|
279821
|
- |
|
phpoutsourcing
|
noahs_classifieds
|
SQL injection vulnerability in the search tool in Noah's Classifieds 1.3 allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors.
|
NVD-CWE-Other
|
CVE-2006-0879
|
2018-10-19 01:29 |
2006-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279822
|
- |
|
phpoutsourcing
|
noahs_classifieds
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) inf parameter; or, when register_g…
|
NVD-CWE-Other
|
CVE-2006-0880
|
2018-10-19 01:29 |
2006-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279823
|
- |
|
phpoutsourcing
|
noahs_classifieds
|
Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) u…
|
NVD-CWE-Other
|
CVE-2006-0881
|
2018-10-19 01:29 |
2006-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279824
|
- |
|
phpoutsourcing
|
noahs_classifieds
|
Directory traversal vulnerability in include.php in Noah's Classifieds 1.3 allows remote attackers to include arbitrary local files via the otherTemplate parameter to index.php.
|
NVD-CWE-Other
|
CVE-2006-0882
|
2018-10-19 01:29 |
2006-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279825
|
- |
|
mozilla
|
thunderbird
|
The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or ca…
|
CWE-20
Improper Input Validation
|
CVE-2006-0884
|
2018-10-19 01:29 |
2006-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279826
|
- |
|
speedproject
|
speedcommander squeez zipstar
|
Directory traversal vulnerability in SpeedProject Squeez 5.1, as used in (1) ZipStar 5.1 and (2) SpeedCommander 11.01.4450, allows remote attackers to overwrite arbitrary files via unspecified manipu…
|
NVD-CWE-Other
|
CVE-2006-0890
|
2018-10-19 01:29 |
2006-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279827
|
- |
|
simple_machines
|
simple_machines_forum
|
Cross-site scripting (XSS) vulnerability in Sources/Register.php in Simple Machine Forum (SMF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For HTTP header…
|
CWE-79
Cross-site Scripting
|
CVE-2006-0896
|
2018-10-19 01:29 |
2006-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279828
|
- |
|
lincoln_d._stein
|
crypt_cbc
|
Crypt::CBC Perl module 2.16 and earlier, when running in RandomIV mode, uses an initialization vector (IV) of 8 bytes, which results in weaker encryption when used with a cipher that requires a large…
|
NVD-CWE-Other
|
CVE-2006-0898
|
2018-10-19 01:29 |
2006-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279829
|
- |
|
4images
|
image_gallery_management_system
|
Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot dot) sequences in the template parameter.
|
NVD-CWE-Other
|
CVE-2006-0899
|
2018-10-19 01:29 |
2006-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279830
|
- |
|
top_line
|
d3jeeb_pro
|
SQL injection vulnerability in D3Jeeb Pro 3 allows remote attackers to execute arbitrary SQL commands via the catid parameter in (1) fastlinks.php and (2) catogary.php.
|
NVD-CWE-Other
|
CVE-2006-0906
|
2018-10-19 01:29 |
2006-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|