|
279781
|
- |
|
tft_gallery
|
tft_gallery
|
TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin password file and obtain password hashes via a d…
|
NVD-CWE-Other
|
CVE-2006-1412
|
2018-10-19 01:32 |
2006-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279782
|
- |
|
nuked-klan
|
nuked-klan
|
SQL injection vulnerability in the Calendar module in nuked-klan 1.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter to index.php.
|
NVD-CWE-Other
|
CVE-2006-1419
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279783
|
- |
|
arabless
|
saphplesson
|
SQL injection vulnerability in print.php in SaphpLesson 2.0 allows remote attackers to execute arbitrary SQL commands via the lessid parameter.
|
NVD-CWE-Other
|
CVE-2006-1420
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279784
|
- |
|
arthur_konze_webdesign
|
akocomment
|
Multiple SQL injection vulnerabilities in akocomment.php in AkoComment 2.0 module for Mambo, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) acnam…
|
NVD-CWE-Other
|
CVE-2006-1421
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279785
|
- |
|
arthur_konze_webdesign
|
akocomment
|
In order to exploit this vulnerability, the 'magic_quotes_gpc' parameter must be disabled.
|
NVD-CWE-Other
|
CVE-2006-1421
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279786
|
- |
|
ubbcentral
|
ubb.threads
|
SQL injection vulnerability in showflat.php in UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2, and earlier, allows remote attackers to execute arbitrary SQL commands via the Number parameter.
|
CWE-89
SQL Injection
|
CVE-2006-1423
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279787
|
- |
|
phpmyfamily
|
phpmyfamily
|
Cross-site scripting (XSS) vulnerability in track.php in phpmyfamily 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.
|
NVD-CWE-Other
|
CVE-2006-1425
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279788
|
- |
|
pixel_motion
|
pixel_motion_blog
|
Multiple SQL injection vulnerabilities in Pixel Motion Blog allow remote attackers to execute arbitrary SQL commands via the (1) date parameter in index.php or bypass authentication via the (2) passw…
|
NVD-CWE-Other
|
CVE-2006-1426
|
2018-10-19 01:32 |
2006-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279789
|
- |
|
apple
|
quicktime
|
Stack-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickDraw PICT image format file containing malformed font information.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-1453
|
2018-10-19 01:32 |
2006-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279790
|
- |
|
apple
|
quicktime
|
Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickDraw PICT image format file with malformed image data.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-1454
|
2018-10-19 01:32 |
2006-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|