|
279001
|
- |
|
pixelpost
|
pixelpost
|
Cross-site scripting (XSS) vulnerability in admin/index.php for Pixelpost 1-5rc1-2 and earlier allows remote attackers to inject arbitrary HTML or web script via the loginmessage parameter.
|
NVD-CWE-Other
|
CVE-2006-2891
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279002
|
- |
|
gantty
|
gantty
|
Cross-site scripting (XSS) vulnerability in index.php in GANTTy 1.0.3 allows remote attackers to inject arbitrary HTML and web script via the message parameter in a login action.
|
NVD-CWE-Other
|
CVE-2006-2892
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279003
|
- |
|
gantty
|
gantty
|
index.php in GANTTy 1.0.3 allows remote attackers to obtain the full path of the web server via an invalid lang parameter in an authenticate action.
|
NVD-CWE-Other
|
CVE-2006-2893
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279004
|
- |
|
mozilla netscape
|
firefox mozilla_suite seamonkey navigator
|
Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read…
|
CWE-20
Improper Input Validation
|
CVE-2006-2894
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279005
|
- |
|
funkboard
|
funkboard
|
profile.php in FunkBoard CF0.71 allows remote attackers to change arbitrary passwords via a modified uid hidden form field in an Edit Profile action.
|
NVD-CWE-Other
|
CVE-2006-2896
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279006
|
- |
|
digium
|
asterisk
|
The IAX2 channel driver (chan_iax2) for Asterisk 1.2.x before 1.2.9 and 1.0.x before 1.0.11 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via truncated IAX 2…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-2898
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279007
|
- |
|
digium
|
asterisk
|
This vulnerability is addressed in the following product releases:
Asterisk, Asterisk, 1.2.9
Asterisk, Asterisk, 1.0.11
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-2898
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279008
|
- |
|
estsoft
|
internetdisk
|
Unspecified vulnerability in ESTsoft InternetDISK versions before 2006/04/20 allows remote authenticated users to execute arbitrary code, possibly by uploading a file with multiple extensions into th…
|
NVD-CWE-Other
|
CVE-2006-2899
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279009
|
- |
|
estsoft
|
internetdisk
|
This vulnerability is addressed in the following product release:
ESTsoft, InternetDISK, (version released 2006.04.20)
|
NVD-CWE-Other
|
CVE-2006-2899
|
2018-10-19 01:43 |
2006-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279010
|
- |
|
d-link
|
dwl-2100ap
|
The web server for D-Link Wireless Access-Point (DWL-2100ap) firmware 2.10na and earlier allows remote attackers to obtain sensitive system information via a request to an arbitrary .cfg file, which …
|
NVD-CWE-Other
|
CVE-2006-2901
|
2018-10-19 01:43 |
2006-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|