Latest CVE Feed
-
5.0
MEDIUMCVE-2006-4959
Sun Secure Global Desktop (SSGD, aka Tarantella) before 4.3 allows remote attackers to obtain sensitive information, including hostnames, versions, and settings details, via unspecified vectors, possibly involving (1) taarchives.cgi, (2) ttaAuthentication... Read more
Affected Products : secure_global_desktop- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4957
SQL injection vulnerability in the GetMember function in functions.php in MyReview 1.9.4 allows remote attackers to execute arbitrary SQL commands via the email parameter to Admin.php.... Read more
Affected Products : myreview- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-4962
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence via the phpExt parameter, as demonstrated by executing PHP code in a log... Read more
Affected Products : php_blue_dragon- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4961
SQL injection vulnerability in the GetModuleConfig function in public_includes/pub_kernel/pbd_modules.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter to index.php.... Read more
Affected Products : php_blue_dragon- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-4963
Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence in the view parameter in the show_view action in the calendarmodule module, as demonstrated... Read more
- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-4964
Cross-site scripting (XSS) vulnerability in MAXdev MDPro 1.0.76 before 20060918 allows remote attackers to inject arbitrary web script or HTML via (1) vectors that bypass the XSS protection mechanisms of the pnVarCleanFromInput function, and (2) unspecifi... Read more
Affected Products : md-pro- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-4958
Multiple cross-site scripting (XSS) vulnerabilities in Sun Secure Global Desktop (SSGD, aka Tarantella) before 4.20.983 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving (1) taarchives.cgi, (2) ttaA... Read more
Affected Products : secure_global_desktop- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-4956
Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote attackers to inject arbitrary web script or HTML via the in_name parameter, as used by the Name field.... Read more
Affected Products : neon_webmail- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4955
Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the (1) savefolder and (2) savefilename parameters.... Read more
Affected Products : neon_webmail- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4953
Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary SQL commands via the (1) adr_sortkey and (2) adr_sortkey_desc parameters in the (a) addrlist servlet, and the (3) sortkey and (4) sortk... Read more
Affected Products : neon_webmail- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4952
The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail folders, specified by the folderid and tofolderid parameters, via the ID parameter.... Read more
Affected Products : neon_webmail- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4948
Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a long file name. NOTE: the provenance of this information is unknown; the det... Read more
Affected Products : tftp_server_tftpdwin- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4945
Multiple PHP remote file inclusion vulnerabilities in Cardway (aka Frederic Boudaud) DigitalWebShop 1.128 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _PHPLIB[libdir] parameter to (1) rechnung.php or (2) prepend.php.... Read more
Affected Products : digitalwebshop- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4949
Cross-site scripting (XSS) vulnerability in the Drupal 4.6 Site Profile Directory (profile_pages.module) before 1.1.2.1 and the Drupal 4.7 Site Profile Directory (profile_pages.module) before 1.2.2.1 allows remote attackers to inject arbitrary web script ... Read more
Affected Products : site_profile_directory_module- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-4947
Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Search Keywords module before 1.15 2006/09/15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "lack of validation on output."... Read more
Affected Products : search_keyword_module- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4946
PHP remote file inclusion vulnerability in include/startup.inc.php in CMSDevelopment Business Card Web Builder (BCWB) 0.99, and possibly 2.5 Beta and earlier, allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.... Read more
Affected Products : business_card_web_builder- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-4937
lib/setup.php in Moodle before 1.6.2 sets the error reporting level to 7 to display E_WARNING messages to users even if debugging is disabled, which might allow remote authenticated users to obtain sensitive information by triggering the messages.... Read more
Affected Products : moodle- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-4942
Moodle before 1.6.2, when the configuration lacks (1) algebra or (2) tex filters, allows remote authenticated users to write LaTeX or MimeTeX output files to the top level of the dataroot directory via (a) filter/algebra/pix.php or (b) filter/tex/pix.php.... Read more
Affected Products : moodle- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4943
course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.... Read more
Affected Products : moodle- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4939
backup/backup_scheduled.php in Moodle before 1.6.2 generates trace data with the full backup pathname even when debugging is disabled, which might allow attackers to obtain the pathname.... Read more
Affected Products : moodle- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025