Latest CVE Feed
-
4.3
MEDIUMCVE-2006-2639
Cross-site scripting (XSS) vulnerability in the input forms in prattmic and Master5006 PHPSimpleChoose 0.3 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element.... Read more
Affected Products : phpsimplechoose- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-2640
Cross-site scripting (XSS) vulnerability in OmegaMw7a.ASP in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allows remote attackers to inject arbitrary web script or HTML via the WCE parameter.... Read more
Affected Products : interneserviceslosungen- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2650
SQL injection vulnerability in cosmicshop/search.php in CosmicShoppingCart allows remote attackers to execute arbitrary SQL commands via the max parameter.... Read more
Affected Products : cosmicshoppingcart- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-2633
Absolute path traversal vulnerability in the copy action in index.php in Andrew Godwin ByteHoard 2.1 and earlier allows remote authenticated users to create or overwrite files in other users' directories by specifying the absolute path of the directory in... Read more
Affected Products : bytehoard- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-2641
** UNVERIFIABLE ** NOTE: this issue does not contain any verifiable or actionable details. Cross-site scripting (XSS) vulnerability in John Frank Asset Manager (AssetMan) 2.4a and earlier allows remote attackers to inject arbitrary web script or HTML vi... Read more
Affected Products : asset_manager- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2634
Cross-site scripting (XSS) vulnerability in Neocrome Land Down Under (LDU) in Neocrome Seditio 102 allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer field.... Read more
Affected Products : seditio- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-2652
Cross-site scripting (XSS) vulnerability in WikiNi 0.4.2 and earlier allows remote attackers to inject arbitrary HTML and web script by editing a Wiki page to contain the script.... Read more
Affected Products : wikini- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-2644
AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the L... Read more
- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-2563
The cURL library (libcurl) in PHP 4.4.2 and 5.1.4 allows attackers to bypass safe mode and read files via a file:// request containing null characters.... Read more
Affected Products : php- Published: May. 29, 2006
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2006-1174
useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly ... Read more
Affected Products : shadow- Published: May. 28, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2453
Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-2006-2480.... Read more
- Published: May. 28, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-2630
Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack vectors.... Read more
- Published: May. 27, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-2631
phpFoX allows remote authenticated users to modify arbitrary accounts via a modified NATIO cookie value, possibly the phpfox_user parameter.... Read more
Affected Products : phpfox- Published: May. 27, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-2629
Race condition in Linux kernel 2.6.15 to 2.6.17, when running on SMP platforms, allows local users to cause a denial of service (crash) by creating and exiting a large number of tasks, then accessing the /proc entry of a task that is exiting, which causes... Read more
Affected Products : linux_kernel- Published: May. 27, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-2608
artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the logfile parameter in a direct request to log.php, which causes the $logfile var... Read more
Affected Products : artmedic_newsletter- Published: May. 26, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-2614
Sun N1 System Manager 1.1 for Solaris 10 before patch 121161-01 records system passwords in the world-readable scripts (1) /cr/hd_jobs_db.sh, (2) /cr/hd_plan_checkin.sh, and (3) /cr/oracle_plan_checkin.sh, which allows local users to obtain System Manager... Read more
Affected Products : n1_system_manager- Published: May. 26, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2616
SQL injection vulnerability in the search script in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to execute arbitrary SQL commands via the uri parameter.... Read more
Affected Products : webhost_directory- Published: May. 26, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2618
Cross-site scripting (XSS) vulnerability in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, might allow remote attackers to inject arbitrary web script or HTML via the "write a review" box. NOTE: since user reviews do not ... Read more
Affected Products : webhost_directory- Published: May. 26, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-2612
Novell Client for Windows 4.8 and 4.9 does not restrict access to the clipboard contents while a machine is locked, which allows users with physical access to read the current clipboard contents by pasting them into the "User Name" field on the login prom... Read more
Affected Products : client- Published: May. 26, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2613
Mozilla Suite 1.7.13, Mozilla Firefox 1.5.0.3 and possibly other versions before before 1.8.0, and Netscape 7.2 and 8.1, and possibly other versions and products, allows remote user-assisted attackers to obtain information such as the installation path by... Read more
- Published: May. 26, 2006
- Modified: Apr. 03, 2025