Latest CVE Feed
-
7.5
HIGHCVE-2006-3430
SQL injection vulnerability in checkprofile.asp in (1) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (2) Novell ZENworks 6.2 SR1 and earlier, allows remote attackers to execute arbitrary SQL commands via the agentid paramete... Read more
- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-3405
Cross-site scripting (XSS) vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) delete, (2) pathext, and (3) edit parameters.... Read more
Affected Products : qtofilemanager- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3426
Directory traversal vulnerability in (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (b) Novell ZENworks 6.2 SR1 and earlier allows remote attackers to overwrite arbitrary files and directories via a .. (dot dot) sequence ... Read more
- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-3407
Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly execute shell code via strings with non-printable characters.... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3419
Tor before 0.1.1.20 uses OpenSSL pseudo-random bytes (RAND_pseudo_bytes) instead of cryptographically strong RAND_bytes, and seeds the entropy value at start-up with 160-bit chunks without reseeding, which makes it easier for attackers to conduct brute fo... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3409
Integer overflow in Tor before 0.1.1.20 allows remote attackers to execute arbitrary code via crafted large inputs, which result in a buffer overflow when elements are added to smartlists.... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3418
Tor before 0.1.1.20 does not validate that a server descriptor's fingerprint line matches its identity key, which allows remote attackers to spoof the fingerprint line, which might be trusted by users or other applications.... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3424
Multiple buffer overflows in WebEx Downloader ActiveX Control, possibly in versions before November 2005, allow remote attackers to execute arbitrary code via unspecified vectors.... Read more
Affected Products : webex_downloader_activex_control- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3421
PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the root parameter in (1) comment.php, (2) admin/comedit.php, (3) admin/test.php, (4) admi... Read more
Affected Products : smartsitecms- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3429
Cross-site scripting (XSS) vulnerability in TigerTom TTCalc 1.0 allows remote attackers to inject arbitrary web script or HTML via the currency parameter in (1) loan.php and (2) mortgage.php. NOTE: the provenance of this information is unknown; the detai... Read more
Affected Products : ttcalc_script- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3416
Tor before 0.1.1.20 kills the circuit when it receives an unrecognized relay command, which causes network circuits to be disbanded. NOTE: while this item is listed under the "Security fixes" section of the developer changelog, the developer clarified on... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3422
PHP remote file inclusion vulnerability in WonderEdit Pro CMS allows remote attackers to execute arbitrary PHP code via the config[template_path] parameter in user_bottom.php, as used by multiple templates including (1) rwb (template/rwb/user_bottom.php),... Read more
Affected Products : wonderedit_pro_cms- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-3406
Directory traversal vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to modify arbitrary files via a .. (dot dot) sequence in the edit parameter.... Read more
Affected Products : qtofilemanager- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3428
Cross-site scripting (XSS) vulnerability in TigerTom TTCalc 1.0 allows remote attackers to inject arbitrary web script or HTML via the year parameter in (1) loan.php and (2) mortgage.php.... Read more
Affected Products : ttcalc_script- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3420
Cross-site request forgery (CSRF) vulnerability in editpost.php in MyBulletinBoard (MyBB) before 1.1.5 allows remote attackers to perform unauthorized actions as a logged in user and delete arbitrary forum posts via a bbcode IMG tag with a modified delete... Read more
Affected Products : mybulletinboard- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-3417
Tor client before 0.1.1.20 prefers entry points based on is_fast or is_stable flags, which could allow remote attackers to be preferred over nodes that are identified as more trustworthy "entry guard" (is_guard) systems by directory authorities.... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3408
Unspecified vulnerability in the directory server (dirserver) in Tor before 0.1.1.20 allows remote attackers to cause an unspecified denial of service via unknown vectors.... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3414
Tor before 0.1.1.20 supports server descriptors that contain hostnames instead of IP addresses, which allows remote attackers to arbitrarily group users by providing preferential address resolution.... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3384
SQL injection vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) texte parameters.... Read more
Affected Products : news- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3386
index.php in Vincent Leclercq News 5.2 allows remote attackers to obtain sensitive information, such as the installation path, via a mail[] parameter with invalid values.... Read more
Affected Products : news- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025