Latest CVE Feed
-
7.5
HIGHCVE-2006-5217
SQL injection vulnerability in giris_yap.asp in Emek Portal 2.1 allows remote attackers to execute arbitrary SQL commands by simultaneously injecting into the user name and pass fields in uyegiris.asp, also known as the Kullanici Adi (k_a) and Sifre (sifr... Read more
Affected Products : emek_portal- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5188
Directory traversal vulnerability in download.php in webGENEius GOOP Gallery 2.0.2 allows remote attackers to read or list data from certain files or directories via unspecified vectors.... Read more
Affected Products : goop_gallery- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5180
PHP remote file inclusion vulnerability in include/main.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.42 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the NWCONF_SYSTEM[server_path] parameter, a different... Read more
Affected Products : newswriter- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5195
Multiple cross-site scripting (XSS) vulnerabilities in Wheatblog 1.0 and 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained from third p... Read more
Affected Products : wheatblog- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5205
Directory traversal vulnerability in Invision Gallery 2.0.7 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the dir parameter in (1) index.php and (2) forum/index.php, when the viewimage command in the gallery module is used... Read more
Affected Products : invision_gallery- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5181
Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the target parameter in (1) change_preferences2.php, (2) create_file.php, (3) upload_local.php, and (4) u... Read more
Affected Products : phpmywebmin- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5186
PHP remote file inclusion vulnerability in functions.php in phpMyProfiler 0.9.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter.... Read more
Affected Products : phpmyprofiler- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5185
Eval injection vulnerability in Template.php in HAMweather 3.9.8.4 and earlier allows remote attackers to execute arbitrary code via a modified query string, which is supplied to an eval function call within the do_parse_code function.... Read more
Affected Products : hamweather- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5192
PHP remote file inclusion vulnerability in includes/footer.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PHPGREETZ_INCLUDE_DIR parameter.... Read more
Affected Products : phpgreetz- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5169
Cross-site scripting (XSS) vulnerability in John Himmelman (aka DaRk2k1) PowerPortal 1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to registering a user. NOTE: the provenance of this informat... Read more
Affected Products : powerportal- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2006-5177
The NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to (1) execute arbitrary code via unspecified vectors involving crafted base64 encoded NTLM Type 3 messages, or (2) cause a denial of service via crafted bas... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-4980
Buffer overflow in the repr function in Python 2.3 through 2.6 before 20060822 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via crafted wide character UTF-32/UCS-4 strings to certain scripts.... Read more
Affected Products : python- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
4.6
MEDIUMCVE-2006-4927
The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec AntiVirus and security products, allow local users to gain privileges by overwriting critical system addresses using a crafted Irp to the ... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5168
Cross-site scripting (XSS) vulnerability in the search functionality in Simon Brown Pebble 2.0.0 RC1 and RC2 allows remote attackers to inject arbitrary web script or HTML via the query string.... Read more
Affected Products : pebble- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
6.2
MEDIUMCVE-2006-5178
Race condition in the symlink function in PHP 5.1.6 and earlier allows local users to bypass the open_basedir restriction by using a combination of symlink, mkdir, and unlink functions to change the file path after the open_basedir check and before the fi... Read more
Affected Products : php- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
4.9
MEDIUMCVE-2006-3741
The perfmonctl system call (sys_perfmonctl) in Linux kernel 2.4.x and 2.6 before 2.6.18, when running on Itanium systems, does not properly track the reference count for file descriptors, which allows local users to cause a denial of service (file descrip... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-5156
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header.... Read more
- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
6.5
MEDIUMCVE-2006-5150
SQL injection vulnerability in the reports system in OpenBiblio before 0.5.2 allows remote attackers with report privileges to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : openbiblio- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5149
Multiple directory traversal vulnerabilities in OpenBiblio before 0.5.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the page parameter to shared/help.php or (2) the tab parameter to shared/header.php.... Read more
Affected Products : openbiblio- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5152
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL that is returned in a large HTTP 404 error message without an explicit charset, a related issue ... Read more
Affected Products : internet_explorer- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025