Show filters
115 Total Results
Displaying 101-110 of 115
Sort by:
Attacker Value
Unknown
CVE-2006-5166
Disclosure Date: October 05, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in functions.php in PHP Web Scripts Easy Banner Free allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter.
0
Attacker Value
Unknown
CVE-2006-3846
Disclosure Date: July 25, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in extadminmenus.class.php in the MultiBanners 1.0.1 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0
Attacker Value
Unknown
CVE-2006-3607
Disclosure Date: July 18, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Banner Exchange Script (aka Banner Exchange Network Script) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the city parameter in (a) insertmember.php, and (2) a PHPSESSID cookie in (b) lostpassword.php, (c) gen_confirm_mem.php, and (d) index.php.
0
Attacker Value
Unknown
CVE-2006-3519
Disclosure Date: July 11, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in The Banner Engine (tbe) 4.0 allow remote attackers to execute arbitrary web script or HTML via the (1) text parameter in a search action to (a) top.php, and the (2) adminpass or (3) adminlogin parameter to (b) signup.php.
0
Attacker Value
Unknown
CVE-2006-3012
Disclosure Date: June 19, 2006 (last updated October 04, 2023)
SQL injection vulnerability in phpBannerExchange before 2.0 Update 6 allows remote attackers to execute arbitrary SQL commands via the (1) login parameter in (a) client/stats.php and (b) admin/stats.php, or the (2) pass parameter in client/stats.php.
0
Attacker Value
Unknown
CVE-2006-3013
Disclosure Date: June 19, 2006 (last updated October 04, 2023)
Interpretation conflict in resetpw.php in phpBannerExchange before 2.0 Update 6 allows remote attackers to execute arbitrary SQL commands via an email parameter containing a null (%00) character after a valid e-mail address, which passes the validation check in the eregi PHP command. NOTE: it could be argued that this vulnerability is due to a bug in the eregi PHP command and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in phpBannerExchange.
0
Attacker Value
Unknown
CVE-2006-2428
Disclosure Date: May 17, 2006 (last updated January 27, 2024)
add.asp in DUware DUbanner 3.1 allows remote attackers to execute arbitrary code by uploading files with arbitrary extensions, such as ASP files, probably due to client-side enforcement that can be bypassed. NOTE: some of these details are obtained from third party information, since the raw source is vague.
0
Attacker Value
Unknown
CVE-2006-1950
Disclosure Date: April 20, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in banners.cgi in PerlCoders BannerFarm 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) aff and (2) cat parameters.
0
Attacker Value
Unknown
CVE-2006-1699
Disclosure Date: April 11, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Aweb Banner Generator 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the banner parameter in view mode.
0
Attacker Value
Unknown
CVE-2006-1213
Disclosure Date: March 14, 2006 (last updated February 22, 2025)
JiRo's Banner System Experience and Professional 1.0 and earlier allows remote attackers to bypass access restrictions and gain privileges via a direct request to certain scripts in the files directory, as demonstrated by using addadmin.asp to create a new administrator account.
0