|
284171
|
- |
|
bloggit
|
bloggit
|
admin.php in BloggIT 1.01 and earlier does not properly establish a user session, which allows remote attackers to gain privileges via a direct request.
|
NVD-CWE-Other
|
CVE-2006-7014
|
2018-10-17 01:29 |
2007-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284172
|
- |
|
phpjobboard
|
phpjobboard
|
phpjobboard allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin.php with adminop=job-edit.
|
NVD-CWE-Other
|
CVE-2006-7016
|
2018-10-17 01:29 |
2007-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284173
|
- |
|
fx-app
|
fx-app
|
The Tools module in fx-APP 0.0.8.1 allows remote attackers to misrepresent the contents of a web page via an arbitrary URL in the url parameter to a showhtml action for index.php, which causes the UR…
|
NVD-CWE-Other
|
CVE-2006-7022
|
2018-10-17 01:29 |
2007-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284174
|
- |
|
fx-app
|
fx-app
|
Multiple cross-site scripting (XSS) vulnerabilities in fx-APP 0.0.8.1 allow remote attackers to inject arbitrary HTML or web script via (1) the search box, and the (2) url, (3) website, (4) comment, …
|
NVD-CWE-Other
|
CVE-2006-7023
|
2018-10-17 01:29 |
2007-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284175
|
- |
|
microsoft
|
isa_server
|
Microsoft Internet Security and Acceleration (ISA) Server 2004 logs unusual ASCII characters in the Host header, including the tab, which allows remote attackers to manipulate portions of the log fil…
|
NVD-CWE-Other
|
CVE-2006-7027
|
2018-10-17 01:29 |
2007-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284176
|
- |
|
microsoft
|
ie
|
Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via certain malformed HTML, possibly involving applet and base tags without required argumen…
|
NVD-CWE-Other
|
CVE-2006-7030
|
2018-10-17 01:29 |
2007-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284177
|
- |
|
super_link_exchange_script
|
super_link_exchange_script
|
Cross-site scripting (XSS) vulnerability in Super Link Exchange Script 1.0 allows remote attackers to inject arbitrary web script or HTML via IMG tags in the search box.
|
NVD-CWE-Other
|
CVE-2006-7033
|
2018-10-17 01:29 |
2007-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284178
|
- |
|
super_link_exchange_script
|
super_link_exchange_script
|
SQL injection vulnerability in directory.php in Super Link Exchange Script 1.0 might allow remote attackers to execute arbitrary SQL queries via the cat parameter.
|
NVD-CWE-Other
|
CVE-2006-7034
|
2018-10-17 01:29 |
2007-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284179
|
- |
|
super_link_exchange_script
|
super_link_exchange_script
|
Directory traversal vulnerability in make_thumbnail.php in Super Link Exchange Script 1.0 allows remote attackers to read arbitrary files via ".." sequences in the imgpath parameter.
|
NVD-CWE-Other
|
CVE-2006-7035
|
2018-10-17 01:29 |
2007-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284180
|
- |
|
andys_chat
|
andys_chat
|
PHP remote file inclusion vulnerability in register.php for Andys Chat 4.5 allows remote attackers to execute arbitrary code via the action parameter. NOTE: this issue was announced by an unreliable…
|
NVD-CWE-Other
|
CVE-2006-7036
|
2018-10-17 01:29 |
2007-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|