|
279601
|
- |
|
mozilla
|
firefox
|
Firefox 1.5.0.1 allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window lo…
|
NVD-CWE-Other
|
CVE-2006-1650
|
2018-10-19 01:33 |
2006-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279602
|
- |
|
ultravnc
|
tabbed_viewer vnc_viewer
|
Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-assisted remote attackers to execute arbitrary code via a malicious server that se…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-1652
|
2018-10-19 01:33 |
2006-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279603
|
- |
|
ultravnc
|
tabbed_viewer vnc_viewer
|
There are two seperate vulnerabilities here; One allows escalated priveleges to authenticated users, the other allows remote unauthenticated users to cause a Denial of Service (DoS).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-1652
|
2018-10-19 01:33 |
2006-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279604
|
- |
|
angelinecms
|
angelinecms
|
PHP remote file inclusion vulnerability in loadkernel.php in AngelineCMS 0.8.1 allows remote attackers to execute arbitrary PHP code via a URL in the installPath parameter.
|
NVD-CWE-Other
|
CVE-2006-1653
|
2018-10-19 01:33 |
2006-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279605
|
- |
|
hp
|
color_laserjet_2500_toolbox color_laserjet_4600_toolbox color_laserjet color_laserjet_2500 color_laserjet_2500l color_laserjet_2500lse color_laserjet_2500n color_laserjet_2500tn<…
|
Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (…
|
NVD-CWE-Other
|
CVE-2006-1654
|
2018-10-19 01:33 |
2006-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279606
|
- |
|
chucky_a._ivey
|
n.t.
|
Cross-site scripting (XSS) vulnerability in index.php in Chucky A. Ivey N.T. 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter, which is not filtered whe…
|
NVD-CWE-Other
|
CVE-2006-1657
|
2018-10-19 01:33 |
2006-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279607
|
- |
|
chucky_a._ivey
|
n.t.
|
Direct static code injection vulnerability in ticker.db.php in Chucky A. Ivey N.T. 1.1.0 allows remote administrators to insert arbitrary PHP code into the config file, which is included other N.T. …
|
NVD-CWE-Other
|
CVE-2006-1658
|
2018-10-19 01:33 |
2006-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279608
|
- |
|
softbiz
|
image_gallery
|
Multiple SQL injection vulnerabilities in Softbiz Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in image_desc.php, (2) provided parameter in template…
|
NVD-CWE-Other
|
CVE-2006-1659
|
2018-10-19 01:33 |
2006-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279609
|
- |
|
softbiz
|
image_gallery
|
This vulnerability most likely affects all versions of Softbiz, Image Gallery.
|
NVD-CWE-Other
|
CVE-2006-1659
|
2018-10-19 01:33 |
2006-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279610
|
- |
|
limbo_cms
|
limbo_cms
|
The frontpage option in Limbo CMS 1.0.4.2 and 1.0.4.1 allows remote attackers to execute arbitrary PHP commands via the Itemid parameter in index.php.
|
NVD-CWE-Other
|
CVE-2006-1662
|
2018-10-19 01:33 |
2006-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|