Latest CVE Feed
-
7.5
HIGHCVE-2006-5147
PHP remote file inclusion vulnerability in wamp_dir/setup/yesno.phtml in VAMP Webmail 2.0beta1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the no_url parameter.... Read more
Affected Products : vamp_webmail- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
6.5
MEDIUMCVE-2006-5150
SQL injection vulnerability in the reports system in OpenBiblio before 0.5.2 allows remote attackers with report privileges to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : openbiblio- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5157
Format string vulnerability in the ActiveX control (ATXCONSOLE.OCX) in TrendMicro OfficeScan Corporate Edition (OSCE) before 7.3 Patch 1 allows remote attackers to execute arbitrary code via format string identifiers in the "Management Console's Remote Cl... Read more
- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5146
Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) funk.php, or the (2) action parameter in (b) tem.php and (c) uss.php.... Read more
Affected Products : yblog- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5159
Stack-based buffer overflow in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving JavaScript. NOTE: the vendor and original researchers have released a follow-up comment disputing the severity of this issu... Read more
Affected Products : firefox- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5140
SQL injection vulnerability in display.php in Lappy512 PHP Krazy Image Host Script (phpkimagehost) 0.7a allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : php_krazy_image_host_script- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5125
Directory traversal vulnerability in window.php, possibly used by home.php, in Joshua Muheim phpMyWebmin 1.0 allows remote attackers to obtain sensitive information via a directory name in the target parameter, which triggers a directory listing through t... Read more
Affected Products : phpmywebmin- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5130
Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) url, (3) title, and (4) about parameters in a forum post. NOTE: t... Read more
Affected Products : jaf_cms- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5121
SQL injection vulnerability in modules/Downloads/admin.php in the Admin section of PostNuke 0.762 allows remote attackers to execute arbitrary SQL commands via the hits parameter.... Read more
Affected Products : postnuke- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5123
Multiple PHP remote file inclusion vulnerabilities in Albrecht Guenther PHProjekt 5.1.x before 5.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lib_path or (2) lang_path parameter in unspecified files, related to code change... Read more
Affected Products : phprojekt- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-5134
Mercury SiteScope 8.2 (8.1.2.0) allows remote authenticated users to cause a denial of service (loss of connectivity to the classic interface) via attempted HTML injection into the "new monitor description" field.... Read more
Affected Products : mercury_sitescope- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5105
Multiple PHP remote file inclusion vulnerabilities in SyntaxCMS 1.1.1 through 1.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the init_path parameter to admin/testing/tests/0030_init_syntax.php, or (2) an unspecified parameter to... Read more
Affected Products : syntaxcms- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5117
phpMyAdmin before 2.9.1-rc1 has a libraries directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via direct requests for certain files.... Read more
Affected Products : phpmyadmin- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5141
PHP remote file inclusion vulnerability in script.php in Kevin A. Gordon Open Geo Targeting (aka geotarget) allows remote attackers to execute arbitrary PHP code via a URL in the anp_path parameter. NOTE: the provenance of this information is unknown; th... Read more
Affected Products : open_geo_targeting- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5118
PHP remote file inclusion vulnerability in index.php3 in the PDD package for PHPSelect Web Development Division allows remote attackers to execute arbitrary PHP code via a URL in the Application_Root parameter.... Read more
Affected Products : web_development_division- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5112
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.... Read more
Affected Products : navicopa_web_server- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5131
module/shout/jafshout.php (aka the shoutbox) in ph03y3nk just another flat file (JAF) CMS 4.0 RC1 allows remote attackers to execute arbitrary code within sections bounded by "<?php" and "?>", possibly due to a static code injection vulnerability involvin... Read more
Affected Products : jaf_cms- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5129
Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) the message parameter, and possibly other parameters, in module/shout/jafshout.p... Read more
Affected Products : jaf_cms- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5104
SQL injection vulnerability in global.php in Jelsoft vBulletin 2.x allows remote attackers to execute arbitrary SQL commands via the templatesused parameter.... Read more
- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5102
PHP remote file inclusion vulnerability in include/editfunc.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.42 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the NWCONF_SYSTEM[server_path] parameter.... Read more
Affected Products : newswriter- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025