|
278711
|
- |
|
usermin webmin
|
usermin webmin
|
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, whi…
|
NVD-CWE-Other
|
CVE-2006-3392
|
2018-10-19 01:47 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278712
|
- |
|
miro_international
|
galleria
|
PHP remote file inclusion vulnerability in galleria.html.php in Galleria Mambo Module 1.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolu…
|
CWE-94
Code Injection
|
CVE-2006-3396
|
2018-10-19 01:47 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278713
|
- |
|
moniwiki
|
moniwiki
|
Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki before 1.1.2-20060702 allows remote attackers to inject arbitrary Javascript via the URL, which is reflected back in an error message,…
|
NVD-CWE-Other
|
CVE-2006-3399
|
2018-10-19 01:47 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278714
|
- |
|
samba
|
samba
|
The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of share connection requests.
|
NVD-CWE-Other
|
CVE-2006-3403
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278715
|
- |
|
qto
|
qtofilemanager
|
Cross-site scripting (XSS) vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) delete, (2) pathext, and (3) edit parameters.
|
NVD-CWE-Other
|
CVE-2006-3405
|
2018-10-19 01:47 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278716
|
- |
|
qto
|
qtofilemanager
|
Directory traversal vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to modify arbitrary files via a .. (dot dot) sequence in the edit parameter.
|
NVD-CWE-Other
|
CVE-2006-3406
|
2018-10-19 01:47 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278717
|
- |
|
smartsitecms
|
smartsitecms
|
PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the root parameter in (1) comment.…
|
NVD-CWE-Other
|
CVE-2006-3421
|
2018-10-19 01:47 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278718
|
- |
|
webex_communications
|
downloader_activexcontrol downloader_java
|
WebEx Downloader ActiveX Control and WebEx Downloader Java before 2.1.0.0 do not validate downloaded components, which allows remote attackers to execute arbitrary code via a website that activates t…
|
CWE-20
Improper Input Validation
|
CVE-2006-3423
|
2018-10-19 01:47 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278719
|
- |
|
webex_communications
|
downloader_activexcontrol downloader_java
|
Upgrade to version 2.1.0.0.
|
CWE-20
Improper Input Validation
|
CVE-2006-3423
|
2018-10-19 01:47 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278720
|
- |
|
lumension novell
|
patchlink_update_server zenworks
|
FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/proxyreg.asp, which…
|
NVD-CWE-Other
|
CVE-2006-3425
|
2018-10-19 01:47 |
2006-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|