|
357451
|
5.0 |
MEDIUM
|
amule
|
amule
|
Multiple unspecified vulnerabilities in aMuleWeb for AMule before 2.1.2 allow remote attackers to read arbitrary image, HTML, or PHP files via unknown vectors, probably related to directory traversal.
|
NVD-CWE-Other
|
CVE-2006-2692
|
2008-09-6 06:05 |
2006-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357452
|
5.0 |
MEDIUM
|
amule
|
amule
|
Successful exploitation requires that the full pathname of the file is known.
This vulnerability is addressed in the following product release:
aMule, aMule, 2.1.2
|
NVD-CWE-Other
|
CVE-2006-2692
|
2008-09-6 06:05 |
2006-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357453
|
5.0 |
MEDIUM
|
jetty
|
jetty
|
Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the same issue as CVE-2…
|
CWE-22
パス・トラバーサル
|
CVE-2006-2758
|
2008-09-6 06:05 |
2006-06-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357454
|
5.0 |
MEDIUM
|
jetty
|
jetty
|
jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary script source code via a capital P in the .jsp extension, and probably other mixed case manipulations.
|
NVD-CWE-Other
|
CVE-2006-2759
|
2008-09-6 06:05 |
2006-06-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357455
|
6.8 |
MEDIUM
|
xiti
|
xiti_tracking_script
|
Multiple cross-site scripting (XSS) vulnerabilities in XiTi Tracking Script 6 and 7 RC allow remote attackers to inject arbitrary web script or HTML via (1) the xtref parameter in xiti.js and (2) an …
|
NVD-CWE-Other
|
CVE-2006-2795
|
2008-09-6 06:05 |
2006-06-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357456
|
5.0 |
MEDIUM
|
jelsoft
|
vbulletin
|
SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter.
|
NVD-CWE-Other
|
CVE-2006-2805
|
2008-09-6 06:05 |
2006-06-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357457
|
4.3 |
MEDIUM
|
visiongate
|
visiongate_portal_system
|
Cross-site scripting (XSS) vulnerability in Print.PHP in VisionGate Portal System allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: The provenance of t…
|
NVD-CWE-Other
|
CVE-2006-2846
|
2008-09-6 06:05 |
2006-06-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357458
|
4.3 |
MEDIUM
|
skoom
|
i.list
|
Cross-site scripting (XSS) vulnerability in i.List 1.5 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the banurl parameter to add.php. NOTE: the provenance of th…
|
NVD-CWE-Other
|
CVE-2006-2957
|
2008-09-6 06:05 |
2006-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357459
|
7.5 |
HIGH
|
arantius
|
vice_stats
|
SQL injection vulnerability in vs_search.php in Arantius Vice Stats before 1.0.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors, a different issue than CVE-2006-2972.
|
NVD-CWE-Other
|
CVE-2006-2981
|
2008-09-6 06:05 |
2006-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357460
|
5.8 |
MEDIUM
|
vizra
|
vizra
|
Cross-site scripting (XSS) vulnerability in a_login.php in Vizra allows remote attackers to inject arbitrary web script or HTML via the message parameter.
|
NVD-CWE-Other
|
CVE-2006-2365
|
2008-09-6 06:04 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357461
|
2.6 |
LOW
|
unclassified_newsboard
|
unclassified_newsboard
|
Directory traversal vulnerability in bb_lib/abbc.css.php in Unclassified NewsBoard (UNB) 1.5.3-d and possibly earlier versions, when register_globals is enabled, allows remote attackers to include ar…
|
NVD-CWE-Other
|
CVE-2006-2406
|
2008-09-6 06:04 |
2006-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357462
|
5.0 |
MEDIUM
|
pioneers
|
pioneers_meta-server
|
Pioneers meta-server before 0.9.55, when the server-console is not installed, allows remote attackers to cause a denial of service (crash) via certain requests from an older gnocatan client to create…
|
NVD-CWE-Other
|
CVE-2006-2441
|
2008-09-6 06:04 |
2006-05-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357463
|
5.0 |
MEDIUM
|
pioneers
|
pioneers_meta-server
|
Successful exploitation requires that the server-console is not installed.
