Show filters
837 Total Results
Displaying 821-830 of 837
Sort by:
Attacker Value
Unknown
CVE-2006-6218
Disclosure Date: December 01, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in index.php in dev4u CMS allow remote attackers to execute arbitrary SQL commands via the (1) seite_id, (2) gruppe_id.php, and (3) go_target parameters.
0
Attacker Value
Unknown
CVE-2006-6219
Disclosure Date: December 01, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in dev4u CMS allow remote attackers to inject arbitrary web script or HTML via the (1) user_name, (2) passwort, and (3) go_target parameters.
0
Attacker Value
Unknown
CVE-2006-4867
Disclosure Date: September 19, 2006 (last updated October 04, 2023)
SQL injection vulnerability in mods.php in GNUTurk 2G and earlier allows remote attackers to execute arbitrary SQL commands via the t_id parameter when the go parameter is "Forum."
0
Attacker Value
Unknown
CVE-2006-4598
Disclosure Date: September 07, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in links.php in ssLinks 1.22 allow remote attackers to execute arbitrary SQL commands via the (1) go parameter and (2) id parameter in a rate action.
0
Attacker Value
Unknown
CVE-2006-4272
Disclosure Date: August 21, 2006 (last updated November 08, 2023)
Jelsoft vBulletin 3.5.4 allows remote attackers to register multiple arbitrary users and cause a denial of service (resource consumption) via a large number of requests to register.php. NOTE: the vendor has disputed this vulnerability, stating "If you have the CAPTCHA enabled then the registrations wont even go through. ... if you are talking about the flood being allowed in the first place then surely this is something that should be handled at the server level.
0
Attacker Value
Unknown
CVE-2006-3597
Disclosure Date: July 18, 2006 (last updated October 04, 2023)
passwd before 1:4.0.13 on Ubuntu 6.06 LTS leaves the root password blank instead of locking it when the administrator selects the "Go Back" option after the final "Installation complete" message and uses the main menu, which causes the password to be zeroed out in the installer's memory.
0
Attacker Value
Unknown
CVE-2006-3042
Disclosure Date: June 15, 2006 (last updated November 08, 2023)
Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) go_info[isp][classes_root] parameter in (a) server.inc.php, and the (2) go_info[server][classes_root] parameter in (b) app.inc.php, (c) login.php, and (d) trylogin.php. NOTE: this issue has been disputed by the vendor, who states that the original researcher "reviewed the installation tarball that is not identical with the resulting system after installtion. The file, where the $go_info array is declared ... is created by the installer.
0
Attacker Value
Unknown
CVE-2006-2315
Disclosure Date: May 12, 2006 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the go_info[server][classes_root] parameter. NOTE: the vendor has disputed this vulnerability, saying that session.inc.php is not under the web root in version 2.2, and register_globals is not enabled
0
Attacker Value
Unknown
CVE-2006-1151
Disclosure Date: March 10, 2006 (last updated February 22, 2025)
Cross-site scripting vulnerability in index.php in M-Phorum 0.2 allows remote attackers to inject arbitrary web script or HTML via the go parameter.
0
Attacker Value
Unknown
CVE-2006-1152
Disclosure Date: March 10, 2006 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in index.php in M-Phorum 0.2 allows remote attackers to include arbitrary files via the go parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0