Latest CVE Feed
-
7.5
HIGHCVE-2006-5526
Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40 and earlier, allow remote attackers to execute arbitrary PHP code via a URL in the foing_root_path parameter in (a) faq.php, (b)... Read more
Affected Products : fully_modded_phpbb- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5537
Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allow remote attackers to inject arbitrary web script or HTML via the (1) upnp:settings/state or (2) upnp:settings/connection parame... Read more
Affected Products : dsl-g624t- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.8
HIGHCVE-2006-5553
Cisco Security Agent (CSA) for Linux 4.5 before 4.5.1.657 and 5.0 before 5.0.0.193, as used by Unified CallManager (CUCM) and Unified Presence Server (CUPS), allows remote attackers to cause a denial of service (resource consumption) via a port scan with ... Read more
- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
6.4
MEDIUMCVE-2006-5544
Visual truncation vulnerability in Microsoft Internet Explorer 7 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a malicious URL containing non-breaking spaces (%A0), which causes the address bar to omit some cha... Read more
- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5555
PHP remote file inclusion vulnerability in constantes.inc.php in EPNadmin 0.7 and 0.7.1 allows remote attackers to execute arbitrary PHP code via the langage parameter.... Read more
Affected Products : epnadmin- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5549
PHP remote file inclusion vulnerability in libraries/amfphp/amf-core/custom/CachedGateway.php in Adobe PHP SDK allows remote attackers to execute arbitrary PHP code via the AMFPHP_BASE parameter. NOTE: this issue has been disputed by a third-party resear... Read more
Affected Products : adobe_php_ria_sdk- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-5542
backend/tcop/postgres.c in PostgreSQL 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) related to duration logging of V3-protocol Execute messages for (1) COMMIT and (2) ROLLBACK SQL statements.... Read more
Affected Products : postgresql- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.9
MEDIUMCVE-2006-5550
The kernel in FreeBSD 6.1 and OpenBSD 4.0 allows local users to cause a denial of service via unspecified vectors involving certain ioctl requests to /dev/crypto.... Read more
- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-5540
backend/parser/analyze.c in PostgreSQL 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) via certain aggregate functions in an UPDATE statement, which are not properly handled during a "MIN/MAX index optimiza... Read more
Affected Products : postgresql- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5523
PHP remote file inclusion vulnerability in common.php in EZ-Ticket 0.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the ezt_root_path parameter.... Read more
Affected Products : ez-ticket- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5517
Multiple PHP remote file inclusion vulnerabilities in Rhode Island Open Meetings Filing Application (OMFA) allow remote attackers to execute arbitrary PHP code via a URL in the PROJECT_ROOT parameter to (1) editmeetings/session.php, (2) email/session.php,... Read more
Affected Products : open_meetings_filing_system- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5515
Cross-site scripting (XSS) vulnerability in lib-history.inc.php in phpAdsNew and phpPgAds before 2.0.8-pr1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to injected data that is stored by a delivery script... Read more
- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5514
SQL injection vulnerability in quiz.php in Web Group Communication Center (WGCC) 0.5.6b and earlier allows remote attackers to execute arbitrary SQL commands via the qzid parameter.... Read more
Affected Products : web_group_communication_center- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5518
Multiple PHP remote file inclusion vulnerabilities in Christopher Fowler (Rhode Island) RSSonate allow remote attackers to execute arbitrary PHP code via a URL in the PROJECT_ROOT parameter to (1) xml2rss.php, (2) config_local.php, (3) rssonate.php, and (... Read more
Affected Products : rssonate- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5519
PHP remote file inclusion vulnerability in Savant2/Savant2_Plugin_options.php in the MambWeather 1.8.1 and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.... Read more
Affected Products : mambweather- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5516
Multiple cross-site scripting (XSS) vulnerabilities in actions/usersettings.php in WikiNi before 0.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) email parameters to wakka.php.... Read more
Affected Products : wikini- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5521
PHP remote file inclusion vulnerability in DNS/RR.php in Net_DNS 0.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpdns_basedir parameter.... Read more
Affected Products : net_dns- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5525
Incomplete blacklist vulnerability in mainfile.php in PHP-Nuke 7.9 and earlier allows remote attackers to conduct SQL injection attacks via (1) "/**/UNION " or (2) " UNION/**/" sequences, which are not rejected by the protection mechanism, as demonstrated... Read more
Affected Products : php-nuke- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5522
Multiple PHP remote file inclusion vulnerabilities in Johannes Erdfelt Kawf 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the config parameter in (1) main.php or (2) user/account/main.php.... Read more
Affected Products : kawf- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5513
SQL injection vulnerability in GeoNetwork opensource before 2.0.3 allows remote attackers to execute arbitrary SQL commands, and complete a login, via unspecified vectors.... Read more
Affected Products : opensource- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025