Latest CVE Feed
-
4.3
MEDIUMCVE-2006-4874
Multiple cross-site scripting (XSS) vulnerabilities in Jupiter CMS allow remote attackers to inject arbitrary web script or HTML via the (1) language[Admin name] and (2) language[Admin back] parameters in (a) modules/blocks.php; the (3) language[Register ... Read more
Affected Products : jupiter_cms- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4877
Variable overwrite vulnerability in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to overwrite arbitrary program variables via multiple vectors that use the extract function, as demonstrated by the table_prefix parameter in (1) ind... Read more
Affected Products : php-post- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2006-4886
The VirusScan On-Access Scan component in McAfee VirusScan Enterprise 7.1.0 and Scan Engine 4.4.00 allows local privileged users to bypass security restrictions and disable the On-Access Scan option by opening the program via the task bar and quickly clic... Read more
- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4875
Unrestricted file upload vulnerability in modules/galleryuploadfunction.php in Jupiter CMS allows remote attackers to upload picture files, and possibly files with arbitrary extensions, to gallery/albums/public.... Read more
Affected Products : jupiter_cms- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4884
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 allow remote attackers to inject arbitrary web script or HTML via (1) the suser parameter in support/rightbar.php, (2) the ticket_id parameter in support/open_tickets.php, and (3... Read more
Affected Products : isupport- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4876
Multiple SQL injection vulnerabilities in Jupiter CMS allow remote attackers to execute arbitrary SQL commands via (1) the user name during login, or the (2) key or (3) fpwusername parameters in modules/register.... Read more
Affected Products : jupiter_cms- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4334
Unspecified vulnerability in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (crash) via a crafted GZIP (gz) archive, which results in a NULL dereference.... Read more
Affected Products : gzip- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4335
Array index error in the make_table function in unlzh.c in the LZH decompression component in gzip 1.3.5, when running on certain platforms, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a ... Read more
Affected Products : gzip- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4336
Buffer underflow in the build_tree function in unpack.c in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted leaf count table that causes a write to a negative index.... Read more
Affected Products : gzip- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4867
SQL injection vulnerability in mods.php in GNUTurk 2G and earlier allows remote attackers to execute arbitrary SQL commands via the t_id parameter when the go parameter is "Forum."... Read more
Affected Products : gnuturk_portal_system- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-4535
The Linux kernel 2.6.17.10 and 2.6.17.11 and 2.6.18-rc5 allows local users to cause a denial of service (crash) via an SCTP socket with a certain SO_LINGER value, possibly related to the patch for CVE-2006-3745. NOTE: older kernel versions for specific L... Read more
- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4869
PHP remote file inclusion vulnerability in phpunity-postcard.php in phpunity.postcard allows remote attackers to execute arbitrary PHP code via a URL in the gallery_path parameter.... Read more
Affected Products : phpunity_postcard- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4870
Multiple PHP remote file inclusion vulnerabilities in AEDating 4.1, and possibly earlier versions, allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) inc/design.inc.php or (2) inc/admin_design.inc.php.... Read more
Affected Products : aedating- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-4868
Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Lan... Read more
- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-4866
Buffer overflow in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via a long extension argument.... Read more
- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4856
Multiple cross-site scripting (XSS) vulnerabilities in Roller WebLogger 2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, or (3) url parameters; (4) certain content parameters in the preview method; or (5) the ... Read more
Affected Products : roller_weblogger- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4862
SQL injection vulnerability in default.aspx in easypage allows remote attackers to execute arbitrary SQL commands via the srch parameter in the Search page.... Read more
Affected Products : easypagecms- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-4860
Multiple unspecified vulnerabilities in (1) index.php, (2) minixml.inc.php, (3) doc.inc.php, (4) element.inc.php, (5) node.inc.php, (6) treecomp.inc.php, (7) forum.html.php, (8) forum.php, (9) antihack.php, (10) content.php, (11) initglobals.php, and (12)... Read more
Affected Products : limbo_cms- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4865
Walter Beschmout PhpQuiz allows remote attackers to obtain sensitive information via a direct request to cfgphpquiz/install.php and other unspecified vectors.... Read more
Affected Products : phpquiz- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-4858
PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.... Read more
Affected Products : serverstat_component- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025