|
346141
|
- |
|
webspell
|
webspell
|
Successful exploitation requires that "magic_quotes_gpc" is disabled.
|
NVD-CWE-Other
|
CVE-2006-4783
|
2017-07-20 10:33 |
2006-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346142
|
- |
|
moodle
|
moodle
|
Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.6.1 and earlier might allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) doc/index.php or …
|
NVD-CWE-Other
|
CVE-2006-4784
|
2017-07-20 10:33 |
2006-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346143
|
- |
|
moodle
|
moodle
|
Moodle 1.6.1 and earlier allows remote attackers to obtain sensitive information via (1) help.php and (2) other unspecified vectors involving scheduled backups.
|
NVD-CWE-Other
|
CVE-2006-4786
|
2017-07-20 10:33 |
2006-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346144
|
- |
|
alphamail
|
alphamail
|
AlphaMail before 1.0.16 allows local users to obtain sensitive information via the logging functionality, which displays unencrypted passwords in an error message. NOTE: some details are obtained fr…
|
NVD-CWE-Other
|
CVE-2006-4787
|
2017-07-20 10:33 |
2006-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346145
|
- |
|
dws_systems_inc.
|
sql-ledger
|
SQL-Ledger before 2.4.4 stores a password in a query string, which might allow context-dependent attackers to obtain the password via a Referer field or browser history.
|
NVD-CWE-Other
|
CVE-2006-4798
|
2017-07-20 10:33 |
2006-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346146
|
- |
|
drupal
|
drupal_userreview_module
|
Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Userreview module before 1.19 2006/09/12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-4821
|
2017-07-20 10:33 |
2006-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346147
|
- |
|
emusoft
|
emucms
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in eMuSOFT emuCMS 0.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) query or (2) page paramete…
|
NVD-CWE-Other
|
CVE-2006-4822
|
2017-07-20 10:33 |
2006-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346148
|
- |
|
claroline dokeos
|
claroline open_source_learning_and_knowledge_management_tool
|
PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to execute arbitrary PHP…
|
CWE-94
Code Injection
|
CVE-2006-4844
|
2017-07-20 10:33 |
2006-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346149
|
- |
|
claroline dokeos
|
claroline open_source_learning_and_knowledge_management_tool
|
Successful exploitation requires that "register_globals" is enabled.
This vulnerability is addressed in the following product release:
Claroline, Claroline, 1.7.8
|
CWE-94
Code Injection
|
CVE-2006-4844
|
2017-07-20 10:33 |
2006-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346150
|
- |
|
citrix
|
access_gateway
|
Unspecified vulnerability in Citrix Access Gateway with Advanced Access Control (AAC) 4.2 before 20060914, when AAC is configured to use LDAP authentication, allows remote attackers to bypass authent…
|
NVD-CWE-Other
|
CVE-2006-4846
|
2017-07-20 10:33 |
2006-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|