|
280051
|
- |
|
tiki
|
tikiwiki_cms\/groupware
|
Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-ar…
|
CWE-200
Information Exposure
|
CVE-2006-5702
|
2018-10-18 06:44 |
2006-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280052
|
- |
|
tiki
|
tikiwiki_cms\/groupware
|
Cross-site scripting (XSS) vulnerability in tiki-featured_link.php in Tikiwiki 1.9.5 allows remote attackers to inject arbitrary web script or HTML via a url parameter that evades filtering, as demon…
|
CWE-79
Cross-site Scripting
|
CVE-2006-5703
|
2018-10-18 06:44 |
2006-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280053
|
- |
|
phpeasydata_pro
|
phpeasydata_pro
|
SQL injection vulnerability in index.php in PHPEasyData Pro 1.4.1 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
|
NVD-CWE-Other
|
CVE-2006-5707
|
2018-10-18 06:44 |
2006-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280054
|
- |
|
eci_telecom
|
b-focus_wireless_802.11bg_adsl2\+_router
|
ECI Telecom B-FOCuS Wireless 802.11b/g ADSL2+ Router allows remote attackers to read arbitrary files via a certain HTTP request, as demonstrated by a request for a router configuration file, related …
|
NVD-CWE-Other
|
CVE-2006-5711
|
2018-10-18 06:44 |
2006-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280055
|
- |
|
freenews
|
freenews
|
Directory traversal vulnerability in aff_news.php in FreeNews 2.1 allows remote attackers to include local files via a .. (dot dot) sequence in the chemin parameter, when the aff_news parameter is no…
|
NVD-CWE-Other
|
CVE-2006-5716
|
2018-10-18 06:44 |
2006-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280056
|
- |
|
zend
|
zend_google_data_client_library_preview
|
Multiple cross-site scripting (XSS) vulnerabilities in Zend Google Data Client Library (ZendGData) Preview 0.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified paramete…
|
NVD-CWE-Other
|
CVE-2006-5717
|
2018-10-18 06:44 |
2006-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280057
|
- |
|
phpmyadmin
|
phpmyadmin
|
Cross-site scripting (XSS) vulnerability in error.php in phpMyAdmin 2.6.4 through 2.9.0.2 allows remote attackers to inject arbitrary web script or HTML via UTF-7 or US-ASCII encoded characters, whic…
|
NVD-CWE-Other
|
CVE-2006-5718
|
2018-10-18 06:44 |
2006-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280058
|
- |
|
bytesfall_explorer
|
bytesfall_explorer
|
SQL injection vulnerability in libs/sessions.lib.php in BytesFall Explorer (bfExplorer) 0.0.6 allows remote attackers to execute arbitrary SQL commands via unspecified parameters, a different issue t…
|
NVD-CWE-Other
|
CVE-2006-5719
|
2018-10-18 06:44 |
2006-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280059
|
- |
|
francisco_burzi
|
php-nuke
|
SQL injection vulnerability in modules/journal/search.php in the Journal module in Francisco Burzi PHP-Nuke 7.9 and earlier allows remote attackers to execute arbitrary SQL commands via the forwhat p…
|
NVD-CWE-Other
|
CVE-2006-5720
|
2018-10-18 06:44 |
2006-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280060
|
- |
|
agnitum
|
outpost_firewall
|
The \Device\SandBox driver in Outpost Firewall PRO 4.0 (964.582.059) allows local users to cause a denial of service (system crash) via an invalid argument to the DeviceIoControl function that trigge…
|
NVD-CWE-Other
|
CVE-2006-5721
|
2018-10-18 06:44 |
2006-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|