Latest CVE Feed
-
7.5
HIGHCVE-2006-4890
Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the dirroot parameter to (1) fckeditor/editor/filemanager/browser/default/connectors/php/connector.php or (2) ... Read more
Affected Products : unak_cms- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4892
SQL injection vulnerability in faqview.asp in Techno Dreams FAQ Manager Package 1.0 allows remote attackers to execute arbitrary SQL commands via the key parameter.... Read more
Affected Products : faq_manager_package- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4895
IDevSpot NexieAffiliate 1.9 and earlier allows remote attackers to delete arbitrary affiliates via a modified id parameter to delete.php.... Read more
Affected Products : nixieaffiliate- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4893
PHP remote file inclusion vulnerability in bb_usage_stats/includes/bb_usage_stats.php in phpBB XS 0.58 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter, a different vector than CVE-2006-4780.... Read more
Affected Products : phpbb_xs- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4894
Cross-site scripting (XSS) vulnerability in forms/lostpassword.php in iDevSpot NixieAffiliate 1.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter.... Read more
Affected Products : nixieaffiliate- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4898
PHP remote file inclusion vulnerability in include/phpxd/phpXD.php in guanxiCRM 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the appconf[rootpath] parameter.... Read more
Affected Products : guanxicrm_business_solution- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4897
CMtextS 1.0 and earlier stores users_logins/admin.txt under the web document root with insufficient access control, which allows remote attackers to obtain the administrator password.... Read more
Affected Products : cmtexts- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4891
SQL injection vulnerability in ArticlesTableview.asp in Techno Dreams Articles & Papers Package 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the key parameter.... Read more
Affected Products : articles_and_papers_package- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2191
Format string vulnerability in Mailman before 2.1.9 allows attackers to execute arbitrary code via unspecified vectors. NOTE: the vendor has disputed this vulnerability, stating that it is "unexploitable.... Read more
Affected Products : mailman- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4878
Directory traversal vulnerability in footer.php in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to read and include arbitrary local files via a .. (dot dot) sequence in the template parameter. NOTE: this was later reported to aff... Read more
Affected Products : php-post- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4338
unlzh.c in the LHZ component in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted GZIP archive.... Read more
Affected Products : gzip- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4337
Buffer overflow in the make_table function in the LHZ component in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted decoding table in a GZIP archive.... Read more
Affected Products : gzip- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4871
SQL injection vulnerability in search_run.asp in Keyvan1 (aka Keyvan Janghorbani) EShoppingPro 1.0 allows remote attackers to execute arbitrary SQL commands via the order parameter.... Read more
Affected Products : eshoppingpro- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4872
SQL injection vulnerability in search.asp in Keyvan1 (aka Keyvan Janghorbani) ECardPro 2.0 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.... Read more
Affected Products : ecardpro- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4883
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot BizDirectory allow remote attackers to inject arbitrary web script or HTML via (1) the stylesheet parameter in Feed.php or (2) the message parameter in status.php.... Read more
Affected Products : bizdirectory- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4885
PHP remote file inclusion vulnerability in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) footer.php and (2) header.php. NOTE: the provenance of this information is unknown; ... Read more
Affected Products : shadowed_portal- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-4887
Apple Remote Desktop (ARD) for Mac OS X 10.2.8 and later does not drop privileges on the remote machine while installing certain applications, which allows local users to bypass authentication and gain privileges by selecting the icon during installation.... Read more
- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4881
Multiple cross-site scripting (XSS) vulnerabilities in David Bennett PHP-Post (PHPp) 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the replyuser parameter in (a) pm.php; (2) the txt_jumpto parameter in (b) dropdown.... Read more
Affected Products : php-post- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4882
SQL injection vulnerability in Review.asp in Julian Roberts Charon Cart 3 allows remote attackers to execute arbitrary SQL commands via the ProductID parameter.... Read more
Affected Products : charon_cart- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4880
David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to obtain sensitive information via a direct request for (1) footer.php, (2) template.php, or (3) lastvisit.php, which reveals the installation path in various error messages.... Read more
Affected Products : php-post- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025