Show filters
56 Total Results
Displaying 31-40 of 56
Sort by:
Attacker Value
Unknown
CVE-2006-6817
Disclosure Date: December 29, 2006 (last updated October 04, 2023)
AlstraSoft Web Host Directory allows remote attackers to obtain sensitive information by requesting any invalid URI, which reveals the path in an error message, a different vulnerability than CVE-2006-2617.
0
Attacker Value
Unknown
CVE-2006-6818
Disclosure Date: December 29, 2006 (last updated October 04, 2023)
AlstraSoft Web Host Directory allows remote attackers to bypass authentication and change the admin password via a direct request to admin/config.
0
Attacker Value
Unknown
CVE-2006-6819
Disclosure Date: December 29, 2006 (last updated October 04, 2023)
AlstraSoft Web Host Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup database via a direct request for admin/backup/db.
0
Attacker Value
Unknown
CVE-2006-4913
Disclosure Date: September 21, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary local files and possibly execute arbitrary code via a .. (dot dot) sequence and trailing null (%00) byte in the lang parameter, as demonstrated by injecting PHP code into a log file.
0
Attacker Value
Unknown
CVE-2006-4591
Disclosure Date: September 06, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller Pro 3.25, allow remote attackers to execute arbitrary PHP code via a URL in the config[template_path] parameter to (1) payment/payment_result.php or (2) /payment/spuser_result.php.
0
Attacker Value
Unknown
CVE-2006-4443
Disclosure Date: August 29, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in myajaxphp.php in AlstraSoft Video Share Enterprise allows remote attackers to execute arbitrary PHP code via a URL in the config[BASE_DIR] parameter.
0
Attacker Value
Unknown
CVE-2006-2618
Disclosure Date: May 26, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, might allow remote attackers to inject arbitrary web script or HTML via the "write a review" box. NOTE: since user reviews do not require administrator privileges, and an auto-approve mechanism exists, this issue is a vulnerability.
0
Attacker Value
Unknown
CVE-2006-2617
Disclosure Date: May 26, 2006 (last updated October 04, 2023)
(1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to obtain the installation path via an invalid entry in the Username field on the login page, which causes the path to be displayed in an SQL error. NOTE: this issue might be resultant from SQL injection.
0
Attacker Value
Unknown
CVE-2006-2616
Disclosure Date: May 26, 2006 (last updated October 04, 2023)
SQL injection vulnerability in the search script in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to execute arbitrary SQL commands via the uri parameter.
0
Attacker Value
Unknown
CVE-2006-2564
Disclosure Date: May 24, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AlstraSoft E-Friends allow remote attackers to inject arbitrary web script or HTML by (1) posting a blog, (2) posting a listing, (3) posting an event, (4) adding comments, or (5) sending a message.
0