Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 614

Количество 331 614

nvd логотип

CVE-2006-1269

почти 20 лет назад

Buffer overflow in the parse function in parse.c in zoo 2.10 might allow local users to execute arbitrary code via long filename command line arguments, which are not properly handled during archive creation. NOTE: since this issue is local and not setuid, the set of attack scenarios is limited, although is reasonable to expect that there are some situations in which the zoo user might automatically list attacker-controlled filenames to add to the zoo archive.

CVSS2: 6.2
EPSS: Низкий
nvd логотип

CVE-2006-1268

почти 20 лет назад

The Internet Key Exchange implementation in Funkwerk X2300 7.2.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2006-1267

почти 20 лет назад

Invision Power Board 2.1.4 allows remote attackers to hijack sessions and possibly gain administrative privileges by obtaining the session ID from the s parameter, then replaying it in another request.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2006-1266

почти 20 лет назад

Cross-site scripting (XSS) vulnerability in Service_Requests.asp in VPMi Enterprise 3.3 allows remote attackers to inject arbitrary web script or HTML via the Request_Name_Display parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-1265

почти 20 лет назад

SQL injection vulnerability in discussion.class.php in xhawk.net discussion 2.0 beta2 allows remote attackers to execute arbitrary SQL commands via the view parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2006-1264

почти 20 лет назад

Cross-site scripting (XSS) vulnerability in xhawk.net discussion 2.0 beta2 allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in a BBCode img tag.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-1263

почти 20 лет назад

Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in WordPress before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-1262

почти 20 лет назад

Multiple SQL injection vulnerabilities in ASPPortal 3.00 have unknown impact and attack vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2006-1261

почти 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in ASPPortal 3.00 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-1260

почти 20 лет назад

Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which bypasses a sanity check.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2006-1259

почти 20 лет назад

Multiple SQL injection vulnerabilities in Maian Support 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) email or (2) pass parameter to admin/index.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2006-1258

почти 20 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.1 allows remote attackers to inject arbitrary web script or HTML via the set_theme parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-1257

почти 20 лет назад

The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a valid username and any password, then going to the main site twice.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2006-1256

почти 20 лет назад

Cross-site scripting (XSS) vulnerability in guestbook.php in Soren Boysen (SkullSplitter) PHP Guestbook 2.6 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2006-1255

почти 20 лет назад

Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string to the (1) LOGIN or (2) SELECT command, a different set of attack vectors and possibly a different vulnerability than CVE-2003-1177.

CVSS2: 10
EPSS: Высокий
nvd логотип

CVE-2006-1254

почти 20 лет назад

Unspecified vulnerability in BorderWare MXtreme 5.0 and 6.0 allows remote attackers to have an unknown impact via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2006-1253

почти 20 лет назад

Unspecified vulnerability in glFTPd before 2.01 RC5 allows remote attackers to bypass IP checks via a crafted DNS hostname, possibly a hostname that appears to be an IP address.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2006-1252

почти 20 лет назад

Eval injection vulnerability in cal.php in Light Weight Calendar (LWC) 1.0 allows remote attackers to execute arbitrary PHP code via the date parameter to index.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2006-1251

почти 20 лет назад

Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-1250

почти 20 лет назад

Unspecified vulnerability in the Webmail module in Winmail before 4.3 has unknown impact and unknown remote attack vectors.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2006-1269

Buffer overflow in the parse function in parse.c in zoo 2.10 might allow local users to execute arbitrary code via long filename command line arguments, which are not properly handled during archive creation. NOTE: since this issue is local and not setuid, the set of attack scenarios is limited, although is reasonable to expect that there are some situations in which the zoo user might automatically list attacker-controlled filenames to add to the zoo archive.

CVSS2: 6.2
0%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-1268

The Internet Key Exchange implementation in Funkwerk X2300 7.2.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

CVSS2: 7.8
2%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-1267

Invision Power Board 2.1.4 allows remote attackers to hijack sessions and possibly gain administrative privileges by obtaining the session ID from the s parameter, then replaying it in another request.

CVSS2: 5.1
1%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-1266

Cross-site scripting (XSS) vulnerability in Service_Requests.asp in VPMi Enterprise 3.3 allows remote attackers to inject arbitrary web script or HTML via the Request_Name_Display parameter.

CVSS2: 4.3
1%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-1265

SQL injection vulnerability in discussion.class.php in xhawk.net discussion 2.0 beta2 allows remote attackers to execute arbitrary SQL commands via the view parameter.

CVSS2: 7.5
1%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-1264

Cross-site scripting (XSS) vulnerability in xhawk.net discussion 2.0 beta2 allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in a BBCode img tag.

CVSS2: 4.3
1%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-1263

Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in WordPress before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
0%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-1262

Multiple SQL injection vulnerabilities in ASPPortal 3.00 have unknown impact and attack vectors.

CVSS2: 7.5
1%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-1261

Multiple cross-site scripting (XSS) vulnerabilities in ASPPortal 3.00 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
1%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-1260

Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which bypasses a sanity check.

CVSS2: 5
26%
Средний
почти 20 лет назад
nvd логотип
CVE-2006-1259

Multiple SQL injection vulnerabilities in Maian Support 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) email or (2) pass parameter to admin/index.php.

CVSS2: 7.5
1%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-1258

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.1 allows remote attackers to inject arbitrary web script or HTML via the set_theme parameter.

CVSS2: 4.3
8%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-1257

The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a valid username and any password, then going to the main site twice.

CVSS2: 7.5
42%
Средний
почти 20 лет назад
nvd логотип
CVE-2006-1256

Cross-site scripting (XSS) vulnerability in guestbook.php in Soren Boysen (SkullSplitter) PHP Guestbook 2.6 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

CVSS2: 2.6
1%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-1255

Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string to the (1) LOGIN or (2) SELECT command, a different set of attack vectors and possibly a different vulnerability than CVE-2003-1177.

CVSS2: 10
87%
Высокий
почти 20 лет назад
nvd логотип
CVE-2006-1254

Unspecified vulnerability in BorderWare MXtreme 5.0 and 6.0 allows remote attackers to have an unknown impact via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 10
3%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-1253

Unspecified vulnerability in glFTPd before 2.01 RC5 allows remote attackers to bypass IP checks via a crafted DNS hostname, possibly a hostname that appears to be an IP address.

CVSS2: 7.5
0%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-1252

Eval injection vulnerability in cal.php in Light Weight Calendar (LWC) 1.0 allows remote attackers to execute arbitrary PHP code via the date parameter to index.php.

CVSS2: 7.5
6%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-1251

Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.

CVSS2: 5
1%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-1250

Unspecified vulnerability in the Webmail module in Winmail before 4.3 has unknown impact and unknown remote attack vectors.

CVSS2: 10
0%
Низкий
почти 20 лет назад

Уязвимостей на страницу