Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-1699 | 1 Aweb | 1 Banner Generator | 2017-07-19 | 2.6 LOW | N/A |
Cross-site scripting (XSS) vulnerability in index.php in Aweb Banner Generator 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the banner parameter in view mode. | |||||
CVE-2006-1706 | 1 Kansok Communications | 1 Shopweezle | 2017-07-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (3) brandID, and (4) album parameters to (c) index.php. NOTE: this issue also produces resultant full path disclosure from invalid SQL queries. | |||||
CVE-2006-1707 | 1 Kansok Communications | 1 Shopweezle | 2017-07-19 | 5.0 MEDIUM | N/A |
index.php in Shopweezle 2.0 allows remote attackers to include arbitrary local files via the url parameter. | |||||
CVE-2006-1709 | 1 Interaktiv | 1 Interaktiv.shop | 2017-07-19 | 6.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in shop_main.cgi in interaktiv.shop 5 allows remote attackers to inject arbitrary web script or HTML via the (1) pn and (2) sbeg parameters. | |||||
CVE-2006-1711 | 1 Plone | 1 Plone | 2017-07-19 | 5.0 MEDIUM | N/A |
Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits. | |||||
CVE-2006-1722 | 1 Suche | 1 Shopxs | 2017-07-19 | 6.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in suche.htm in ShopXS 4.0 allows remote attackers to inject arbitrary web script or HTML via the Suchstring1 (aka search) parameter. | |||||
CVE-2006-1743 | 1 Jbook | 1 Jbook | 2017-07-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in form.php in JBook 1.4 allow remote attackers to execute arbitrary SQL commands via the (1) nom or (2) mail parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2006-1746 | 1 Tincan | 1 Phplist | 2017-07-19 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in PHPList 2.10.2 and earlier allows remote attackers to include arbitrary local files via the (1) GLOBALS[database_module] or (2) GLOBALS[language_module] parameters, which overwrite the underlying $GLOBALS variable. | |||||
CVE-2006-1750 | 1 Jmb Software | 1 Autogallery | 2017-07-19 | 2.6 LOW | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Autogallery 0.41 allow remote attackers to inject arbitrary web script or HTML via the (1) pic or (2) show parameters. | |||||
CVE-2006-1751 | 1 Michiel Van Baak | 1 Mvblog | 2017-07-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in MvBlog before 1.6 allow remote attackers to execute arbitrary SQL commands via unknown vectors. | |||||
CVE-2006-1752 | 1 Michiel Van Baak | 1 Mvblog | 2017-07-19 | 2.6 LOW | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in the backend in MvBlog before 1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) body fields in a comment. | |||||
CVE-2006-1753 | 1 Debian | 1 Debian Linux | 2017-07-19 | 3.6 LOW | N/A |
A cron job in fcheck before 2.7.59 allows local users to overwrite arbitrary files via a symlink attack on a temporary file. | |||||
CVE-2006-1760 | 1 Jetphotosoft.com | 1 Jetphoto | 2017-07-19 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in JetPhoto allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) Classic.view/thumbnail.php, (2) Classic.view/gallery.php, (3) Classic.view/detail.php, or (4) Orange.view/detail.php; or (5) the name parameter in Orange.view/slideshow.php. | |||||
CVE-2006-1766 | 1 Papoo | 1 Papoo | 2017-07-19 | 6.4 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in Papoo 2.1.5, and 3 beta1 and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) getlang and (2) reporeid parameter in (a) index.php, (3) menuid parameter in (b) plugin.php and (c) forumthread.php, and (4) msgid parameter in forumthread.php. | |||||
CVE-2006-1773 | 1 Phpkit | 1 Phpkit | 2017-07-19 | 6.4 MEDIUM | N/A |
SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands via the contentid parameter, possibly involving content/news.php. | |||||
CVE-2006-1794 | 1 Mambo | 1 Mambo | 2017-07-19 | 7.6 HIGH | N/A |
SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function in (a) includes/mambo.php; and (3) the $filter variable to the showCategory function in the com_content component (content.php). | |||||
CVE-2006-1797 | 1 Netbsd | 1 Netbsd | 2017-07-19 | 4.9 MEDIUM | N/A |
The kernel in NetBSD-current before September 28, 2005 allows local users to cause a denial of service (system crash) by using the SIOCGIFALIAS ioctl to gather information on a non-existent alias of a network interface, which causes a NULL pointer dereference. | |||||
CVE-2006-1800 | 1 Simplemedia | 1 Simplebbs | 2017-07-19 | 7.5 HIGH | N/A |
Directory traversal vulnerability in posts.php in SimpleBBS 1.0.6 through 1.1 allows remote attackers to include and execute arbitrary files via ".." sequences in the language cookie, as demonstrated by by injecting the code into the gl_session cookie of users.php, which is stored in error.log. | |||||
CVE-2006-1814 | 1 Netbsd | 1 Netbsd | 2017-07-19 | 2.1 LOW | N/A |
NetBSD 1.6, 2.0, 2.1 and 3.0 allows local users to cause a denial of service (memory exhaustion) by using the sysctl system call to lock a large buffer into physical memory. | |||||
CVE-2006-1815 | 1 Tritanium Scripts | 1 Tritanium Bulletin Board | 2017-07-19 | 2.6 LOW | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) newuser_realname and (2) newuser_icq parameters, a different vector than CVE-2006-1768. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |