Latest CVE Feed
-
7.5
HIGHCVE-2006-5181
Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the target parameter in (1) change_preferences2.php, (2) create_file.php, (3) upload_local.php, and (4) u... Read more
Affected Products : phpmywebmin- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5180
PHP remote file inclusion vulnerability in include/main.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.42 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the NWCONF_SYSTEM[server_path] parameter, a different... Read more
Affected Products : newswriter- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5190
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in the (a) banner_manager.php, (b) banner_statistics.php, (c) countrie... Read more
Affected Products : oscommerce- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5203
Invision Power Board (IPB) 2.1.7 and earlier allows remote restricted administrators to inject arbitrary web script or HTML, or execute arbitrary SQL commands, via a forum description that contains a crafted image with PHP code, which is executed when the... Read more
Affected Products : invision_power_board- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5217
SQL injection vulnerability in giris_yap.asp in Emek Portal 2.1 allows remote attackers to execute arbitrary SQL commands by simultaneously injecting into the user name and pass fields in uyegiris.asp, also known as the Kullanici Adi (k_a) and Sifre (sifr... Read more
Affected Products : emek_portal- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5197
PDshopPro stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) /pdshoppro.mdb, (2) /data/pdshoppro.mdb, or (3) /shoppro/data/pdshoppro.mdb.... Read more
Affected Products : pdshoppro- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5195
Multiple cross-site scripting (XSS) vulnerabilities in Wheatblog 1.0 and 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained from third p... Read more
Affected Products : wheatblog- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5205
Directory traversal vulnerability in Invision Gallery 2.0.7 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the dir parameter in (1) index.php and (2) forum/index.php, when the viewimage command in the gallery module is used... Read more
Affected Products : invision_gallery- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5142
Stack-based buffer overflow in CA BrightStor ARCserve Backup R11.5 client and server allows remote attackers to execute arbitrary code via long messages to the CheyenneDS Mailslot.... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
4.9
MEDIUMCVE-2006-3741
The perfmonctl system call (sys_perfmonctl) in Linux kernel 2.4.x and 2.6 before 2.6.18, when running on Itanium systems, does not properly track the reference count for file descriptors, which allows local users to cause a denial of service (file descrip... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-5156
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header.... Read more
- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5158
The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (process crash) and deny access to NFS exports via unspecified vectors that trigger a kernel oops (null dereference) and... Read more
- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5159
Stack-based buffer overflow in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving JavaScript. NOTE: the vendor and original researchers have released a follow-up comment disputing the severity of this issu... Read more
Affected Products : firefox- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5146
Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) funk.php, or the (2) action parameter in (b) tem.php and (c) uss.php.... Read more
Affected Products : yblog- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5167
Multiple PHP remote file inclusion vulnerabilities in BasiliX 1.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) BSX_LIBDIR parameter in scripts in /files/ including (a) abook.php3, (b) compose-attach.php3, (c) com... Read more
Affected Products : basilix_webmail- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5165
PHP remote file inclusion vulnerability in inc/functions.inc.php in Skrypty PPA Gallery 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the config[ppa_root_path] parameter.... Read more
Affected Products : ppa_gallery- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
6.4
MEDIUMCVE-2006-5161
IBM Client Security Password Manager stores and distributes saved passwords based upon the title of a website, which allows remote attackers to obtain username and password credentials by changing the title of an HTML page.... Read more
Affected Products : client_security_password_manager- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5145
Multiple SQL injection vulnerabilities in OlateDownload 3.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter in details.php or the (2) query parameter in search.php.... Read more
Affected Products : olatedownload- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
8.1
HIGHCVE-2006-5160
Multiple unspecified vulnerabilities in Mozilla Firefox have unspecified vectors and impact, as claimed during ToorCon 2006. NOTE: the vendor and original researchers have released a follow-up comment disputing this issue, in which one researcher states ... Read more
Affected Products : firefox- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5152
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL that is returned in a large HTTP 404 error message without an explicit charset, a related issue ... Read more
Affected Products : internet_explorer- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025