Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2006-4853

    SQL injection vulnerability in kategorix.asp in Haberx 1.02 through 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in kategorihaberx.asp.... Read more

    Affected Products : haberx
    • Published: Sep. 19, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4849

    PHP remote file inclusion vulnerability in header.php in MobilePublisherPHP 1.5 RC2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.... Read more

    Affected Products : mobilepublisherphp
    • Published: Sep. 19, 2006
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2006-4844

    PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter.... Read more

    • Published: Sep. 19, 2006
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2006-4845

    PHP remote file inclusion vulnerability in includes/footer.html.inc.php in TeamCal Pro 2.8.001 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tc_config[app_root] parameter.... Read more

    Affected Products : teamcal_pro
    • Published: Sep. 19, 2006
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2006-4846

    Unspecified vulnerability in Citrix Access Gateway with Advanced Access Control (AAC) 4.2 before 20060914, when AAC is configured to use LDAP authentication, allows remote attackers to bypass authentication via unknown vectors.... Read more

    Affected Products : access_gateway
    • Published: Sep. 19, 2006
    • Modified: Apr. 03, 2025
  • 6.5

    MEDIUM
    CVE-2006-4847

    Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long (1) XCRC, (2) XSHA1, or (3) XMD5 commands.... Read more

    Affected Products : ws_ftp_server ws_ftp_server
    • Published: Sep. 19, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4848

    Multiple PHP remote file inclusion vulnerabilities in Brian Fraval Hitweb 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the REP_CLASS parameter to (1) index.php, (2) arbo.php, (3) framepoint.php, (4) genpage.php, (5) lienvalider.ph... Read more

    Affected Products : hitweb
    • Published: Sep. 19, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4851

    PHP remote file inclusion vulnerability in system/_b/contentFiles/gBHTMLEditor.php in BolinOS 4.5.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gBRootPath parameter. NOTE: the provenance of this information is unkno... Read more

    Affected Products : bolinos
    • Published: Sep. 19, 2006
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2006-4850

    PHP remote file inclusion vulnerability in system/_b/contentFiles/gBIndex.php in BolinOS 4.5.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gBRootPath parameter.... Read more

    Affected Products : blinos
    • Published: Sep. 19, 2006
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2006-4829

    Multiple cross-site scripting (XSS) vulnerabilities in David Czarnecki Blojsom 2.31 allow remote attackers to inject arbitrary web script or HTML via the (1) blog-category-description, (2) blog-entry-title, (3) rss-enclosure-url, (4) technorati-tagsi, or ... Read more

    Affected Products : blojsom
    • Published: Sep. 15, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-4838

    Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) root_url and (2) dcp_version parameters in (a) admin/inc/footer.inc.php, and the root_url, (3) page_top_name... Read more

    Affected Products : dcp-portal
    • Published: Sep. 15, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4837

    Multiple PHP remote file inclusion vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) library/lib.php and (2) library/editor/editor.php. NOTE: the same primary issue can be use... Read more

    Affected Products : dcp-portal
    • Published: Sep. 15, 2006
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2006-4831

    Unspecified vulnerability in IP over DNS is now easy (iodine) before 0.3.2 has unknown impact and attack vectors, related to "potential security problems."... Read more

    Affected Products : iodine iodine
    • Published: Sep. 15, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4823

    PHP remote file inclusion vulnerability in scripts/news_page.php in Reamday Enterprises Magic News Pro 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter.... Read more

    Affected Products : magic_news_pro
    • Published: Sep. 15, 2006
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2006-4830

    Directory traversal vulnerability in EditBlogTemplatesPlugin.java in David Czarnecki Blojsom 2.30 allows remote attackers to have an unknown impact by sending an HTTP request with a certain value of blogTemplate.... Read more

    Affected Products : blojsom
    • Published: Sep. 15, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-4821

    Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Userreview module before 1.19 2006/09/12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more

    Affected Products : drupal_userreview_module
    • Published: Sep. 15, 2006
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2006-4836

    SQL injection vulnerability in login.php in DCP-Portal SE 6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: The lostpassword.php and calendar.php vectors are already covered by CVE-2005-3365, and the search.p... Read more

    Affected Products : dcp-portal
    • Published: Sep. 15, 2006
    • Modified: Apr. 03, 2025
  • 7.8

    HIGH
    CVE-2006-4833

    Verso NetPerformer FRAD ACT SDM-95xx 7.xx (R1) and earlier, SDM-93xx 10.x.x (R2) and earlier, and SDM-92xx 9.x.x (R1) and earlier allow remote attackers to cause a denial of service (hang or reboot) via an ICMP packet with the same destination and source ... Read more

    Affected Products : frame_relay_access_device_act
    • Published: Sep. 15, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4828

    PHP remote file inclusion vulnerability in zipndownload.php in PhotoPost 4.0 through 4.6 allows remote attackers to execute arbitrary PHP code via a URL in the PP_PATH parameter.... Read more

    Affected Products : photopost_php_pro
    • Published: Sep. 15, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4824

    PHP remote file inclusion vulnerability in lib/activeutil.php in Quicksilver Forums (QSF) 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the set[include_path] parameter.... Read more

    Affected Products : quicksilver_forums
    • Published: Sep. 15, 2006
    • Modified: Apr. 03, 2025
Showing 20 of 294860 Results