|
279401
|
- |
|
symantec
|
antivirus_scan_engine
|
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses the same private DSA key for each installation, which allows remote attackers to conduct man-in-the-middle attacks and …
|
NVD-CWE-Other
|
CVE-2006-0231
|
2018-10-20 00:43 |
2006-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279402
|
- |
|
symantec
|
antivirus_scan_engine
|
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with insufficient access control, which allows remote att…
|
NVD-CWE-Other
|
CVE-2006-0232
|
2018-10-20 00:43 |
2006-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279403
|
- |
|
microblog
|
microblog
|
Cross-site scripting (XSS) vulnerability in functions.php in microBlog 2.0 RC-10 allows remote attackers to inject arbitrary web script and HTML via a javascript: URI in a [url] BBcode tag.
|
CWE-79
Cross-site Scripting
|
CVE-2006-0233
|
2018-10-20 00:43 |
2006-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279404
|
- |
|
microblog
|
microblog
|
SQL injection vulnerability in index.php in microBlog 2.0 RC-10 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters.
|
NVD-CWE-Other
|
CVE-2006-0234
|
2018-10-20 00:43 |
2006-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279405
|
- |
|
white_angle
|
white_album
|
SQL injection vulnerability in WhiteAlbum 2.5 allows remote attackers to execute arbitrary SQL commands via the dir parameter to pictures.php.
|
NVD-CWE-Other
|
CVE-2006-0235
|
2018-10-20 00:43 |
2006-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279406
|
- |
|
mozilla
|
thunderbird
|
GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an attachment with a filename containing a large numbe…
|
CWE-94
Code Injection
|
CVE-2006-0236
|
2018-10-20 00:43 |
2006-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279407
|
- |
|
8pixel.net
|
simple_blog
|
Multiple cross-site scripting (XSS) vulnerabilities in Simple Blog 2.1 allow remote attackers to inject arbitrary web script or HTML via (1) a comment to comments.asp and (2) possibly certain other f…
|
NVD-CWE-Other
|
CVE-2006-0239
|
2018-10-20 00:43 |
2006-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279408
|
- |
|
webmobo
|
wbnews
|
Cross-site scripting vulnerability in WBNews 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the Name field.
|
NVD-CWE-Other
|
CVE-2006-0241
|
2018-10-20 00:43 |
2006-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279409
|
- |
|
php_fusebox
|
php_fusebox
|
Cross-site scripting vulnerability in index.php in PHP Fusebox 4.0.6 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter.
|
NVD-CWE-Other
|
CVE-2006-0242
|
2018-10-20 00:43 |
2006-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279410
|
- |
|
benders_calendar
|
benders_calendar
|
SQL injection vulnerability in Benders Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by the (1) year, (2) month, and (3) day paramete…
|
NVD-CWE-Other
|
CVE-2006-0252
|
2018-10-20 00:43 |
2006-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|