|
280051
|
- |
|
typo3
|
typo3
|
his vulnerability is addressed in the following product release:
Typo3, Typo3, 4.0.4
|
NVD-CWE-Other
|
CVE-2006-6690
|
2018-10-18 06:49 |
2006-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280052
|
- |
|
oracle
|
application_server_portal
|
CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting…
|
NVD-CWE-Other
|
CVE-2006-6697
|
2018-10-18 06:49 |
2006-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280053
|
- |
|
oracle
|
application_server_portal
|
Multiple CRLF injection vulnerabilities in Oracle Portal 9.0.2 and possibly other versions allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF…
|
NVD-CWE-Other
|
CVE-2006-6699
|
2018-10-18 06:49 |
2006-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280054
|
- |
|
atmail
|
atmail_webmail
|
Cross-site request forgery (CSRF) vulnerability in util.pl in @Mail WebMail 4.51, and util.php in 5.x before 5.03, allows remote attackers to modify arbitrary settings and perform unauthorized action…
|
CWE-352
Origin Validation Error
|
CVE-2006-6701
|
2018-10-18 06:49 |
2006-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280055
|
- |
|
oracle
|
oracle10g oracle9i
|
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Portal 9i and 10g allow remote attackers to inject arbitrary JavaScript via the tc parameter in webapp/jsp/container_tabs.jsp, and other …
|
NVD-CWE-Other
|
CVE-2006-6703
|
2018-10-18 06:49 |
2006-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280056
|
- |
|
powerscripts
|
powerclan
|
PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the sett…
|
NVD-CWE-Other
|
CVE-2006-6715
|
2018-10-18 06:49 |
2006-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280057
|
- |
|
alliedtelesyn
|
at-9000_24_ethernetswitch
|
The Allied Telesis AT-9000/24 Ethernet switch accepts management packets from arbitrary VLANs, contrary to the documentation, which allows remote attackers to conduct attacks against the switch from …
|
NVD-CWE-Other
|
CVE-2006-6717
|
2018-10-18 06:49 |
2006-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280058
|
- |
|
alliedtelesyn
|
at-9000_24_ethernetswitch
|
The Allied Telesis AT-9000/24 Ethernet switch has a default password for its admin account, "manager," which allows remote attackers to perform unauthorized actions.
|
NVD-CWE-Other
|
CVE-2006-6718
|
2018-10-18 06:49 |
2006-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280059
|
- |
|
netbsd openbsd
|
netbsd openbsd
|
OpenBSD and NetBSD permit usermode code to kill the display server and write to the X.Org /dev/xf86 device, which allows local users with root privileges to reduce securelevel by replacing the System…
|
NVD-CWE-Other
|
CVE-2006-6730
|
2018-10-18 06:49 |
2006-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280060
|
- |
|
osticket
|
osticket_sts
|
Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web script or HTML via the e parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2006-6733
|
2018-10-18 06:49 |
2006-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|