Latest CVE Feed
-
7.2
HIGHCVE-2006-4803
The Fan-Out Linux and UNIX receiver scripts in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors involving certain environment variables and "code injection."... Read more
- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4437
Eval injection vulnerability in Tagger LE allows remote attackers to execute arbitrary PHP code via the query string in (1) tags.php, (2) sign.php, and (3) admin/index.php.... Read more
Affected Products : tagger_le- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2006-4801
Race condition in Deja Vu, as used in Roxio Toast Titanium 7 and possibly other products, allows local users to execute arbitrary code via temporary files, including dejavu_manual.rb, which are executed with raised privileges.... Read more
Affected Products : toast- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4793
Multiple SQL injection vulnerabilities in icerik.asp in TualBLOG 1.0 allow remote attackers to execute arbitrary SQL commands, as demonstrated by the icerikno parameter.... Read more
Affected Products : tualblog- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4797
Cross-site scripting (XSS) vulnerability in tag.php in CloudNine Interactive CJ Tag Board 3.0 allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a url BBcode tag in the cjmsg parameter.... Read more
Affected Products : cj_tag_board- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4799
Buffer overflow in ffmpeg for xine-lib before 1.1.2 might allow context-dependent attackers to execute arbitrary code via a crafted AVI file and "bad indexes", a different vulnerability than CVE-2005-4048 and CVE-2006-2802.... Read more
Affected Products : xine-lib- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4796
Cross-site scripting (XSS) vulnerability in forum.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter (strtopicsortord variable).... Read more
Affected Products : snitz_forums_2000- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4794
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the query string (PATH_INFO) in (1) contact.php, (2) download.php, (3) admin.php, (4) fpw.php, (5) news.php, (6) search.php... Read more
Affected Products : e107- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4798
SQL-Ledger before 2.4.4 stores a password in a query string, which might allow context-dependent attackers to obtain the password via a Referer field or browser history.... Read more
Affected Products : sql-ledger- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-4795
Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport software in HP-UX B.11.11 and B.11.23 before 20060912 allows local users to cause a denial of service via unspecified vectors.... Read more
Affected Products : hp-ux- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4790
verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by ... Read more
Affected Products : gnutls- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4779
PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitrax Premodded phpBB 1.0.6-R3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more
Affected Products : vitrax_premodded_phpbb- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-4787
AlphaMail before 1.0.16 allows local users to obtain sensitive information via the logging functionality, which displays unencrypted passwords in an error message. NOTE: some details are obtained from third party information.... Read more
Affected Products : alphamail- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2006-4782
src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication and gain sensitive information stored in the database via a modified userID parameter in a write action to admin/database.php... Read more
Affected Products : webspell- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4785
SQL injection vulnerability in blog/edit.php in Moodle 1.6.1 and earlier allows remote attackers to execute arbitrary SQL commands via the format parameter as stored in the $blogEntry variable, which is not properly handled by the insert_record function, ... Read more
Affected Products : moodle- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4784
Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.6.1 and earlier might allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) doc/index.php or (2) files/index.php.... Read more
Affected Products : moodle- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4786
Moodle 1.6.1 and earlier allows remote attackers to obtain sensitive information via (1) help.php and (2) other unspecified vectors involving scheduled backups.... Read more
Affected Products : moodle- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4783
SQL injection vulnerability in squads.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the squadID parameter.... Read more
Affected Products : webspell- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-4789
Buffer overflow in Open Movie Editor 0.0.20060901 allows local users to cause a denial of service (system crash) or execute arbitrary code via a long project name in an open_movie_editor_project XML tag.... Read more
Affected Products : open_movie_editor- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4778
SQL injection vulnerability in Creative Commons Tools ccHost before 3.0 allows remote attackers to execute arbitrary SQL commands via a crafted URL, which is used to populate the file ID. NOTE: Some details are obtained from third party information.... Read more
Affected Products : cchost- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025