Show filters
735 Total Results
Displaying 691-700 of 735
Sort by:
Attacker Value
Unknown
CVE-2006-1943
Disclosure Date: April 20, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Smarter Scripts IntelliLink Pro 5.06 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter in addlink_lwp.cgi and the (2) id, (3) forgotid, and (4) forgotpass parameters in edit.cgi.
0
Attacker Value
Unknown
CVE-2006-1749
Disclosure Date: April 12, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in config.php in phpListPro 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the returnpath parameter. NOTE: this issue was later reported to affect 2.01 as well.
0
Attacker Value
Unknown
CVE-2006-1648
Disclosure Date: April 06, 2006 (last updated February 22, 2025)
SMART SynchronEyes Student and Teacher 6.0, and possibly earlier versions, allows remote attackers to cause a denial of service (memory consumption) via a certain packet to the Teacher discovery port that causes SynchronEyes to connect to the attacker's machine and read a value that is used as a parameter to malloc.
0
Attacker Value
Unknown
CVE-2006-1647
Disclosure Date: April 06, 2006 (last updated February 22, 2025)
An unspecified "logical programming mistake" in SMART SynchronEyes Student and Teacher 6.0, and possibly earlier versions, allows remote attackers to cause a denial of service via a large packet to the Teacher discovery port (UDP port 5496), which causes a thread to terminate and prevents communications on that port.
0
Attacker Value
Unknown
CVE-2006-1623
Disclosure Date: April 05, 2006 (last updated February 22, 2025)
Unspecified vulnerability in main.php in an unspecified "file created by Andries Bruinsma," possibly a FleXiBle Development (FXB) application, allows remote attackers to include and execute arbitrary PHP code. NOTE: this disclosure is extremely vague and has very little information about the specific vulnerability type. In addition, there is little public information on the named product. Finally, an XSS vector is implied in the subject line, but because there is no other information and evidence of a cut-and-paste error, it will not be assigned a separate CVE identifier unless additional information is provided.
0
Attacker Value
Unknown
CVE-2006-1385
Disclosure Date: March 24, 2006 (last updated February 22, 2025)
Stack-based buffer overflow in the parseTaggedData function in WavePacket.mm in KisMAC R54 through R73p allows remote attackers to execute arbitrary code via multiple SSIDs in a Cisco vendor tag in a 802.11 management frame.
0
Attacker Value
Unknown
CVE-2006-1013
Disclosure Date: March 07, 2006 (last updated February 22, 2025)
PHP remote file include vulnerability in index.php in SMartBlog (aka SMBlog) 1.2 allows remote attackers to include and execute arbitrary PHP files via (1) the pg parameter and (2) a query string without a parameter.
0
Attacker Value
Unknown
CVE-2006-0750
Disclosure Date: February 18, 2006 (last updated February 22, 2025)
SQL injection vulnerability in army.php in supersmashbrothers (SSB) Army System 2.1.0 for Invision Power Board (IPB) allows remote attackers to execute arbitrary SQL commands via the userstat parameter in an army action to index.php.
0
Attacker Value
Unknown
CVE-2006-0355
Disclosure Date: January 22, 2006 (last updated February 22, 2025)
Helmsman Research (aka CoolUtils) HomeFtp 1.1 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command and an NLST command.
0
Attacker Value
Unknown
CVE-2005-3083
Disclosure Date: September 27, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 0.10 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
0