|
279261
|
- |
|
drupal
|
drupal
|
SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) da…
|
NVD-CWE-Other
|
CVE-2006-2742
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279262
|
- |
|
drupal
|
drupal
|
This vulnerability is addressed in the following product releases:
Drupal, Drupal, 4.6.7
Drupal, Drupal, 4.7.1
|
NVD-CWE-Other
|
CVE-2006-2742
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279263
|
- |
|
drupal
|
drupal
|
Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitra…
|
NVD-CWE-Other
|
CVE-2006-2743
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279264
|
- |
|
drupal
|
drupal
|
Successful exploitation requires that the "mod_mime" module is installed in Apache, and that a " .htaccess" file has not been used to restrict access to the directory.
This vulnerability is addresse…
|
NVD-CWE-Other
|
CVE-2006-2743
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279265
|
- |
|
facile_interactive_web
|
facile_interactive_web
|
PHP remote file inclusion vulnerability in p-popupgallery.php in F@cile Interactive Web 0.8.41 through 0.8.5 allows remote attackers to execute arbitrary PHP code via a URL in the l parameter.
|
NVD-CWE-Other
|
CVE-2006-2744
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279266
|
- |
|
facile_interactive_web
|
facile_interactive_web
|
Multiple PHP remote file inclusion vulnerabilities in F@cile Interactive Web 0.8.5 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the…
|
NVD-CWE-Other
|
CVE-2006-2745
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279267
|
- |
|
facile_interactive_web
|
facile_interactive_web
|
Successful exploitation requires that "register_globals" is enabled.
|
NVD-CWE-Other
|
CVE-2006-2745
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279268
|
- |
|
facile_interactive_web
|
facile_interactive_web
|
Multiple cross-site scripting (XSS) vulnerabilities in F@cile Interactive Web 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) lang parameter in index.php, …
|
NVD-CWE-Other
|
CVE-2006-2746
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279269
|
- |
|
fredi_bach
|
phpmydesktop_arcade
|
Directory traversal vulnerability in index.php in PhpMyDesktop|arcade 1.0 FINAL allows remote attackers to read arbitrary files or execute PHP code via a .. (dot dot) sequence and trailing null (%00)…
|
NVD-CWE-Other
|
CVE-2006-2747
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279270
|
- |
|
fredi_bach
|
phpmydesktop_arcade
|
Successful exploitation requires that "magic_quotes_gpc" is disabled.
|
NVD-CWE-Other
|
CVE-2006-2747
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|