Latest CVE Feed
-
2.6
LOWCVE-2006-4914
Directory traversal vulnerability in A.l-Pifou 1.8p2 allows remote attackers to read arbitrary files via ".." sequences in the ze_langue_02 cookie, as demonstrated by using the choix_lng parameter to choix_langue.php to indirectly set the cookie, then acc... Read more
Affected Products : a.l-pifou- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4910
The web administration interface (mainApp) to Cisco IDS before 4.1(5c), and IPS 5.0 before 5.0(6p1) and 5.1 before 5.1(2) allows remote attackers to cause a denial of service (unresponsive device) via a crafted SSLv2 Client Hello packet.... Read more
- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-4438
Heap-based buffer overflow in SpIDer for Dr.Web Scanner for Linux 4.33, and possibly earlier versions, allows remote attackers to execute arbitrary code via an LHA archive with an extended header that contains a long directory name.... Read more
Affected Products : dr.web- Published: Sep. 20, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4890
Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the dirroot parameter to (1) fckeditor/editor/filemanager/browser/default/connectors/php/connector.php or (2) ... Read more
Affected Products : unak_cms- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4891
SQL injection vulnerability in ArticlesTableview.asp in Techno Dreams Articles & Papers Package 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the key parameter.... Read more
Affected Products : articles_and_papers_package- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4897
CMtextS 1.0 and earlier stores users_logins/admin.txt under the web document root with insufficient access control, which allows remote attackers to obtain the administrator password.... Read more
Affected Products : cmtexts- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4898
PHP remote file inclusion vulnerability in include/phpxd/phpXD.php in guanxiCRM 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the appconf[rootpath] parameter.... Read more
Affected Products : guanxicrm_business_solution- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4894
Cross-site scripting (XSS) vulnerability in forms/lostpassword.php in iDevSpot NixieAffiliate 1.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter.... Read more
Affected Products : nixieaffiliate- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4893
PHP remote file inclusion vulnerability in bb_usage_stats/includes/bb_usage_stats.php in phpBB XS 0.58 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter, a different vector than CVE-2006-4780.... Read more
Affected Products : phpbb_xs- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4892
SQL injection vulnerability in faqview.asp in Techno Dreams FAQ Manager Package 1.0 allows remote attackers to execute arbitrary SQL commands via the key parameter.... Read more
Affected Products : faq_manager_package- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4895
IDevSpot NexieAffiliate 1.9 and earlier allows remote attackers to delete arbitrary affiliates via a modified id parameter to delete.php.... Read more
Affected Products : nixieaffiliate- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4878
Directory traversal vulnerability in footer.php in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to read and include arbitrary local files via a .. (dot dot) sequence in the template parameter. NOTE: this was later reported to aff... Read more
Affected Products : php-post- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4884
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 allow remote attackers to inject arbitrary web script or HTML via (1) the suser parameter in support/rightbar.php, (2) the ticket_id parameter in support/open_tickets.php, and (3... Read more
Affected Products : isupport- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4876
Multiple SQL injection vulnerabilities in Jupiter CMS allow remote attackers to execute arbitrary SQL commands via (1) the user name during login, or the (2) key or (3) fpwusername parameters in modules/register.... Read more
Affected Products : jupiter_cms- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4879
SQL injection vulnerability in profile.php in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.... Read more
Affected Products : php-post- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4336
Buffer underflow in the build_tree function in unpack.c in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted leaf count table that causes a write to a negative index.... Read more
Affected Products : gzip- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4874
Multiple cross-site scripting (XSS) vulnerabilities in Jupiter CMS allow remote attackers to inject arbitrary web script or HTML via the (1) language[Admin name] and (2) language[Admin back] parameters in (a) modules/blocks.php; the (3) language[Register ... Read more
Affected Products : jupiter_cms- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4877
Variable overwrite vulnerability in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to overwrite arbitrary program variables via multiple vectors that use the extract function, as demonstrated by the table_prefix parameter in (1) ind... Read more
Affected Products : php-post- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4335
Array index error in the make_table function in unlzh.c in the LZH decompression component in gzip 1.3.5, when running on certain platforms, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a ... Read more
Affected Products : gzip- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2006-4886
The VirusScan On-Access Scan component in McAfee VirusScan Enterprise 7.1.0 and Scan Engine 4.4.00 allows local privileged users to bypass security restrictions and disable the On-Access Scan option by opening the program via the task bar and quickly clic... Read more
- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025