Total
288746 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2006-6862 | 1 Outfront | 1 Spooky Login | 2024-11-21 | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Outfront Spooky Login 2.7 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) login/login.asp or (2) login/register.asp. | ||||
CVE-2006-6861 | 1 Outfront | 1 Spooky Login | 2024-11-21 | N/A |
Multiple SQL injection vulnerabilities in Outfront Spooky Login 2.7 allow remote attackers to execute arbitrary SQL commands via (1) the UserUpdate parameter to login/register.asp or (2) unspecified parameters to includes/a_register.asp. | ||||
CVE-2006-6860 | 1 Mythcontrol | 1 Mythcontrol | 2024-11-21 | N/A |
Buffer overflow in the sendToMythTV function in MythControlServer.c in MythControl 1.0 and earlier allows remote attackers to execute arbitrary code via a crafted sendStr string to the Bluetooth interface. NOTE: some of these details are obtained from third party information. | ||||
CVE-2006-6859 | 1 Website Designs For Less | 1 Click N Print Coupons | 2024-11-21 | N/A |
SQL injection vulnerability in coupon_detail.asp in Website Designs For Less Click N' Print Coupons 2005.01 and earlier allows remote attackers to execute arbitrary SQL commands via the key parameter. | ||||
CVE-2006-6858 | 1 Miredo | 1 Miredo | 2024-11-21 | N/A |
Miredo 0.9.8 through 1.0.5 does not properly authenticate a Teredo bubble during UDP hole punching with HMAC-MD5-64 hashing, which allows remote attackers to impersonate an arbitrary Teredo client. | ||||
CVE-2006-6857 | 1 Docebolms | 1 Docebolms | 2024-11-21 | N/A |
Cross-site scripting (XSS) vulnerability in modules/credits/credits.php in Docebo LMS allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | ||||
CVE-2006-6856 | 1 Webtext | 1 Webtext | 2024-11-21 | N/A |
Direct static code injection vulnerability in WebText CMS 0.4.5.2 and earlier allows remote attackers to inject arbitrary PHP code into a script in wt/users/ via the im parameter during a profile edit (edycja) operation, which is then executed via a direct request for this script. | ||||
CVE-2006-6855 | 1 Aidex | 1 Mini-webserver | 2024-11-21 | N/A |
AIDeX Mini-WebServer 1.1 early release 3 allows remote attackers to cause a denial of service (daemon crash) via a flood of HTTP GET requests, possibly related to display of HTTP log data by the GUI. NOTE: some of these details are obtained from third party information. | ||||
CVE-2006-6854 | 1 De Marchi Daniele | 1 Quickcam | 2024-11-21 | N/A |
The qcamvc_video_init function in qcamvc.c in De Marchi Daniele QuickCam VC Linux device driver (aka quickcam-vc) 1.0.9 and earlier does not properly check a boundary, triggering memory corruption, which might allow attackers to execute arbitrary code via a crafted QuickCam object. | ||||
CVE-2006-6853 | 1 Mozilla | 1 Durian Web Application Server | 2024-11-21 | N/A |
Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary code via a long string in a crafted packet to TCP port 4002. | ||||
CVE-2006-6852 | 1 Tdiary | 1 Tdiary | 2024-11-21 | N/A |
Eval injection vulnerability in tDiary 2.0.3 and 2.1.4.200 61127 allows remote authenticated users to execute arbitrary Ruby code via unspecified vectors, possibly related to incorrect input validation by (1) conf.rhtml and (2) i.conf.rhtml. NOTE: some of these details are obtained from third party information. | ||||
CVE-2006-6851 | 1 Mobilelib | 1 Mobilelib Gold | 2024-11-21 | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in contact_us.php in ac4p Mobilelib gold 2 allow remote attackers to inject arbitrary web script or HTML via the (1) email or (2) errr parameter. | ||||
CVE-2006-6850 | 1 Shadowed Works | 1 Shadowed Portal | 2024-11-21 | N/A |
PHP remote file inclusion vulnerability in include.php in the Roster Module (character_roster) in Shadowed Portal 5.7 allows remote attackers to execute arbitrary PHP code via a URL in the mod_root parameter. | ||||
CVE-2006-6849 | 1 Cahier De Textes | 1 Cahier De Textes | 2024-11-21 | N/A |
administration/index.php in Cahier de texte (CDT) 2.2 does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions. | ||||
CVE-2006-6848 | 1 Aspticker | 1 Aspticker | 2024-11-21 | N/A |
SQL injection vulnerability in admin.asp in ASPTicker 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO, possibly related to the Password parameter. | ||||
CVE-2006-6847 | 1 Realnetworks | 1 Realplayer | 2024-11-21 | N/A |
An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the RealPlayer.OpenURLInPlayerBrowser method with a long second argument. | ||||
CVE-2006-6846 | 1 Cybercoded | 1 While You Were Out Inout Board | 2024-11-21 | N/A |
Multiple SQL injection vulnerabilities in While You Were Out (WYWO) InOut Board 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the num parameter in (a) phonemessage.asp, (2) the catcode parameter in (b) faqDsp.asp, and the (3) Username and (4) Password fields in (c) login.asp. | ||||
CVE-2006-6845 | 1 Cmsmadesimple | 1 Cms Made Simple | 2024-11-21 | N/A |
Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the cntnt01searchinput parameter in a Search action. | ||||
CVE-2006-6844 | 1 Cmsmadesimple | 1 Cms Made Simple | 2024-11-21 | N/A |
Cross-site scripting (XSS) vulnerability in the optional user comment module in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the user comment form. | ||||
CVE-2006-6843 | 1 Joomla | 1 Be It Easypartner Component | 2024-11-21 | N/A |
PHP remote file inclusion vulnerability in the BE IT EasyPartner 0.0.9 beta component for Joomla! allows remote attackers to execute arbitrary PHP code via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. |