Show filters
92 Total Results
Displaying 71-80 of 92
Sort by:
Attacker Value
Unknown
CVE-2006-3902
Disclosure Date: July 27, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in phpFaber TopSites 2.0.9 allows remote attackers to inject arbitrary web script or HTML via the i_cat parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2006-3770
Disclosure Date: July 24, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in index.php in phpFaber TopSites 2.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) i_cat or (2) method parameters.
0
Attacker Value
Unknown
CVE-2006-2849
Disclosure Date: June 06, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in includes/webdav/server.php in Bytehoard 2.1 Epsilon/Delta allows remote attackers to execute arbitrary PHP code via a URL in the bhconfig[bhfilepath] parameter.
0
Attacker Value
Unknown
CVE-2006-2793
Disclosure Date: June 03, 2006 (last updated October 04, 2023)
SQL injection vulnerability in Anket.asp in ASPSitem 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.
0
Attacker Value
Unknown
CVE-2006-2794
Disclosure Date: June 03, 2006 (last updated October 04, 2023)
Hesabim.asp in ASPSitem 2.0 and earlier allows remote attackers to read private messages of other users via a modified id parameter.
0
Attacker Value
Unknown
CVE-2006-2639
Disclosure Date: May 30, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the input forms in prattmic and Master5006 PHPSimpleChoose 0.3 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element.
0
Attacker Value
Unknown
CVE-2006-2544
Disclosure Date: May 23, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Xtreme Topsites 1.1, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchthis parameter in lostid.php and (2) id parameter in stats.php. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2006-2543
Disclosure Date: May 23, 2006 (last updated October 04, 2023)
Xtreme Topsites 1.1 allows remote attackers to trigger MySQL errors and possibly conduct SQL injection attacks via unspecified vectors in join.php.
0
Attacker Value
Unknown
CVE-2006-2545
Disclosure Date: May 23, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Xtreme Topsites 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in stats.php and (2) unspecified inputs in lostid.php, probably the searchthis parameter. NOTE: one or more of these vectors might be resultant from SQL injection.
0
Attacker Value
Unknown
CVE-2006-2339
Disclosure Date: May 12, 2006 (last updated October 04, 2023)
SQL injection vulnerability in index.php in evoTopsites 2.x and evoTopsites Pro 2.x allows remote attackers to execute arbitrary SQL commands via the (1) cat_id and (2) id parameters.
0