Show filters
120 Total Results
Displaying 111-120 of 120
Sort by:
Attacker Value
Unknown
CVE-2006-3765
Disclosure Date: July 21, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Huttenlocher Webdesign hwdeGUEST 2.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, as demonstrated by the "name input" field in new_entry.php.
0
Attacker Value
Unknown
CVE-2006-3395
Disclosure Date: July 06, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in top.php in SiteBuilder-FX 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter.
0
Attacker Value
Unknown
CVE-2006-2609
Disclosure Date: May 26, 2006 (last updated October 04, 2023)
artmedic newsletter 4.1.2 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the email parameter to newsletter_log.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2006-2608
Disclosure Date: May 26, 2006 (last updated October 04, 2023)
artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the logfile parameter in a direct request to log.php, which causes the $logfile variable to be redefined to an attacker-controlled value, as demonstrated by injecting PHP code into info.php.
0
Attacker Value
Unknown
CVE-2006-2119
Disclosure Date: May 01, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in event/index.php in Artmedic Event allows remote attackers to execute arbitrary code via a URL in the page parameter.
0
Attacker Value
Unknown
CVE-2006-1422
Disclosure Date: March 28, 2006 (last updated February 22, 2025)
SQL injection vulnerability in details_view.php in PHP Booking Calendar 1.0c and earlier allows remote attackers to execute arbitrary SQL commands via the event_id parameter.
0
Attacker Value
Unknown
CVE-2006-1421
Disclosure Date: March 28, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in akocomment.php in AkoComment 2.0 module for Mambo, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) acname or (2) contentid parameter.
0
Attacker Value
Unknown
CVE-2004-0624
Disclosure Date: December 06, 2004 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in index.php for Artmedic links 5.0 (artmedic_links5) allows remote attackers to execute arbitrary PHP code by modifying the id parameter to reference a URL on a remote web server that contains the code.
0
Attacker Value
Unknown
CVE-2004-0398
Disclosure Date: July 07, 2004 (last updated February 22, 2025)
Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.
0
Attacker Value
Unknown
CVE-2004-0179
Disclosure Date: June 01, 2004 (last updated February 22, 2025)
Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.
0