Latest CVE Feed
-
7.5
HIGHCVE-2006-5131
module/shout/jafshout.php (aka the shoutbox) in ph03y3nk just another flat file (JAF) CMS 4.0 RC1 allows remote attackers to execute arbitrary code within sections bounded by "<?php" and "?>", possibly due to a static code injection vulnerability involvin... Read more
Affected Products : jaf_cms- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5102
PHP remote file inclusion vulnerability in include/editfunc.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.42 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the NWCONF_SYSTEM[server_path] parameter.... Read more
Affected Products : newswriter- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5112
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.... Read more
Affected Products : navicopa_web_server- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5104
SQL injection vulnerability in global.php in Jelsoft vBulletin 2.x allows remote attackers to execute arbitrary SQL commands via the templatesused parameter.... Read more
- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5109
Devellion CubeCart 2.0.x allows remote attackers to obtain sensitive information via a direct request for (1) link_navi.php or (2) spotlight.php, which reveals the path in various error messages. NOTE: the information.php, language.php, list_docs.php, po... Read more
Affected Products : cubecart- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5100
PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the WN_BASEDIR parameter.... Read more
Affected Products : webnews- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-5119
Multiple cross-site scripting (XSS) vulnerabilities in Zen Cart 1.3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) admin_name or (2) admin_pass parameter in (a) admin/login.php, or the (3) admin_email parameter in (b) admin/pa... Read more
- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5103
PHP remote file inclusion vulnerability in admin/index2.php in bbsNew 2.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the "right" parameter.... Read more
Affected Products : bbsnew- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5111
The libksba library 0.9.12 and possibly other versions, as used by gpgsm in the newpg package on SUSE LINUX, allows attackers to cause a denial of service (application crash) via a malformed X.509 certificate in a signature.... Read more
- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5137
Multiple direct static code injection vulnerabilities in Groupee UBB.threads 6.5.1.1 allow remote attackers to (1) inject PHP code via a theme[] array parameter to admin/doedittheme.php, which is injected into includes/theme.inc.php; (2) inject PHP code v... Read more
Affected Products : ubb.threads- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5116
Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyAdmin before 2.9.1-rc1 allow remote attackers to perform unauthorized actions as another user by (1) directly setting a token in the URL though dynamic variable evaluation and (2) unsettin... Read more
Affected Products : phpmyadmin- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5107
Multiple SQL injection vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter in admin/forgot_pass.php, (2) the order_id parameter in view_order.php, (3) the view_doc parameter ... Read more
Affected Products : cubecart- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5101
PHP remote file inclusion vulnerability in include.php in Comdev CSV Importer 3.1 and possibly 4.1, as used in (1) Comdev Contact Form 3.1, (2) Comdev Customer Helpdesk 3.1, (3) Comdev Events Calendar 3.1, (4) Comdev FAQ Support 3.1, (5) Comdev Guestbook ... Read more
Affected Products : comdev_csv_importer- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-5134
Mercury SiteScope 8.2 (8.1.2.0) allows remote authenticated users to cause a denial of service (loss of connectivity to the classic interface) via attempted HTML injection into the "new monitor description" field.... Read more
Affected Products : mercury_sitescope- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5141
PHP remote file inclusion vulnerability in script.php in Kevin A. Gordon Open Geo Targeting (aka geotarget) allows remote attackers to execute arbitrary PHP code via a URL in the anp_path parameter. NOTE: the provenance of this information is unknown; th... Read more
Affected Products : open_geo_targeting- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-5120
Multiple cross-site scripting (XSS) vulnerabilities in Scott Metoyer Red Mombin 0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) index.php and (2) process_login.php.... Read more
Affected Products : red_mombin- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5117
phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via direct requests for certain files.... Read more
Affected Products : phpmyadmin- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5125
Directory traversal vulnerability in window.php, possibly used by home.php, in Joshua Muheim phpMyWebmin 1.0 allows remote attackers to obtain sensitive information via a directory name in the target parameter, which triggers a directory listing through t... Read more
Affected Products : phpmywebmin- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5121
SQL injection vulnerability in modules/Downloads/admin.php in the Admin section of PostNuke 0.762 allows remote attackers to execute arbitrary SQL commands via the hits parameter.... Read more
Affected Products : postnuke- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5123
Multiple PHP remote file inclusion vulnerabilities in Albrecht Guenther PHProjekt 5.1.x before 5.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lib_path or (2) lang_path parameter in unspecified files, related to code change... Read more
Affected Products : phprojekt- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025