Latest CVE Feed
-
5.0
MEDIUMCVE-2006-4899
The ePPIServlet script in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, when running on Windows, allows remote attackers to obtain the web server path via a "'" (single quote) in the PIProfile function, which leaks the ... Read more
- Published: Sep. 22, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-4901
Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, and eTrust Audit 1.5 and r8, allows remote attackers to spoof alerts and conduct replay attacks by invoking eTSAPISend.exe with the desired arguments.... Read more
- Published: Sep. 22, 2006
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2006-4900
Directory traversal vulnerability in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, allows remote authenticated users to read and delete arbitrary files via ".." sequences in the eSCCAdHocHtmlFile parameter to eSMPAuditS... Read more
- Published: Sep. 22, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-3508
Heap-based buffer overflow in the AirPort wireless driver on Apple Mac OS X 10.4.7 allows physically proximate attackers to cause a denial of service (crash), gain privileges, and execute arbitrary code via a crafted frame that is not properly handled dur... Read more
- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-3507
Multiple stack-based buffer overflows in the AirPort wireless driver on Apple Mac OS X 10.3.9 and 10.4.7 allow physically proximate attackers to execute arbitrary code by injecting crafted frames into a wireless network.... Read more
- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-3509
Integer overflow in the API for the AirPort wireless driver on Apple Mac OS X 10.4.7 might allow physically proximate attackers to cause a denial of service (crash) or execute arbitrary code in third-party wireless software that uses the API via crafted f... Read more
- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4923
Cross-site scripting (XSS) vulnerability in search.php in eSyndiCat Portal System allows remote attackers to inject arbitrary web script or HTML via the what parameter.... Read more
Affected Products : esyndicat_portal_system- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4917
Cross-site scripting (XSS) vulnerability in search.php in PT News 1.7.8 allows remote attackers to inject arbitrary web script or HTML via the pgname parameter.... Read more
Affected Products : pt_news- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4920
Multiple PHP remote file inclusion vulnerabilities in Site@School (S@S) 2.4.02 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the cmsdir parameter to (1) starnet/modules/sn_allbum/slideshow.php, and (2) starnet/themes/editab... Read more
Affected Products : siteatschool- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4921
PHP remote file inclusion vulnerability in Site@School (S@S) 2.4.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cmsdir parameter to starnet/modules/include/include.php. NOTE: some of these details are obtained from t... Read more
Affected Products : siteatschool- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4915
Cross-site scripting (XSS) vulnerability in index.php in Innovate Portal 2.0 allows remote attackers to inject arbitrary web script or HTML via the content parameter.... Read more
Affected Products : innovate_portal- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4922
Unrestricted file upload vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02 and earlier allows remote attackers to upload and execute arbitrary files with executable extensions.... Read more
Affected Products : siteatschool- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4919
Directory traversal vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter.... Read more
Affected Products : siteatschool- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4916
SQL injection vulnerability in uye_profil.asp in Tekman Portal (TR) 1.0 allows remote attackers to execute arbitrary SQL commands via the uye_id parameter.... Read more
Affected Products : tekman_portal- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4918
Multiple PHP remote file inclusion vulnerabilities in Simple Discussion Board 0.1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) env_dir parameter to (a) blank.php, (b) admin.php, or (c) builddb.php, and the (2) script_root pa... Read more
Affected Products : simple_discussion_board- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4914
Directory traversal vulnerability in A.l-Pifou 1.8p2 allows remote attackers to read arbitrary files via ".." sequences in the ze_langue_02 cookie, as demonstrated by using the choix_lng parameter to choix_langue.php to indirectly set the cookie, then acc... Read more
Affected Products : a.l-pifou- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4912
PHP remote file inclusion vulnerability in PHP DocWriter 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the script parameter.... Read more
Affected Products : php_docwriter- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4906
SQL injection vulnerability in modules/calendar/week.php in More.groupware 0.74 allows remote attackers to execute arbitrary SQL commands via the new_calendarid parameter.... Read more
Affected Products : more.groupware- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4913
Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary local files and possibly execute arbitrary code via a .. (dot dot) sequence and trailing null (%00) byte in the lang pa... Read more
Affected Products : e-friends- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4907
OSU 3.11alpha and 3.10a allows remote attackers to obtain sensitive information via a URL to a non-existent file, which displays the web root path in the resulting error message.... Read more
Affected Products : osu_httpd- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025