Latest CVE Feed
-
5.1
MEDIUMCVE-2006-4850
PHP remote file inclusion vulnerability in system/_b/contentFiles/gBIndex.php in BolinOS 4.5.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gBRootPath parameter.... Read more
Affected Products : blinos- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4851
PHP remote file inclusion vulnerability in system/_b/contentFiles/gBHTMLEditor.php in BolinOS 4.5.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gBRootPath parameter. NOTE: the provenance of this information is unkno... Read more
Affected Products : bolinos- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4844
PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter.... Read more
- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4848
Multiple PHP remote file inclusion vulnerabilities in Brian Fraval Hitweb 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the REP_CLASS parameter to (1) index.php, (2) arbo.php, (3) framepoint.php, (4) genpage.php, (5) lienvalider.ph... Read more
Affected Products : hitweb- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-4847
Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long (1) XCRC, (2) XSHA1, or (3) XMD5 commands.... Read more
- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4825
Multiple cross-site scripting (XSS) vulnerabilities in cl_files/index.php in SoftComplex PHP Event Calendar 1.5.1, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) ti, (2) bi, or (3) cbgi parameters.... Read more
Affected Products : php_event_calendar- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4827
Multiple PHP remote file inclusion vulnerabilities in Vmist Downstat 1.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the art parameter to (1) admin.php, (2) chart.php, (3) modes.php, or (4) stats.php.... Read more
Affected Products : downstat- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-4833
Verso NetPerformer FRAD ACT SDM-95xx 7.xx (R1) and earlier, SDM-93xx 10.x.x (R2) and earlier, and SDM-92xx 9.x.x (R1) and earlier allow remote attackers to cause a denial of service (hang or reboot) via an ICMP packet with the same destination and source ... Read more
Affected Products : frame_relay_access_device_act- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4828
PHP remote file inclusion vulnerability in zipndownload.php in PhotoPost 4.0 through 4.6 allows remote attackers to execute arbitrary PHP code via a URL in the PP_PATH parameter.... Read more
Affected Products : photopost_php_pro- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4822
Multiple cross-site scripting (XSS) vulnerabilities in index.php in eMuSOFT emuCMS 0.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) query or (2) page parameters.... Read more
Affected Products : emucms- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4824
PHP remote file inclusion vulnerability in lib/activeutil.php in Quicksilver Forums (QSF) 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the set[include_path] parameter.... Read more
Affected Products : quicksilver_forums- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4836
SQL injection vulnerability in login.php in DCP-Portal SE 6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: The lostpassword.php and calendar.php vectors are already covered by CVE-2005-3365, and the search.p... Read more
Affected Products : dcp-portal- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4834
PHP remote file inclusion vulnerability in index.php in Jule Slootbeek phpQuiz 0.01 allows remote attackers to execute arbitrary PHP code via a URL in the pagename parameter.... Read more
Affected Products : phpquiz- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4821
Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Userreview module before 1.19 2006/09/12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : drupal_userreview_module- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4826
PHP remote file inclusion vulnerability in bottom.php in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.... Read more
Affected Products : shadowed_portal- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4835
Bluview Blue Magic Board (BMB) (aka BMForum) 5.5 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) db_mysql_error.php, (4) langlist.php, (5) sendmail.php, or (6) style.php, which reveals th... Read more
Affected Products : blue_magic_board- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4823
PHP remote file inclusion vulnerability in scripts/news_page.php in Reamday Enterprises Magic News Pro 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter.... Read more
Affected Products : magic_news_pro- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-4829
Multiple cross-site scripting (XSS) vulnerabilities in David Czarnecki Blojsom 2.31 allow remote attackers to inject arbitrary web script or HTML via the (1) blog-category-description, (2) blog-entry-title, (3) rss-enclosure-url, (4) technorati-tagsi, or ... Read more
Affected Products : blojsom- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-4830
Directory traversal vulnerability in EditBlogTemplatesPlugin.java in David Czarnecki Blojsom 2.30 allows remote attackers to have an unknown impact by sending an HTTP request with a certain value of blogTemplate.... Read more
Affected Products : blojsom- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-4831
Unspecified vulnerability in IP over DNS is now easy (iodine) before 0.3.2 has unknown impact and attack vectors, related to "potential security problems."... Read more
- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025