|
280511
|
- |
|
drupal
|
drupal
|
This vulnerability is addressed in the following product releases:
Drupal, Drupal, 4.6.7
Drupal, Drupal, 4.7.1
|
NVD-CWE-Other
|
CVE-2006-2742
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280512
|
- |
|
drupal
|
drupal
|
Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitra…
|
NVD-CWE-Other
|
CVE-2006-2743
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280513
|
- |
|
drupal
|
drupal
|
Successful exploitation requires that the "mod_mime" module is installed in Apache, and that a " .htaccess" file has not been used to restrict access to the directory.
This vulnerability is addresse…
|
NVD-CWE-Other
|
CVE-2006-2743
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280514
|
- |
|
facile_interactive_web
|
facile_interactive_web
|
PHP remote file inclusion vulnerability in p-popupgallery.php in F@cile Interactive Web 0.8.41 through 0.8.5 allows remote attackers to execute arbitrary PHP code via a URL in the l parameter.
|
NVD-CWE-Other
|
CVE-2006-2744
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280515
|
- |
|
facile_interactive_web
|
facile_interactive_web
|
Multiple PHP remote file inclusion vulnerabilities in F@cile Interactive Web 0.8.5 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the…
|
NVD-CWE-Other
|
CVE-2006-2745
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280516
|
- |
|
facile_interactive_web
|
facile_interactive_web
|
Successful exploitation requires that "register_globals" is enabled.
|
NVD-CWE-Other
|
CVE-2006-2745
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280517
|
- |
|
facile_interactive_web
|
facile_interactive_web
|
Multiple cross-site scripting (XSS) vulnerabilities in F@cile Interactive Web 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) lang parameter in index.php, …
|
NVD-CWE-Other
|
CVE-2006-2746
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280518
|
- |
|
fredi_bach
|
phpmydesktop_arcade
|
Directory traversal vulnerability in index.php in PhpMyDesktop|arcade 1.0 FINAL allows remote attackers to read arbitrary files or execute PHP code via a .. (dot dot) sequence and trailing null (%00)…
|
NVD-CWE-Other
|
CVE-2006-2747
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280519
|
- |
|
fredi_bach
|
phpmydesktop_arcade
|
Successful exploitation requires that "magic_quotes_gpc" is disabled.
|
NVD-CWE-Other
|
CVE-2006-2747
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280520
|
- |
|
open_searchable_image_catalogue
|
open_searchable_image_catalogue
|
SQL injection vulnerability in the do_mysql_query function in core.php for Open Searchable Image Catalogue (OSIC) before 0.7.0.1 allows remote attackers to inject arbitrary SQL commands via multiple …
|
NVD-CWE-Other
|
CVE-2006-2748
|
2018-10-19 01:41 |
2006-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|