Latest CVE Feed
-
5.6
MEDIUMCVE-2006-2448
Linux kernel before 2.6.16.21 and 2.6.17, when running on PowerPC, does not perform certain required access_ok checks, which allows local users to read arbitrary kernel memory on 64-bit systems (signal_64.c) and cause a denial of service (crash) and possi... Read more
- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-3085
xt_sctp in netfilter for Linux kernel before 2.6.17.1 allows attackers to cause a denial of service (infinite loop) via an SCTP chunk with a 0 length.... Read more
Affected Products : linux_kernel- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3196
index.php in singapore 0.10.0 and earlier allows remote attackers to obtain the installation path via an invalid template parameter, which reveals the path in an error message.... Read more
Affected Products : singapore- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3170
CS-Forum before 0.82 allows remote attackers to obtain sensitive information via unspecified manipulations, possibly involving an empty collapse[] or readall parameter to index.php, which reveals the installation path in an error message.... Read more
Affected Products : cs-forum- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3195
Cross-site scripting (XSS) vulnerability in index.php in singapore 0.10.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the template parameter.... Read more
Affected Products : singapore- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3185
PHP remote file inclusion vulnerability in data/header.php in CMS Faethon 1.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the mainpath parameter.... Read more
Affected Products : cms_faethon- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3175
Multiple PHP remote file inclusion vulnerabilities in mcGuestbook 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) admin.php, (2) ecrire.php, and (3) lire.php. NOTE: it was later reported that the ecrire.php ... Read more
Affected Products : mcguestbook- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3190
SQL injection vulnerability in administration/includes/login/auth.php in HotPlug CMS 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameters.... Read more
Affected Products : hotplug_cms- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3178
Directory traversal vulnerability in extract_chmLib example program in CHM Lib (chmlib) before 0.38 allows remote attackers to overwrite arbitrary files via a CHM archive containing files with a .. (dot dot) in their filename.... Read more
Affected Products : chm_lib- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3182
Directory traversal vulnerability in index.php in MobeScripts Mobile Space Community 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the uid parameter in the rss page.... Read more
Affected Products : mobile_space_community- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3173
Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) path[cb] parameter to (a) libraries/comment/postComment.php and (b) modules/poll/poll.php, (2) rel parame... Read more
Affected Products : content\*builder- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3191
Cross-site scripting (XSS) vulnerability in comment.php in MPCS 0.2 allows remote attackers to inject arbitrary web script or HTML via the pageid parameter.... Read more
Affected Products : mpcs- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3180
Cross-site scripting (XSS) vulnerability in ftp_index.php in Confixx Pro 3.0 allows remote attackers to inject arbitrary web script or HTML via the path parameter.... Read more
Affected Products : confixx- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-3194
Directory traversal vulnerability in index.php in singapore 0.10.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the (1) gallery and (2) template parameter.... Read more
Affected Products : singapore- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3176
SQL injection vulnerability in xarancms_haupt.php in xarancms 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : xaran_cms- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3179
Cross-site scripting (XSS) vulnerability in tools_ftp_pwaendern.php in Confixx Pro 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the account parameter.... Read more
Affected Products : confixx- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3187
Multiple cross-site scripting (XSS) vulnerabilities in Sharky e-shop 3.05 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) maingroup and (2) secondgroup parameters to (a) search_prod_list.asp, and the (3) maingroup par... Read more
Affected Products : sharky_e-shop- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3193
Multiple PHP remote file inclusion vulnerabilities in Grayscale BandSite CMS 1.1.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) includes/content/contact_content.php; mu... Read more
Affected Products : bandsite_cms- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3181
SQL injection vulnerability in index.php in MobeScripts Mobile Space Community 2.0 allows remote attackers to execute arbitrary SQL commands via the browse parameter.... Read more
Affected Products : mobile_space_community- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3186
Multiple cross-site scripting (XSS) vulnerabilities in CMS Faethon 1.3.2 allow remote attackers to inject arbitrary web script or HTML via the mainpath parameter to (1) data/footer.php and (2) admin/header.php. NOTE: the provenance of this information is... Read more
Affected Products : cms_faethon- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025