipegallery
|
snipe_gallery
|
Multiple cross-site scripting (XSS) vulnerabilities in Snipe Gallery 3.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in view.php, (2) …
|
CWE-79
Cross-site Scripting
|
CVE-2006-1826
|
2018-10-19 01:36 |
2006-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279577
|
- |
|
opera
|
opera_browser
|
Integer signedness error in Opera before 8.54 allows remote attackers to execute arbitrary code via long values in a stylesheet attribute, which pass a length check. NOTE: a sign extension problem m…
|
CWE-189
Numeric Errors
|
CVE-2006-1834
|
2018-10-19 01:36 |
2006-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279578
|
- |
|
vincent_hor
|
calendarix calendarix_advanced
|
Cross-site scripting (XSS) vulnerability in yearcal.php in Calendarix allows remote attackers to inject arbitrary web script or HTML via the ycyear parameter.
|
NVD-CWE-Other
|
CVE-2006-1835
|
2018-10-19 01:36 |
2006-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279579
|
- |
|
symantec
|
liveupdate norton_antivirus norton_internet_security norton_personal_firewall norton_system_works norton_utilities
|
Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a…
|
NVD-CWE-Other
|
CVE-2006-1836
|
2018-10-19 01:36 |
2006-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279580
|
- |
|
php_album
|
php_album
|
PHP remote file inclusion vulnerability in language.php in PHP Album 0.3.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary code via an FTP URL in the data_dir parame…
|
NVD-CWE-Other
|
CVE-2006-1839
|
2018-10-19 01:36 |
2006-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|