Latest CVE Feed
-
7.5
HIGHCVE-2006-4607
admin/index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to bypass authentication controls by setting the ID_ADMIN and SUPER_ADMIN parameters to 1.... Read more
Affected Products : jacome_php-revista- Published: Sep. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4602
Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a .php extension, which is uploaded to the img/wiki/ direc... Read more
Affected Products : tikiwiki_cms\/groupware- Published: Sep. 07, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-4608
Multiple cross-site scripting (XSS) vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) cadena parameter in busqueda.php and the (2) email parameter in lista.php.... Read more
Affected Products : jacome_php-revista- Published: Sep. 07, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-4614
PDAapps Verichat for Pocket PC 1.30bh stores usernames and passwords in plaintext in the Windows Mobile registry, which allows local users to obtain sensitive information via keys under \HKEY_CURRENT_USER\Software\PDAapps\VeriChat.... Read more
Affected Products : pocket_pc- Published: Sep. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4611
Buffer overflow in the _tor_resolve function in dsocks.c in dsocks before 1.4 allows remote attackers to execute arbitrary code via unspecified vectors, possibly involving a long node name.... Read more
Affected Products : dsocks- Published: Sep. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4601
SQL injection vulnerability in index.php in Annuaire 1Two 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : 1two- Published: Sep. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4604
PHP remote file inclusion vulnerability in LFXlib/access_manager.php in Lanifex Database of Managed Objects (DMO) 2.3 Beta and earlier allows remote attackers to execute arbitrary PHP code via the _incMgr parameter.... Read more
Affected Products : lanifex- Published: Sep. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4597
SQL injection vulnerability in devam.asp in ICBlogger 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the YID parameter.... Read more
Affected Products : icblogger- Published: Sep. 07, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-4619
The start update window in update.exe in Avira AntiVir PersonalEdition Classic 7.0 build 151 allows local users to gain system privileges via a "Shatter" style attack on the (1) IParam parameter, and the (2) PBM_GETRANGE and (3) PBM_SETRANGE messages in a... Read more
Affected Products : antivir_personal- Published: Sep. 07, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4610
PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the page parameter.... Read more
Affected Products : grapagenda- Published: Sep. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4617
Unrestricted file upload vulnerability in fileupload.html in vtiger CRM 4.2.4, and possibly earlier versions, allows remote attackers to upload and execute arbitrary files with executable extensions in the /cashe/mails folder.... Read more
Affected Products : vtiger_crm- Published: Sep. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4606
Multiple SQL injection vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to execute arbitrary SQL commands via the (1) id_temas parameter in busqueda_tema.php, the (2) cadena parameter in busqueda.php, the (3) id_autor parameter i... Read more
Affected Products : jacome_php-revista- Published: Sep. 07, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-4615
Shape Services IM+ Mobile Instant Messenger for Pocket PC 3.10 stores usernames and passwords in plaintext in %PROGRAMFILES%\IMPlus\implus.cfg, which allows local users to obtain sensitive information by reading the file.... Read more
Affected Products : im\+_mobile_instant_messenger- Published: Sep. 07, 2006
- Modified: Apr. 03, 2025
-
2.3
LOWCVE-2006-4600
slapd in OpenLDAP before 2.3.25 allows remote authenticated users with selfwrite Access Control List (ACL) privileges to modify arbitrary Distinguished Names (DN).... Read more
Affected Products : openldap- Published: Sep. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4598
Multiple SQL injection vulnerabilities in links.php in ssLinks 1.22 allow remote attackers to execute arbitrary SQL commands via the (1) go parameter and (2) id parameter in a rate action.... Read more
Affected Products : sslinks- Published: Sep. 07, 2006
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2006-4586
The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticated users to perform unauthorized actions, as demonstrated by modifying user settings via the id parameter to /membres/modif_profil.php,... Read more
Affected Products : tr_forum- Published: Sep. 06, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4584
Tr Forum 2.0 allows remote attackers to bypass authentication and add an administrative account via the login and password parameters to admin/insert_admin.php.... Read more
Affected Products : tr_forum- Published: Sep. 06, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4594
Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpAtm) 1.21 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the include_location parameter in (1) confirm.php or (2) login.php. NOTE: the ... Read more
Affected Products : php_advanced_transfer_manager- Published: Sep. 06, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4592
Incomplete blacklist vulnerability in default.asp in 8pixel.net Simple Blog 2.3 and earlier allows remote attackers to conduct SQL injection attacks via ">" characters in the id parameter, which are not filtered by the protection mechanism.... Read more
Affected Products : simple_blog- Published: Sep. 06, 2006
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2006-4585
SQL injection vulnerability in admin/editer.php in Tr Forum 2.0 allows remote authenticated users to execute arbitrary SQL commands via the id2 parameter. NOTE: this can be leveraged with other Tr Forum vulnerabilities to allow unauthenticated attackers ... Read more
Affected Products : tr_forum- Published: Sep. 06, 2006
- Modified: Apr. 03, 2025