|
279761
|
- |
|
mybulletinboard
|
mybulletinboard
|
Multiple cross-site scripting (XSS) vulnerabilities in member.php in MyBulletin Board (MyBB) 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) aim, (2) yahoo, (3) msn, o…
|
NVD-CWE-Other
|
CVE-2006-1272
|
2018-10-19 01:31 |
2006-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279762
|
- |
|
avira
|
antivir_personal
|
Classic Planer in AntiVir PersonalEdition Classic 7 does not drop privileges before executing external programs, which allows local users to gain privileges via notepad.exe, which is used to display …
|
NVD-CWE-Other
|
CVE-2006-1274
|
2018-10-19 01:31 |
2006-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279763
|
- |
|
upoint
|
at1_file_store
|
Cross-site scripting (XSS) vulnerability in signup.php in @1 File Store 2006.03.07 allows remote attackers to inject arbitrary web script or HTML via the (1) real_name, (2) email, and (3) login param…
|
NVD-CWE-Other
|
CVE-2006-1277
|
2018-10-19 01:31 |
2006-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279764
|
- |
|
upoint
|
\@1_file_store
|
SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3)…
|
CWE-89
SQL Injection
|
CVE-2006-1278
|
2018-10-19 01:31 |
2006-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279765
|
- |
|
upoint
|
\@1_file_store
|
Successful exploitation requires that the "magic_quotes_gpc" parameter is disabled.
|
CWE-89
SQL Injection
|
CVE-2006-1278
|
2018-10-19 01:31 |
2006-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279766
|
- |
|
mybulletinboard
|
mybulletinboard
|
Cross-site scripting (XSS) vulnerability in member.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vulnerability t…
|
NVD-CWE-Other
|
CVE-2006-1281
|
2018-10-19 01:31 |
2006-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279767
|
- |
|
mybulletinboard
|
mybulletinboard
|
CRLF injection vulnerability in inc/function.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to conduct cross-site scripting (XSS), poison caches, or hijack pages via CRLF (%0A%0D) sequenc…
|
NVD-CWE-Other
|
CVE-2006-1282
|
2018-10-19 01:31 |
2006-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279768
|
- |
|
milkeyway
|
milkeyway_captive_portal
|
Multiple SQL injection vulnerabilities in Milkeyway Captive Portal 0.1 and 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username, (2) password, (3) team, (4) level, (5) …
|
NVD-CWE-Other
|
CVE-2006-1289
|
2018-10-19 01:31 |
2006-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279769
|
- |
|
milkeyway
|
milkeyway_captive_portal
|
Multiple cross-site scripting (XSS) vulnerabilities in Milkeyway Captive Portal 0.1 and 0.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) ipAddress, (2) act, (3) usernam…
|
NVD-CWE-Other
|
CVE-2006-1290
|
2018-10-19 01:31 |
2006-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279770
|
- |
|
astalavista_it_engineering
|
contrexx
|
Cross-site scripting (XSS) vulnerability in index.php in Contrexx CMS 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF).
|
NVD-CWE-Other
|
CVE-2006-1293
|
2018-10-19 01:31 |
2006-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|