|
280841
|
- |
|
university_of_british_columbia
|
ipeer
|
PHP remote file inclusion vulnerability in University of British Columbia iPeer 2.0, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE…
|
NVD-CWE-Other
|
CVE-2006-5594
|
2018-10-18 06:43 |
2006-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280842
|
- |
|
oracle
|
apex
|
Cross-site scripting (XSS) vulnerability in Oracle Application Express (formerly HTML DB) before 2.2.1 allows remote attackers to inject arbitrary HTML or web script via the WWV_FLOW_ITEM_HELP packag…
|
NVD-CWE-Other
|
CVE-2006-5599
|
2018-10-18 06:43 |
2006-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280843
|
- |
|
axalto
|
protiva
|
Axalto Protiva 1.1, possibly only non-commercial versions, stores passwords in plaintext in files with insecure permissions, which allows local users to gain privileges by reading the passwords from …
|
NVD-CWE-Other
|
CVE-2006-5600
|
2018-10-18 06:43 |
2006-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280844
|
- |
|
bytesfall_explorer
|
bytesfall_explorer
|
Multiple SQL injection vulnerabilities in BytesFall Explorer (bfExplorer) 0.0.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the username ($User variable) to login/doLog…
|
CWE-89
SQL Injection
|
CVE-2006-5606
|
2018-10-18 06:43 |
2006-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280845
|
- |
|
inca
|
im-204_adsl_router
|
Directory traversal vulnerability in /cgi-bin/webcm in INCA IM-204 allows remote attackers to read arbitrary files via a "/./." (modified dot dot) sequences in the getpage parameter.
|
NVD-CWE-Other
|
CVE-2006-5607
|
2018-10-18 06:43 |
2006-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280846
|
- |
|
torrentflux
|
torrentflux
|
Directory traversal vulnerability in dir.php in TorrentFlux 2.1 allows remote attackers to list arbitrary directories via "\.\./" sequences in the dir parameter.
|
NVD-CWE-Other
|
CVE-2006-5609
|
2018-10-18 06:43 |
2006-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280847
|
- |
|
michel_pradel
|
gestart
|
PHP remote file inclusion vulnerability in aide.php3 (aka aide.php) in GestArt beta 1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the aide parameter.
|
CWE-94
Code Injection
|
CVE-2006-5612
|
2018-10-18 06:43 |
2006-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280848
|
- |
|
textpattern
|
textpattern
|
PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the txpcfg[txpath] par…
|
NVD-CWE-Other
|
CVE-2006-5615
|
2018-10-18 06:43 |
2006-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280849
|
- |
|
thepeak
|
thepeak_file_upload_manager
|
Directory traversal vulnerability in index.php in Thepeak File Upload Manager 1.3 allows remote attackers to read or download arbitrary files via a base64-encoded file path containing a .. (dot dot) …
|
NVD-CWE-Other
|
CVE-2006-5617
|
2018-10-18 06:43 |
2006-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280850
|
- |
|
sh-news
|
sh-news
|
Multiple PHP remote file inclusion vulnerabilities in SH-News 3.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the scriptpath parameter to (1) report.php, (2) archive…
|
NVD-CWE-Other
|
CVE-2006-5282
|
2018-10-18 06:42 |
2006-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|