Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 418

Количество 374 418

nvd логотип

CVE-2006-1832

больше 20 лет назад

sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-1831

больше 20 лет назад

Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows remote attackers to execute arbitrary commands via a leading ; (semicolon) in the name parameter in a systemdoc action, which is injected into phpinfo.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2006-1830

больше 20 лет назад

Sun Java Studio Enterprise 8, when installed as root, creates certain files with world-writable permissions, which allows local users to execute arbitrary commands via unspecified vectors.

CVSS2: 3.7
EPSS: Низкий
nvd логотип

CVE-2006-1829

больше 20 лет назад

EAServer Manager in Sybase EAServer 5.2 and 5.3 allows remote authenticated users, possibly guests, to obtain password credentials of arbitrary users via unspecified vectors involving (1) connection caches, (2) open password prompts, and (3) stored custom connection profiles.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2006-1828

больше 20 лет назад

SQL injection vulnerability in php121language.php in PHP121 1.4 allows remote attackers to execute arbitrary SQL commands and execute arbitrary code via the sess_username variable, as set by the php121un HTTP COOKIE parameter, which is used in multiple files including php121login.php. NOTE: the code execution occurs because the SQL query results are used in an include statement.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2006-1827

больше 20 лет назад

Integer signedness error in format_jpeg.c in Asterisk 1.2.6 and earlier allows remote attackers to execute arbitrary code via a length value that passes a length check as a negative number, but triggers a buffer overflow when it is used as an unsigned length.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2006-1826

больше 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Snipe Gallery 3.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in view.php, (2) keyword parameter in search.php, and (3) image_id parameter in image.php. NOTE: it is possible that vectors 1 and 3 are resultant from SQL injection.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-1825

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2006-1824

больше 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PhpGuestbook.php in PhpGuestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Website, and (3) Comment parameter.

CVSS2: 1.2
EPSS: Низкий
nvd логотип

CVE-2006-1823

больше 20 лет назад

Directory traversal vulnerability in FarsiNews 2.5.3 Pro and earlier allows remote attackers to obtain the installation path via ".." sequences in the archive parameter to index.php, which leaks the full pathname in an error message.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2006-1822

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in search.php in FarsiNews 2.5.3 Pro and earlier allows remote attackers to inject arbitrary web script or HTML via the selected_search_arch parameter.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2006-1821

больше 20 лет назад

Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the id parameter.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2006-1820

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this might be resultant from the directory traversal vulnerability.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2006-1819

больше 20 лет назад

Directory traversal vulnerability in the loadConfig function in index.php in phpWebSite 0.10.2 and earlier allows remote attackers to include arbitrary local files and execute arbitrary PHP code via the hub_dir parameter, as demonstrated by including access_log. NOTE: in some cases, arbitrary remote file inclusion could be performed under PHP 5 using an SMB share argument such as "\\systemname\sharename".

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2006-1818

больше 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly including the (1) first_name and (2) last_name parameter in myaccounts.php. NOTE: portions of these details were obtained from third party sources instead of the original disclosure.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2006-1817

больше 20 лет назад

SQL injection vulnerability in authcheck.php in warforge.NEWS 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) authusername and possibly the (2) authpassword cookie.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2006-1816

больше 20 лет назад

PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers to execute arbitrary code via a URL in the systempath parameter to (1) ImpExModule.php, (2) ImpExController.php, and (3) ImpExDisplay.php.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-1815

больше 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) newuser_realname and (2) newuser_icq parameters, a different vector than CVE-2006-1768. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2006-1814

больше 20 лет назад

NetBSD 1.6, 2.0, 2.1 and 3.0 allows local users to cause a denial of service (memory exhaustion) by using the sysctl system call to lock a large buffer into physical memory.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2006-1813

больше 20 лет назад

Directory traversal vulnerability in index.php in phpWebFTP 3.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter.

CVSS2: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2006-1832

sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action.

