Latest CVE Feed
-
7.5
HIGHCVE-2006-5225
Multiple SQL injection vulnerabilities in AAIportal before 1.4.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : aaiportal- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5228
Multiple SQL injection vulnerabilities in the Google Gadget login.php (gadget/login.php) in Rob Hensley ackerTodo 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) up_login, (2) up_pass, or (3) up_num_tasks parameters.... Read more
Affected Products : ackertodo- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5226
PHP remote file inclusion vulnerability in moteur/moteur.php in Prologin.fr Freenews 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.... Read more
Affected Products : freenews- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5222
Multiple PHP remote file inclusion vulnerabilities in Dimension of phpBB 0.2.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/themen_portal_mitte.php or (2) includes/logger_engin... Read more
Affected Products : dimension_of_phpbb- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5227
Cross-site scripting (XSS) vulnerability in admin.php in TorrentFlux 2.1 allows remote attackers to inject arbitrary web script or HTML via (1) the $user_agent variable, probably obtained from the User-Agent HTTP header, and possibly (2) the $ip_resolved ... Read more
Affected Products : torrentflux- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2006-3876
Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via a crafted Data record in a PPT file, a different vulnerabi... Read more
Affected Products : office- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5223
PHP remote file inclusion vulnerability in includes/functions_user_viewed_posts.php in the Nivisec User Viewed Posts Tracker module 1.0 and earlier for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more
Affected Products : user_viewed_posts_tracker- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5216
Stack-based buffer overflow in Sergey Lyubka Simple HTTPD (shttpd) 1.34 allows remote attackers to execute arbitrary code via a long URI.... Read more
Affected Products : simple_httpd- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.4
MEDIUMCVE-2006-5179
Intoto iGateway VPN and iGateway SSL-VPN allow context-dependent attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) "public exponent" or (2) "public modulus" values in X.509 certificates that require extra ti... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5207
PHP remote file inclusion vulnerability in images/smileys/smileys_packs.php in phpMyTeam 2.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the smileys_dir parameter.... Read more
Affected Products : phpmyteam- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5182
PHP remote file inclusion vulnerability in frontpage.php in Dan Jensen Travelsized CMS 0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the setup_folder parameter.... Read more
Affected Products : travelsized_cms- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5187
PHP remote file inclusion vulnerability in includes/functions.php in Bulletin Board Ace (BBaCE) 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more
Affected Products : bulletin_board_ace- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.8
HIGHCVE-2006-5196
The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with MfcISAPICommand set to SecretProc and a long string in the Secret parameter.... Read more
Affected Products : surfboard- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5208
Multiple SQL injection vulnerabilities in PHP Classifieds 7.1 allow remote attackers to execute arbitrary SQL commands via (1) the catid_search parameter in search.php and (2) the catid parameter in index.php.... Read more
Affected Products : php_classifieds- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5191
PHP remote file inclusion vulnerability in includes/functions_static_topics.php in the Nivisec Static Topics module for phpBB 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more
Affected Products : phpbb- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5194
Cross-site scripting (XSS) vulnerability in index.php in net2ftp 0.93 allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : net2ftp- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5183
Multiple PHP remote file inclusion vulnerabilities in Dayfox Designs Dayfox Blog 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the slogin parameter in the (1) adminlog.php, (2) postblog.php, (3) index.php, or (4) index2.php script ... Read more
Affected Products : dayfox_blog- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5202
Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to Security.tri, as demonstrated using the SecurityMode and layout paramet... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2006-5176
Buffer overflow in NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to execute arbitrary code via "the signature field of NTLM Type 1 messages".... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-2006-5213
Sun Solaris 10 before 20061006 uses "incorrect and insufficient permission checks" that allow local users to intercept or spoof packets by creating a raw socket on a link aggregation (network device aggregation).... Read more
Affected Products : solaris- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025