LoK-Crew

3 exploits Active since Apr 2006
CVE-2006-1754 EXPLOITDB text WRITEUP
SWSoft Confixx <3.1.2 - SQL Injection
SQL injection vulnerability in index.php in SWSoft Confixx 3.0.6, 3.0.8, and 3.1.2 allows remote attackers to execute arbitrary SQL commands via the SID parameter.
CVE-2006-2423 EXPLOITDB text WORKING POC
Swsoft Confixx < 3.1.2 - XSS
Cross-site scripting (XSS) vulnerability in ftplogin/index.php in Confixx 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the login parameter.
CVE-2006-1925 EXPLOITDB text WRITEUP
Cutephp Cutenews - XSS
Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify files via the source parameter in the (1) editnews or (2) doeditnews action. NOTE: this can also produce resultant XSS when the target file does not exist.