CVSS2: 5
7%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1831

Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows remote attackers to execute arbitrary commands via a leading ; (semicolon) in the name parameter in a systemdoc action, which is injected into phpinfo.php.

CVSS2: 7.5
8%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1830

Sun Java Studio Enterprise 8, when installed as root, creates certain files with world-writable permissions, which allows local users to execute arbitrary commands via unspecified vectors.

CVSS2: 3.7
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1829

EAServer Manager in Sybase EAServer 5.2 and 5.3 allows remote authenticated users, possibly guests, to obtain password credentials of arbitrary users via unspecified vectors involving (1) connection caches, (2) open password prompts, and (3) stored custom connection profiles.

CVSS2: 4
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1828

SQL injection vulnerability in php121language.php in PHP121 1.4 allows remote attackers to execute arbitrary SQL commands and execute arbitrary code via the sess_username variable, as set by the php121un HTTP COOKIE parameter, which is used in multiple files including php121login.php. NOTE: the code execution occurs because the SQL query results are used in an include statement.

CVSS2: 5.1
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1827

Integer signedness error in format_jpeg.c in Asterisk 1.2.6 and earlier allows remote attackers to execute arbitrary code via a length value that passes a length check as a negative number, but triggers a buffer overflow when it is used as an unsigned length.

CVSS2: 6.4
7%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1826

Multiple cross-site scripting (XSS) vulnerabilities in Snipe Gallery 3.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in view.php, (2) keyword parameter in search.php, and (3) image_id parameter in image.php. NOTE: it is possible that vectors 1 and 3 are resultant from SQL injection.

CVSS2: 4.3
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1825

Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.

CVSS2: 6.8
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1824

Multiple cross-site scripting (XSS) vulnerabilities in PhpGuestbook.php in PhpGuestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Website, and (3) Comment parameter.

CVSS2: 1.2
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1823

Directory traversal vulnerability in FarsiNews 2.5.3 Pro and earlier allows remote attackers to obtain the installation path via ".." sequences in the archive parameter to index.php, which leaks the full pathname in an error message.

CVSS2: 6.4
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1822

Cross-site scripting (XSS) vulnerability in search.php in FarsiNews 2.5.3 Pro and earlier allows remote attackers to inject arbitrary web script or HTML via the selected_search_arch parameter.

CVSS2: 5.8
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1821

Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the id parameter.

CVSS2: 6.4
3%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1820

Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this might be resultant from the directory traversal vulnerability.

CVSS2: 5.8
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1819

Directory traversal vulnerability in the loadConfig function in index.php in phpWebSite 0.10.2 and earlier allows remote attackers to include arbitrary local files and execute arbitrary PHP code via the hub_dir parameter, as demonstrated by including access_log. NOTE: in some cases, arbitrary remote file inclusion could be performed under PHP 5 using an SMB share argument such as "\\systemname\sharename".

CVSS2: 7.5
4%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1818

Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly including the (1) first_name and (2) last_name parameter in myaccounts.php. NOTE: portions of these details were obtained from third party sources instead of the original disclosure.

CVSS2: 2.6
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1817

SQL injection vulnerability in authcheck.php in warforge.NEWS 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) authusername and possibly the (2) authpassword cookie.

CVSS2: 2.6
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1816

PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers to execute arbitrary code via a URL in the systempath parameter to (1) ImpExModule.php, (2) ImpExController.php, and (3) ImpExDisplay.php.

CVSS2: 5
3%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1815

Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) newuser_realname and (2) newuser_icq parameters, a different vector than CVE-2006-1768. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 2.6
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1814

NetBSD 1.6, 2.0, 2.1 and 3.0 allows local users to cause a denial of service (memory exhaustion) by using the sysctl system call to lock a large buffer into physical memory.

CVSS2: 2.1
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1813

Directory traversal vulnerability in index.php in phpWebFTP 3.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter.

CVSS2: 6.4
2%
Низкий
больше 20 лет назад

Уязвимостей на страницу