Latest CVE Feed
-
10.0
HIGHCVE-2006-5025
Multiple unspecified vulnerabilities in Paisterist Simple HTTP Scanner (sHTTPScanner) before 0.2 have unknown impact and attack vectors.... Read more
Affected Products : simple_http_scanner- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5016
Unrestricted file upload vulnerability in admin/x_image.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, allows remote attackers to upload arbitrary files to the /imagebank directory.... Read more
Affected Products : e-vision_cms- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5038
The FiWin SS28S WiFi VoIP SIP/Skype Phone, firmware version 01_02_07, has a hard-coded username and password, which allows remote attackers to gain administrative access via telnet.... Read more
Affected Products : ss28s_wifi_voip_sip_skype_phone- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5044
Unspecified vulnerability in Prince Clan (Princeclan) Chess component (com_pcchess) 0.8 and earlier for Mambo and Joomla! has unspecified impact and attack vectors.... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5020
Multiple PHP remote file inclusion vulnerabilities in SolidState 0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the base_path parameter in manager/pages/ scripts including (1) AccountsPage.class.php, (2) AddInvoicePage.c... Read more
Affected Products : solidstate- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5022
PHP remote file inclusion vulnerability in includes/global.php in Joshua Wilson pNews System 1.1.0 (aka PowerNews) allows remote attackers to execute arbitrary PHP code via a URL in the nbs parameter.... Read more
Affected Products : pnews- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5042
Unspecified vulnerability in mosMedia (com_mosmedia) 1.0.8 and earlier for Joomla! has unspecified impact and attack vectors.... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-5018
ContentKeeper 123.25 and earlier places passwords in cleartext in an INPUT element in cgi-bin/ck/changepw.cgi, which allows remote authenticated users to obtain passwords via this URI.... Read more
Affected Products : contentkeeper- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5036
MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) att... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5047
Unspecified vulnerability in rsgallery2.html.php in RS Gallery2 component (com_rsgallery2) before 1.11.3 for Joomla! allows attackers to execute arbitrary code.... Read more
Affected Products : rs_gallery2- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5050
Directory traversal vulnerability in httpd in Rob Landley BusyBox allows remote attackers to read arbitrary files via URL-encoded "%2e%2e/" sequences in the URI.... Read more
Affected Products : busybox- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5040
Unspecified vulnerability in SEF404x (com_sef) for Joomla! has unspecified impact and attack vectors.... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-5026
Multiple unspecified vulnerabilities in Paisterist Simple HTTP Scanner (sHTTPScanner) before 0.3 have unknown impact and attack vectors.... Read more
Affected Products : simple_http_scanner- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5031
Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, followed by a filename ending with "%00" and a ... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5043
Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the sbp parameter to (1) file_upload.php or (2) image_upload... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5048
Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier for Joomla! allow remote attackers to execute arbitrary code via a URL in the mosConfig_absolute_path parameter in (1) configinsert.php,... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2006-4694
Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office XP and Office 2003 allows user-assisted attackers to execute arbitrary code via a crafted record in a PPT file, as exploited by malware such as Exploit:Win32/Controlppt.W, Exploit:Wi... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.2
HIGHCVE-2006-5009
Unspecified vulnerability in xlock in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands and overwrite arbitrary files via unspecified vectors, possibly involving a buffer overflow.... Read more
Affected Products : aix- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.2
HIGHCVE-2006-5011
Untrusted search path vulnerability in snappd in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via a Trojan horse program, involving the "system subroutine".... Read more
Affected Products : aix- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.8
HIGHCVE-2006-5013
Sun Solaris 10 before patch 118855-16 (20060925), when run on x64 systems using IPv6, allows remote attackers to cause a denial of service (kernel panic) via crafted IPv6 packets.... Read more
Affected Products : solaris- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025