|
279011
|
- |
|
particle_soft
|
particle_links
|
Directory traversal vulnerability in Particle Links 1.2.2 might allow remote attackers to access arbitrary files via ".." sequences in an HTTP request. NOTE: it is not clear whether this issue is le…
|
NVD-CWE-Other
|
CVE-2006-2902
|
2018-10-19 01:43 |
2006-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279012
|
- |
|
particle_soft
|
particle_links
|
Cross-site scripting (XSS) vulnerability in admin.php in Particle Links 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
|
NVD-CWE-Other
|
CVE-2006-2903
|
2018-10-19 01:43 |
2006-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279013
|
- |
|
particle_soft
|
particle_links
|
SQL injection vulnerability in index.php in Partial Links 1.2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter.
|
NVD-CWE-Other
|
CVE-2006-2904
|
2018-10-19 01:43 |
2006-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279014
|
- |
|
particle_soft
|
particle_links
|
Partial Links 1.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) page_footer.php and (2) page_header.php, which displays the path in an error message.
|
NVD-CWE-Other
|
CVE-2006-2905
|
2018-10-19 01:43 |
2006-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279015
|
- |
|
mybulletinboard
|
mybulletinboard
|
The domecode function in inc/functions_post.php in MyBulletinBoard (MyBB) 1.1.2, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the username field, which is us…
|
NVD-CWE-Other
|
CVE-2006-2908
|
2018-10-19 01:43 |
2006-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279016
|
- |
|
picozip
|
picozip
|
Stack-based buffer overflow in the info tip shell extension (zipinfo.dll) in PicoZip 4.01 allows remote attackers to execute arbitrary code via a long filename in an (1) ACE, (2) RAR, or (3) ZIP arch…
|
NVD-CWE-Other
|
CVE-2006-2909
|
2018-10-19 01:43 |
2006-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279017
|
- |
|
hotwebscripts
|
cms_mundo
|
SQL injection vulnerability in controlpanel/index.php in CMS Mundo before 1.0 build 008 allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
NVD-CWE-Other
|
CVE-2006-2911
|
2018-10-19 01:43 |
2006-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279018
|
- |
|
out_of_the_trees_web_design
|
selectapix
|
Multiple SQL injection vulnerabilities in SelectaPix 1.31 allow remote attackers to execute arbitrary SQL commands via the (1) albumID parameter to (a) view_album.php or (b) index.php, (2) imageID pa…
|
NVD-CWE-Other
|
CVE-2006-2912
|
2018-10-19 01:43 |
2006-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279019
|
- |
|
deluxebb
|
deluxebb
|
PHP remote file inclusion vulnerability in DeluxeBB 1.06 allows remote attackers to execute arbitrary code via a URL in the templatefolder parameter to (1) postreply.php, (2) posting.php, (3) and pm/…
|
NVD-CWE-Other
|
CVE-2006-2914
|
2018-10-19 01:43 |
2006-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279020
|
- |
|
deluxebb
|
deluxebb
|
Multiple SQL injection vulnerabilities in DeluxeBB 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) hideemail, (2) languagex, (3) xthetimeoffset, and (4) xthetimeformat param…
|
NVD-CWE-Other
|
CVE-2006-2915
|
2018-10-19 01:43 |
2006-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|