Show filters
92 Total Results
Displaying 71-80 of 92
Sort by:
Attacker Value
Unknown

CVE-2006-3902

Disclosure Date: July 27, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in phpFaber TopSites 2.0.9 allows remote attackers to inject arbitrary web script or HTML via the i_cat parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-3770

Disclosure Date: July 24, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in index.php in phpFaber TopSites 2.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) i_cat or (2) method parameters.
0
Attacker Value
Unknown

CVE-2006-2849

Disclosure Date: June 06, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in includes/webdav/server.php in Bytehoard 2.1 Epsilon/Delta allows remote attackers to execute arbitrary PHP code via a URL in the bhconfig[bhfilepath] parameter.
0
Attacker Value
Unknown

CVE-2006-2793

Disclosure Date: June 03, 2006 (last updated October 04, 2023)
SQL injection vulnerability in Anket.asp in ASPSitem 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.
0
Attacker Value
Unknown

CVE-2006-2794

Disclosure Date: June 03, 2006 (last updated October 04, 2023)
Hesabim.asp in ASPSitem 2.0 and earlier allows remote attackers to read private messages of other users via a modified id parameter.
0
Attacker Value
Unknown

CVE-2006-2639

Disclosure Date: May 30, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the input forms in prattmic and Master5006 PHPSimpleChoose 0.3 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element.
0
Attacker Value
Unknown

CVE-2006-2544

Disclosure Date: May 23, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Xtreme Topsites 1.1, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchthis parameter in lostid.php and (2) id parameter in stats.php. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-2543

Disclosure Date: May 23, 2006 (last updated October 04, 2023)
Xtreme Topsites 1.1 allows remote attackers to trigger MySQL errors and possibly conduct SQL injection attacks via unspecified vectors in join.php.
0
Attacker Value
Unknown

CVE-2006-2545

Disclosure Date: May 23, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Xtreme Topsites 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in stats.php and (2) unspecified inputs in lostid.php, probably the searchthis parameter. NOTE: one or more of these vectors might be resultant from SQL injection.
0
Attacker Value
Unknown

CVE-2006-2339

Disclosure Date: May 12, 2006 (last updated October 04, 2023)
SQL injection vulnerability in index.php in evoTopsites 2.x and evoTopsites Pro 2.x allows remote attackers to execute arbitrary SQL commands via the (1) cat_id and (2) id parameters.
0