|
344021
|
- |
|
farsinews
|
farsinews
|
Directory traversal vulnerability in jscripts/tiny_mce/tiny_mce_gzip.php in FarsiNews 3.0 BETA 1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing null (%00)…
|
NVD-CWE-Other
|
CVE-2006-3602
|
2018-10-19 01:48 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344022
|
- |
|
flatnuke
|
flatnuke
|
The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote …
|
NVD-CWE-Other
|
CVE-2006-3608
|
2018-10-19 01:48 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344023
|
- |
|
flatnuke
|
flatnuke
|
Successful exploitation requires that Gallery uploads are enabled.
|
NVD-CWE-Other
|
CVE-2006-3608
|
2018-10-19 01:48 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344024
|
- |
|
orbitcoders
|
orbitmatrix
|
Cross-site scripting (XSS) vulnerability in index.php in Orbitcoders OrbitMATRIX 1.0 allows remote attackers to inject arbitrary web script or HTML via the page_name parameter with an IMG tag contain…
|
NVD-CWE-Other
|
CVE-2006-3609
|
2018-10-19 01:48 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344025
|
- |
|
orbitcoders
|
orbitmatrix
|
index.php in Orbitcoders OrbitMATRIX 1.0 allows remote attackers to obtain sensitive information (partial database schema) via a modified page_name parameter, which reflects portions of an SQL query …
|
NVD-CWE-Other
|
CVE-2006-3610
|
2018-10-19 01:48 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344026
|
- |
|
chamberland_technology
|
ezwaiter_online
|
Multiple cross-site scripting (XSS) vulnerabilities in Chamberland Technology ezWaiter 3.0 Online and possibly Enterprise Software (aka enterprise edition) allow remote attackers to inject arbitrary …
|
NVD-CWE-Other
|
CVE-2006-3613
|
2018-10-19 01:48 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344027
|
- |
|
orbitcoders
|
orbitmatrix
|
index.php in Orbitcoders OrbitMATRIX 1.0 allows remote attackers to trigger a SQL error via the page_name parameter, possibly due to a SQL injection vulnerability.
|
NVD-CWE-Other
|
CVE-2006-3614
|
2018-10-19 01:48 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344028
|
- |
|
carbonize
|
lazarus_guestbook
|
Multiple cross-site scripting (XSS) vulnerabilities in Carbonize Lazarus Guestbook 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in codes-en…
|
NVD-CWE-Other
|
CVE-2006-3616
|
2018-10-19 01:48 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344029
|
- |
|
pixelated_by_lev
|
pixelated_by_lev_guestbook
|
Cross-site scripting (XSS) vulnerability in pblguestbook.php in Pixelated By Lev (PBL) Guestbook 1.32 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) …
|
NVD-CWE-Other
|
CVE-2006-3617
|
2018-10-19 01:48 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344030
|
- |
|
pixelated_by_lev
|
pixelated_by_lev_guestbook
|
SQL injection vulnerability in pblguestbook.php in Pixelated By Lev (PBL) Guestbook 1.32 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) website…
|
NVD-CWE-Other
|
CVE-2006-3618
|
2018-10-19 01:48 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|