Latest CVE Feed
-
5.0
MEDIUMCVE-2006-3146
The TOSRFBD.SYS driver for Toshiba Bluetooth Stack 4.00.29 and earlier on Windows allows remote attackers to cause a denial of service (reboot) via a L2CAP echo request that triggers an out-of-bounds memory access, similar to "Ping o' Death" and as demons... Read more
- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3140
SQL injection vulnerability in index.php in openCI 1.0 BETA 0.20.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : openci- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3159
pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built May 14 2003) allows local users to read portions of restricted files via a symlink attack on msg.conf in a directory identified by the CONFIGROOT environment variable, which returns th... Read more
- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-3132
Cross-site scripting (XSS) vulnerability in qtofm.php4 in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter, as originally reported for index.php.... Read more
Affected Products : qtofilemanager- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3129
Multiple cross-site scripting (XSS) vulnerabilities in index.php in NC LinkList 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) view parameters.... Read more
Affected Products : nc_linklist- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3130
SQL injection vulnerability in index.php in Clubpage allows remote attackers to execute arbitrary SQL commands via the category parameter.... Read more
Affected Products : clubpage- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3131
Multiple cross-site scripting (XSS) vulnerabilities in Clubpage allow remote attackers to inject arbitrary web script or HTML via the (1) news_archive, (2) language, and (3) intranetLogin parameters in (a) index.php; the (4) sites_id parameter in (b) site... Read more
Affected Products : clubpage- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3014
Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the s... Read more
Affected Products : excel- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-3128
choose_file.php in easy-CMS 0.1.2, when mod_mime is installed, does not restrict uploads of filenames with multiple extensions, which allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a GIF file extension, then directly ac... Read more
Affected Products : easy-cms- Published: Jun. 21, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-3127
Memory leak in Network Security Services (NSS) 3.11, as used in Sun Java Enterprise System 2003Q4 through 2005Q1 and Java System Directory Server 5.2, allows remote attackers to cause a denial of service (memory consumption) by performing a large number o... Read more
- Published: Jun. 21, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-2931
CMS Mundo before 1.0 build 008 does not properly verify uploaded image files, which allows remote attackers to execute arbitrary PHP code by uploading and later directly accessing certain files.... Read more
Affected Products : cms_mundo- Published: Jun. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2911
SQL injection vulnerability in controlpanel/index.php in CMS Mundo before 1.0 build 008 allows remote attackers to execute arbitrary SQL commands via the username parameter.... Read more
Affected Products : cms_mundo- Published: Jun. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3112
Chipmailer 1.09 allows remote attackers to obtain sensitive information via a direct request to php.php, which displays the output of the phpinfo function.... Read more
Affected Products : chipmailer- Published: Jun. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3110
Cross-site scripting (XSS) vulnerability in main.php in Chipmailer 1.09 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) betreff, (3) mail, and (4) text parameters.... Read more
Affected Products : chipmailer- Published: Jun. 21, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3102
Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execute arbitrary PHP code by uploading arbitrary files with double extensions, which are stored for a small period of t... Read more
Affected Products : bitweaver- Published: Jun. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3106
Cross-site scripting (XSS) vulnerability in index.php in phpMyDesktop|Arcade 1.0 allows remote attackers to inject arbitrary web script or HTML via the subsite parameter in the subsite todo.... Read more
Affected Products : phpmydesktop_arcade- Published: Jun. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3109
Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), allows remote attackers to inject arbitrary web script or HTML via the (1) pattern parameter in ccmadmin/ph... Read more
Affected Products : call_manager- Published: Jun. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3103
Cross-site scripting (XSS) vulnerability in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error parameter in users/login.php and the (2) feedback parameter in articles/index.php.... Read more
Affected Products : bitweaver- Published: Jun. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3104
users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals the installation path and database information in the resultant error message.... Read more
Affected Products : bitweaver- Published: Jun. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3101
Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error, (2) SSL, and (3) Ok parameters.... Read more
Affected Products : secure_access_control_server- Published: Jun. 21, 2006
- Modified: Apr. 03, 2025