Latest CVE Feed
-
5.0
MEDIUMCVE-2006-4765
NETGEAR DG834GT Wireless ADSL router running firmware 1.01.28 allows attackers to cause a denial of service (device hang) via a long string in the username field in the login window.... Read more
Affected Products : dg834gt- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4746
PHP remote file inclusion vulnerability in news/include/customize.php in Web Server Creator 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the l parameter.... Read more
Affected Products : web_server_creator- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4734
Multiple SQL injection vulnerabilities in tiki-g-admin_processes.php in Tikiwiki 1.9.4 allow remote attackers to execute arbitrary SQL commands via the (1) pid and (2) where parameters.... Read more
Affected Products : tikiwiki_cms\/groupware- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4743
WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.php, (2) akismet.php, (3) archive.php, (4) archives.php, (5) attachment.php, (6) blogger.php, (7) comments.php, (8) comments-popup.php, ... Read more
Affected Products : wordpress- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4742
Cross-site scripting (XSS) vulnerability in user_add.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.... Read more
Affected Products : phplinkexchange- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4741
PHP remote file inclusion vulnerability in bits_listings.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute arbitrary code via the svr_rootPhpStart parameter.... Read more
Affected Products : phplinkexchange- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4733
PHP remote file inclusion vulnerability in sipssys/code/box.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) 0.3.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the config[sipssys] parameter. NOTE: the... Read more
Affected Products : sips- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4750
PHP remote file inclusion vulnerability in openi-admin/base/fileloader.php in OPENi-CMS 1.0.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the config[openi_dir] parameter.... Read more
Affected Products : openi-cms- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2006-4745
ScaryBear PocketExpense Pro 3.9.1 uses an internally recorded key to protect a data file whose contents are stored in plaintext, which allows local users to disable authentication and access the file by modifying a certain value in the file header.... Read more
Affected Products : pocketexpense_pro- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4749
Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpATM) 1.20 allow remote attackers to execute arbitrary PHP code via the include_location parameter in (1) activate.php, (2) configure.php, (3) fileop.php, (4) getimg.ph... Read more
Affected Products : php_advanced_transfer_manager- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4736
Multiple SQL injection vulnerabilities in index.php in CMS.R. 5.5 allow remote attackers to execute arbitrary SQL commands via the (1) adminname and (2) adminpass parameters. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : cms.r.- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4735
Kellan Elliott-McCrea MagpieRSS allows remote attackers to obtain sensitive information via a direct request for (1) rss_fetch.inc.php or (2) rss_parse.inc.php, which reveals the path in various error messages.... Read more
Affected Products : magpierss- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4748
Multiple SQL injection vulnerabilities in F-ART BLOG:CMS 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) xagent, (2) xpath, (3) xreferer, and (4) xdns parameters in (a) admin/plugins/NP_Log.php, and the (5) pitem parameter in (b) ... Read more
Affected Products : blog_cms- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4744
Abidia (1) O-Anywhere and (2) Abidia Wireless transmit authentication credentials in cleartext, which allows remote attackers to obtain sensitive information by sniffing.... Read more
- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4753
Directory traversal vulnerability in index.php in PHProg before 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.... Read more
Affected Products : phprog- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4756
SQL injection vulnerability in alpha.php in phpMyDirectory 10.4.6 and earlier allows remote attackers to execute arbitrary SQL commands via the letter parameter. NOTE: the provenance of this information is unknown; the details are obtained from third par... Read more
Affected Products : phpmydirectory- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4739
Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the OriginalImageData parameter to phpthumb.php.... Read more
Affected Products : jetbox_cms- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4755
Cross-site scripting (XSS) vulnerability in alpha.php in phpMyDirectory 10.4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the letter parameter. NOTE: the provenance of this information is unknown; the details are obtai... Read more
Affected Products : phpmydirectory- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4738
PHP remote file inclusion vulnerability in phpthumb.php in Jetbox CMS allows remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter. NOTE: The relative_script_path vector is already covered by CVE-2006-2270.... Read more
Affected Products : jetbox_cms- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4737
SQL injection vulnerability in index.php in Jetbox CMS allows remote attackers to inject arbitrary web script or HTML via the item parameter. NOTE: The view vector is already covered by CVE-2006-3586.2.... Read more
Affected Products : jetbox_cms- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025