Show filters
548 Total Results
Displaying 491-500 of 548
Sort by:
Attacker Value
Unknown

CVE-2006-3896

Disclosure Date: December 19, 2006 (last updated October 04, 2023)
The NeoScale Systems CryptoStor 700 series appliance before 2.6 relies on client-side ActiveX code for smartcard authentication, which allows remote attackers to bypass smartcard authentication, and gain access if able to present a valid username and password, by disabling ActiveX.
0
Attacker Value
Unknown

CVE-2006-6248

Disclosure Date: December 04, 2006 (last updated October 04, 2023)
index.php in GPhotos 1.5 allows remote attackers to obtain sensitive information via an invalid rep parameter, which reveals the full path in an error message.
0
Attacker Value
Unknown

CVE-2006-5095

Disclosure Date: September 29, 2006 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in index.php in MyPhotos 0.1.3b beta allows remote attackers to execute arbitrary PHP code via the includesdir parameter. NOTE: this issue is disputed by CVE on 20060927, since the includesdir is defined before being used when the product is installed according to the provided instructions
0
Attacker Value
Unknown

CVE-2006-5057

Disclosure Date: September 28, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Ktools.net PhotoStore allow remote attackers to inject arbitrary web script or HTML via the (1) gid parameter in details.php, or the (2) photogid parameter in view_photog.php.
0
Attacker Value
Unknown

CVE-2006-4775

Disclosure Date: September 14, 2006 (last updated October 04, 2023)
The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) and CatOS allows remote attackers to cause a denial of service by sending a VTP update with a revision value of 0x7FFFFFFF, which is incremented to 0x80000000 and is interpreted as a negative number in a signed context.
0
Attacker Value
Unknown

CVE-2006-3678

Disclosure Date: July 26, 2006 (last updated October 04, 2023)
TippingPoint IPS running the TippingPoint Operating System (TOS) before 2.2.4.6519 allows remote attackers to "force the device into layer 2 fallback (L2FB)", causing a denial of service (page fault), via a malformed packet.
0
Attacker Value
Unknown

CVE-2006-3027

Disclosure Date: June 15, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) CAT_ID parameter in (a) subphotos.asp and (b) subLevel2.asp, the (2) AL_ID parameter in (c) photo.asp, and the (3) SUB_ID parameter in (d) subLevel2.asp.
0
Attacker Value
Unknown

CVE-2006-2955

Disclosure Date: June 12, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice 7.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) New Category (newcategory) or (2) apage parameter to (a) edtalbum.asp, or the (3) cat or (4) albumid parameter to (b) album.asp.
0
Attacker Value
Unknown

CVE-2006-2397

Disclosure Date: May 16, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in GPhotos 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) rep parameter to (a) index.php or (b) diapo.php or (2) image parameter to (c) affich.php. NOTE: item 1a might be resultant from directory traversal.
0
Attacker Value
Unknown

CVE-2006-2398

Disclosure Date: May 16, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in GPhotos 1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the rep parameter.
0