Latest CVE Feed
-
5.0
MEDIUMCVE-2006-5016
Unrestricted file upload vulnerability in admin/x_image.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, allows remote attackers to upload arbitrary files to the /imagebank directory.... Read more
Affected Products : e-vision_cms- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5035
Multiple cross-site scripting (XSS) vulnerabilities in Paul Smith Computer Services vCAP 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the statusmsg parameter in RegisterPage.cgi or (2) a URI corresponding to a nonexistent fi... Read more
Affected Products : vcap- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5030
SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sort parameter.... Read more
Affected Products : content_management_system- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5032
PHP remote file inclusion vulnerability in dix.php3 in PHPartenaire 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the url_phpartenaire parameter.... Read more
Affected Products : phpartenaire- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5049
Unspecified vulnerability in Classifieds (com_classifieds) component 1.3 and earlier for Joomla! has unspecified impact and attack vectors.... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5037
MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_src parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. ... Read more
Affected Products : mysource_matrix- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5029
SQL injection vulnerability in thread.php in WoltLab Burning Board (wBB) 2.3.x allows remote attackers to obtain the version numbers of PHP, MySQL, and wBB via the page parameter. NOTE: this issue might be a forced SQL error. Also, the original report wa... Read more
Affected Products : burning_board- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5038
The FiWin SS28S WiFi VoIP SIP/Skype Phone, firmware version 01_02_07, has a hard-coded username and password, which allows remote attackers to gain administrative access via telnet.... Read more
Affected Products : ss28s_wifi_voip_sip_skype_phone- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5036
MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) att... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2006-4694
Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office XP and Office 2003 allows user-assisted attackers to execute arbitrary code via a crafted record in a PPT file, as exploited by malware such as Exploit:Win32/Controlppt.W, Exploit:Wi... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
9.0
HIGHCVE-2006-5014
Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.... Read more
Affected Products : cpanel- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-5008
Unspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attackers to execute arbitrary commands and overwrite arbitrary files via unspecified vectors.... Read more
Affected Products : aix- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
4.6
MEDIUMCVE-2006-5007
Untrusted search path vulnerability in uucp in IBM AIX 5.2.0 and 5.3.0 allows local users to local users to gain privileges via a Trojan horse program involving uux.... Read more
Affected Products : aix- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-5004
Unspecified vulnerability in the rdist command in IBM AIX 5.2.0 and 5.3.0 allows local users to overwrite arbitrary files via unspecified vectors.... Read more
Affected Products : aix- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.2
HIGHCVE-2006-5005
Unspecified vulnerability in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors involving /etc/slip.login.... Read more
Affected Products : aix- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
6.6
MEDIUMCVE-2006-5012
Unspecified vulnerability in Sun Solaris 8, 9, and 10 before 20060925 allows local users to cause a denial of service (disable syslog) and prevent security messages from being logged via unspecified vectors.... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5002
Unspecified vulnerability in IBM Inventory Scout for AIX 2.2.0.0 through 2.2.0.9 (invscoutClient_VPD_Survey) allows attackers to overwrite arbitrary files via unspecified vectors.... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.2
HIGHCVE-2006-5003
Unspecified vulnerability in the named8 command in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors.... Read more
Affected Products : aix- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.2
HIGHCVE-2006-5006
Buffer overflow in cfgmgr in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a long directory path argument.... Read more
Affected Products : aix- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.2
HIGHCVE-2006-5010
Untrusted search path vulnerability in acctctl in IBM AIX 5.3.0 allows local users to execute arbitrary commands by modifying the path to point to a malicious mkdir program.... Read more
Affected Products : aix- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025