|
280211
|
- |
|
the_cacti_group
|
cacti
|
SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) third arguments to cmd…
|
NVD-CWE-Other
|
CVE-2006-6799
|
2018-10-18 06:49 |
2006-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280212
|
- |
|
limbo_cms
|
event_module
|
PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to execute arbitrary PHP code via a URL in the lm_absolute_path parameter.
|
NVD-CWE-Other
|
CVE-2006-6800
|
2018-10-18 06:49 |
2006-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280213
|
- |
|
limbo_cms
|
event_module
|
Successful exploitation requires that "register_globals" is enabled.
|
NVD-CWE-Other
|
CVE-2006-6800
|
2018-10-18 06:49 |
2006-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280214
|
- |
|
dmxready
|
dmxready_secure_login_manager
|
Multiple cross-site scripting (XSS) vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified parameters to…
|
NVD-CWE-Other
|
CVE-2006-6815
|
2018-10-18 06:49 |
2006-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280215
|
- |
|
dmxready
|
dmxready_secure_login_manager
|
Multiple SQL injection vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) set_preferences.asp, (2) send_pa…
|
NVD-CWE-Other
|
CVE-2006-6816
|
2018-10-18 06:49 |
2006-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280216
|
- |
|
alstrasoft
|
webhost_directory
|
AlstraSoft Web Host Directory allows remote attackers to obtain sensitive information by requesting any invalid URI, which reveals the path in an error message, a different vulnerability than CVE-200…
|
NVD-CWE-Other
|
CVE-2006-6817
|
2018-10-18 06:49 |
2006-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280217
|
- |
|
alstrasoft
|
webhost_directory
|
AlstraSoft Web Host Directory allows remote attackers to bypass authentication and change the admin password via a direct request to admin/config.
|
NVD-CWE-Other
|
CVE-2006-6818
|
2018-10-18 06:49 |
2006-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280218
|
- |
|
alstrasoft
|
webhost_directory
|
AlstraSoft Web Host Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup database via a direct request for ad…
|
NVD-CWE-Other
|
CVE-2006-6819
|
2018-10-18 06:49 |
2006-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280219
|
- |
|
php_icalendar
|
php_icalendar
|
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) getdate para…
|
CWE-79
Cross-site Scripting
|
CVE-2006-6824
|
2018-10-18 06:49 |
2006-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280220
|
- |
|
neocrome
|
land_down_under
|
SQL injection vulnerability in Journal.inc.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the w parameter to journal.php.
|
NVD-CWE-Other
|
CVE-2006-6835
|
2018-10-18 06:49 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|