This vulnerability is addressed in the following product release:
Pioneers, Pioneers, 0.9.49
|
NVD-CWE-Other
|
CVE-2006-2441
|
2008-09-6 06:04 |
2006-05-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357464
|
4.6 |
MEDIUM
|
knowledgetree
|
knowledgetree
|
The Debian package of knowledgetree 2.0.7 creates environment.php with world-readable permissions, which allows local users to obtain sensitive information such as the username and password for the K…
|
NVD-CWE-Other
|
CVE-2006-2443
|
2008-09-6 06:04 |
2006-05-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357465
|
5.0 |
MEDIUM
|
out_of_the_trees_web_design
|
selectapix
|
view_album.php in SelectaPix 1.31 and earlier allows remote attackers to obtain the installation path via a certain request, which displays the path in an error message, possibly due to an invalid or…
|
NVD-CWE-Other
|
CVE-2006-2463
|
2008-09-6 06:04 |
2006-05-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357466
|
7.5 |
HIGH
|
s9y
|
serendipity
|
config.php in S9Y Serendipity 1.0 beta 2 allows remote attackers to inject arbitrary PHP code by editing values that are stored in config.php and later executed. NOTE: the provenance of this informa…
|
NVD-CWE-Other
|
CVE-2006-1910
|
2008-09-6 06:03 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357467
|
5.0 |
MEDIUM
|
dbbs
|
dbbs
|
SQL injection vulnerability in topics.php in DbbS 2.0-alpha and earlier allows remote attackers to execute arbitrary SQL commands via the fcategoryid parameter.
|
NVD-CWE-Other
|
CVE-2006-1915
|
2008-09-6 06:03 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357468
|
4.0 |
MEDIUM
|
ibm
|
lotus_notes
|
The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Boo…
|
NVD-CWE-Other
|
CVE-2006-1948
|
2008-09-6 06:03 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357469
|
7.5 |
HIGH
|
mybulletinboard
|
mybulletinboard
|
SQL injection vulnerability in index.php in MyBB (MyBulletinBoard) before 1.04 allows remote attackers to execute arbitrary SQL commands via the referrer parameter.
|
NVD-CWE-Other
|
CVE-2006-1974
|
2008-09-6 06:03 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357470
|
2.6 |
LOW
|
stadtaus.com
|
php-gastebuch
|
Cross-site scripting (XSS) vulnerability in guestbook_newentry.php in PHP-Gastebuch 1.61 allows remote attackers to inject arbitrary web script or HTML via the Kommentar field.
|
NVD-CWE-Other
|
CVE-2006-1975
|
2008-09-6 06:03 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357471
|
2.6 |
LOW
|
geekforgod.net
|
prayer_request_board
|
Cross-site scripting (XSS) vulnerability in addRequest.php in Prayer Request Board (PRB) Beta 1 before 20060320 allows remote attackers to inject arbitrary web script or HTML via the Request field.
|
NVD-CWE-Other
|
CVE-2006-1976
|
2008-09-6 06:03 |
2006-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357472
|
7.5 |
HIGH
|
php_thumbnail_autoindex
|
php_thumbnail_autoindex
|
PHP remote file inclusion vulnerability in Thumbnail AutoIndex before 2.0 allows remote attackers to execute arbitrary PHP code via (1) README.html or (2) HEADER.html.
