|
278691
|
- |
|
alan_ward
|
a-cart
|
A-CART 2.0 stores the acart2_0.mdb file under the web document root with insufficient access control, which allows remote attackers to obtain username and password information.
|
NVD-CWE-Other
|
CVE-2006-2948
|
2018-10-19 01:44 |
2006-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278692
|
- |
|
mybulletinboard
|
mybulletinboard
|
Cross-site scripting (XSS) vulnerability in private.php in MyBB 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the do parameter.
|
NVD-CWE-Other
|
CVE-2006-2949
|
2018-10-19 01:44 |
2006-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278693
|
- |
|
mybulletinboard
|
mybulletinboard
|
This vulnerability is addressed in the following product release:
MyBB, MyBB, 1.1.3
|
NVD-CWE-Other
|
CVE-2006-2949
|
2018-10-19 01:44 |
2006-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278694
|
- |
|
npds
|
npds
|
Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) header.php, (2) contact.php, or (3) forum_extender.php, which rev…
|
CWE-200
Information Exposure
|
CVE-2006-2950
|
2018-10-19 01:44 |
2006-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278695
|
- |
|
npds
|
npds
|
Multiple cross-site scripting (XSS) vulnerabilities in Net Portal Dynamic System (NPDS) 5.10 and earlier allow remote attackers to inject arbitrary web script and HTML via the (1) Titlesitename or (2…
|
CWE-79
Cross-site Scripting
|
CVE-2006-2951
|
2018-10-19 01:44 |
2006-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278696
|
- |
|
net_portal_dynamic_system
|
net_portal_dynamic_system
|
Directory traversal vulnerability in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the …
|
NVD-CWE-Other
|
CVE-2006-2952
|
2018-10-19 01:44 |
2006-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278697
|
- |
|
snitz_communications
|
snitz_forums_2000
|
SQL injection vulnerability in inc_header.asp in Snitz Forum 3.4.05 and earlier allows remote attackers to execute arbitrary SQL commands via the %strCookieURL%.GROUP parameter in a cookie.
|
NVD-CWE-Other
|
CVE-2006-2959
|
2018-10-19 01:44 |
2006-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278698
|
- |
|
joomla
|
joomla
|
PHP remote file inclusion vulnerability in includes/joomla.php in Joomla! 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the includepath parameter.
|
NVD-CWE-Other
|
CVE-2006-2960
|
2018-10-19 01:44 |
2006-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278699
|
- |
|
it-direkt
|
cabacos_web_cms
|
Cross-site scripting (XSS) vulnerability in Suchergebnisse.asp in Cabacos Web CMS 3.8.498 and earlier allows remote attackers to inject arbitrary web script or HTML via the suchtext parameter.
|
NVD-CWE-Other
|
CVE-2006-2963
|
2018-10-19 01:44 |
2006-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278700
|
- |
|
xtreme_scripts
|
download_manager
|
Multiple PHP remote file inclusion vulnerabilities in Xtreme Scripts Download Manager (aka Xtreme Downloads) 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter i…
|
NVD-CWE-Other
|
CVE-2006-2964
|
2018-10-19 01:44 |
2006-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|