Latest CVE Feed
-
6.8
MEDIUMCVE-2006-5114
Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) ~urlmime or (2) ~command parameter, different vectors than CVE-2003... Read more
Affected Products : internet_transaction_server- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5126
PHP remote file inclusion vulnerability in index.php in John Himmelman (aka DaRk2k1) PowerPortal 1.3a allows remote attackers to execute arbitrary PHP code via a URL in the file_name[] parameter.... Read more
Affected Products : powerportal- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
4.9
MEDIUMCVE-2006-5122
Multiple cross-site scripting (XSS) vulnerabilities in Mercury SiteScope 8.2 (8.1.2.0) allow remote authenticated users to inject arbitrary web script or HTML via (1) "any field create name field" except "create new group name" or (2) any description fiel... Read more
Affected Products : mercury_sitescope- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5101
PHP remote file inclusion vulnerability in include.php in Comdev CSV Importer 3.1 and possibly 4.1, as used in (1) Comdev Contact Form 3.1, (2) Comdev Customer Helpdesk 3.1, (3) Comdev Events Calendar 3.1, (4) Comdev FAQ Support 3.1, (5) Comdev Guestbook ... Read more
Affected Products : comdev_csv_importer- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5138
Groupee UBB.threads 6.5.1.1 allows remote attackers to obtain sensitive information via a direct request for cron/php/subscriptions.php, which reveals the path in an error message.... Read more
Affected Products : ubb.threads- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-4391
Buffer overflow in Apple ImageIO on Apple Mac OS X 10.4 through 10.4.7 allows remote attackers to execute arbitrary code via a malformed JPEG2000 image.... Read more
Affected Products : mac_os_x- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
3.7
LOWCVE-2006-4393
Unspecified vulnerability in LoginWindow in Apple Mac OS X 10.4 through 10.4.7, when Fast User Switching is enabled, allows local users to gain access to Kerberos tickets of other users.... Read more
Affected Products : mac_os_x- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-4394
A logic error in LoginWindow in Apple Mac OS X 10.4 through 10.4.7, allows network accounts without GUIds to bypass service access controls and log into the system using loginwindow via unknown vectors.... Read more
Affected Products : mac_os_x- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-4395
Unspecified vulnerability in QuickDraw Manager in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows context-dependent attackers to cause a denial of service ("memory corruption" and crash) via a crafted PICT image that is not properly handled by a cert... Read more
Affected Products : mac_os_x- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-4390
CFNetwork in Apple Mac OS X 10.4 through 10.4.7 and 10.3.9 allows remote SSL sites to appear as trusted sites by using encryption without authentication, which can cause the lock icon in Safari to be displayed even when the site's identity cannot be trust... Read more
Affected Products : mac_os_x- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
4.6
MEDIUMCVE-2006-4397
Unchecked error condition in LoginWindow in Apple Mac OS X 10.4 through 10.4.7 prevents Kerberos tickets from being destroyed if a user does not successfully log on to a network account from the login window, which might allow later users to gain access t... Read more
Affected Products : mac_os_x- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-4399
User interface inconsistency in Workgroup Manager in Apple Mac OS X 10.4 through 10.4.7 appears to allow administrators to change the authentication type from crypt to ShadowHash passwords for accounts in a NetInfo parent, when such an operation is not ac... Read more
- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
4.6
MEDIUMCVE-2006-4387
Apple Mac OS X 10.4 through 10.4.7, when the administrator clears the "Allow user to administer this computer" checkbox in System Preferences for a user, does not remove the user's account from the appserveradm or appserverusr groups, which still allows t... Read more
Affected Products : mac_os_x- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.2
HIGHCVE-2006-4392
The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, allows local users to gain privileges via a parent process that forces an exception in a setuid child and uses Mach exception ports to mo... Read more
- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5098
lib/exec/fetch.php in DokuWiki before 2006-03-09e allows remote attackers to cause a denial of service (CPU consumption) via large w and h parameters, when resizing an image.... Read more
Affected Products : dokuwiki- Published: Sep. 29, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5099
lib/exec/fetch.php in DokuWiki before 2006-03-09e, when conf[imconvert] is configured to use ImageMagick, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) w and (2) h parameters, which are not filtered when invokin... Read more
Affected Products : dokuwiki- Published: Sep. 29, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5094
PHP remote file inclusion vulnerability in includes/functions_kb.php in the phpBB XS 2 (Spain version) allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter, a different vector than CVE-2006-4780 or CVE-2006-4893... Read more
Affected Products : phpbb_xs- Published: Sep. 29, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5095
PHP remote file inclusion vulnerability in index.php in MyPhotos 0.1.3b beta allows remote attackers to execute arbitrary PHP code via the includesdir parameter. NOTE: this issue is disputed by CVE on 20060927, since the includesdir is defined before bei... Read more
Affected Products : myphotos- Published: Sep. 29, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5096
Multiple cross-site scripting (XSS) vulnerabilities in index.php in VirtueMart (formerly known as mambo-phpShop) Joomla! eCommerce Edition CMS 1.0.11, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the Itemid param... Read more
Affected Products : virtuemart_joomla_ecommerrce_edition_cms- Published: Sep. 29, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5097
PHP remote file inclusion vulnerability in index.php in net2ftp, possibly 0.1 through 0.62, allows remote attackers to execute arbitrary PHP code via a URL in the application_rootdir parameter. NOTE: this issue has been disputed by a third party researche... Read more
Affected Products : net2ftp- Published: Sep. 29, 2006
- Modified: Apr. 09, 2025