Latest CVE Feed
-
5.0
MEDIUMCVE-2006-5034
Directory traversal vulnerability in Paul Smith Computer Services vCAP 1.9.0 Beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.... Read more
Affected Products : vcap- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-5024
Multiple unspecified vulnerabilities in Paisterist Simple HTTP Scanner (sHTTPScanner) before 0.4 have unknown impact and attack vectors.... Read more
Affected Products : simple_http_scanner- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5019
Google Mini 4.4.102.M.36 and earlier allows remote attackers to obtain sensitive information via a direct request for /search with an invalid client parameter, which reveals the path in an error message.... Read more
Affected Products : mini_search_appliance- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-5025
Multiple unspecified vulnerabilities in Paisterist Simple HTTP Scanner (sHTTPScanner) before 0.2 have unknown impact and attack vectors.... Read more
Affected Products : simple_http_scanner- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5023
SQL injection vulnerability in kategori.asp in xweblog 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the kategori parameter.... Read more
Affected Products : xweblog- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5033
Unspecified vulnerability in StoresAndCalendarsList.cgi in Paul Smith Computer Services vCAP 1.9.0 Beta and earlier allows remote attackers to cause a denial of service via the session parameter, possibly related to format string specifiers or malformed U... Read more
Affected Products : vcap- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5046
Unspecified vulnerability in RS Gallery2 (com_rsgallery2) 1.11.3 and earlier for Joomla! has unspecified impact and attack vectors, related to lack of "hardened language files."... Read more
Affected Products : rs_gallery2- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2006-5021
Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP code via a URL in (1) the root parameter in imgen.php, and the root_path parameter in (2) admin/config.php, (3) common.php, and (4) ad... Read more
Affected Products : redblog- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5027
Jeroen Vennegoor JevonCMS, possibly pre alpha, allows remote attackers to obtain sensitive information via a direct request for php/main/phplib files (1) db_msql.inc, (2) db_mssql.inc, (3) db_mysql.inc, (4) db_oci8.inc, (5) db_odbc.inc, (6) db_oracle.inc,... Read more
Affected Products : jevoncms- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5049
Unspecified vulnerability in Classifieds (com_classifieds) component 1.3 and earlier for Joomla! has unspecified impact and attack vectors.... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5035
Multiple cross-site scripting (XSS) vulnerabilities in Paul Smith Computer Services vCAP 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the statusmsg parameter in RegisterPage.cgi or (2) a URI corresponding to a nonexistent fi... Read more
Affected Products : vcap- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5030
SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sort parameter.... Read more
Affected Products : content_management_system- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5029
SQL injection vulnerability in thread.php in WoltLab Burning Board (wBB) 2.3.x allows remote attackers to obtain the version numbers of PHP, MySQL, and wBB via the page parameter. NOTE: this issue might be a forced SQL error. Also, the original report wa... Read more
Affected Products : burning_board- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5032
PHP remote file inclusion vulnerability in dix.php3 in PHPartenaire 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the url_phpartenaire parameter.... Read more
Affected Products : phpartenaire- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5037
MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_src parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. ... Read more
Affected Products : mysource_matrix- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5022
PHP remote file inclusion vulnerability in includes/global.php in Joshua Wilson pNews System 1.1.0 (aka PowerNews) allows remote attackers to execute arbitrary PHP code via a URL in the nbs parameter.... Read more
Affected Products : pnews- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5020
Multiple PHP remote file inclusion vulnerabilities in SolidState 0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the base_path parameter in manager/pages/ scripts including (1) AccountsPage.class.php, (2) AddInvoicePage.c... Read more
Affected Products : solidstate- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5044
Unspecified vulnerability in Prince Clan (Princeclan) Chess component (com_pcchess) 0.8 and earlier for Mambo and Joomla! has unspecified impact and attack vectors.... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5042
Unspecified vulnerability in mosMedia (com_mosmedia) 1.0.8 and earlier for Joomla! has unspecified impact and attack vectors.... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-5018
ContentKeeper 123.25 and earlier places passwords in cleartext in an INPUT element in cgi-bin/ck/changepw.cgi, which allows remote authenticated users to obtain passwords via this URI.... Read more
Affected Products : contentkeeper- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025