|
278651
|
- |
|
mkportal
|
mkportal
|
Directory traversal vulnerability in index.php in MKPortal 1.0.1 Final allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language cookie, a…
|
NVD-CWE-Other
|
CVE-2006-3554
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278652
|
- |
|
php_fusion
|
php_fusion
|
Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PHP-Fusion before 6.01.3 allow remote attackers to inject arbitrary web script or HTML by using edit_profile.php to upload a (1) a…
|
NVD-CWE-Other
|
CVE-2006-3555
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278653
|
- |
|
extcalendar
|
extcalendar
|
PHP remote file inclusion vulnerability in extcalendar.php in Mohamed Moujami ExtCalendar 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
|
CWE-94
Code Injection
|
CVE-2006-3556
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278654
|
- |
|
mt_orumcek
|
mt_orumcek_toplist
|
MT Orumcek Toplist 2.2 stores DB/orumcektoplist.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request.
|
NVD-CWE-Other
|
CVE-2006-3557
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278655
|
- |
|
arif_supriyanto
|
auracms
|
Multiple cross-site scripting (XSS) vulnerabilities in Arif Supriyanto auraCMS 1.62 allow remote attackers to inject arbitrary web script or HTML via (1) the judul_artikel parameter in teman.php and …
|
NVD-CWE-Other
|
CVE-2006-3558
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278656
|
- |
|
arif_supriyanto
|
auracms
|
Multiple SQL injection vulnerabilities in Arif Supriyanto auraCMS 1.62 allow remote attackers to execute arbitrary SQL commands and delete all shoutbox messages via the (1) name and (2) pesan paramet…
|
NVD-CWE-Other
|
CVE-2006-3559
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278657
|
- |
|
blue_dojo
|
graffiti_forums
|
SQL injection vulnerability in topics.php in Blue Dojo Graffiti Forums 1.0 allows remote attackers to execute arbitrary SQL commands via the f parameter.
|
NVD-CWE-Other
|
CVE-2006-3560
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278658
|
- |
|
bt
|
voyager_2091_wireless_adsl_router
|
BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication process and gain sensitive information, such as co…
|
CWE-200 CWE-264
Information Exposure Permissions, Privileges, and Access Controls
|
CVE-2006-3561
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278659
|
- |
|
easy-cms
|
easy-cms
|
choose_file.php in easy-CMS 0.1.2, when mod_mime is installed, does not restrict uploads of filenames with multiple extensions, which allows remote attackers to execute arbitrary PHP code by uploadin…
|
NVD-CWE-Other
|
CVE-2006-3128
|
2018-10-19 01:46 |
2006-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278660
|
- |
|
qto
|
qtofilemanager
|
Cross-site scripting (XSS) vulnerability in qtofm.php4 in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter, as originally reported for index.php.
|
NVD-CWE-Other
|
CVE-2006-3132
|
2018-10-19 01:46 |
2006-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|