Latest CVE Feed
-
6.8
MEDIUMCVE-2006-4751
Cross-site scripting (XSS) vulnerability in index.php in Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the errcode parameter.... Read more
Affected Products : expandable_home_page_cms- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4743
WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.php, (2) akismet.php, (3) archive.php, (4) archives.php, (5) attachment.php, (6) blogger.php, (7) comments.php, (8) comments-popup.php, ... Read more
Affected Products : wordpress- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4734
Multiple SQL injection vulnerabilities in tiki-g-admin_processes.php in Tikiwiki 1.9.4 allow remote attackers to execute arbitrary SQL commands via the (1) pid and (2) where parameters.... Read more
Affected Products : tikiwiki_cms\/groupware- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4746
PHP remote file inclusion vulnerability in news/include/customize.php in Web Server Creator 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the l parameter.... Read more
Affected Products : web_server_creator- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4742
Cross-site scripting (XSS) vulnerability in user_add.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.... Read more
Affected Products : phplinkexchange- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4747
Multiple cross-site scripting (XSS) vulnerabilities in IdevSpot TextAds allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter in delete.php and (2) the error parameter in error.php.... Read more
Affected Products : textads- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4756
SQL injection vulnerability in alpha.php in phpMyDirectory 10.4.6 and earlier allows remote attackers to execute arbitrary SQL commands via the letter parameter. NOTE: the provenance of this information is unknown; the details are obtained from third par... Read more
Affected Products : phpmydirectory- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4739
Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the OriginalImageData parameter to phpthumb.php.... Read more
Affected Products : jetbox_cms- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4755
Cross-site scripting (XSS) vulnerability in alpha.php in phpMyDirectory 10.4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the letter parameter. NOTE: the provenance of this information is unknown; the details are obtai... Read more
Affected Products : phpmydirectory- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-4754
Cross-site scripting (XSS) vulnerability in index.php in PHProg before 1.1 allows remote attackers to inject arbitrary web script or HTML via the album parameter, which is used in an opendir call. NOTE: the same primary issue can be used for full path di... Read more
Affected Products : phprog- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-3739
Integer overflow in the CIDAFM function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted Adobe Font Metrics (AFM) files with a modified number of character metrics (StartCharMetrics), which leads to a heap-based... Read more
- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-3740
Integer overflow in the scan_cidfont function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted (1) CMap and (2) CIDFont font data with modified item counts in the (a) begincodespacerange, (b) cidrange, and (c) n... Read more
- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4731
Multiple directory traversal vulnerabilities in (1) login.pl and (2) admin.pl in (a) SQL-Ledger before 2.6.19 and (b) LedgerSMB before 1.0.0p1 allow remote attackers to execute arbitrary Perl code via an unspecified terminal parameter value containing ../... Read more
- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4382
Multiple buffer overflows in Apple QuickTime before 7.1.3 allow user-assisted remote attackers to execute arbitrary code via a crafted QuickTime movie.... Read more
Affected Products : quicktime- Published: Sep. 12, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-4640
Unspecified vulnerability in Adobe Flash Player before 9.0.16.0 allows user-assisted remote attackers to bypass the allowScriptAccess protection via unspecified vectors.... Read more
Affected Products : flash_player- Published: Sep. 12, 2006
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2006-3442
Unspecified vulnerability in Pragmatic General Multicast (PGM) in Microsoft Windows XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted multicast message.... Read more
Affected Products : windows_xp- Published: Sep. 12, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-0001
Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts.... Read more
- Published: Sep. 12, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4389
Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted FlashPix (FPX) file, which triggers an exception that leads to an operation on an uninitialized object.... Read more
Affected Products : quicktime- Published: Sep. 12, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0032
Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which ... Read more
- Published: Sep. 12, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4384
Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via the COLOR_64 chunk in a FLIC (FLC) movie.... Read more
Affected Products : quicktime- Published: Sep. 12, 2006
- Modified: Apr. 03, 2025