Latest CVE Feed
-
7.5
HIGHCVE-2006-3162
PHP remote file inclusion vulnerability in include/inc_foot.php in SmartSiteCMS 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.... Read more
Affected Products : smartsitecms- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3151
Cross-site scripting (XSS) vulnerability in index.php in AssoCIateD (aka ACID) 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the menu parameter.... Read more
Affected Products : associated_cms- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-3143
Cross-site scripting (XSS) vulnerability in icue_login.asp in Maximus SchoolMAX 4.0.1 and earlier iCue and iParent applications allows remote attackers to inject arbitrary web script or HTML via the error_msg parameter.... Read more
Affected Products : schoolmax- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3144
PHP remote file inclusion vulnerability in micro_cms_files/microcms-include.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) and earlier allows remote attackers to execute arbitrary PHP code via a URL in the microcms_path parameter. NOTE: it was ... Read more
Affected Products : micro_cms- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3138
Multiple cross-site scripting (XSS) vulnerabilities in phpMyDirectory 10.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PIC parameter in offers-pix.php, (2) from parameter in cp/index.php, and (3) action paramete... Read more
Affected Products : phpmydirectory- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3137
Cross-site scripting (XSS) vulnerability in productDetail.asp in Edge eCommerce Shop allows remote attackers to inject arbitrary web script or HTML via the cart_id parameter.... Read more
Affected Products : edge_ecommerce_shop- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3148
SQL injection vulnerability, possibly in search.inc.php, in Open-Realty 2.3.1 allows remote attackers to execute arbitrary SQL commands via the sorttype parameter to index.php.... Read more
Affected Products : open-realty- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3149
Cross-site scripting (XSS) vulnerability in topic.php in phpMyForum 4.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlight parameter.... Read more
Affected Products : phpmyforum- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-3157
Cross-site scripting (XSS) vulnerability in index.php in Thinkfactory UltimateGoogle 1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the REQ parameter.... Read more
Affected Products : ultimategoogle- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3160
Cross-site scripting (XSS) vulnerability in fm.php in ONEdotOH Simple File Manager (SFM) 0.24a and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.... Read more
Affected Products : simple_file_manager- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3156
Cross-site scripting (XSS) vulnerability in index.cgi in Ultimate eShop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the subid parameter.... Read more
Affected Products : ultimate_eshop- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3150
SQL injection vulnerability in index.php in CavoxCms 1.0.16 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.... Read more
Affected Products : cavoxcms- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3164
SQL injection vulnerability in category.php in TPL Design tplShop 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the first_row parameter.... Read more
Affected Products : tplshop- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3154
SQL injection vulnerability in index.pl in Ultimate Estate 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : ultimate_estate- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3142
SQL injection vulnerability in forum.php in VBZooM 1.11 allows remote attackers to execute arbitrary SQL commands via the MainID parameter.... Read more
Affected Products : vbzoom- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3152
Multiple SQL injection vulnerabilities in phpTRADER 4.9 SP5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sectio parameter in (a) login.php, (b) write_newad.php, (c) newad.php, (d) printad.php, (e) askseller.php, (f) bro... Read more
Affected Products : phptrader- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3166
Cross-site scripting (XSS) vulnerability in propview.php in Free Realty 2.9-0.6 and earlier allows remote attackers to execute arbitrary web script or HTML via the sort parameter.... Read more
Affected Products : free_realty- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2006-3136
Multiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LIBS parameter in (1) path/action.php, and to files in path/nucleus including (2) media.php, (3) /xmlrpc/server.php, ... Read more
Affected Products : nucleus_cms- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-3147
Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gain host admin privileges, list all resellers, or change resellers' passwords via unspecified vectors. NOTE: due to the lack of precise ... Read more
Affected Products : hosting_controller- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3139
Multiple SQL injection vulnerabilities in war.php in Virtual War (VWar) 1.5.0 R14 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) showgame, (3) sortorder, and (4) sortby parameters.... Read more
Affected Products : virtual_war- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025