Latest CVE Feed
-
5.0
MEDIUMCVE-2006-2710
Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 uses the same invariant RSA key for all installations, which allows remote attackers with the key to decrypt communications.... Read more
Affected Products : class_5_enterprise_vulnerability_management- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2707
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could allow remote attackers to distribute malicious updates to clients.... Read more
Affected Products : class_5_enterprise_vulnerability_management- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2706
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause a denial of service via forged "session start" messages that cause AVR to connect to arbitrary hosts.... Read more
Affected Products : class_5_enterprise_vulnerability_management- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2708
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 allows remote attackers to read portions of process memory via a modified size for (1) EM_GET_CE_PARAMETER and (2) EM_SET_CE_PARAMETER messages, which leads to a buffer overflow (probably an ove... Read more
Affected Products : class_5_enterprise_vulnerability_management- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1515
Buffer overflow in the addnewword function in typespeed 0.4.4 and earlier might allow remote attackers to execute arbitrary code via unknown vectors.... Read more
Affected Products : typespeed- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-2697
Multiple SQL injection vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) startletter parameter in userview.asp and the (2) forumname parameter in topics.asp.... Read more
Affected Products : easy-content_forums- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-2699
Cross-site scripting (XSS) vulnerability in getimage.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to inject arbitrary HTML or web script via the image argument in a show action.... Read more
Affected Products : geeklog- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-2685
PHP remote file inclusion vulnerability in Basic Analysis and Security Engine (BASE) 1.2.4 and earlier, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via a URL in the BASE_path parameter to (1) base_qry_common.php, (... Read more
Affected Products : basic_analysis_and_security_engine- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2692
Multiple unspecified vulnerabilities in aMuleWeb for AMule before 2.1.2 allow remote attackers to read arbitrary image, HTML, or PHP files via unknown vectors, probably related to directory traversal.... Read more
Affected Products : amule- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2694
Multiple PHP remote file inclusion vulnerabilities in EzUpload Pro 2.10 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) form.php, (2) customize.php, and (3) initialize.php.... Read more
Affected Products : ezupload_pro- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-1175
The WeOnlyDo! SFTP (wodSFTP) ActiveX control is marked as safe for scripting, which allows remote attackers to read and write files in arbitrary locations by accessing the control from a web page.... Read more
Affected Products : weonlydo_sftp- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-2700
SQL injection vulnerability in admin/auth.inc.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via the loginname parameter.... Read more
Affected Products : geeklog- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-2680
Cross-site scripting (XSS) vulnerability in index.php in AZ Photo Album Script Pro allows remote attackers to inject arbitrary web script or HTML via the gazpart parameter.... Read more
Affected Products : az_photo_album_script_pro- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2677
SiteScape Forum 7.2 and possibly earlier stores the avf.rc configuraiton file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive path information.... Read more
Affected Products : sitescape_forum- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-2686
PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[AA_INC_PATH] parameter in (1) cached.php3, (2) cron.php3, (3) discussion.php3, (4) filldisc.php3, (5) filler.php3, ... Read more
Affected Products : actionapps- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2676
Dispatch.cgi/_user/uservCard/ in SiteScape Forum 7.2 and possibly earlier generates different responses in a way that allows remote attackers to enumerate valid usernames.... Read more
Affected Products : sitescape_forum- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2701
SQL injection vulnerability in Geeklog 1.4.0sr2 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to story submission.... Read more
Affected Products : geeklog- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-2689
Multiple cross-site scripting (XSS) vulnerabilities in EVA-Web 2.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) debut_image parameter in (a) article-album.php3, (2) date parameter in (b) rubrique.php3, and the (3... Read more
Affected Products : eva-web- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-2687
Cross-site scripting (XSS) vulnerability in adduser.php in PHP-AGTC Membership System 1.1a and earlier allows remote attackers to inject arbitrary web script or HTML via the email address (useremail parameter).... Read more
Affected Products : php-agtc_membership_system- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-2695
admin/upprocess.php in DGNews 1.5 and earlier allows remote attackers to execute arbitrary code by uploading scripts with arbitrary extensions to the img directory.... Read more
Affected Products : dgnews- Published: May. 31, 2006
- Modified: Apr. 03, 2025