|
279881
|
- |
|
avira
|
antivir_personal
|
Classic Planer in AntiVir PersonalEdition Classic 7 does not drop privileges before executing external programs, which allows local users to gain privileges via notepad.exe, which is used to display …
|
NVD-CWE-Other
|
CVE-2006-1274
|
2018-10-19 01:31 |
2006-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279882
|
- |
|
upoint
|
at1_file_store
|
Cross-site scripting (XSS) vulnerability in signup.php in @1 File Store 2006.03.07 allows remote attackers to inject arbitrary web script or HTML via the (1) real_name, (2) email, and (3) login param…
|
NVD-CWE-Other
|
CVE-2006-1277
|
2018-10-19 01:31 |
2006-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279883
|
- |
|
upoint
|
\@1_file_store
|
SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3)…
|
CWE-89
SQL Injection
|
CVE-2006-1278
|
2018-10-19 01:31 |
2006-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279884
|
- |
|
upoint
|
\@1_file_store
|
Successful exploitation requires that the "magic_quotes_gpc" parameter is disabled.
|
CWE-89
SQL Injection
|
CVE-2006-1278
|
2018-10-19 01:31 |
2006-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279885
|
- |
|
mybulletinboard
|
mybulletinboard
|
Cross-site scripting (XSS) vulnerability in member.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vulnerability t…
|
NVD-CWE-Other
|
CVE-2006-1281
|
2018-10-19 01:31 |
2006-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279886
|
- |
|
mybulletinboard
|
mybulletinboard
|
CRLF injection vulnerability in inc/function.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to conduct cross-site scripting (XSS), poison caches, or hijack pages via CRLF (%0A%0D) sequenc…
|
NVD-CWE-Other
|
CVE-2006-1282
|
2018-10-19 01:31 |
2006-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279887
|
- |
|
milkeyway
|
milkeyway_captive_portal
|
Multiple SQL injection vulnerabilities in Milkeyway Captive Portal 0.1 and 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username, (2) password, (3) team, (4) level, (5) …
|
NVD-CWE-Other
|
CVE-2006-1289
|
2018-10-19 01:31 |
2006-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279888
|
- |
|
milkeyway
|
milkeyway_captive_portal
|
Multiple cross-site scripting (XSS) vulnerabilities in Milkeyway Captive Portal 0.1 and 0.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) ipAddress, (2) act, (3) usernam…
|
NVD-CWE-Other
|
CVE-2006-1290
|
2018-10-19 01:31 |
2006-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279889
|
- |
|
astalavista_it_engineering
|
contrexx
|
Cross-site scripting (XSS) vulnerability in index.php in Contrexx CMS 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF).
|
NVD-CWE-Other
|
CVE-2006-1293
|
2018-10-19 01:31 |
2006-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279890
|
- |
|
symantec_veritas
|
backup_exec backup_exec_remote_agent
|
Unspecified vulnerability in Veritas Backup Exec for Windows Server Remote Agent 9.1 through 10.1, for Netware Servers and Remote Agent 9.1 and 9.2, and Remote Agent for Linux Servers 10.0 and 10.1 a…
|
NVD-CWE-Other
|
CVE-2006-1297
|
2018-10-19 01:31 |
2006-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|