Show filters
56 Total Results
Displaying 31-40 of 56
Sort by:
Attacker Value
Unknown

CVE-2006-6817

Disclosure Date: December 29, 2006 (last updated October 04, 2023)
AlstraSoft Web Host Directory allows remote attackers to obtain sensitive information by requesting any invalid URI, which reveals the path in an error message, a different vulnerability than CVE-2006-2617.
0
Attacker Value
Unknown

CVE-2006-6818

Disclosure Date: December 29, 2006 (last updated October 04, 2023)
AlstraSoft Web Host Directory allows remote attackers to bypass authentication and change the admin password via a direct request to admin/config.
0
Attacker Value
Unknown

CVE-2006-6819

Disclosure Date: December 29, 2006 (last updated October 04, 2023)
AlstraSoft Web Host Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup database via a direct request for admin/backup/db.
0
Attacker Value
Unknown

CVE-2006-4913

Disclosure Date: September 21, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary local files and possibly execute arbitrary code via a .. (dot dot) sequence and trailing null (%00) byte in the lang parameter, as demonstrated by injecting PHP code into a log file.
0
Attacker Value
Unknown

CVE-2006-4591

Disclosure Date: September 06, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller Pro 3.25, allow remote attackers to execute arbitrary PHP code via a URL in the config[template_path] parameter to (1) payment/payment_result.php or (2) /payment/spuser_result.php.
0
Attacker Value
Unknown

CVE-2006-4443

Disclosure Date: August 29, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in myajaxphp.php in AlstraSoft Video Share Enterprise allows remote attackers to execute arbitrary PHP code via a URL in the config[BASE_DIR] parameter.
0
Attacker Value
Unknown

CVE-2006-2618

Disclosure Date: May 26, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, might allow remote attackers to inject arbitrary web script or HTML via the "write a review" box. NOTE: since user reviews do not require administrator privileges, and an auto-approve mechanism exists, this issue is a vulnerability.
0
Attacker Value
Unknown

CVE-2006-2617

Disclosure Date: May 26, 2006 (last updated October 04, 2023)
(1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to obtain the installation path via an invalid entry in the Username field on the login page, which causes the path to be displayed in an SQL error. NOTE: this issue might be resultant from SQL injection.
0
Attacker Value
Unknown

CVE-2006-2616

Disclosure Date: May 26, 2006 (last updated October 04, 2023)
SQL injection vulnerability in the search script in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to execute arbitrary SQL commands via the uri parameter.
0
Attacker Value
Unknown

CVE-2006-2564

Disclosure Date: May 24, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AlstraSoft E-Friends allow remote attackers to inject arbitrary web script or HTML by (1) posting a blog, (2) posting a listing, (3) posting an event, (4) adding comments, or (5) sending a message.
0