|
NVD-CWE-Other
|
CVE-2006-2098
|
2008-09-6 06:03 |
2006-04-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357473
|
5.0 |
MEDIUM
|
jupiter_cms
|
jupiter_cms
|
Directory traversal vulnerability in index.php in Jupiter CMS 1.1.4 and 1.1.5 allows remote attackers to read arbitrary files via ".." sequences terminated by a %00 (null) character in the n paramete…
|
NVD-CWE-Other
|
CVE-2006-2105
|
2008-09-6 06:03 |
2006-04-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357474
|
6.4 |
MEDIUM
|
duware
|
duclassified
|
SQL injection vulnerability in detail.asp in DUclassified allows remote attackers to execute arbitrary SQL commands via the iPro parameter. NOTE: the provenance of this information is unknown; the d…
|
NVD-CWE-Other
|
CVE-2006-2132
|
2008-09-6 06:03 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357475
|
7.5 |
HIGH
|
invision_power_services
|
invision_power_board
|
SQL injection vulnerability in index.php in Invision Power Board allows remote attackers to execute arbitrary SQL commands via the pid parameter in a reputation action. NOTE: the provenance of this …
|
NVD-CWE-Other
|
CVE-2006-2217
|
2008-09-6 06:03 |
2006-05-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357476
|
5.0 |
MEDIUM
|
internet_key_exchange
|
internet_key_exchange
|
The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in the Shoichi Sakane KAME Project racoon, as used by NetBSD 1.6, 2.x before 20060119, certain FreeBSD releases, and possibly…
|
NVD-CWE-Other
|
CVE-2006-1646
|
2008-09-6 06:02 |
2006-04-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357477
|
7.2 |
HIGH
|
vserver
|
util-vserver
|
vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is invalid and non-numeric, which might cause local users to inadvertently execute dangerous commands as r…
|
NVD-CWE-Other
|
CVE-2006-1656
|
2008-09-6 06:02 |
2006-04-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357478
|
2.6 |
LOW
|
phpwebgallery
|
phpwebgallery
|
Cross-site scripting (XSS) vulnerability in search.php in PHPWebGallery 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vulnerability than CVE-2…
|
NVD-CWE-Other
|
CVE-2006-1674
|
2008-09-6 06:02 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357479
|
7.5 |
HIGH
|
aweb
|
scripts_seller
|
Buy.php in Aweb Scripts Seller uses predictable cookies for authentication based on the time and the script number, which allows remote attackers to bypass authentication.
|
NVD-CWE-Other
|
CVE-2006-1700
|
2008-09-6 06:02 |
2006-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357480
|
4.6 |
MEDIUM
|
joey_hess
|
bsdgames
|
Buffer overflow in pl_main.c in sail in BSDgames before 2.17-7 allows local users to execute arbitrary code via a long player name that is used in a scanf function call.
|
NVD-CWE-Other
|
CVE-2006-1744
|
2008-09-6 06:02 |
2006-04-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357481
|
7.2 |
HIGH
|
debian
|
debian_linux
|
debconf in Debian GNU/Linux, when configuring mnogosearch in the mnogosearch-common 3.2.31-1 package, uses the world-readable config.dat file instead of the restricted passwords.dat for storing the c…
|
NVD-CWE-Other
|
CVE-2006-1772
|
2008-09-6 06:02 |
2006-04-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357482
|
4.3 |
MEDIUM
|
phpbb_group
|
phpbb
|
Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.19 allow remote attackers to inject arbitrary web script or HTML via the (1) Site Description field in (a) admin_board.php, the (2) Gr…
|
NVD-CWE-Other
|
CVE-2006-1775
|
2008-09-6 06:02 |
2006-04-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357483
|
10.0 |
HIGH
|
mailenable
|
mailenable_enterprise mailenable_professional mailenable_standard
|
Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edition before 1.22 has unknown attack vectors and impact rel…
|
NVD-CWE-Other
|
CVE-2006-1792
|
2008-09-6 06:02 |
2006-04-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357484
|
7.6 |
HIGH
|
runcms
|
runcms
|
Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) class.forumposts.php and (2) forumpollrenderer.php. N…
|
NVD-CWE-Other
|
CVE-2006-1793
|
2008-09-6 06:02 |
2006-04-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357485
|
7.6 |
HIGH
|
runcms
|
runcms
|
Succesful exploitation requires that register_globals = On & allow_url_fopen = On
|
NVD-CWE-Other
|
CVE-2006-1793
|
2008-09-6 06:02 |
2006-04-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357486
|
6.8 |
MEDIUM
|
wordpress
|
wordpress
|
Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other versions before 2.0.1, allows remote attackers to inj…
|
NVD-CWE-Other
|
CVE-2006-1796
|
2008-09-6 06:02 |
2006-04-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357487
|
6.8 |
MEDIUM
|
wordpress
|
wordpress
|
The vulnerability manifests itself only when viewed by IE.
