|
357401
|
10.0 |
HIGH
|
blojsom
|
blojsom
|
Directory traversal vulnerability in EditBlogTemplatesPlugin.java in David Czarnecki Blojsom 2.30 allows remote attackers to have an unknown impact by sending an HTTP request with a certain value of …
|
NVD-CWE-Other
|
CVE-2006-4830
|
2008-09-6 06:10 |
2006-09-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357402
|
10.0 |
HIGH
|
blojsom
|
blojsom
|
This vulnerability is addressed in the following product release:
Blojsom, Blojsom, 2.31
|
NVD-CWE-Other
|
CVE-2006-4830
|
2008-09-6 06:10 |
2006-09-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357403
|
10.0 |
HIGH
|
limbo_cms
|
limbo_cms
|
Multiple unspecified vulnerabilities in (1) index.php, (2) minixml.inc.php, (3) doc.inc.php, (4) element.inc.php, (5) node.inc.php, (6) treecomp.inc.php, (7) forum.html.php, (8) forum.php, (9) antiha…
|
NVD-CWE-Other
|
CVE-2006-4860
|
2008-09-6 06:10 |
2006-09-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357404
|
4.6 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
Buffer overflow in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via a long extension argument.
|
NVD-CWE-Other
|
CVE-2006-4866
|
2008-09-6 06:10 |
2006-09-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357405
|
4.3 |
MEDIUM
|
idevspot
|
isupport
|
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 allow remote attackers to inject arbitrary web script or HTML via (1) the suser parameter in support/rightbar.php, (2) the…
|
NVD-CWE-Other
|
CVE-2006-4884
|
2008-09-6 06:10 |
2006-09-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357406
|
5.0 |
MEDIUM
|
microsoft
|
ie
|
Microsoft Internet Explorer 6 and earlier allows remote attackers to cause a denial of service (application hang) via a CSS-formatted HTML INPUT element within a DIV element that has a larger size th…
|
NVD-CWE-Other
|
CVE-2006-4888
|
2008-09-6 06:10 |
2006-09-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357407
|
4.9 |
MEDIUM
|
novell
|
edirectory
|
Unspecified vulnerability in the NCPENGINE in Novell eDirectory 8.7.3.8 allows local users to cause a denial of service (CPU consumption) via unspecified vectors, as originally demonstrated using a N…
|
NVD-CWE-Other
|
CVE-2006-4185
|
2008-09-6 06:09 |
2006-08-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357408
|
4.9 |
MEDIUM
|
novell
|
edirectory
|
This vulnerability is addressed in the following product release:
Novell, eDirectory, 8.7.3 SP9
|
NVD-CWE-Other
|
CVE-2006-4185
|
2008-09-6 06:09 |
2006-08-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357409
|
2.1 |
LOW
|
novell
|
edirectory
|
The iManager in eMBoxClient.jar in Novell eDirectory 8.7.3.8 writes passwords in plaintext to a log file, which allows local users to obtain passwords by reading the file.
|
NVD-CWE-Other
|
CVE-2006-4186
|
2008-09-6 06:09 |
2006-08-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357410
|
4.3 |
MEDIUM
|
panda
|
panda_activescan
|
Cross-site scripting (XSS) vulnerability in ascan_6.asp in Panda ActiveScan 5.53.00 allows remote attackers to inject arbitrary web script or HTML via the email parameter.
|
NVD-CWE-Other
|
CVE-2006-4295
|
2008-09-6 06:09 |
2006-08-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357411
|
5.0 |
MEDIUM
|
cisco
|
content_services_switch_11000
|
The ArrowPoint cookie functionality for Cisco 11000 series Content Service Switches specifies an internal IP address if the administrator does not specify a string option, which allows remote attacke…
|
NVD-CWE-Other
|
CVE-2006-4352
|
2008-09-6 06:09 |
2006-08-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357412
|
7.5 |
HIGH
|
redblog
|
redblog
|
PHP remote file inclusion vulnerability in index.php in RedBLoG 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. NOTE: the provenance of this informati…
|
NVD-CWE-Other
|
CVE-2006-4366
|
2008-09-6 06:09 |
2006-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357413
|
4.3 |
MEDIUM
|
pmwiki
|
pmwiki
|
Cross-site scripting (XSS) vulnerability in PmWiki before 2.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "table markups".
