|
279321
|
- |
|
sphider
|
sphider
|
Multiple cross-site scripting (XSS) vulnerabilities in search.php in Sphider allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO and (2) the category parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2006-2506
|
2018-10-19 01:40 |
2006-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279322
|
- |
|
teake_nutma
|
foing
|
Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing 0.2.0 through 0.7.0, as used with phpBB, allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path …
|
NVD-CWE-Other
|
CVE-2006-2507
|
2018-10-19 01:40 |
2006-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279323
|
- |
|
yourfreeworld
|
stylish_text_ads_script
|
SQL injection vulnerability in tr1.php in YourFreeWorld.com Stylish Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly involving an attack vector…
|
NVD-CWE-Other
|
CVE-2006-2508
|
2018-10-19 01:40 |
2006-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279324
|
- |
|
yourfreeworld
|
short_url_and_url_tracker_script
|
SQL injection vulnerability in login.php in YourFreeWorld.com Short Url & Url Tracker Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2006-2509
|
2018-10-19 01:40 |
2006-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279325
|
- |
|
yourfreeworld
|
short_url_and_url_tracker_script
|
Cross-site scripting (XSS) vulnerability in the URL submission form in YourFreeWorld.com Short Url & Url Tracker Script allows remote attackers to inject arbitrary web script or HTML via an unspecifi…
|
NVD-CWE-Other
|
CVE-2006-2510
|
2018-10-19 01:40 |
2006-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279326
|
- |
|
frontrange
|
iheat
|
The ActiveX version of FrontRange iHEAT allows remote authenticated users to run arbitrary programs or access arbitrary files on the host machine by uploading a file with an extension that is not ass…
|
NVD-CWE-Other
|
CVE-2006-2511
|
2018-10-19 01:40 |
2006-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279327
|
- |
|
hiox_india
|
guest_book
|
Cross-site scripting (XSS) vulnerability in index.php in Hiox Guestbook 3.1 allows remote attackers to inject arbitrary web script or HTML via the input forms for signing the guestbook.
|
NVD-CWE-Other
|
CVE-2006-2515
|
2018-10-19 01:40 |
2006-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279328
|
- |
|
xoops
|
xoops
|
mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite variables such as $xoopsOption['nocommon'] and conduct directory traversal attacks o…
|
CWE-22
Path Traversal
|
CVE-2006-2516
|
2018-10-19 01:40 |
2006-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279329
|
- |
|
xoops
|
xoops
|
Successful exploitation requires that "register_globals" is enabled, and that "magic_quotes_gpc" is disabled.
|
CWE-22
Path Traversal
|
CVE-2006-2516
|
2018-10-19 01:40 |
2006-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279330
|
- |
|
phpwcms
|
phpwcms
|
Cross-site scripting (XSS) vulnerability in phpwcms 1.2.5-DEV allows remote attackers to inject arbitrary web script or HTML via the BL[be_cnt_plainhtml] parameter to include/inc_tmpl/content/cnt6.in…
|
NVD-CWE-Other
|
CVE-2006-2518
|
2018-10-19 01:40 |
2006-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|