|
279731
|
- |
|
drupal
|
drupal
|
This vulnerability affects Drupal versions 4.6.x before 4.6.6, as well as versions 4.5.x before 4.5.8
|
CWE-287
Improper Authentication
|
CVE-2006-1228
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279732
|
- |
|
belchior_foundry
|
vcard
|
Multiple cross-site scripting (XSS) vulnerabilities in create.php in vCard 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) card_id, (2) uploaded, (3) card_fontsize, or (…
|
CWE-79
Cross-site Scripting
|
CVE-2006-1230
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279733
|
- |
|
julian_pawlowski
|
capi4hylafax
|
CAPI4HylaFAX 1.3, when compiled with GENERATE_DEBUGSFFDATAFILE set, allows local users to modify arbitrary files via a symlink attack on the c2faxrecv_dbgdatafile.sff temporary file.
|
NVD-CWE-Other
|
CVE-2006-1231
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279734
|
- |
|
dsportal
|
dsdownload
|
Multiple SQL injection vulnerabilities in DSDownload 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) key and (2) category parameters to (a) s…
|
NVD-CWE-Other
|
CVE-2006-1232
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279735
|
- |
|
dsportal
|
dsdownload
|
"magic_quotes_gpc" parameter must be disabled in order for this vulnerability to be exploited. This vulnerability may affect DSPortal, DSDownload versions previous to 1.0 as well.
|
NVD-CWE-Other
|
CVE-2006-1232
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279736
|
- |
|
mikael_software
|
wmnews
|
Multiple cross-site scripting (XSS) vulnerabilities in WMNews allow remote attackers to inject arbitrary web script or HTML via the (1) ArtCat parameter to wmview.php, (2) ctrrowcol parameter to foot…
|
NVD-CWE-Other
|
CVE-2006-1233
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279737
|
- |
|
dsportal
|
dscounter
|
SQL injection vulnerability in index.php in DSCounter 1.2, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FO…
|
NVD-CWE-Other
|
CVE-2006-1234
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279738
|
- |
|
dsportal
|
dscounter
|
Successful exploitation requires that the "magic_quotes_gpc" parameter is disabled.
|
NVD-CWE-Other
|
CVE-2006-1234
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279739
|
- |
|
david_ravenscroft
|
hithost
|
Directory traversal vulnerability in admin/deleteuser.php in HitHost 1.0.0 might allow remote attackers to delete directories (possibly only empty directories) via the $deleteuser variable. NOTE: th…
|
NVD-CWE-Other
|
CVE-2006-1235
|
2018-10-19 01:31 |
2006-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279740
|
- |
|
dsportal
|
dsnewsletter
|
Multiple SQL injection vulnerabilities in DSNewsletter 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the email parameter to (1) include/sub.php, (2…
|
NVD-CWE-Other
|
CVE-2006-1237
|
2018-10-19 01:31 |
2006-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|