Show filters
204 Total Results
Displaying 71-80 of 204
Sort by:
Attacker Value
Unknown

CVE-2006-1380

Disclosure Date: March 24, 2006 (last updated February 22, 2025)
ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possibly other versions before 5.7.0.1121, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying ISNTSysMonitor.exe.
0
Attacker Value
Unknown

CVE-2006-1119

Disclosure Date: March 09, 2006 (last updated February 22, 2025)
fantastico in Cpanel does not properly handle when it has insufficient permissions to perform certain file operations, which allows remote authenticated users to obtain the full pathname, which is leaked in a PHP error message.
0
Attacker Value
Unknown

CVE-2006-1079

Disclosure Date: March 09, 2006 (last updated February 22, 2025)
htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
0
Attacker Value
Unknown

CVE-2006-0859

Disclosure Date: February 23, 2006 (last updated February 22, 2025)
Michael Salzer Guestbox 0.6, and other versions before 0.8, allows remote attackers to post an admin comment to a guestbook entry via a certain modified form, possibly related to the nummer parameter.
0
Attacker Value
Unknown

CVE-2006-0700

Disclosure Date: February 15, 2006 (last updated February 22, 2025)
imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions.
0
Attacker Value
Unknown

CVE-2006-0697

Disclosure Date: February 15, 2006 (last updated February 22, 2025)
Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.
0
Attacker Value
Unknown

CVE-2006-0008

Disclosure Date: February 14, 2006 (last updated February 22, 2025)
The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.
0
Attacker Value
Unknown

CVE-2006-0553

Disclosure Date: February 14, 2006 (last updated February 22, 2025)
PostgreSQL 8.1.0 through 8.1.2 allows authenticated database users to gain additional privileges via "knowledge of the backend protocol" using a crafted SET ROLE to other database users, a different vulnerability than CVE-2006-0678.
0
Attacker Value
Unknown

CVE-2006-0023

Disclosure Date: February 08, 2006 (last updated February 22, 2025)
Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs." NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.
0
Attacker Value
Unknown

CVE-2006-0527

Disclosure Date: February 02, 2006 (last updated February 22, 2025)
BIND 4 (BIND4) and BIND 8 (BIND8), if used as a target forwarder, allows remote attackers to gain privileged access via a "Kashpureff-style DNS cache corruption" attack.
0