|
279871
|
- |
|
website_designs_for_less
|
inventory_manager
|
Cross-site scripting (XSS) vulnerability in inventory/display/display_results.asp in Website Designs For Less Inventory Manager allows remote attackers to inject arbitrary web script or HTML via the …
|
NVD-CWE-Other
|
CVE-2006-5942
|
2018-10-18 06:46 |
2006-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279872
|
- |
|
website_designs_for_less
|
inventory_manager
|
Multiple SQL injection vulnerabilities in inventory/display/imager.asp in Website Designs for Less Inventory Manager allow remote attackers to execute arbitrary SQL commands via the (1) pictable, (2)…
|
NVD-CWE-Other
|
CVE-2006-5943
|
2018-10-18 06:46 |
2006-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279873
|
- |
|
exophpdesk
|
exophpdesk
|
PHP remote file inclusion vulnerability in pipe.php in Exophpdesk 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file parameter.
|
NVD-CWE-Other
|
CVE-2006-5951
|
2018-10-18 06:46 |
2006-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279874
|
- |
|
20_20_applications
|
20_20_datashed
|
SQL injection vulnerability in listings.asp in 20/20 DataShed (aka Real Estate Listing System) allows remote attackers to execute arbitrary SQL commands via the itemID parameter. NOTE: some of these…
|
NVD-CWE-Other
|
CVE-2006-5955
|
2018-10-18 06:46 |
2006-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279875
|
- |
|
infinicart
|
infinicart
|
Multiple cross-site scripting (XSS) vulnerabilities in INFINICART allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password fields in (a) login.asp, (3) sear…
|
NVD-CWE-Other
|
CVE-2006-5958
|
2018-10-18 06:46 |
2006-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279876
|
- |
|
hpecs_shopping_cart
|
hpecs_shopping_cart
|
Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) se…
|
NVD-CWE-Other
|
CVE-2006-5962
|
2018-10-18 06:46 |
2006-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279877
|
- |
|
passgo
|
sso_plus
|
PassGo SSO Plus 2.1.0.32, and probably earlier versions, uses insecure permissions (Everyone/Full Control) for the PassGo Technologies directory, which allows local users to gain privileges by modify…
|
NVD-CWE-Other
|
CVE-2006-5965
|
2018-10-18 06:46 |
2006-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279878
|
- |
|
panda
|
activescan
|
Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to (1) reboot the system using the Reinicializar method in the ActiveScan.1 ActiveX control, or (2) determine arbi…
|
CWE-399
Resource Management Errors
|
CVE-2006-5966
|
2018-10-18 06:46 |
2006-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279879
|
- |
|
panda
|
activescan
|
This vulnerability is addressed in the following product release:
Panda, ActiveScan, 5.54.01
|
CWE-399
Resource Management Errors
|
CVE-2006-5966
|
2018-10-18 06:46 |
2006-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279880
|
- |
|
panda
|
activescan
|
Race condition in Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to cause memory corruption and execute arbitrary code via unknown vectors related to multiple in…
|
NVD-CWE-Other
|
CVE-2006-5967
|
2018-10-18 06:46 |
2006-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|