Latest CVE Feed
-
7.5
HIGHCVE-2006-4054
Multiple PHP remote file inclusion vulnerabilities in ME Download System 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) Vb8878b936c2bd8ae0cab parameter to (a) inc/sett_style.php or (b) inc/sett_smilies.php; or the (2) Vb6c4d... Read more
Affected Products : me_download_system- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4069
Multiple cross-site scripting (XSS) vulnerabilities in Elaine Aquino Online Zone Journals (OZJournals) 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) m and (2) c parameters in index.php, (3) a search action, and (4) a "submi... Read more
Affected Products : ozjournals- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4057
Buffer overflow in the preview_create function in gui.cpp in Mitch Murray Eremove 1.4 allows remote attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via a large email attachment.... Read more
Affected Products : eremove- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4064
SQL injection vulnerability in default.asp in YenerTurk Haber Script 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it was later reported reported that 2.0 is also affected.... Read more
Affected Products : yenerturk_haber_script- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4070
Format string vulnerability in Imendio Planner 0.13 allows user-assisted attackers to execute arbitrary code via format string specifiers in a filename.... Read more
Affected Products : imendio_planner- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4061
PHP remote file inclusion vulnerability in index.php in Thomas Pequet phpPrintAnalyzer 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep_par_rapport_racine parameter. NOTE: this issue has be... Read more
Affected Products : phpprintanalyzer- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4053
PHP remote file inclusion vulnerability in templates/header.php in ME Download System 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the Vb8878b936c2bd8ae0cab parameter.... Read more
Affected Products : me_download_system- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-4058
Cross-site scripting (XSS) vulnerability in archive.php in Simplog 0.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyw parameter when performing a search. NOTE: some details are obtained from third party informat... Read more
Affected Products : simplog- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4059
Multiple PHP remote file inclusion vulnerabilities in USOLVED NEWSolved Lite 1.9.2, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) newsscript_lyt.php, (2) newsticker/newsscript_get.php... Read more
Affected Products : newsolved_lite- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4062
PHP remote file inclusion vulnerability in usr/extensions/get_tree.inc.php in Dmitry Sheiko SAPID Shop 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[root_path] parameter.... Read more
Affected Products : sapid_shop- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4060
PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_dir parameter.... Read more
Affected Products : visual_events_calendar- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4063
Multiple PHP remote file inclusion vulnerabilities in Csaba Godor SAPID Blog Beta 2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_blog_infochannel.inc.php, (b) usr/exten... Read more
Affected Products : sapid_blog_beta_2- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4065
Multiple PHP remote file inclusion vulnerabilities in Dmitry Sheiko SAPID Gallery 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_calendar.inc.php or the (2) GLOBALS[r... Read more
Affected Products : sapid_gallery- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4052
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Simple Shop 2.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) admin/index.php, (2) admin/adminindex.php, (3) admin/ad... Read more
Affected Products : php_simple_shop- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4068
The pswd.js script relies on the client to calculate whether a username and password match hard-coded hashed values for a server, and uses a hashing scheme that creates a large number of collisions, which makes it easier for remote attackers to conduct of... Read more
Affected Products : pswd.js- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4056
Multiple SQL injection vulnerabilities in the authentication process in katzlbt (a) The Address Book 1.04e and earlier and (b) The Address Book Reloaded before 2.0-rc4 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) pa... Read more
- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4050
PHP remote file inclusion vulnerability in auto_check_renewals.php in phpAutoMembersArea (phpAMA) 3.2.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter.... Read more
Affected Products : phpautomembersarea- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4055
Multiple PHP remote file inclusion vulnerabilities in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the tsep_config[absPath] parameter to (1) include/colorswitch.php, (2)... Read more
Affected Products : tsep- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4051
PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter.... Read more
Affected Products : php_live_helper- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4067
Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 404 ("Not Found") error page. NOTE: some of these detail... Read more
- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025