Latest CVE Feed
-
5.0
MEDIUMCVE-2006-2676
Dispatch.cgi/_user/uservCard/ in SiteScape Forum 7.2 and possibly earlier generates different responses in a way that allows remote attackers to enumerate valid usernames.... Read more
Affected Products : sitescape_forum- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2701
SQL injection vulnerability in Geeklog 1.4.0sr2 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to story submission.... Read more
Affected Products : geeklog- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-2689
Multiple cross-site scripting (XSS) vulnerabilities in EVA-Web 2.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) debut_image parameter in (a) article-album.php3, (2) date parameter in (b) rubrique.php3, and the (3... Read more
Affected Products : eva-web- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-2687
Cross-site scripting (XSS) vulnerability in adduser.php in PHP-AGTC Membership System 1.1a and earlier allows remote attackers to inject arbitrary web script or HTML via the email address (useremail parameter).... Read more
Affected Products : php-agtc_membership_system- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-2695
admin/upprocess.php in DGNews 1.5 and earlier allows remote attackers to execute arbitrary code by uploading scripts with arbitrary extensions to the img directory.... Read more
Affected Products : dgnews- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2691
Unspecified "information leakage" vulnerabilities in aMuleWeb for AMule before 2.1.2 allow remote attackers to access arbitrary images, including dynamically generated images, via unknown vectors.... Read more
Affected Products : amule- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-2678
Multiple cross-site scripting (XSS) vulnerabilities in Pre News Manager 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) index.php, and the (2) nid parameter to (b) news_detail.php, (c) email_story.php, (d)... Read more
Affected Products : pre_news_manager- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-2682
PHP remote file inclusion vulnerability in BE_config.php in Back-End CMS 0.7.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _PSL[classdir] parameter.... Read more
Affected Products : back-end_cms- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-2684
Cross-site scripting (XSS) vulnerability in the search module in CMS Mundo 1.0 allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter.... Read more
Affected Products : cms_mundo- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-2698
Geeklog 1.4.0sr2 and earlier allows remote attackers to obtain the full installation path via a direct request and possibly invalid arguments to (1) layout/professional/functions.php or (2) getimage.php.... Read more
Affected Products : geeklog- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2702
vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which vars.php uses to redefine $_SERVER['REMOTE_ADDR'].... Read more
Affected Products : wordpress- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-2681
PHP remote file inclusion vulnerability in SocketMail Lite and Pro 2.2.6 and earlier, when register_globals and magic_quotes are enabled, allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter to (1) index.php and (2) i... Read more
Affected Products : socketmail- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-2679
Unspecified vulnerability in the VPN Client for Windows Graphical User Interface (GUI) (aka the VPN client dialer) in Cisco VPN Client for Windows 4.8.00.* and earlier, except for 4.7.00.0533, allows local authenticated, interactive users to gain privileg... Read more
Affected Products : vpn_client- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2006-2693
Directory traversal vulnerability in admin/admin_hacks_list.php in Nivisec Hacks List 1.20 and earlier for phpBB, when register_globals is enabled, allows remote attackers to read arbitrary files via a ".." in the phpEx parameter.... Read more
Affected Products : hacks_list- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-2683
PHP remote file inclusion vulnerability in 404.php in open-medium.CMS 0.25 allows remote attackers to execute arbitrary PHP code via a URL in the REDSYS[MYPATH][TEMPLATES] parameter.... Read more
Affected Products : open-medium_cms- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-2690
An unspecified script in EVA-Web 2.1.2 and earlier, probably index.php, allows remote attackers to obtain the full path of the web server via invalid (1) perso or (2) aide parameters.... Read more
Affected Products : eva-web- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-2688
SQL injection vulnerability in the employees node (class.employee.inc) in Achievo 1.1.0 and earlier and 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the atkselector parameter.... Read more
Affected Products : achievo- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-2696
Cross-site scripting (XSS) vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) startletter parameter in userview.asp and the (2) catid parameter in topics.asp.... Read more
Affected Products : easy-content_forums- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-2672
Multiple cross-site scripting (XSS) vulnerabilities in Realty Pro One allow remote attackers to inject arbitrary web script or HTML via the (1) listingid parameter to (a) images.php, (b) index_other.php, or (c) request_info.php; (2) propertyid parameter t... Read more
Affected Products : realty_pro_one- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2668
Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 2.05 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) modules/credits/business.php, (2) modules/credits/credits.php, or (3) modules/credits/help.ph... Read more
Affected Products : docebolms- Published: May. 30, 2006
- Modified: Apr. 03, 2025