Latest CVE Feed
-
7.5
HIGHCVE-2006-3851
SQL injection vulnerability in upgradev1.php in X7 Chat 2.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the old_prefix parameter.... Read more
Affected Products : x7_chat- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3119
The fbgs framebuffer Postscript/PDF viewer in fbi before 2.01 has a typo that prevents a filter from working correctly, which allows user-assisted attackers to bypass the filter and execute malicious Postscript commands.... Read more
Affected Products : fbi- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3846
PHP remote file inclusion vulnerability in extadminmenus.class.php in the MultiBanners 1.0.1 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.... Read more
Affected Products : mambo_multibanners- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3841
Cross-site scripting (XSS) vulnerability in WebScarab before 20060718-1904, when used with Microsoft Internet Explorer 6 SP2 or Konqueror 3.5.3, allows remote attackers to inject arbitrary web script or HTML via the URL, which is not sanitized before bein... Read more
Affected Products : webscarab- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3852
Cross-site scripting (XSS) vulnerability in index.php in Micro GuestBook allows remote attackers to execute arbitrary SQL commands via the (1) name or (2) comment ("text") fields.... Read more
Affected Products : micro_guestbook- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3842
Cross-site scripting (XSS) vulnerability in Zoho Virtual Office 3.2 Build 3210 allows remote attackers to execute arbitrary web script or HTML via an HTML message.... Read more
Affected Products : zoho_virtual_office- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-3844
Buffer overflow in Quick 'n Easy FTP Server 3.0 allows remote authenticated users to execute arbitrary commands via a long argument to the LIST command, a different issue than CVE-2006-2027.... Read more
Affected Products : quick_n_easy_ftp_server- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-3845
Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a LHA archive.... Read more
Affected Products : winrar- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3619
Directory traversal vulnerability in FastJar 0.93, as used in Gnu GCC 4.1.1 and earlier, and 3.4.6 and earlier, allows user-assisted attackers to overwrite arbitrary files via a .jar file containing filenames with "../" sequences.... Read more
Affected Products : fastjar- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3816
Krusader 1.50-beta1 up to 1.70.0 stores passwords for remote connections in cleartext in the bookmark file (krbookmarks.xml), which allows attackers to steal passwords by obtaining the file.... Read more
Affected Products : krusader- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3834
EJ3 TOPo 2.2.178 includes the password in cleartext in the ID field to index.php, which allows context-dependent attackers to obtain entry passwords via log files, referrers, or other vectors.... Read more
Affected Products : topo- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3833
index.php in EJ3 TOPo 2.2.178 allows remote attackers to overwrite existing entries and establish new passwords for the overwritten entries via a URL with a modified entry ID.... Read more
Affected Products : topo- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3823
SQL injection vulnerability in index.php in GeodesicSolutions (1) GeoAuctions Premier 2.0.3 and (2) GeoClassifieds Basic 2.0.3 allows remote attackers to execute arbitrary SQL commands via the b parameter.... Read more
- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-3828
Incomplete blacklist vulnerability in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to bypass SQL injection protection mechanisms by using commas, quote characters, pound sign (#) characters, "UNI... Read more
Affected Products : boastmachine- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3825
The IPv4 implementation in Sun Solaris 10 before 20060721 allows local users to select routes that differ from the routing table, possibly facilitating firewall bypass or unauthorized network communication.... Read more
Affected Products : solaris- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3814
Buffer overflow in the Loader_XM::load_instrument_internal function in loader_xm.cpp for Cheese Tracker 0.9.9 and earlier allows user-assisted attackers to execute arbitrary code via a crafted file with a large amount of extra data.... Read more
Affected Products : cheese_tracker- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3836
Directory traversal vulnerability in index.php in UNIDOmedia Chameleon LE 1.203 and earlier, and possibly Chameleon PRO, allows remote attackers to read arbitrary files via the rmid parameter.... Read more
Affected Products : chameleon_le- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3822
SQL injection vulnerability in index.php in GeodesicSolutions GeoAuctions Enterprise 1.0.6 allows remote attackers to execute arbitrary SQL commands via the d parameter.... Read more
Affected Products : geoauctions_enterprise- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3831
The Backup selection in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier uses predicable filenames for database backups and stores the files under the web root with insufficient access control, which allows remote attackers to obtain sensitiv... Read more
Affected Products : boastmachine- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3835
Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preceding a filename with a mapped extension, as demonstrated by URLs ending with /;index.jsp and /;help.do.... Read more
Affected Products : tomcat- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025