|
NVD-CWE-Other
|
CVE-2006-4453
|
2008-09-6 06:09 |
2006-08-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357414
|
10.0 |
HIGH
|
paessler
|
ipcheck_server_monitor
|
Paessler IPCheck Server Monitor before 5.3.3.639/640 does not properly implement a "list of acceptable host IP addresses in the probe settings," which has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2006-4461
|
2008-09-6 06:09 |
2006-09-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357415
|
5.0 |
MEDIUM
|
moderngigabyte
|
modernbill
|
ModernBill 5.0.4 and earlier uses cURL with insecure settings for CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST that do not verify SSL certificates, which allows remote attackers to read network …
|
NVD-CWE-Other
|
CVE-2006-4499
|
2008-09-6 06:09 |
2006-09-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357416
|
4.3 |
MEDIUM
|
devellion
|
cubecart
|
Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the links array.
|
NVD-CWE-Other
|
CVE-2006-4525
|
2008-09-6 06:09 |
2006-09-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357417
|
7.5 |
HIGH
|
devellion
|
cubecart
|
SQL injection vulnerability in includes/content/viewCat.inc.php in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the sea…
|
NVD-CWE-Other
|
CVE-2006-4526
|
2008-09-6 06:09 |
2006-09-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357418
|
2.6 |
LOW
|
devellion
|
cubecart
|
includes/content/gateway.inc.php in CubeCart 3.0.12 and earlier, when magic_quotes_gpc is disabled, uses an insufficiently restrictive regular expression to validate the gateway parameter, which allo…
|
NVD-CWE-Other
|
CVE-2006-4527
|
2008-09-6 06:09 |
2006-09-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357419
|
5.0 |
MEDIUM
|
ibm
|
lotus_notes
|
IBM Lotus Notes 6.0, 6.5, and 7.0 does not properly handle replies to e-mail messages with alternate name users when the (1) "Save As Draft" option is used or (2) a "," (comma) is inside the "phrase"…
|
NVD-CWE-Other
|
CVE-2006-3778
|
2008-09-6 06:08 |
2006-07-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357420
|
4.0 |
MEDIUM
|
kailash_nadh
|
boastmachine
|
The Languages selection in the admin interface in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to upload files with arbitrary extensions to…
|
NVD-CWE-Other
|
CVE-2006-3830
|
2008-09-6 06:08 |
2006-07-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357421
|
4.3 |
MEDIUM
|
dokeos
|
dokeos
|
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos before 1.6.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-3924
|
2008-09-6 06:08 |
2006-07-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357422
|
5.0 |
MEDIUM
|
pswd.js
|
pswd.js
|
The pswd.js script relies on the client to calculate whether a username and password match hard-coded hashed values for a server, and uses a hashing scheme that creates a large number of collisions, …
|
CWE-255
証明書・パスワード管理
|
CVE-2006-4068
|
2008-09-6 06:08 |
2006-08-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357423
|
10.0 |
HIGH
|
david_walker
|
phpautomembersarea
|
Unspecified vulnerability in phpAutoMembersArea (phpAMA) before 3.2.4 has unknown impact and attack vectors, related to "a potential security exploit which is critical."
|
NVD-CWE-Other
|
CVE-2006-4084
|
2008-09-6 06:08 |
2006-08-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357424
|
10.0 |
HIGH
|
david_walker
|
phpautomembersarea
|
Upgrade to 3.2.4
|
NVD-CWE-Other
|
CVE-2006-4084
|
2008-09-6 06:08 |
2006-08-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357425
|
6.4 |
MEDIUM
|
tor
|
tor
|
TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier for remote attackers to conduct brute force attacks on the en…
|
NVD-CWE-Other
|
CVE-2006-3411
|
2008-09-6 06:07 |
2006-07-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357426
|
6.4 |
MEDIUM
|
tor
|
tor
|
Tor before 0.1.1.20 does not sufficiently obey certain firewall options, which allows remote attackers to bypass intended access restrictions for dirservers, direct connections, or proxy servers.
