Show filters
92 Total Results
Displaying 81-90 of 92
Sort by:
Attacker Value
Unknown

CVE-2006-2149

Disclosure Date: May 03, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in sources/lostpw.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the CONFIG[path] parameter, as demonstrated by including a GIF that contains PHP code.
0
Attacker Value
Unknown

CVE-2006-1964

Disclosure Date: April 21, 2006 (last updated October 04, 2023)
SQL injection vulnerability in Haberler.asp in ASPSitem 1.83 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2006-1878

Disclosure Date: April 20, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in phpFaber TopSites allows remote attackers to inject arbitrary web script or HTML via the page parameter.
0
Attacker Value
Unknown

CVE-2006-1541

Disclosure Date: March 30, 2006 (last updated February 22, 2025)
SQL injection vulnerability in Default.asp in EzASPSite 2.0 RC3 and earlier allows remote attackers to execute arbitrary SQL commands and obtain the SHA1 hash of the admin password via the Scheme parameter.
0
Attacker Value
Unknown

CVE-2006-0654

Disclosure Date: February 13, 2006 (last updated February 22, 2025)
check.php in Hinton Design phpht Topsites 1.3 does not validate passwords when using cookies, which allows remote attackers to bypass authentication via unspecified cookies.
0
Attacker Value
Unknown

CVE-2006-0655

Disclosure Date: February 13, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in (1) link_edited.php and (2) link_added.php in Hinton Design phpht Topsites 1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2006-0653

Disclosure Date: February 13, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Hinton Design phpht Topsites 1.3 allow remote attackers to execute arbitrary SQL commands via multiple vectors including the username parameter.
0
Attacker Value
Unknown

CVE-2006-0184

Disclosure Date: January 12, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in AspTopSites allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to goto.asp or (2) password parameter to includeloginuser.asp.
0
Attacker Value
Unknown

CVE-2005-4661

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The notifyendsubs cron job in Campsite before 2.3.3 sends an e-mail message containing a certain unencrypted MySQL password, which allows remote attackers to sniff the password.
0
Attacker Value
Unknown

CVE-2005-3515

Disclosure Date: November 06, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Topsites script allows remote attackers to inject arbitrary web script or HTML via the ID parameter.
0