|
279631
|
- |
|
webtoolmaster_software
|
winhki
|
Directory traversal vulnerability in WinHKI 1.6 and earlier allows user-assisted attackers to overwrite arbitrary files via a (1) RAR, (2) TAR, (3) ZIP, or (4) TAR.GZ archive with a file whose file n…
|
NVD-CWE-Other
|
CVE-2006-1323
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279632
|
- |
|
invision_power_services
|
invision_power_board
|
Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board 2.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) result_type, (2) search_in, (3) nav, (4) fo…
|
NVD-CWE-Other
|
CVE-2006-1326
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279633
|
- |
|
skull-splitter
|
download_counter_wallpaper
|
SQL injection vulnerability in count.php in Skull-Splitter PHP Downloadcounter for Wallpapers 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) count_fieldname, (2) url_fieldn…
|
NVD-CWE-Other
|
CVE-2006-1328
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279634
|
- |
|
phpwebsite
|
phpwebsite
|
Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid parameter to (1) friend.php or (2) article.php.
|
CWE-89
SQL Injection
|
CVE-2006-1330
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279635
|
- |
|
maian_script_world
|
maian_weblog
|
Multiple SQL injection vulnerabilities in Maian Weblog 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) entry and (2) email parameters to (a) print.php and (b) mail.php.
|
NVD-CWE-Other
|
CVE-2006-1334
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279636
|
- |
|
extcalendar
|
extcalendar
|
Cross-site scripting vulnerability in calendar.php in ExtCalendar 1.0 and possibly other versions before 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) year, (2) month…
|
NVD-CWE-Other
|
CVE-2006-1336
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279637
|
- |
|
extcalendar
|
extcalendar
|
This issue is reportedly addressed in ExtCalendar 2.0. Symantec has not confirmed this fix. Affected users are advised to contact the vendor for further information.
|
NVD-CWE-Other
|
CVE-2006-1336
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279638
|
- |
|
cutephp
|
cutenews
|
Directory traversal vulnerability in inc/functions.inc.php in CuteNews 1.4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to include arbitrary files via a ..…
|
NVD-CWE-Other
|
CVE-2006-1339
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279639
|
- |
|
cutephp
|
cutenews
|
CuteNews 1.4.1 and possibly other versions allows remote attackers to obtain the installation path via unspecified vectors involving an invalid file path.
|
NVD-CWE-Other
|
CVE-2006-1340
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279640
|
- |
|
cutephp
|
cutenews
|
Successful exploitation requires that the "register_globals" parameter is enabled.
|
NVD-CWE-Other
|
CVE-2006-1340
|
2018-10-19 01:32 |
2006-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|