|
278901
|
- |
|
sun
|
management\+center
|
The Oracle database component in Sun Management Center (Sun MC) 3.6.1, 3.6, and 3.5 Update 1 has a default account, which allows remote attackers to obtain database access and execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2007-6480
|
2018-10-31 01:25 |
2007-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278902
|
- |
|
sun
|
ray_server_software
|
Unspecified vulnerability in the Device Manager daemon (utdevmgrd) in Sun Ray Server Software 2.0, 3.0, 3.1, and 3.1.1 allows remote attackers to cause a denial of service (daemon crash) via unspecif…
|
NVD-CWE-noinfo
|
CVE-2007-6482
|
2018-10-31 01:25 |
2007-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278903
|
- |
|
microsoft
|
office windows_2003_server windows_xp
|
The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileg…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-0008
|
2018-10-31 01:25 |
2006-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278904
|
- |
|
sun
|
solaris sunos
|
Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004…
|
NVD-CWE-Other
|
CVE-2006-0161
|
2018-10-31 01:25 |
2006-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278905
|
- |
|
php
|
php
|
Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL …
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2006-0200
|
2018-10-31 01:25 |
2006-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278906
|
- |
|
php
|
php
|
Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/se…
|
CWE-94
Code Injection
|
CVE-2006-0207
|
2018-10-31 01:25 |
2006-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278907
|
- |
|
php
|
php
|
Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP…
|
CWE-79
Cross-site Scripting
|
CVE-2006-0208
|
2018-10-31 01:25 |
2006-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278908
|
- |
|
oracle
|
weblogic_portal
|
BEA WebLogic Portal 8.1 through SP3 stores the password for the RDBMS Authentication provider in cleartext in the config.xml file, which allows attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2006-0423
|
2018-10-31 01:25 |
2006-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278909
|
- |
|
oracle
|
weblogic_portal
|
BEA WebLogic Portal 8.1 through SP4 allows remote attackers to obtain the source for a deployment descriptor file via unknown vectors.
|
NVD-CWE-Other
|
CVE-2006-0425
|
2018-10-31 01:25 |
2006-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278910
|
- |
|
oracle
|
weblogic_portal
|
Unspecified vulnerability in BEA WebLogic Portal 8.1 SP3 through SP5, when using Web Services Remote Portlets (WSRP), allows remote attackers to access restricted web resources via crafted URLs.
|
NVD-CWE-Other
|
CVE-2006-0428
|
2018-10-31 01:25 |
2006-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|