Latest CVE Feed
-
7.5
HIGHCVE-2006-5254
PHP remote file inclusion vulnerability in registration_detailed.inc.php in Mark Van Bellen Detailed User Registration (com_registration_detailed), aka regdetailed, 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mos... Read more
Affected Products : extended_registration- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5252
PHP remote file inclusion vulnerability in includes/core.lib.php in Webmedia Explorer 2.8.7 allows remote attackers to execute arbitrary PHP code via a URL in the path_include parameter.... Read more
Affected Products : webmedia_explorer- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5263
Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter, as demonstrated by a parameter value naming an Apa... Read more
Affected Products : phpmyagenda- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5261
Multiple PHP remote file inclusion vulnerabilities in PHPMyNews 1.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the cfg_include_dir parameter in (1) disp_form.php3, (2) disp_smileys.php3, (3) little_news.php3, and (4) ind... Read more
Affected Products : phpmynews- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5259
PHP remote file inclusion vulnerability in param_editor.php in Compteur 2 allows remote attackers to execute arbitrary PHP code via a URL in the folder parameter.... Read more
Affected Products : compteur- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5251
PHP remote file inclusion vulnerability in index.php in Deep CMS 2.0a allows remote attackers to execute arbitrary PHP code via a URL in the ConfigDir parameter. NOTE: the provenance of this information is unknown; the details are obtained from third par... Read more
Affected Products : deep_cms- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
6.5
MEDIUMCVE-2006-5262
CRLF injection vulnerability in lib/session.php in Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary IMAP commands via a CRLF sequence in a mailbox name. NOTE: the attack crosses privilege boundaries if the IMA... Read more
Affected Products : hastymail- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5253
PHP remote file inclusion vulnerability in strload.php in Dayana Networks phpOnline (aka PHP-Online) 2.1 allows remote attackers to execute arbitrary PHP code via a URL in the LangFile parameter.... Read more
Affected Products : phponline- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5258
The spell checking component of (1) Asbru Web Content Management before 6.1.22, (2) Asbru Web Content Editor before 6.0.22, and (3) Asbru Website Manager before 6.0.22 allows remote attackers to execute arbitrary commands via an unspecified parameter that... Read more
- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5255
PHP remote file inclusion vulnerability in addnews.php in Greg Neustaetter gCards 1.13 allows remote attackers to execute arbitrary PHP code via a URL in the languagefile parameter. NOTE: another researcher has observed that languageFile is defined befor... Read more
Affected Products : gcards- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5256
PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the includePath parameter.... Read more
Affected Products : claroline- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5264
Cross-site scripting (XSS) vulnerability in sql.php in MysqlDumper 1.21 b6 allows remote attackers to inject arbitrary web script or HTML via the db parameter.... Read more
Affected Products : mysqldumper- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-4813
The __block_prepare_write function in fs/buffer.c for Linux kernel 2.6.x before 2.6.13 does not properly clear buffers during certain error conditions, which allows local users to read portions of files that have been unlinked.... Read more
Affected Products : linux_kernel- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5243
Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Doc 1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) down_stat.php, (2) file.php, (3... Read more
Affected Products : easy_doc- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5245
Eazy Cart allows remote attackers to bypass authentication and gain administrative access via a direct request for admin/home/index.php, and possibly other PHP scripts under admin/.... Read more
Affected Products : eazy_cart- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5244
Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Blog 1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) down_stat.php, (2) file.php, (... Read more
Affected Products : easy_blog- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
7.8
HIGHCVE-2006-5248
Eazy Cart stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a customer database via a direct request for admin/config/customer.dat. NOTE: the provenance of this information is unkn... Read more
Affected Products : eazy_cart- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5249
PHP remote file inclusion vulnerability in tagmin/delTagUser.php in TagIt! Tagboard 2.1.B Build 2 (tagit2b) allows remote attackers to execute arbitrary PHP code via a URL in the configpath parameter.... Read more
Affected Products : tagboard- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
4.9
MEDIUMCVE-2006-4516
Integer signedness error in FreeBSD 6.0-RELEASE allows local users to cause a denial of service (memory corruption and kernel panic) via a PT_LWPINFO ptrace command with a large negative data value that satisfies a signed maximum value check but is used i... Read more
Affected Products : freebsd- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5250
PHP remote file inclusion vulnerability in lib/googlesearch/GoogleSearch.php in BlueShoes 4.6_public and earlier allows remote attackers to execute arbitrary PHP code via a URL in the APP[path][lib] parameter, a different vector than CVE-2006-2864.... Read more
Affected Products : blueshoes_framework- Published: Oct. 12, 2006
- Modified: Apr. 09, 2025