|
NVD-CWE-Other
|
CVE-2006-3412
|
2008-09-6 06:07 |
2006-07-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357427
|
5.0 |
MEDIUM
|
tor
|
tor
|
The privoxy configuration file in Tor before 0.1.1.20, when run on Apple OS X, logs all data via the "logfile", which allows attackers to obtain potentially sensitive information.
|
NVD-CWE-Other
|
CVE-2006-3413
|
2008-09-6 06:07 |
2006-07-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357428
|
5.0 |
MEDIUM
|
tor
|
tor
|
Tor before 0.1.1.20 supports server descriptors that contain hostnames instead of IP addresses, which allows remote attackers to arbitrarily group users by providing preferential address resolution.
|
NVD-CWE-Other
|
CVE-2006-3414
|
2008-09-6 06:07 |
2006-07-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357429
|
6.4 |
MEDIUM
|
tor
|
tor
|
Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITM) attack via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-3415
|
2008-09-6 06:07 |
2006-07-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357430
|
6.4 |
MEDIUM
|
tor
|
tor
|
Tor client before 0.1.1.20 prefers entry points based on is_fast or is_stable flags, which could allow remote attackers to be preferred over nodes that are identified as more trustworthy "entry guard…
|
NVD-CWE-Other
|
CVE-2006-3417
|
2008-09-6 06:07 |
2006-07-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357431
|
5.0 |
MEDIUM
|
tor
|
tor
|
Tor before 0.1.1.20 does not validate that a server descriptor's fingerprint line matches its identity key, which allows remote attackers to spoof the fingerprint line, which might be trusted by user…
|
NVD-CWE-Other
|
CVE-2006-3418
|
2008-09-6 06:07 |
2006-07-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357432
|
5.0 |
MEDIUM
|
tor
|
tor
|
Tor before 0.1.1.20 uses OpenSSL pseudo-random bytes (RAND_pseudo_bytes) instead of cryptographically strong RAND_bytes, and seeds the entropy value at start-up with 160-bit chunks without reseeding,…
|
NVD-CWE-Other
|
CVE-2006-3419
|
2008-09-6 06:07 |
2006-07-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357433
|
5.0 |
MEDIUM
|
phpmaillist
|
phpmaillist
|
PHPMailList 1.8.0 stores sensitive information under the web document root iwth insufficient access control, which allows remote attackers to obtain email addresses of subscribers, configuration info…
|
NVD-CWE-Other
|
CVE-2006-3483
|
2008-09-6 06:07 |
2006-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357434
|
5.0 |
MEDIUM
|
virtuastore
|
virtuastore
|
VirtuaStore 2.0 stores sensitive files under the web root with insufficient access control, which allows remote attackers to obtain local database information by directly accessing database/virtuasto…
|
NVD-CWE-Other
|
CVE-2006-3487
|
2008-09-6 06:07 |
2006-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357435
|
5.0 |
MEDIUM
|
virtuastore
|
virtuastore
|
Absolute path traversal vulnerability in administrador.asp in VirtuaStore 2.0 allows remote attackers to possibly read arbitrary directories or files via an absolute path with Windows drive letter in…
|
NVD-CWE-Other
|
CVE-2006-3488
|
2008-09-6 06:07 |
2006-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357436
|
7.5 |
HIGH
|
sensesites
|
commonsense_cms
|
SQL injection vulnerability in search.php in SenseSites CommonSense CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the Date parameter. NOTE: the provenance of this information…
|
NVD-CWE-Other
|
CVE-2006-3576
|
2008-09-6 06:07 |
2006-07-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357437
|
7.5 |
HIGH
|
lifetype
|
lifetype
|
SQL injection vulnerability in index.php in LifeType 1.0.5 allows remote attackers to execute arbitrary SQL commands via the Date parameter in a Default op.