This vulnerability is addressed in the following product release:
Wordpress 2.0.1-1
|
NVD-CWE-Other
|
CVE-2006-1796
|
2008-09-6 06:02 |
2006-04-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357488
|
7.5 |
HIGH
|
datenbank_module woltlab
|
datenbank_module burning_board
|
SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) dat…
|
NVD-CWE-Other
|
CVE-2006-1094
|
2008-09-6 06:01 |
2006-03-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357489
|
7.5 |
HIGH
|
logit
|
logit
|
PHP remote file include vulnerability in logIT 1.3 and 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter. NOTE: the provenance of this information is unknown; t…
|
NVD-CWE-Other
|
CVE-2006-1099
|
2008-09-6 06:01 |
2006-03-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357490
|
7.5 |
HIGH
|
nodez
|
nodez
|
Nodez 4.6.1.1 and earlier stores sensitive data in the list.gtdat file under the web document root with insufficient access control, which allows remote attackers to obtain usernames and password has…
|
NVD-CWE-Other
|
CVE-2006-1164
|
2008-09-6 06:01 |
2006-03-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357491
|
4.3 |
MEDIUM
|
runcms
|
runcms
|
Cross-site scripting (XSS) vulnerability in bigshow.php in Runcms 1.x allows remote attackers to inject arbitrary web script or HTML via the id parameter.
|
NVD-CWE-Other
|
CVE-2006-1216
|
2008-09-6 06:01 |
2006-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357492
|
4.3 |
MEDIUM
|
wordpress
|
wordpress
|
Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in WordPress before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-1263
|
2008-09-6 06:01 |
2006-03-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357493
|
4.3 |
MEDIUM
|
university_of_washington
|
pubcookie
|
Multiple cross-site scripting (XSS) vulnerabilities in the Microsoft IIS ISAPI filter (aka application server module) in University of Washington Pubcookie 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 be…
|
NVD-CWE-Other
|
CVE-2006-1394
|
2008-09-6 06:01 |
2006-03-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357494
|
4.3 |
MEDIUM
|
upoint
|
at1_event_publisher
|
Multiple cross-site scripting (XSS) vulnerabilities in UPOINT @1 Event Publisher allow remote attackers to inject arbitrary web script or HTML via the (1) Event, (2) Description, (3) Time, (4) Websit…
|
NVD-CWE-Other
|
CVE-2006-1436
|
2008-09-6 06:01 |
2006-04-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357495
|
5.0 |
MEDIUM
|
upoint
|
at1_event_publisher
|
UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attackers to read private comments via a direct request to eve…
|
NVD-CWE-Other
|
CVE-2006-1437
|
2008-09-6 06:01 |
2006-04-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357496
|
5.0 |
MEDIUM
|
avaya
|
vsu_100 vsu_10000 vsu_2000 vsu_7500 csu_5000
|
The Internet Key Exchange version 1 (IKEv1) implementation in Avaya VSU 100, 2000, 7500, 10000, and CSU 5000, when running IPSec, allows remote attackers to cause a denial of service (crash) via cert…
|
NVD-CWE-Other
|
CVE-2006-0718
|
2008-09-6 06:00 |
2006-02-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357497
|
7.5 |
HIGH
|
nocc
|
nocc
|
NOCC Webmail 1.0 stores e-mail attachments in temporary files with predictable filenames, which makes it easier for remote attackers to execute arbitrary code by accessing the e-mail attachment via d…
|
NVD-CWE-Other
|
CVE-2006-0892
|
2008-09-6 06:00 |
2006-02-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357498
|
5.0 |
MEDIUM
|
nocc
|
nocc
|
NOCC Webmail 1.0 allows remote attackers to obtain sensitive information via a direct request to (1) the profiles directory, which leaks e-mail addresses contained in filenames of profiles, and (2) t…
|
NVD-CWE-Other
|
CVE-2006-0893
|
2008-09-6 06:00 |
2006-02-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357499
|
4.3 |
MEDIUM
|
nocc
|
nocc
|
Multiple cross-site scripting (XSS) vulnerabilities in NOCC Webmail 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the html_error_occurred parameter in error.php, (2) html_…
|
NVD-CWE-Other
|
CVE-2006-0894
|
2008-09-6 06:00 |
2006-02-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357500
|
5.0 |
MEDIUM
|
nocc
|
nocc
|
NOCC Webmail 1.0 allows remote attackers to obtain the installation path via a direct request to html/header.php.
|
NVD-CWE-Other
|
CVE-2006-0895
|
2008-09-6 06:00 |
2006-02-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|