Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-3681 | 1 Awstats | 1 Awstats | 2017-07-19 | 2.6 LOW | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in AWStats 6.5 build 1.857 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) refererpagesfilter, (2) refererpagesfilterex, (3) urlfilterex, (4) urlfilter, (5) hostfilter, or (6) hostfilterex parameters, a different set of vectors than CVE-2006-1945. | |||||
CVE-2006-3682 | 1 Awstats | 1 Awstats | 2017-07-19 | 5.0 MEDIUM | N/A |
awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode or (3) month parameters. | |||||
CVE-2006-3695 | 1 Edgewall Software | 1 Trac | 2017-07-19 | 6.8 MEDIUM | N/A |
Trac before 0.9.6 does not disable the "raw" or "include" commands when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows remote attackers to read arbitrary files, perform cross-site scripting (XSS) attacks, or cause a denial of service via unspecified vectors. NOTE: this might be related to CVE-2006-3458. | |||||
CVE-2006-3696 | 1 Agnitum | 1 Outpost Firewall | 2017-07-19 | 2.1 LOW | N/A |
filtnt.sys in Outpost Firewall Pro before 3.51.759.6511 (462) allows local users to cause a denial of service (crash) via long arguments to mshta.exe. | |||||
CVE-2006-3726 | 1 Intervations | 1 Filecopa | 2017-07-19 | 6.5 MEDIUM | N/A |
Buffer overflow in FileCOPA FTP Server before 1.01 released on 18th July 2006, allows remote authenticated attackers to execute arbitrary code via a long argument to the LIST command. | |||||
CVE-2006-3732 | 1 Cisco | 1 Cs-mars | 2017-07-19 | 5.0 MEDIUM | N/A |
Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1 ships with an Oracle database that contains several default accounts and passwords, which allows attackers to obtain sensitive information. | |||||
CVE-2006-3734 | 1 Cisco | 1 Cs-mars | 2017-07-19 | 7.2 HIGH | N/A |
Multiple unspecified vulnerabilities in the Command Line Interface (CLI) for Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allow local CS-MARS administrators to execute arbitrary commands as root. | |||||
CVE-2006-3755 | 1 Flushcms | 1 Flushcms | 2017-07-19 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in Include/editor/class.rich.php in FlushCMS 1.0.0-pre2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the class_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |||||
CVE-2006-3758 | 1 Mybulletinboard | 1 Mybulletinboard | 2017-07-19 | 7.5 HIGH | N/A |
inc/init.php in Archive Mode (Light) in MyBB (aka MyBulletinBoard) 1.1.4 calls the extract function with EXTR_OVERWRITE on HTTP POST and GET variables, which allows remote attackers to overwrite arbitrary variables, as demonstrated via an SQL injection using the _SERVER[HTTP_CLIENT_IP] parameter in archive/index.php. | |||||
CVE-2006-3759 | 1 Mybulletinboard | 1 Mybulletinboard | 2017-07-19 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in MyBB (aka MyBulletinBoard) 1.1.4, related has unspecified impact and attack vectors related to "user group manipulation." | |||||
CVE-2006-3760 | 1 Mybulletinboard | 1 Mybulletinboard | 2017-07-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) 1.1.4 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2006-3776 | 1 Idevspot | 2 Autohost, Phphostbot | 2017-07-19 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in order/index.php in IDevSpot (1) PhpHostBot 1.0 and (2) AutoHost 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | |||||
CVE-2006-3777 | 1 Idevspot | 1 Phplinkexchange | 2017-07-19 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in index.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | |||||
CVE-2006-3783 | 1 Sun | 1 Solaris | 2017-07-19 | 4.9 MEDIUM | N/A |
Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors involving (1) the /net mount point and (2) the "-hosts" map in a mount point. | |||||
CVE-2006-3819 | 1 Twiki | 1 Twiki | 2017-07-19 | 7.5 HIGH | N/A |
Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via an HTTP POST request containing a parameter name starting with "TYPEOF". | |||||
CVE-2006-3820 | 1 Gerrit Van Aaken | 1 Loudblog | 2017-07-19 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in loudblog/index.php in Loudblog before 0.5 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |||||
CVE-2006-3825 | 1 Sun | 1 Solaris | 2017-07-19 | 2.1 LOW | N/A |
The IPv4 implementation in Sun Solaris 10 before 20060721 allows local users to select routes that differ from the routing table, possibly facilitating firewall bypass or unauthorized network communication. | |||||
CVE-2006-3844 | 1 Pablo Software Solutions | 1 Quick N Easy Ftp Server | 2017-07-19 | 6.5 MEDIUM | N/A |
Buffer overflow in Quick 'n Easy FTP Server 3.0 allows remote authenticated users to execute arbitrary commands via a long argument to the LIST command, a different issue than CVE-2006-2027. | |||||
CVE-2006-3845 | 1 Rarlab | 1 Winrar | 2017-07-19 | 9.3 HIGH | N/A |
Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a LHA archive. | |||||
CVE-2006-3887 | 1 Aol | 1 Ygp Screensaver Activex Control | 2017-07-19 | 7.5 HIGH | N/A |
Buffer overflow in AOL You've Got Pictures (YGP) Screensaver ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors. |