Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    2
    Critical Level Threats
    0
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2006-6258

    The phpmyadmin subsystem in AlternC 0.9.5 and earlier transmits the SQL password in cleartext in a cookie, which might allow remote attackers to obtain the password by sniffing or by conducting a cross-site scripting (XSS) attack.

    Last Modified: Apr 23, 2026
    Published: Dec 04, 2006

    CVE-2006-6256

    Cross-site scripting (XSS) vulnerability in the file manager in admin/bro_main.php in AlternC 0.9.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a folder name.

    Last Modified: Apr 23, 2026
    Published: Dec 04, 2006

    CVE-2006-6257

    The file manager in AlternC 0.9.5 and earlier, when warnings are enabled in PHP, allows remote attackers to obtain sensitive information via certain folder names such as ones composed of JavaScript code, which reveal the path in a warning message.

    Last Modified: Apr 23, 2026
    Published: Dec 04, 2006

    CVE-2006-6259

    Multiple directory traversal vulnerabilities in (a) class/functions.php and (b) class/m_bro.php in AlternC 0.9.5 and earlier allow remote attackers to (1) create arbitrary files and directories via a .. (dot dot) in the "create name" field and (2) read arbitrary files via a .. (dot dot) in the "web root" field when configuring a subdomain.

    Last Modified: Apr 23, 2026
    Published: Dec 04, 2006
    Items Per Page
    Alternc Vulnerabilities & Security CVEs | CVE-DB