Latest CVE Feed
-
2.6
LOWCVE-2006-5432
Multiple direct static code injection vulnerabilities in db/txt.inc.php in phpPowerCards 2.10, when register_globals is enabled, allow remote attackers to create or overwrite arbitrary files via the (1) email[to], (2) email[from], (3) name[to], (4) name[f... Read more
Affected Products : phppowercards- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5440
PHP remote file inclusion vulnerability in adminfoot.php in Comdev Form Designer 4.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: the provenance of this informati... Read more
Affected Products : comdev_form_designer- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5438
PHP remote file inclusion vulnerability in adminfoot.php in Comdev Forum 4.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: the provenance of this information is un... Read more
Affected Products : comdev_forum- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5435
PHP remote file inclusion vulnerability in groupcp.php in phpBB 2.0.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: CVE and the vendor dispute this vulnerability because $phpbb_root_p... Read more
Affected Products : phpbb- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5436
PHP remote file inclusion vulnerability in index.php in FreeFAQ 1.0.e allows remote attackers to execute arbitrary PHP code via a URL in the faqpath parameter.... Read more
Affected Products : freefaq- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5437
Directory traversal vulnerability in upgrade.php in phpAdsNew 2.0.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the phpAds_config[language] parameter. NOTE: this issue could not be reproduced by a third party... Read more
Affected Products : phpadsnew- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5433
PHP remote file inclusion vulnerability in modules/guestbook/index.php in ALiCE-CMS 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[local_root] parameter.... Read more
Affected Products : alice_cms- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5434
PHP remote file inclusion vulnerability in p-news.php in P-News 1.16 and 1.17 allows remote attackers to execute arbitrary PHP code via a URL in the pn_lang parameter.... Read more
Affected Products : p-news- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5441
PHP remote file inclusion vulnerability in adminfoot.php in Comdev Web Blogger 4.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: the provenance of this information... Read more
Affected Products : comdev_web_blogger- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
7.2
HIGHCVE-2006-4926
The NDIS-TDI Hooking Engine, as used in the (1) KLICK (KLICK.SYS) and (2) KLIN (KLIN.SYS) device drivers 2.0.0.281 for in Kaspersky Labs Anti-Virus 6.0.0.303 and other Anti-Virus and Internet Security products, allows local users to execute arbitrary code... Read more
- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5423
PHP remote file inclusion vulnerability in admin/admin_module.php in Lou Portail 1.4.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the g_admin_rep parameter. NOTE: the provenance of this information is unknown... Read more
Affected Products : lou_portail- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5430
Cross-site scripting (XSS) vulnerability in the search functionality in db-central (dbc) Enterprise CMS and db-central CMS allows remote attackers to inject arbitrary web script or HTML via the needle parameter. NOTE: the provenance of this information i... Read more
- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5426
PHP remote file inclusion vulnerability in lib/lcUser.php in LoCal Calendar System 1.1 remote attackers to execute arbitrary PHP code via a URL in the LIBDIR parameter.... Read more
Affected Products : local_calendar_system- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5431
PHP remote file inclusion vulnerability in gorum/dbproperty.php in PHPOutsourcing Zorum 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the appDirName parameter.... Read more
Affected Products : zorum- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5428
rpc.php in Cerberus Helpdesk 3.2.1 does not verify a client's privileges for a display_get_requesters operation, which allows remote attackers to bypass the GUI login and obtain sensitive information (ticket data) via a direct request.... Read more
Affected Products : cerberus_helpdesk- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5425
XORP (eXtensible Open Router Platform) 1.2 and 1.3 allows remote attackers to cause a denial of service (application crash) via an Open Shortest Path First (OSPF) Link State Advertisement (LSA) with an invalid LSA length field.... Read more
Affected Products : extensible_open_router_platform- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5427
PHP remote file inclusion vulnerability in plugins/main.php in Php AMX 0.9.0, when register_globals is enabled or magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the plug_path parameter.... Read more
Affected Products : php_amx- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5429
Multiple PHP remote file inclusion vulnerabilities in Barry Nauta BRIM 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the renderer parameter in template.tpl.php in (1) templates/barrel/, (2) templates/sidebar/, (3) tem... Read more
Affected Products : brim- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5424
Unspecified vulnerability in Justsystem Ichitaro 2006, 2006 trial version, and Government 2006 allows remote attackers to execute arbitrary code via a modified document, possibly because of a buffer overflow, a different vulnerability than CVE-2006-4326.... Read more
- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5418
PHP remote file inclusion vulnerability in archive/archive_topic.php in pbpbb archive for search engines (SearchIndexer) (aka phpBBSEI) for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more
Affected Products : searchindexer- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025