Latest CVE Feed
-
5.8
MEDIUMCVE-2006-3189
Cross-site scripting (XSS) vulnerability in administration/tblcontent/login1.php in HotPlug CMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.... Read more
Affected Products : hotplug_cms- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3171
CRLF injection vulnerability in CS-Forum before 0.82 allows remote attackers to inject arbitrary email headers via a newline character in the email parameter to ajouter.php.... Read more
Affected Products : cs-forum- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3197
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a POST that contains hexadecimal-encoded HTML.... Read more
Affected Products : invision_power_board- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3168
SQL injection vulnerability in CS-Forum before 0.82 allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) debut parameters in (a) read.php, and the (3) search and (4) debut parameters in (b) index.php.... Read more
Affected Products : cs-forum- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3141
Cross-site scripting (XSS) vulnerability in details.cfm in Tradingeye Shop R4 and earlier allows remote attackers to inject arbitrary web script or HTML via the image parameter.... Read more
Affected Products : tradingeye_shop- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3163
Multiple SQL injection vulnerabilities in galeria.php in IMGallery 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start or (2) sort parameters.... Read more
Affected Products : imgallery- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3158
index.php in Eduha Meeting does not properly restrict file extensions before permitting a file upload, which allows remote attackers to bypass security checks and upload or execute arbitrary php code via the add action.... Read more
Affected Products : eduha_meeting- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3165
SQL injection vulnerability in propview.php in Free Realty 2.9-0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the sort parameter.... Read more
Affected Products : free_realty- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3153
Cross-site scripting (XSS) vulnerability in index.pl in Ultimate Estate 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.... Read more
Affected Products : ultimate_estate- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3162
PHP remote file inclusion vulnerability in include/inc_foot.php in SmartSiteCMS 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.... Read more
Affected Products : smartsitecms- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3151
Cross-site scripting (XSS) vulnerability in index.php in AssoCIateD (aka ACID) 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the menu parameter.... Read more
Affected Products : associated_cms- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-3143
Cross-site scripting (XSS) vulnerability in icue_login.asp in Maximus SchoolMAX 4.0.1 and earlier iCue and iParent applications allows remote attackers to inject arbitrary web script or HTML via the error_msg parameter.... Read more
Affected Products : schoolmax- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3144
PHP remote file inclusion vulnerability in micro_cms_files/microcms-include.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) and earlier allows remote attackers to execute arbitrary PHP code via a URL in the microcms_path parameter. NOTE: it was ... Read more
Affected Products : micro_cms- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3138
Multiple cross-site scripting (XSS) vulnerabilities in phpMyDirectory 10.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PIC parameter in offers-pix.php, (2) from parameter in cp/index.php, and (3) action paramete... Read more
Affected Products : phpmydirectory- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3137
Cross-site scripting (XSS) vulnerability in productDetail.asp in Edge eCommerce Shop allows remote attackers to inject arbitrary web script or HTML via the cart_id parameter.... Read more
Affected Products : edge_ecommerce_shop- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3148
SQL injection vulnerability, possibly in search.inc.php, in Open-Realty 2.3.1 allows remote attackers to execute arbitrary SQL commands via the sorttype parameter to index.php.... Read more
Affected Products : open-realty- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3149
Cross-site scripting (XSS) vulnerability in topic.php in phpMyForum 4.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlight parameter.... Read more
Affected Products : phpmyforum- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-3157
Cross-site scripting (XSS) vulnerability in index.php in Thinkfactory UltimateGoogle 1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the REQ parameter.... Read more
Affected Products : ultimategoogle- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3160
Cross-site scripting (XSS) vulnerability in fm.php in ONEdotOH Simple File Manager (SFM) 0.24a and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.... Read more
Affected Products : simple_file_manager- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3156
Cross-site scripting (XSS) vulnerability in index.cgi in Ultimate eShop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the subid parameter.... Read more
Affected Products : ultimate_eshop- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025