Latest CVE Feed
-
2.6
LOWCVE-2006-1745
Cross-site scripting (XSS) vulnerability in login.php in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third... Read more
Affected Products : bitweaver- Published: Apr. 12, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1748
Cross-site scripting (XSS) vulnerability in XMB Forum 1.9.5 allows remote attackers to inject arbitrary web script or HTML by uploading a Flash (.SWF) video that contains a getURL function call, which causes the video to be rendered without disabling Acti... Read more
Affected Products : xmb_forum- Published: Apr. 12, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1674
Cross-site scripting (XSS) vulnerability in search.php in PHPWebGallery 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vulnerability than CVE-2006-1675.... Read more
Affected Products : phpwebgallery- Published: Apr. 10, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1673
Cross-site scripting (XSS) vulnerability in vbugs.php in Dark_Wizard vBug Tracker 3.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter.... Read more
Affected Products : vbug_tracker- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3227
Interpretation conflict between Internet Explorer and other web browsers such as Mozilla, Opera, and Firefox might allow remote attackers to modify the visual presentation of web pages and possibly bypass protection mechanisms such as content filters via ... Read more
Affected Products : internet_explorer- Published: Jun. 26, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1554
Cross-site scripting (XSS) vulnerability in VSNS Lemon 3.2.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter while adding a comment.... Read more
Affected Products : vsns_lemon- Published: Mar. 31, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1476
Windows Firewall in Microsoft Windows XP SP2 produces incorrect application block alerts when the application filename is ".exe" (with no characters before the "."), which might allow local user-assisted users to trick a user into unblocking a Trojan hors... Read more
Affected Products : windows_xp- Published: Mar. 29, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2003-1577
Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files, and conduct cross-site scripting (XSS) attacks involving the iP... Read more
Affected Products : one_web_server- Published: Feb. 05, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-3039
Cross-site scripting (XSS) vulnerability in index.php in Cescripts Realty Home Rent allows remote attackers to inject arbitrary web script or HTML via the sel_menu parameter. NOTE: the vendor notified CVE on 20060823 that "All issues concerning this scri... Read more
Affected Products : realty_home_rent- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2538
IE Tab 1.0.9 plugin for Mozilla Firefox 1.5.0.3 allows remote user-assisted attackers to cause a denial of service (application crash), possibly due to a null dereference, via certain Javascript, as demonstrated using a url parameter to the content/reload... Read more
- Published: May. 22, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2997
Cross-site scripting (XSS) vulnerability in ZMS 2.9 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the raw parameter in the search field.... Read more
Affected Products : zms- Published: Jun. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-0593
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes th... Read more
- Published: Mar. 04, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2519
Directory traversal vulnerability in include/inc_ext/spaw/spaw_control.class.php in phpwcms 1.2.5-DEV allows remote attackers to include arbitrary local files via .. (dot dot) sequences in the spaw_root parameter. NOTE: CVE analysis suggests that this is... Read more
Affected Products : phpwcms- Published: May. 22, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3061
Multiple cross-site scripting (XSS) vulnerabilities in 5 Star Review allow remote attackers to inject arbitrary web script or HTML via the (1) sort parameter in index2.php, (2) item_id parameter in report.php, (3) search_term parameter (aka the "search bo... Read more
Affected Products : five_star_review_script- Published: Jun. 19, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3050
Directory traversal vulnerability in detail.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the template parameter.... Read more
Affected Products : sixcms- Published: Jun. 16, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3225
Cross-site scripting (XSS) vulnerability in Sun ONE Application Server 7 before Update 9, Java System Application Server 7 2004Q2 before Update 5, and Java System Application Server Enterprise Edition 8.1 2005 Q1 allows remote attackers to inject arbitrar... Read more
- Published: Jun. 26, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-0626
Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.... Read more
Affected Products : squid- Published: Mar. 08, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-3921
Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets containing HTML that an administrator views via an HTTP interface to the contents of memory buf... Read more
Affected Products : ios- Published: Nov. 30, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2572
Cross-site scripting (XSS) vulnerability in index.php in DGBook 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) homepage, (3) email, and (4) address parameters.... Read more
Affected Products : dgbook- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1801
The vCard viewer in Nokia 9500 allows attackers to cause a denial of service (crash) via a vCard with a long Name field, which causes the crash when the user views it.... Read more
Affected Products : 9500- Published: May. 26, 2005
- Modified: Apr. 03, 2025