|
NVD-CWE-Other
|
CVE-2006-3577
|
2008-09-6 06:07 |
2006-07-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357438
|
5.0 |
MEDIUM
|
fujitsu
|
serverview
|
Directory traversal vulnerability in Fujitsu ServerView 2.50 up to 3.60L98 and 4.10L11 up to 4.11L81 allows remote attackers to read arbitrary files via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-3578
|
2008-09-6 06:07 |
2006-07-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357439
|
4.3 |
MEDIUM
|
fujitsu
|
serverview
|
Cross-site scripting (XSS) vulnerability in Fujitsu ServerView 2.50 up to 3.60L98 and 4.10L11 up to 4.11L81 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-3579
|
2008-09-6 06:07 |
2006-07-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357440
|
4.3 |
MEDIUM
|
fujitsu
|
serverview
|
This vulnerability is addressed in the following product releases:
Fujitsu, ServerView, 3.60L99
Fujitsu, ServerView, 4.20L11B
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2006-3579
|
2008-09-6 06:07 |
2006-07-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357441
|
7.2 |
HIGH
|
ubuntu
|
ubuntu_linux
|
passwd before 1:4.0.13 on Ubuntu 6.06 LTS leaves the root password blank instead of locking it when the administrator selects the "Go Back" option after the final "Installation complete" message and …
|
NVD-CWE-Other
|
CVE-2006-3597
|
2008-09-6 06:07 |
2006-07-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357442
|
2.6 |
LOW
|
cutephp
|
cutenews
|
Cross-site scripting (XSS) vulnerability in Index.PHP in CuteNews 1.4.5 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information i…
|
NVD-CWE-Other
|
CVE-2006-3661
|
2008-09-6 06:07 |
2006-07-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357443
|
10.0 |
HIGH
|
kde
|
kdebase
|
The KDE PAM configuration shipped with Fedora Core 5 causes KDM passwords to be cached, which allows attackers to login without a password by attempting to log in multiple times.
|
NVD-CWE-Other
|
CVE-2006-3742
|
2008-09-6 06:07 |
2006-09-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357444
|
6.8 |
MEDIUM
|
lucid_designs
|
lucid_calendar
|
Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea Lucid Calendar 0.22 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: the provenance …
|
NVD-CWE-Other
|
CVE-2006-3025
|
2008-09-6 06:06 |
2006-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357445
|
6.8 |
MEDIUM
|
lucid_designs
|
lucid_calendar
|
Lucid Designs, Lucid Calendar, 0.22 is unsupported. A new, supported version of this product will be released in the near future.
|
NVD-CWE-Other
|
CVE-2006-3025
|
2008-09-6 06:06 |
2006-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357446
|
4.3 |
MEDIUM
|
emailarchitect
|
email_server
|
Cross-site scripting (XSS) vulnerability in EmailArchitect Email Server 6.1 allows remote attackers to inject arbitrary Javascript via an HTML div tag with a carriage return between the onmouseover a…
|
NVD-CWE-Other
|
CVE-2006-3108
|
2008-09-6 06:06 |
2006-06-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357447
|
1.2 |
LOW
|
canonical
|
spread
|
spread uses a temporary file with a static filename based on the port number, which allows local users to cause a denial of service by creating the file during a race condition between unlink and bin…
|
NVD-CWE-Other
|
CVE-2006-3118
|
2008-09-6 06:06 |
2006-07-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357448
|
7.5 |
HIGH
|
mambo
|
mambo
|
SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.
|
NVD-CWE-Other
|
CVE-2006-3263
|
2008-09-6 06:06 |
2006-06-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357449
|
7.5 |
HIGH
|
mpg123
|
mpg123
|
Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not properly terminated before being used with the strnc…
|
NVD-CWE-Other
|
CVE-2006-3355
|
2008-09-6 06:06 |
2006-07-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357450
|
7.2 |
HIGH
|
ubuntu
|
ubuntu_linux
|
passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileg…
|
NVD-CWE-Other
|
CVE-2006-3378
|
2008-09-6 06:06 |
2006-07-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|