Show filters
535 Total Results
Displaying 491-500 of 535
Sort by:
Attacker Value
Unknown
CVE-2006-2424
Disclosure Date: May 17, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in ezUserManager 1.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the ezUserManager_Path parameter to ezusermanager_pwd_forgott.php, possibly due to an issue in ezusermanager_core.inc.php.
0
Attacker Value
Unknown
CVE-2006-2403
Disclosure Date: May 16, 2006 (last updated October 04, 2023)
Buffer overflow in FileZilla before 2.2.23 allows remote attackers to execute arbitrary commands via unknown attack vectors.
0
Attacker Value
Unknown
CVE-2006-2232
Disclosure Date: May 05, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Scriptsez Cute Guestbook 20060211 allows remote attackers to inject arbitrary web script or HTML via the Comments field when signing the guestbook.
0
Attacker Value
Unknown
CVE-2006-2173
Disclosure Date: May 04, 2006 (last updated October 04, 2023)
Buffer overflow in FileZilla FTP Server 2.2.22 allows remote authenticated attackers to cause a denial of service and possibly execute arbitrary code via a long (1) PORT or (2) PASS followed by the MLSD command, or (2) the remote server interface, as demonstrated by the Infigo FTPStress Fuzzer.
0
Attacker Value
Unknown
CVE-2006-2099
Disclosure Date: April 29, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in UltraISO 8.0.0.1392 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image.
0
Attacker Value
Unknown
CVE-2006-1541
Disclosure Date: March 30, 2006 (last updated February 22, 2025)
SQL injection vulnerability in Default.asp in EzASPSite 2.0 RC3 and earlier allows remote attackers to execute arbitrary SQL commands and obtain the SHA1 hash of the admin password via the Scheme parameter.
0
Attacker Value
Unknown
CVE-2006-1163
Disclosure Date: March 12, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Nodez 4.6.1.1 allows remote attackers to inject arbitrary web script or HTML via the op parameter. NOTE: it is possible that this issue is resultant from the directory traversal vulnerability.
0
Attacker Value
Unknown
CVE-2006-1164
Disclosure Date: March 12, 2006 (last updated February 22, 2025)
Nodez 4.6.1.1 and earlier stores sensitive data in the list.gtdat file under the web document root with insufficient access control, which allows remote attackers to obtain usernames and password hashes by directly accessing list.gtdat.
0
Attacker Value
Unknown
CVE-2006-1162
Disclosure Date: March 12, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in Nodez 4.6.1.1 and earlier allows remote attackers to read or include arbitrary PHP files via a .. (dot dot) in the op parameter, as demonstrated by inserting malicious Email parameters into list.gtdat, then accessing list.gtdat using the op parameter.
0
Attacker Value
Unknown
CVE-2006-0938
Disclosure Date: March 01, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the RefererURL parameter.
0