|
344721
|
- |
|
x7_group
|
x7_chat
|
Directory traversal vulnerability in help/index.php in X7 Chat 2.0 and earlier allows remote attackers to include arbitrary files via .. (dot dot) sequences in the help_file parameter.
|
NVD-CWE-Other
|
CVE-2006-2156
|
2018-10-19 01:38 |
2006-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344722
|
- |
|
russcom_network
|
loginphp
|
CRLF injection vulnerability in help.php in Russcom Network Loginphp allows remote attackers to spoof e-mails and inject MIME headers via CRLF sequences in the email address.
|
NVD-CWE-Other
|
CVE-2006-2159
|
2018-10-19 01:38 |
2006-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344723
|
- |
|
russcom_network
|
loginphp
|
Cross-site scripting (XSS) vulnerability in Russcom Network Loginphp (Russcom.Loginphp) allows remote attackers to inject arbitrary web script or HTML via the username field when registering.
|
NVD-CWE-Other
|
CVE-2006-2160
|
2018-10-19 01:38 |
2006-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344724
|
- |
|
cam_development erik_dienske roger_aelbrecht
|
cam_unzip abakt tzipbuilder
|
Buffer overflow in (1) TZipBuilder 1.79.03.01, (2) Abakt 0.9.2 and 0.9.3-beta1, (3) CAM UnZip 4.0 and 4.3, and possibly other products, allows user-assisted attackers to execute arbitrary code via a …
|
NVD-CWE-Other
|
CVE-2006-2161
|
2018-10-19 01:38 |
2006-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344725
|
- |
|
sloughflash
|
sf-users
|
Cross-site scripting (XSS) vulnerability in SloughFlash SF-Users 1.0, possibly in register.php, allows remote attackers to inject arbitrary web script or HTML by setting the username field to contain…
|
NVD-CWE-Other
|
CVE-2006-2167
|
2018-10-19 01:38 |
2006-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344726
|
- |
|
fileprotection_express
|
fileprotection_express
|
FileProtection Express 1.0.1 and earlier allows remote attackers to bypass authentication via a cookie with an Admin value of 1.
|
NVD-CWE-Other
|
CVE-2006-2168
|
2018-10-19 01:38 |
2006-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344727
|
- |
|
gene6
|
g6_ftp_server
|
Buffer overflow in Gene6 FTP Server 3.1.0 allows remote authenticated attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to (1) MKD or (2) XMKD, as…
|
NVD-CWE-Other
|
CVE-2006-2172
|
2018-10-19 01:38 |
2006-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344728
|
- |
|
ftrainsoft
|
fast_click
|
PHP remote file inclusion vulnerability in FtrainSoft Fast Click 2.3.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) show.php or (2) top.php.
|
NVD-CWE-Other
|
CVE-2006-2175
|
2018-10-19 01:38 |
2006-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344729
|
- |
|
bitdamaged
|
geoblog
|
Cross-site scripting (XSS) vulnerability in viewcat.php in geoBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
|
NVD-CWE-Other
|
CVE-2006-2177
|
2018-10-19 01:38 |
2006-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344730
|
- |
|
zenphoto
|
zenphoto
|
zenphoto 1.0.1 beta and earlier allow remote attackers to obtain sensitive information via a direct request for the (1) /photos/themes/default/ and (2) /photos/themes/testing/ URIs, which reveals the…
|
NVD-CWE-Other
|
CVE-2006-2186
|
2018-10-19 01:38 |
2006-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|