|
346071
|
- |
|
new-place
|
captivate
|
Cross-site scripting (XSS) vulnerability in gallery.php in Captivate 1.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter, which is reflected in an error message.
|
CWE-79
Cross-site Scripting
|
CVE-2006-2796
|
2017-07-20 10:31 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346072
|
- |
|
toenda_software_development
|
toendacms
|
Cross-site scripting (XSS) vulnerability in content_footer.php in toendaCMS 0.7.0 allows remote attackers to inject arbitrary web scripts or HTML via the print_url variable. NOTE: the provenance of …
|
NVD-CWE-Other
|
CVE-2006-2799
|
2017-07-20 10:31 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346073
|
- |
|
toenda_software_development
|
toendacms
|
Successful exploitation requires that the user is running a browser that has not URL-encoded the request (e.g. Internet Explorer).
|
NVD-CWE-Other
|
CVE-2006-2799
|
2017-07-20 10:31 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346074
|
- |
|
unak
|
unak_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in Unak CMS 1.5 RC2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) u_a or (2) u_s parameters. NOTE: this mi…
|
CWE-79
Cross-site Scripting
|
CVE-2006-2800
|
2017-07-20 10:31 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346075
|
- |
|
unak
|
unak_cms
|
Multiple SQL injection vulnerabilities in Unak CMS 1.5 RC2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) u_a or (2) u_s parameters.
|
NVD-CWE-Other
|
CVE-2006-2801
|
2017-07-20 10:31 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346076
|
- |
|
goss
|
icm
|
Cross-site scripting (XSS) vulnerability in index.cfm in Goss Intelligent Content Management (iCM) 7.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword param…
|
NVD-CWE-Other
|
CVE-2006-2804
|
2017-07-20 10:31 |
2006-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346077
|
- |
|
tekno.portal
|
tekno.portal
|
SQL injection vulnerability in bolum.php in tekno.Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the detai…
|
NVD-CWE-Other
|
CVE-2006-2817
|
2017-07-20 10:31 |
2006-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346078
|
- |
|
cpanel
|
cpanel
|
cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts that share physical directories, which might allow a local user to byp…
|
NVD-CWE-Other
|
CVE-2006-2825
|
2017-07-20 10:31 |
2006-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346079
|
- |
|
phplib_team
|
phplib
|
SQL injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a allows remote attackers to execute arbitrary SQL commands via the id variable, which is set by a client through a …
|
NVD-CWE-Other
|
CVE-2006-2826
|
2017-07-20 10:31 |
2006-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346080
|
- |
|
tibco
|
hawk hawk_monitoring_agent runtime_agent
|
Buffer overflow in Hawk Monitoring Agent (HMA) for TIBCO Hawk before 4.6.1 and TIBCO Runtime Agent (TRA) before 5.4 allows authenticated users to execute arbitrary code via the configuration for tibh…
|
NVD-CWE-Other
|
CVE-2006-2829
|
2017-07-20 10:31 |
2006-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|