Latest CVE Feed
-
7.5
HIGHCVE-2006-4978
Multiple SQL injection vulnerabilities in Walter Beschmout PhpQuiz 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the univers parameter in score.php and (2) the quiz_id parameter in home.php, accessed through the front/ U... Read more
Affected Products : phpquiz- Published: Sep. 25, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4975
Yahoo! Messenger for WAP permits saving messages that contain JavaScript, which allows user-assisted remote attackers to inject arbitrary web script or HTML via a URL at the online service.... Read more
Affected Products : messenger- Published: Sep. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4979
Direct static code injection vulnerability in cfgphpquiz/install.php in Walter Beschmout PhpQuiz 1.2 and earlier allows remote attackers to inject arbitrary PHP code in config.inc.php via modified configuration settings.... Read more
Affected Products : phpquiz- Published: Sep. 25, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-4967
Multiple cross-site scripting (XSS) vulnerabilities in NextAge Cart allow remote attackers to inject arbitrary web script or HTML via (1) the CatId parameter in a product category action in index.php or (2) the SearchWd parameter in an index search action... Read more
Affected Products : nextage_shopping_cart- Published: Sep. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4974
Buffer overflow in Ipswitch WS_FTP Limited Edition (LE) 5.08 allows remote FTP servers to execute arbitrary code via a long response to a PASV command.... Read more
Affected Products : ws_ftp_server- Published: Sep. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4968
PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more
Affected Products : pnphpbb- Published: Sep. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4969
Multiple PHP remote file inclusion vulnerabilities in WAHM E-Commerce Pie Cart Pro allow remote attackers to execute arbitrary PHP code via a URL in the Inc_Dir parameter in (1) affiliates.php, (2) orders.php, (3) events.php, (4) index.php, (5) articles.p... Read more
Affected Products : pie_cart_pro- Published: Sep. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4973
Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual Motion Interactive Systems DotNetNuke before 3.3.5, and 4.x before 4.3.5, allows remote attackers to inject arbitrary HTML via the error parameter.... Read more
Affected Products : dotnetnuke- Published: Sep. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4965
Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter that identifies resources outsi... Read more
Affected Products : quicktime- Published: Sep. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4966
PHP remote file inclusion vulnerability in inc/ifunctions.php in chumpsoft phpQuestionnaire (phpQ) 3.12 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[phpQRootDir] parameter.... Read more
Affected Products : phpquestionnaire- Published: Sep. 25, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-4958
Multiple cross-site scripting (XSS) vulnerabilities in Sun Secure Global Desktop (SSGD, aka Tarantella) before 4.20.983 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving (1) taarchives.cgi, (2) ttaA... Read more
Affected Products : secure_global_desktop- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-4963
Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence in the view parameter in the show_view action in the calendarmodule module, as demonstrated... Read more
- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-4964
Cross-site scripting (XSS) vulnerability in MAXdev MDPro 1.0.76 before 20060918 allows remote attackers to inject arbitrary web script or HTML via (1) vectors that bypass the XSS protection mechanisms of the pnVarCleanFromInput function, and (2) unspecifi... Read more
Affected Products : md-pro- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-4956
Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote attackers to inject arbitrary web script or HTML via the in_name parameter, as used by the Name field.... Read more
Affected Products : neon_webmail- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4953
Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary SQL commands via the (1) adr_sortkey and (2) adr_sortkey_desc parameters in the (a) addrlist servlet, and the (3) sortkey and (4) sortk... Read more
Affected Products : neon_webmail- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4955
Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the (1) savefolder and (2) savefilename parameters.... Read more
Affected Products : neon_webmail- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4952
The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail folders, specified by the folderid and tofolderid parameters, via the ID parameter.... Read more
Affected Products : neon_webmail- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4961
SQL injection vulnerability in the GetModuleConfig function in public_includes/pub_kernel/pbd_modules.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter to index.php.... Read more
Affected Products : php_blue_dragon- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-4962
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence via the phpExt parameter, as demonstrated by executing PHP code in a log... Read more
Affected Products : php_blue_dragon- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4957
SQL injection vulnerability in the GetMember function in functions.php in MyReview 1.9.4 allows remote attackers to execute arbitrary SQL commands via the email parameter to Admin.php.... Read more
Affected Products : myreview- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025