Show filters
87 Total Results
Displaying 61-70 of 87
Sort by:
Attacker Value
Unknown
CVE-2006-3387
Disclosure Date: July 06, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in sources/post.php in Fusion News 1.0, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the fil_config parameter, which can be used to execute PHP code that has been injected into a log file.
0
Attacker Value
Unknown
CVE-2006-2763
Disclosure Date: June 02, 2006 (last updated October 04, 2023)
SQL injection vulnerability in Pre News Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) index.php, and the (2) nid parameter to (b) news_detail.php, (c) email_story.php, (d) thankyou.php, (e) printable_view.php, (f) tella_friend.php, and (g) send_comments.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. It is possible that this is primary to CVE-2006-2678.
0
Attacker Value
Unknown
CVE-2006-2678
Disclosure Date: May 31, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Pre News Manager 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) index.php, and the (2) nid parameter to (b) news_detail.php, (c) email_story.php, (d) thankyou.php, (e) printable_view.php, (f) tella_friend.php, and (g) send_comments.php.
0
Attacker Value
Unknown
CVE-2006-2136
Disclosure Date: May 02, 2006 (last updated October 04, 2023)
SQL injection vulnerability in news.php in AZNEWS allows remote attackers to execute arbitrary SQL commands via the ID parameter.
0
Attacker Value
Unknown
CVE-2006-1838
Disclosure Date: April 19, 2006 (last updated October 04, 2023)
edit_kategorie.php in Fuju News 1.0 allows remote attackers to bypass authentication by setting the authorized cookie.
0
Attacker Value
Unknown
CVE-2006-1837
Disclosure Date: April 19, 2006 (last updated October 04, 2023)
SQL injection vulnerability in archiv2.php in Fuju News 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
0
Attacker Value
Unknown
CVE-2006-1818
Disclosure Date: April 18, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly including the (1) first_name and (2) last_name parameter in myaccounts.php. NOTE: portions of these details were obtained from third party sources instead of the original disclosure.
0
Attacker Value
Unknown
CVE-2006-1817
Disclosure Date: April 18, 2006 (last updated October 04, 2023)
SQL injection vulnerability in authcheck.php in warforge.NEWS 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) authusername and possibly the (2) authpassword cookie.
0
Attacker Value
Unknown
CVE-2006-1612
Disclosure Date: April 04, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in visview.php in aWebNews 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) yname, (2) emailadd, (3) subject, and (4) comment parameters.
0
Attacker Value
Unknown
CVE-2006-1613
Disclosure Date: April 04, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in aWebNews 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user123 variable in (a) login.php or (b) fpass.php; or (2) cid parameter to (c) visview.php.
0