|
288471
|
- |
|
freestyle
|
freestyle_wiki
|
FreeStyle Wiki (fswiki) 3.6.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request for …
|
NVD-CWE-Other
|
CVE-2006-6889
|
2017-10-19 10:29 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288472
|
- |
|
voc-project
|
voodoo_chat
|
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remote attackers to download passwords via a direct request for data/users.dat.
|
NVD-CWE-Other
|
CVE-2006-6890
|
2017-10-19 10:29 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288473
|
- |
|
vz_forum
|
vz_forum
|
Vz (Adp) Forum 2.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrative account name and password hash via a …
|
NVD-CWE-Other
|
CVE-2006-6891
|
2017-10-19 10:29 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288474
|
- |
|
fersch
|
formbankserver
|
formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a denial of service (daemon crash) via multiple requests containing many /../ se…
|
NVD-CWE-Other
|
CVE-2006-6910
|
2017-10-19 10:29 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288475
|
- |
|
digitizing_quote_and_ordering_system
|
digitizing_quote_and_ordering_system
|
SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users to execute arbitrary SQL commands via the ordernum parameter.
|
NVD-CWE-Other
|
CVE-2006-6911
|
2017-10-19 10:29 |
2006-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288476
|
- |
|
nitrotech
|
nitrotech
|
Directory traversal vulnerability in includes/common.php in NitroTech 0.0.3a, as distributed before 2006, allows remote attackers to include arbitrary files via ".." sequences in the root parameter.
|
NVD-CWE-Other
|
CVE-2006-6938
|
2017-10-19 10:29 |
2007-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288477
|
- |
|
freewebshop
|
freewebshop
|
index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to obtain sensitive information via an invalid action parameter in an info operation, which discloses the path in an error message.
|
NVD-CWE-Other
|
CVE-2006-6941
|
2017-10-19 10:29 |
2007-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288478
|
- |
|
joomla
|
rs_gallery2
|
PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for Joomla! allows attackers to execute arbitrary PHP code via the mosConfig_absolu…
|
CWE-94
Code Injection
|
CVE-2006-6962
|
2017-10-19 10:29 |
2007-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288479
|
- |
|
centipaid
|
centipaid
|
PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.2 and earlier allows remote attackers to execute arbitrary code via a URL in the absolute_path parameter.
|
CWE-94
Code Injection
|
CVE-2006-6976
|
2017-10-19 10:29 |
2007-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288480
|
- |
|
minibb
|
keyword_replacer
|
PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a module for miniBB, allows remote attackers to execute arbitrary PHP code via a …
|
NVD-CWE-Other
|
CVE-2006-7156
|
2017-10-19 10:29 |
2007-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|