Latest CVE Feed
-
4.3
MEDIUMCVE-2006-4796
Cross-site scripting (XSS) vulnerability in forum.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter (strtopicsortord variable).... Read more
Affected Products : snitz_forums_2000- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4794
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the query string (PATH_INFO) in (1) contact.php, (2) download.php, (3) admin.php, (4) fpw.php, (5) news.php, (6) search.php... Read more
Affected Products : e107- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4798
SQL-Ledger before 2.4.4 stores a password in a query string, which might allow context-dependent attackers to obtain the password via a Referer field or browser history.... Read more
Affected Products : sql-ledger- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-4795
Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport software in HP-UX B.11.11 and B.11.23 before 20060912 allows local users to cause a denial of service via unspecified vectors.... Read more
Affected Products : hp-ux- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4790
verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by ... Read more
Affected Products : gnutls- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4779
PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitrax Premodded phpBB 1.0.6-R3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more
Affected Products : vitrax_premodded_phpbb- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-4787
AlphaMail before 1.0.16 allows local users to obtain sensitive information via the logging functionality, which displays unencrypted passwords in an error message. NOTE: some details are obtained from third party information.... Read more
Affected Products : alphamail- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2006-4782
src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication and gain sensitive information stored in the database via a modified userID parameter in a write action to admin/database.php... Read more
Affected Products : webspell- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4785
SQL injection vulnerability in blog/edit.php in Moodle 1.6.1 and earlier allows remote attackers to execute arbitrary SQL commands via the format parameter as stored in the $blogEntry variable, which is not properly handled by the insert_record function, ... Read more
Affected Products : moodle- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4784
Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.6.1 and earlier might allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) doc/index.php or (2) files/index.php.... Read more
Affected Products : moodle- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4786
Moodle 1.6.1 and earlier allows remote attackers to obtain sensitive information via (1) help.php and (2) other unspecified vectors involving scheduled backups.... Read more
Affected Products : moodle- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4783
SQL injection vulnerability in squads.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the squadID parameter.... Read more
Affected Products : webspell- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-4789
Buffer overflow in Open Movie Editor 0.0.20060901 allows local users to cause a denial of service (system crash) or execute arbitrary code via a long project name in an open_movie_editor_project XML tag.... Read more
Affected Products : open_movie_editor- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4778
SQL injection vulnerability in Creative Commons Tools ccHost before 3.0 allows remote attackers to execute arbitrary SQL commands via a crafted URL, which is used to populate the file ID. NOTE: Some details are obtained from third party information.... Read more
Affected Products : cchost- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4788
PHP remote file inclusion vulnerability in includes/log.inc.php in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled and _SESSION[permission] parameter is set to "yes", allows remote attackers to execute arbitrary PHP code... Read more
Affected Products : signkorn_guestbook- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4781
Heap-based buffer overflow in FutureSoft TFTP Server Multithreaded (MT) 1.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by sending a crafted packet to port 69/UDP, which triggers the overflow when constr... Read more
Affected Products : tftp_server_multithreaded- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4780
PHP remote file inclusion vulnerability in includes/functions.php in phpBB XS 0.58 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more
Affected Products : phpbb_xs- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4771
Cross-site scripting (XSS) vulnerability in haut.php in ForumJBC 4 allows remote attackers to inject arbitrary web script or HTML via the nb_connecte parameter.... Read more
Affected Products : forumjbc- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-4725
Adobe ColdFusion MX 7 and 7.01 allows local users to bypass security restrictions and call components (CFC) within a sandbox from CFML templates that are located outside of the sandbox.... Read more
Affected Products : coldfusion- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4773
Sun StorEdge 6130 Array Controllers with firmware 06.12.10.11 and earlier allow remote attackers to cause a denial of service (controller reboot) via a flood of traffic on the LAN.... Read more
Affected Products : storedge_6130_arrays- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025