|
346001
|
- |
|
usermin webmin
|
usermin webmin
|
Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source c…
|
CWE-79
Cross-site Scripting
|
CVE-2006-4542
|
2017-07-20 10:33 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346002
|
- |
|
usermin webmin
|
usermin webmin
|
This vulnerability is addressed in the following product releases:
Webmin, Webmin, 1.296
Usermin, Usermin, 1.226
|
CWE-79
Cross-site Scripting
|
CVE-2006-4542
|
2017-07-20 10:33 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346003
|
- |
|
retro64
|
cr64loader_activex_control
|
Buffer overflow in the Retro64 / Miniclip CR64Loader ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors involving an HTML document that references the CLSID of …
|
NVD-CWE-Other
|
CVE-2006-4555
|
2017-07-20 10:33 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346004
|
- |
|
phpnuke
|
myheadlines
|
Cross-site scripting (XSS) vulnerability in the MyHeadlines before 4.3.2 module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the myh_op parameter to modules.php.
|
NVD-CWE-Other
|
CVE-2006-4563
|
2017-07-20 10:33 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346005
|
- |
|
simplemachines
|
smf
|
SQL injection vulnerability in Sources/ManageBoards.php in Simple Machines Forum 1.1 RC3 allows remote attackers to execute arbitrary SQL commands via the cur_cat parameter.
|
CWE-89
SQL Injection
|
CVE-2006-4564
|
2017-07-20 10:33 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346006
|
- |
|
simplemachines
|
smf
|
Successful exploitation requires privileges to add a new board.
|
CWE-89
SQL Injection
|
CVE-2006-4564
|
2017-07-20 10:33 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346007
|
- |
|
jetstat.com
|
js_asp_faq_manager
|
SQL injection vulnerability in admin/default.asp in Jetstat.com JS ASP Faq Manager 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the uid parameter, a different vector…
|
NVD-CWE-Other
|
CVE-2006-4590
|
2017-07-20 10:33 |
2006-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346008
|
- |
|
mailenable
|
mailenable_enterprise mailenable_professional mailenable_standard
|
SMTP service in MailEnable Standard, Professional, and Enterprise before ME-10014 (20060904) allows remote attackers to cause a denial of service via an SPF lookup for a domain with a large number of…
|
NVD-CWE-Other
|
CVE-2006-4616
|
2017-07-20 10:33 |
2006-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346009
|
- |
|
vcd-db
|
vcd-db
|
Cross-site scripting (XSS) vulnerability in VCD-db before 0.983 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors when handling comments.
|
NVD-CWE-Other
|
CVE-2006-4628
|
2017-07-20 10:33 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346010
|
- |
|
squiz
|
mysource_classic
|
Unspecified vulnerability in MySource Classic 2.14.6, and possibly earlier, allows remote authenticated users, with superuser privileges, to inject arbitrary PHP code via unspecified vectors related …
|
NVD-CWE-Other
|
CVE-2006-4635
|
2017-07-20 10:33 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|