Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-2395 | 1 Popsoft Digital | 1 Popphoto | 2017-07-19 | 5.0 MEDIUM | N/A |
PHP remote file inclusion vulnerability in resources/includes/popp.config.loader.inc.php in PopSoft Digital PopPhoto Studio 3.5.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter (cfg['popphoto_base_path'] variable). NOTE: Pixaria has notified CVE that "PopPhoto is NOT a product of Pixaria. It was a product of PopSoft Digital and is only hosted by Pixaria as a courtesy... The vulnerability listed was patched by the previous vendor and all previous users have received this update." | |||||
CVE-2006-2396 | 1 Phpodp | 1 Phpodp | 2017-07-19 | 5.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in phpODP 1.5h allows remote attackers to inject arbitrary web script via the browse parameter. | |||||
CVE-2006-2403 | 1 Filezilla | 1 Filezilla | 2017-07-19 | 7.5 HIGH | N/A |
Buffer overflow in FileZilla before 2.2.23 allows remote attackers to execute arbitrary commands via unknown attack vectors. | |||||
CVE-2006-2415 | 1 Flexchat | 1 Flexchat | 2017-07-19 | 5.8 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in FlexChat 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) CFTOKEN parameter in (a) index.cfm and (3) CFTOKEN and (4) CFID parameter in (b) chat.cfm. | |||||
CVE-2006-2417 | 1 Phpmyadmin | 1 Phpmyadmin | 2017-07-19 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.x before 2.8.0.4 allows remote attackers to inject arbitrary web script or HTML via the theme parameter in unknown scripts. NOTE: the lang parameter is already covered by CVE-2006-2031. | |||||
CVE-2006-2418 | 1 Phpmyadmin | 1 Phpmyadmin | 2017-07-19 | 6.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerabilities in certain versions of phpMyAdmin before 2.8.0.4 allow remote attackers to inject arbitrary web script or HTML via the db parameter in unknown scripts. | |||||
CVE-2006-2420 | 1 Mozilla | 1 Bugzilla | 2017-07-19 | 4.3 MEDIUM | N/A |
Bugzilla 2.20rc1 through 2.20 and 2.21.1, when using RSS 1.0, allows remote attackers to conduct cross-site scripting (XSS) attacks via a title element with HTML encoded sequences such as ">", which are automatically decoded by some RSS readers. NOTE: this issue is not in Bugzilla itself, but rather due to design or documentation inconsistencies within RSS, or implementation vulnerabilities in RSS readers. While this issue normally would not be included in CVE, it is being identified since the Bugzilla developers have addressed it. | |||||
CVE-2006-2421 | 1 Pragma Systems | 1 Fortressssh | 2017-07-19 | 7.5 HIGH | N/A |
Stack-based buffer overflow in Pragma FortressSSH 4.0.7.20 allows remote attackers to execute arbitrary code via long SSH_MSG_KEXINIT messages, which may cause an overflow when being logged. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2006-2422 | 1 Coinsoft Technologies | 1 Phpcoin | 2017-07-19 | 5.0 MEDIUM | N/A |
phpCOIN 1.2.3 and earlier stores messages based upon e-mail addresses, which allows remote authenticated users to read messages for other users by adding the sender's e-mail address as an "additional contact". | |||||
CVE-2006-2438 | 1 Caucho Technology | 1 Resin | 2017-07-19 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in the viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to read arbitrary files under other web roots via the contextpath parameter. NOTE: this issue can produce resultant path disclosure when the parameter is invalid. | |||||
CVE-2006-2461 | 1 Bea | 1 Weblogic Server | 2017-07-19 | 5.0 MEDIUM | N/A |
BEA WebLogic Server before 8.1 Service Pack 4 does not properly set the Quality of Service in certain circumstances, which prevents some transmissions from being encrypted via SSL, and allows remote attackers to more easily read potentially sensitive network traffic. | |||||
CVE-2006-2462 | 1 Bea | 1 Weblogic Server | 2017-07-19 | 5.0 MEDIUM | N/A |
BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service Pack 6, may send sensitive data over non-secure channels when using JTA transactions, which allows remote attackers to read potentially sensitive network traffic. | |||||
CVE-2006-2464 | 1 Bea | 1 Weblogic Server | 2017-07-19 | 4.6 MEDIUM | N/A |
stopWebLogic.sh in BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service Pack 6 displays the administrator password to stdout when executed, which allows local users to obtain the password by viewing a local display. | |||||
CVE-2006-2466 | 1 Bea | 1 Weblogic Server | 2017-07-19 | 2.6 LOW | N/A |
BEA WebLogic Server 8.1 up to SP4 and 7.0 up to SP6 allows remote attackers to obtain the source code of JSP pages during certain circumstances related to a "timing window" when a compilation error occurs, aka the "JSP showcode vulnerability." | |||||
CVE-2006-2467 | 1 Bea | 1 Weblogic Server | 2017-07-19 | 4.0 MEDIUM | N/A |
BEA WebLogic Server 8.1 up to SP4, 7.0 up to SP6, and 6.1 up to SP7 displays the internal IP address of the WebLogic server in the WebLogic Server Administration Console, which allows remote authenticated administrators to determine the address. | |||||
CVE-2006-2468 | 1 Bea | 1 Weblogic Server | 2017-07-19 | 4.0 MEDIUM | N/A |
The WebLogic Server Administration Console in BEA WebLogic Server 8.1 up to SP4 and 7.0 up to SP6 displays the domain name in the Console login form, which allows remote attackers to obtain sensitive information. | |||||
CVE-2006-2469 | 1 Bea | 1 Weblogic Server | 2017-07-19 | 7.5 HIGH | N/A |
The HTTP handlers in BEA WebLogic Server 9.0, 8.1 up to SP5, 7.0 up to SP6, and 6.1 up to SP7 stores the username and password in cleartext in the WebLogic Server log when access to a web application or protected JWS fails, which allows attackers to gain privileges. | |||||
CVE-2006-2470 | 1 Bea | 1 Weblogic Server | 2017-07-19 | 7.5 HIGH | N/A |
Unspecified vulnerability in the WebLogic Server Administration Console for BEA WebLogic Server 9.0 prevents the console from setting custom JDBC security policies correctly, which could allow attackers to bypass intended policies. | |||||
CVE-2006-2471 | 1 Bea | 1 Weblogic Server | 2017-07-19 | 5.0 MEDIUM | N/A |
Multiple vulnerabilities in BEA WebLogic Server 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 leak sensitive information to remote attackers, including (1) DNS and IP addresses to address to T3 clients, (2) internal sensitive information using GetIORServlet, (3) certain "server details" in exceptions when invalid XML is provided, and (4) a stack trace in a SOAP fault. | |||||
CVE-2006-2472 | 1 Bea | 1 Weblogic Server | 2017-07-19 | 4.9 MEDIUM | N/A |
Unspecified vulnerability in BEA WebLogic Server 9.1 and 9.0, 8.1 through SP5, 7.0 through SP6, and 6.1 through SP7 allows untrusted applications to obtain private server keys. |