|
278911
|
- |
|
joomla
|
pc_cookbook
|
Successful exploitation requires that "register_globals" is enabled.
|
CWE-94
Code Injection
|
CVE-2006-3530
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278912
|
- |
|
pivot
|
pivot
|
includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers to obtain privileges and upload arbitrary files vi…
|
NVD-CWE-Other
|
CVE-2006-3531
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278913
|
- |
|
pivot
|
pivot
|
PHP file inclusion vulnerability in includes/edit_new.php in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a FTP URL or full …
|
NVD-CWE-Other
|
CVE-2006-3532
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278914
|
- |
|
pivot
|
pivot
|
Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) fg, (2) …
|
NVD-CWE-Other
|
CVE-2006-3533
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278915
|
- |
|
randshop
|
randshop
|
PHP remote file inclusion vulnerability in index.php in Randshop before 1.2 allows remote attackers to execute arbitrary PHP code via the dateiPfad parameter, a different vector than CVE-2006-3375.
|
NVD-CWE-Other
|
CVE-2006-3537
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278916
|
- |
|
randshop
|
randshop
|
This vulnerability is addressed in the following product release:
Randshop, Randshop, 1.2
|
NVD-CWE-Other
|
CVE-2006-3537
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278917
|
- |
|
beatificfaith
|
eprayer
|
Multiple cross-site scripting (XSS) vulnerabilities in demo.php in BeatificFaith Eprayer Alpha allow remote attackers to inject arbitrary web script or HTML via the SRC attribute of a SCRIPT element …
|
NVD-CWE-Other
|
CVE-2006-3538
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278918
|
- |
|
zonelabs
|
zonealarm_security_suite
|
Check Point Zone Labs ZoneAlarm Internet Security Suite 6.5.722.000, 6.1.737.000, and possibly other versions do not properly validate RegSaveKey, RegRestoreKey, and RegDeleteKey function calls, whic…
|
NVD-CWE-Other
|
CVE-2006-3540
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278919
|
- |
|
kyberna
|
ky2help
|
SQL injection vulnerability in Meine Links (aka My Links) in Kyberna ky2help allows remote authenticated users to execute arbitrary SQL commands via unspecified "textboxes."
|
NVD-CWE-Other
|
CVE-2006-3541
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278920
|
- |
|
boxcar_media
|
shopping_cart
|
Multiple cross-site scripting (XSS) vulnerabilities in Garry Glendown Shopping Cart 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) shop name field in (a) editshop.php, …
|
NVD-CWE-Other
|
CVE-2006-3542
|
2018-10-19 01:47 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|