Latest CVE Feed
-
5.0
MEDIUMCVE-2006-2591
Unspecified vulnerability in e107 before 0.7.5 has unknown impact and remote attack vectors related to an "emailing exploit".... Read more
Affected Products : e107- Published: May. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2605
Cross-site scripting (XSS) vulnerability in DSChat 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the chatbox, probably involving the ctext parameter to send.php.... Read more
Affected Products : dschat- Published: May. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2592
Unspecified vulnerability in DSChat 1.0 allows remote attackers to execute arbitrary PHP code via the Nickname field, which is not sanitized before creating a file in a user directory. NOTE: the provenance of this information is unknown; the details are ... Read more
Affected Products : dschat- Published: May. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2581
Cross-site scripting (XSS) vulnerability in Wiki content in RWiki 2.1.0pre1 through 2.1.0 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more
Affected Products : rwiki- Published: May. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2582
The editing form in RWiki 2.1.0pre1 through 2.1.0 allows remote attackers to execute arbitrary Ruby code via unknown attack vectors.... Read more
Affected Products : rwiki- Published: May. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2587
Buffer overflow in the WebTool HTTP server component in (1) PunkBuster before 1.229, as used by multiple products including (2) America's Army 1.228 and earlier, (3) Battlefield 1942 1.158 and earlier, (4) Battlefield 2 1.184 and earlier, (5) Battlefield ... Read more
Affected Products : punkbuster- Published: May. 25, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-2586
Cross-site scripting (XSS) vulnerability in IpLogger 1.7 and earlier allows remote attackers to inject arbitrary HTML or web script via the HTTP_REFERER header in an HTTP request.... Read more
Affected Products : iplogger- Published: May. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2584
Multiple cross-site scripting (XSS) vulnerabilities in post.php in SkyeBox 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) message parameters. NOTE: the provenance of this information is unknown; the details ar... Read more
Affected Products : skyebox- Published: May. 25, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-2590
SQL injection vulnerability in e107 before 0.7.5 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.... Read more
Affected Products : e107- Published: May. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2606
Cross-site scripting (XSS) vulnerability in Chatty, possibly 1.0.2 and other versions, allows remote attackers to inject arbitrary web script or HTML via the username.... Read more
Affected Products : chatty- Published: May. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2549
Stack-based buffer overflow in PDF Form Filling and Flattening Tool before 3.1.0.12 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long field names.... Read more
Affected Products : pdf_form_filling_and_flattening_tool- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-2574
Multiple unspecified vulnerabilities in Software Distributor in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allow local users to gain privileges via unspecified attack vectors.... Read more
Affected Products : hp-ux- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-2577
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in (1) where_cms, (2) where_lms, (3) where_upgrade, (4) BBC_LIB_PATH, and (5) ... Read more
Affected Products : docebo- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2575
The setFrame function in Lib/2D/Surface.hpp for NetPanzer 0.8 and earlier allows remote attackers to cause a denial of service (crash) via a client flag (frameNum) that is greater than 41, which triggers an assert error.... Read more
Affected Products : netpanzer- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-2576
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in (1) GLOBALS[where_framework] to (a) lib.simplesel.php, (b) lib.filelist.php... Read more
Affected Products : docebo- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2571
Cross-site scripting (XSS) vulnerability in search.html in Alkacon OpenCms 6.0.0, 6.0.2, and 6.0.3 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search action.... Read more
Affected Products : opencms- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2569
SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows remote attackers to execute arbitrary SQL commands via the cat parameter.... Read more
- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2570
PHP remote file inclusion vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS["CLPath"] parameter to (1) reconfig.php and (2) srxclr.php. NOTE: this might be due to a globals overwrite is... Read more
Affected Products : calogic_calendars- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-2568
PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute arbitrary PHP code via a URL in the thispath parameter.... Read more
Affected Products : ubb.threads- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2579
Unspecified vulnerability in HP OpenView Storage Data Protector 5.1 and 5.5 allows remote attackers to execute arbitrary code via unknown vectors.... Read more
Affected Products : openview_storage_data_protector- Published: May. 24, 2006
- Modified: Apr. 03, 2025