Show filters
284 Total Results
Displaying 261-270 of 284
Sort by:
Attacker Value
Unknown

CVE-2006-3071

Disclosure Date: June 19, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in MP3 Search/Archive 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter, as used by the "search box", and (2) res parameter.
0
Attacker Value
Unknown

CVE-2006-1611

Disclosure Date: April 04, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in KGB Archiver before 1.1.5.22 allows remote attackers to overwrite arbitrary files wile decompressing an archive, possibly due to directory traversal sequences in a filename.
0
Attacker Value
Unknown

CVE-2006-0931

Disclosure Date: February 28, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a TAR archive.
0
Attacker Value
Unknown

CVE-2006-0932

Disclosure Date: February 28, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a ZIP archive.
0
Attacker Value
Unknown

CVE-2006-0758

Disclosure Date: February 18, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via a URL encoded expression in the query string in (1) index.php and (2) possibly certain other scripts, which is not properly cleansed when accessed from the $_SERVER['PHP_SELF'] variable.
0
Attacker Value
Unknown

CVE-2006-0759

Disclosure Date: February 18, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain parameters in (4) calendar.event.php, (5) index.php, (6) pop.download.php, (7) read.bounce.php, (8) rules.block.php, (9) language.php, and (10) certain other scripts; and allow remote authenticated users to execute arbitrary SQL commands via (11) the folderid parameter in index.php and (12) possibly other parameters in certain other scripts, because $_SERVER['PHP_SELF'] is improperly handled.
0
Attacker Value
Unknown

CVE-2006-0757

Disclosure Date: February 18, 2006 (last updated February 22, 2025)
Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain parameters in (4) calendar.event.php, (5) index.php, (6) pop.download.php, (7) read.bounce.php, (8) rules.block.php, (9) language.php, and (10) certain other scripts, as demonstrated by an addressbook.update.php request with a contactgroupid value of phpinfo() preceded by facilitators.
0
Attacker Value
Unknown

CVE-2005-4460

Disclosure Date: December 21, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Beehive Forum 0.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Description, and (3) Comment fields to (a) links.php and (b) links_add.php.
0
Attacker Value
Unknown

CVE-2005-4419

Disclosure Date: December 20, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in CategoryResults.cfm in Honeycomb Archive and Honeycomb Archive Enterprise 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) series, (2) cat_parent, (3) cat, and (4) div parameters.
0
Attacker Value
Unknown

CVE-2005-4420

Disclosure Date: December 20, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Honeycomb Archive Enterprise 3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keyword parameter in search.cfm.
0