|
280421
|
- |
|
mandiant
|
first_response
|
FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode with SSL enabled, allows remote attackers to cause a denial of service (refused connections) via malformed requests,…
|
NVD-CWE-Other
|
CVE-2006-6475
|
2018-10-18 06:48 |
2006-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280422
|
- |
|
mandiant
|
first_response
|
Successful exploitation requires that the affected products are run in daemon mode with SSL enabled.
This vulnerability is addressed in the following product release:
Mandiant, First Response, 1.1.1
|
NVD-CWE-Other
|
CVE-2006-6475
|
2018-10-18 06:48 |
2006-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280423
|
- |
|
mandiant
|
first_response
|
FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode and when the agent is bound to 0.0.0.0 (all interfaces), opens sockets in non-exclusive mode, which allows local use…
|
NVD-CWE-Other
|
CVE-2006-6476
|
2018-10-18 06:48 |
2006-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280424
|
- |
|
mandiant
|
first_response
|
Successful exploitation requires that the affected products are run in daemon mode and when the agent is bound to 0.0.0.0 (all interfaces).
This vulnerability is addressed in the following product r…
|
NVD-CWE-Other
|
CVE-2006-6476
|
2018-10-18 06:48 |
2006-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280425
|
- |
|
mandiant
|
first_response
|
FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode and configured to use only HTTP, allows local users to modify requests and responses between a client and an agent b…
|
NVD-CWE-Other
|
CVE-2006-6477
|
2018-10-18 06:48 |
2006-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280426
|
- |
|
mandiant
|
first_response
|
Sucessful exploitation requires that the affected products are run in daemon mode and configured to use only HTTP.
This vulnerability is addressed in the following product release:
Mandiant, First …
|
NVD-CWE-Other
|
CVE-2006-6477
|
2018-10-18 06:48 |
2006-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280427
|
- |
|
scriptphp
|
annoncescripthp
|
Multiple SQL injection vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) email.php, the (2) no parameter in (b) voirannon…
|
NVD-CWE-Other
|
CVE-2006-6478
|
2018-10-18 06:48 |
2006-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280428
|
- |
|
scriptphp
|
annoncescripthp
|
Multiple cross-site scripting (XSS) vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the email parameter in (1) erreurinscription.php, (2) Temp…
|
NVD-CWE-Other
|
CVE-2006-6479
|
2018-10-18 06:48 |
2006-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280429
|
- |
|
scriptphp
|
annoncescripthp
|
Successful exploitation requires that "register_globals" is enabled.
|
NVD-CWE-Other
|
CVE-2006-6479
|
2018-10-18 06:48 |
2006-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280430
|
- |
|
scriptphp
|
annoncescripthp
|
admin/admin_membre/fiche_membre.php in AnnonceScriptHP 2.0 allows remote attackers to obtain sensitive information via the idmembre parameter, which discloses the passwords for arbitrary users.
|
NVD-CWE-Other
|
CVE-2006-6480
|
2018-10-18 06:48 |
2006-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|