|
280321
|
- |
|
aspburst
|
mynewsletter
|
Multiple SQL injection vulnerabilities in myNewsletter 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the UserName parameter in (1) validatelogin.asp or (2) adminlogin…
|
NVD-CWE-Other
|
CVE-2006-2887
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280322
|
- |
|
pixelpost
|
pixelpost
|
Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL commands, and leverage them to gain administrator privileges, via…
|
NVD-CWE-Other
|
CVE-2006-2889
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280323
|
- |
|
pixelpost
|
pixelpost
|
Pixelpost 1-5rc1-2 and earlier, when register_globals is enabled, allows remote attackers to gain administrator privileges and conduct other attacks by setting the _SESSION["pixelpost_admin"] paramet…
|
NVD-CWE-Other
|
CVE-2006-2890
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280324
|
- |
|
pixelpost
|
pixelpost
|
Cross-site scripting (XSS) vulnerability in admin/index.php for Pixelpost 1-5rc1-2 and earlier allows remote attackers to inject arbitrary HTML or web script via the loginmessage parameter.
|
NVD-CWE-Other
|
CVE-2006-2891
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280325
|
- |
|
gantty
|
gantty
|
Cross-site scripting (XSS) vulnerability in index.php in GANTTy 1.0.3 allows remote attackers to inject arbitrary HTML and web script via the message parameter in a login action.
|
NVD-CWE-Other
|
CVE-2006-2892
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280326
|
- |
|
gantty
|
gantty
|
index.php in GANTTy 1.0.3 allows remote attackers to obtain the full path of the web server via an invalid lang parameter in an authenticate action.
|
NVD-CWE-Other
|
CVE-2006-2893
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280327
|
- |
|
mozilla netscape
|
firefox mozilla_suite seamonkey navigator
|
Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read…
|
CWE-20
Improper Input Validation
|
CVE-2006-2894
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280328
|
- |
|
funkboard
|
funkboard
|
profile.php in FunkBoard CF0.71 allows remote attackers to change arbitrary passwords via a modified uid hidden form field in an Edit Profile action.
|
NVD-CWE-Other
|
CVE-2006-2896
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280329
|
- |
|
digium
|
asterisk
|
The IAX2 channel driver (chan_iax2) for Asterisk 1.2.x before 1.2.9 and 1.0.x before 1.0.11 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via truncated IAX 2…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-2898
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280330
|
- |
|
digium
|
asterisk
|
This vulnerability is addressed in the following product releases:
Asterisk, Asterisk, 1.2.9
Asterisk, Asterisk, 1.0.11
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-2898
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|