|
345741
|
- |
|
francisco_burzi
|
php-nuke
|
The CAPTCHA functionality in php-Nuke 6.0 through 7.9 uses fixed challenge/response pairs that only vary once per day based on the User Agent (HTTP_USER_AGENT), which allows remote attackers to bypas…
|
NVD-CWE-Other
|
CVE-2006-0805
|
2018-10-19 01:29 |
2006-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345742
|
- |
|
john_lim
|
adodb
|
Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page par…
|
CWE-79
Cross-site Scripting
|
CVE-2006-0806
|
2018-10-19 01:29 |
2006-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345743
|
- |
|
njstar
|
chinese_word_processor japanese_word_processor
|
Stack-based buffer overflow in NJStar Chinese and Japanese Word Processor 4.x and 5.x before 5.10 allows user-assisted attackers to execute arbitrary code via font names in NJStar (.njx) documents.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-0807
|
2018-10-19 01:29 |
2006-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345744
|
- |
|
visnetic
|
visnetic_antivirus_plug-in_for_mail_server
|
The VisNetic AntiVirus Plug-in (DKAVUpSch.exe) for Mail Server 4.6.0.4, 4.6.1.1, and possibly other versions before 4.6.1.2, does not drop privileges before executing other programs, which allows loc…
|
NVD-CWE-Other
|
CVE-2006-0812
|
2018-10-19 01:29 |
2006-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345745
|
- |
|
winace
|
winace
|
Heap-based buffer overflow in WinACE 2.60 allows user-assisted attackers to execute arbitrary code via a large header block in an ARJ archive.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2006-0813
|
2018-10-19 01:29 |
2006-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345746
|
- |
|
lighttpd
|
lighttpd
|
response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via requests that contain trailing (1) "." (dot) and (2) space…
|
NVD-CWE-Other
|
CVE-2006-0814
|
2018-10-19 01:29 |
2006-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345747
|
- |
|
networkactiv
|
networkactiv_web_server
|
NetworkActiv Web Server 3.5.15 allows remote attackers to read script source code via a crafted URL with a "/" (forward slash) after the file extension.
|
NVD-CWE-Other
|
CVE-2006-0815
|
2018-10-19 01:29 |
2006-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345748
|
- |
|
orionserver
|
orion_application_server
|
Orion Application Server before 2.0.7, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the extension of a URL.
|
NVD-CWE-Other
|
CVE-2006-0816
|
2018-10-19 01:29 |
2006-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345749
|
- |
|
orionserver
|
orion_application_server
|
Update to version 2.0.7 or contact the vendor for a patch.
|
NVD-CWE-Other
|
CVE-2006-0816
|
2018-10-19 01:29 |
2006-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345750
|
- |
|
deerfield icewarp merak
|
visnetic_mail_server web_mail mail_server
|
Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer before 8.5.0.5 allows remote attackers to in…
|
NVD-CWE-Other
|
CVE-2006-0817
|
2018-10-19 01:29 |
2006-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|