Latest CVE Feed
-
5.0
MEDIUMCVE-2006-3368
Efone 20000723 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.... Read more
Affected Products : efone- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3373
Unspecified vulnerability in the client/bin/logfetch script in Hobbit 4.2-beta allows local users to read arbitrary files, related to logfetch running as setuid root.... Read more
Affected Products : hobbit_monitor- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3376
Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products including (1) wv, (2) abiword, (3) freetype, (4) gimp, (5) libgsf, and (6) imagemagick allows remote attackers to execute arbitrary code via the MaxRecordSize header field in a W... Read more
- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3380
Algorithmic complexity vulnerability in FreeStyle Wiki before 3.6.2 allows remote attackers to cause a denial of service (CPU consumption) by performing a diff between large, crafted pages that trigger the worst case.... Read more
Affected Products : freestyle_wiki- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3357
Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code by repeatedly setting the Image field of a... Read more
Affected Products : internet_explorer- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3371
Eupla Foros 1.0 stores the inc/config.inc file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information, including the database configuration.... Read more
Affected Products : foros- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3364
SQL injection vulnerability in index.php in the NP_SEO plugin in BLOG:CMS before 4.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : blog_cms- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3372
Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of service (application crash) via a DHTML setAttributeNode function call with zero arguments, which triggers a null dereference.... Read more
Affected Products : safari- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3374
PHP remote file inclusion vulnerability in index.php in Randshop 1.2 and earlier, including 0.9.3, allows remote attackers to execute arbitrary PHP code via a URL in the incl parameter.... Read more
Affected Products : randshop- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3375
PHP remote file inclusion vulnerability in includes/header.inc.php in Randshop 1.1.1 allows remote attackers to execute arbitrary PHP code via the dateiPfad parameter.... Read more
Affected Products : randshop- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3395
PHP remote file inclusion vulnerability in top.php in SiteBuilder-FX 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter.... Read more
Affected Products : sitebuilder-fx- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3387
Directory traversal vulnerability in sources/post.php in Fusion News 1.0, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the fil_config parameter, which can be used to execute PHP code t... Read more
Affected Products : fusion_news- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3390
WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2) wp-content, and (3) wp-includes directories, possibly due to uninitialized variables.... Read more
Affected Products : wordpress- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3391
The Execute function in iMBCContents ActiveX Control before 2.0.0.59 allows remote attackers to execute arbitrary files via the file URI handler.... Read more
Affected Products : imbccontents_activex_control- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-3385
Cross-site scripting (XSS) vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) id and (2) disabled parameters.... Read more
Affected Products : news- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3394
SQL injection vulnerability in the files mod in index.php in BXCP 0.3.0.4 allows remote attackers to execute arbitrary SQL commands via the where parameter in a view action.... Read more
Affected Products : bxcp- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3358
Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being returned... Read more
Affected Products : newsphp- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3366
Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2) l... Read more
Affected Products : v3_chat- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3379
Algorithmic complexity vulnerability in Hiki Wiki 0.6.0 through 0.6.5 and 0.8.0 through 0.8.5 allows remote attackers to cause a denial of service (CPU consumption) by performing a diff between large, crafted pages that trigger the worst case.... Read more
Affected Products : hiki_wiki- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3365
V3 Chat allows remote attackers to obtain the installation path via (1) an invalid id parameter to mail/index.php or (2) membername parameter to messenger/online.php, which displays the path in an error page due to an incorrect SQL statement.... Read more
Affected Products : v3_chat- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025