Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-7076 | 1 Phpbb Group | 1 Phpbb Advanced Guestbook | 2017-07-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to inject arbitrary web script or HTML via the entry parameter. NOTE: this issue might be resultant from SQL injection. | |||||
CVE-2006-7077 | 1 Phpbb Group | 1 Phpbb Advanced Guestbook | 2017-07-28 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to execute arbitrary SQl commands via the entry parameter. | |||||
CVE-2006-7082 | 1 Rigter Portal System | 1 Rigter Portal System | 2017-07-28 | 7.5 HIGH | N/A |
Rigter Portal System (RPS) 1.0, 2.0, and 3.0 allows remote attackers to bypass authentication and upload arbitrary files via direct requests to (1) adm/photos/images.php and (2) adm/down/files.php. | |||||
CVE-2006-7083 | 1 Rigter Portal System | 1 Rigter Portal System | 2017-07-28 | 4.3 MEDIUM | N/A |
Directory traversal vulnerability in index.php in Rigter Portal System (RPS) 1.0, 2.0, and 3.0 allows remote attackers to read arbitrary files via ".." sequences in the id parameter. | |||||
CVE-2006-7085 | 1 Rigter Portal System | 1 Rigter Portal System | 2017-07-28 | 4.3 MEDIUM | N/A |
Rigter Portal System (RPS) 1.0, 2.0, and 3.0 allows remote attackers to add arbitrary content and conduct XSS attacks via a direct request to add_art.php. NOTE: this issue was originally reported as SQL injection, but this is not likely. | |||||
CVE-2006-7088 | 1 Simple Php Forum | 1 Simple Php Forum | 2017-07-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Simple PHP Forum before 0.4 allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) logon_user.php and (2) update_profile.php. | |||||
CVE-2006-7089 | 1 Ban | 1 Ban | 2017-07-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in connexion.php in Ban 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2006-7090 | 1 Phpbb Security | 1 Phpbb Security | 2017-07-28 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in phpbb_security.php in phpBB Security 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the php_root_path parameter. | |||||
CVE-2006-7095 | 1 Klink | 1 Dim3 | 2017-07-28 | 10.0 HIGH | N/A |
Integer signedness error in the network_receive_packet function in socket.c in dimension 3 engine (dim3) 1.5 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large data_len value, which is cast to a signed short and results in a buffer overflow. | |||||
CVE-2006-7096 | 1 Klink | 1 Dim3 | 2017-07-28 | 10.0 HIGH | N/A |
Buffer overflow in the network_host_handle_join function in host.c in dimension 3 engine (dim3) 1.5 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long nickname. | |||||
CVE-2006-7098 | 1 Debian | 1 Apache | 2017-07-28 | 6.6 MEDIUM | N/A |
The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl. | |||||
CVE-2006-7104 | 1 Mambo | 1 Mostlyce | 2017-07-28 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a component for Mambo 4.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |||||
CVE-2006-7105 | 1 Smarty | 1 Smarty | 2017-07-28 | 7.5 HIGH | N/A |
** DISPUTED ** PHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty 2.6.9 allows remote attackers to execute arbitrary PHP code via a URL in the filename parameter. NOTE: in the original disclosure, filename is used in a function definition, so this report is probably incorrect. | |||||
CVE-2006-7109 | 1 Drupal | 1 Imce Module | 2017-07-28 | 6.5 MEDIUM | N/A |
Unrestricted file upload vulnerability in IMCE before 1.6, a Drupal module, allows remote authenticated users to upload arbitrary PHP code via a filename with a double extension such as .php.gif. | |||||
CVE-2006-7110 | 1 Drupal | 1 Imce Module | 2017-07-28 | 5.5 MEDIUM | N/A |
Directory traversal vulnerability in the delete function in IMCE before 1.6, a Drupal module, allows remote authenticated users to delete arbitrary files via ".." sequences. | |||||
CVE-2006-7111 | 1 Futomis Cgi Cafe | 1 Kmail Cgi | 2017-07-28 | 7.5 HIGH | N/A |
Unspecified vulnerability in Futomi's CGI Cafe KMail CGI 1.0.3 and earlier allows remote attackers to bypass authentication and obtain unauthorized email access via unspecified vectors. | |||||
CVE-2006-7113 | 1 Planerd.net | 1 P-news | 2017-07-28 | 7.5 HIGH | N/A |
Unrestricted file upload vulnerability in P-News 2.0 allows remote attackers to upload and execute arbitrary files via an avatar file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2006-7114 | 1 Planerd.net | 1 P-news | 2017-07-28 | 5.0 MEDIUM | N/A |
P-News 2.0 stores db/user.txt under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and password hashes via a direct request. NOTE: this might be the same issue as CVE-2006-6888. | |||||
CVE-2006-7121 | 1 Linksys | 1 Spa921 | 2017-07-28 | 7.8 HIGH | N/A |
The HTTP server in Linksys SPA-921 VoIP Desktop Phone allows remote attackers to cause a denial of service (reboot) via (1) a long URL, or a long (2) username or (3) password during Basic Authentication. | |||||
CVE-2006-7133 | 1 Php Upload Tool | 1 Php Upload Tool | 2017-07-28 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in upload/bin/download.php in Upload Tool for PHP 1.0 allows remote attackers to read arbitrary files via (1) ".." sequences or (2) absolute pathnames in the filename parameter. |