Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2006-4977

    Multiple unrestricted file upload vulnerabilities in (1) back/upload_img.php and (2) admin/upload_img.php in Walter Beschmout PhpQuiz 1.2 and earlier allow remote attackers to upload arbitrary PHP code to the phpquiz/img_quiz folder via the (a) upload, (b... Read more

    Affected Products : phpquiz
    • Published: Sep. 25, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4974

    Buffer overflow in Ipswitch WS_FTP Limited Edition (LE) 5.08 allows remote FTP servers to execute arbitrary code via a long response to a PASV command.... Read more

    Affected Products : ws_ftp_server
    • Published: Sep. 25, 2006
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2006-4967

    Multiple cross-site scripting (XSS) vulnerabilities in NextAge Cart allow remote attackers to inject arbitrary web script or HTML via (1) the CatId parameter in a product category action in index.php or (2) the SearchWd parameter in an index search action... Read more

    Affected Products : nextage_shopping_cart
    • Published: Sep. 25, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4969

    Multiple PHP remote file inclusion vulnerabilities in WAHM E-Commerce Pie Cart Pro allow remote attackers to execute arbitrary PHP code via a URL in the Inc_Dir parameter in (1) affiliates.php, (2) orders.php, (3) events.php, (4) index.php, (5) articles.p... Read more

    Affected Products : pie_cart_pro
    • Published: Sep. 25, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4968

    PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more

    Affected Products : pnphpbb
    • Published: Sep. 25, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-4976

    The Date Library in John Lim ADOdb Library for PHP allows remote attackers to obtain sensitive information via a direct request for (1) server.php, (2) adodb-errorpear.inc.php, (3) adodb-iterator.inc.php, (4) adodb-pear.inc.php, (5) adodb-perf.inc.php, (6... Read more

    Affected Products : adodb_date_library
    • Published: Sep. 25, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-4975

    Yahoo! Messenger for WAP permits saving messages that contain JavaScript, which allows user-assisted remote attackers to inject arbitrary web script or HTML via a URL at the online service.... Read more

    Affected Products : messenger
    • Published: Sep. 25, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-4965

    Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter that identifies resources outsi... Read more

    Affected Products : quicktime
    • Published: Sep. 25, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4966

    PHP remote file inclusion vulnerability in inc/ifunctions.php in chumpsoft phpQuestionnaire (phpQ) 3.12 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[phpQRootDir] parameter.... Read more

    Affected Products : phpquestionnaire
    • Published: Sep. 25, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4954

    The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying (1) passwords and (2) permissions, (3) viewing profile ... Read more

    Affected Products : neon_webmail
    • Published: Sep. 23, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4957

    SQL injection vulnerability in the GetMember function in functions.php in MyReview 1.9.4 allows remote attackers to execute arbitrary SQL commands via the email parameter to Admin.php.... Read more

    Affected Products : myreview
    • Published: Sep. 23, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4951

    Neon WebMail for Java before 5.08 allows remote attackers to execute arbitrary Java (JSP) code by sending an e-mail message with a JSP file attachment, which is stored under the web root with a predictable filename.... Read more

    Affected Products : neon_webmail
    • Published: Sep. 23, 2006
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2006-4950

    Cisco IOS 12.2 through 12.4 before 20060920, as used by Cisco IAD2430, IAD2431, and IAD2432 Integrated Access Devices, the VG224 Analog Phone Gateway, and the MWR 1900 and 1941 Mobile Wireless Edge Routers, is incorrectly identified as supporting DOCSIS, ... Read more

    Affected Products : ios
    • Published: Sep. 23, 2006
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2006-4960

    Cross-site scripting (XSS) vulnerability in index.php Php Blue Dragon 2.9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the m parameter, which is reflected in an error message resulting from a failed SQL query.... Read more

    Affected Products : php_blue_dragon
    • Published: Sep. 23, 2006
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2006-4962

    Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence via the phpExt parameter, as demonstrated by executing PHP code in a log... Read more

    Affected Products : php_blue_dragon
    • Published: Sep. 23, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-4959

    Sun Secure Global Desktop (SSGD, aka Tarantella) before 4.3 allows remote attackers to obtain sensitive information, including hostnames, versions, and settings details, via unspecified vectors, possibly involving (1) taarchives.cgi, (2) ttaAuthentication... Read more

    Affected Products : secure_global_desktop
    • Published: Sep. 23, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4961

    SQL injection vulnerability in the GetModuleConfig function in public_includes/pub_kernel/pbd_modules.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter to index.php.... Read more

    Affected Products : php_blue_dragon
    • Published: Sep. 23, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4953

    Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary SQL commands via the (1) adr_sortkey and (2) adr_sortkey_desc parameters in the (a) addrlist servlet, and the (3) sortkey and (4) sortk... Read more

    Affected Products : neon_webmail
    • Published: Sep. 23, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-4955

    Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the (1) savefolder and (2) savefilename parameters.... Read more

    Affected Products : neon_webmail
    • Published: Sep. 23, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4952

    The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail folders, specified by the folderid and tofolderid parameters, via the ID parameter.... Read more

    Affected Products : neon_webmail
    • Published: Sep. 23, 2006
    • Modified: Apr. 03, 2025
Showing 20 of 294799 Results