Latest CVE Feed
-
7.5
HIGHCVE-2006-2887
Multiple SQL injection vulnerabilities in myNewsletter 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the UserName parameter in (1) validatelogin.asp or (2) adminlogin.asp.... Read more
Affected Products : mynewsletter- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2897
Cross-site scripting (XSS) vulnerability in FunkBoard 0.71 allows remote attackers to inject arbitrary HTML or web script via unspecified vectors.... Read more
Affected Products : funkboard- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-2881
Multiple PHP remote file inclusion vulnerabilities in DreamAccount 3.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the da_path parameter in the (1) auth.cookie.inc.php, (2) auth.header.i... Read more
Affected Products : dreamaccount- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2886
view.php in KnowledgeTree Open Source 3.0.3 and earlier allows remote attackers to obtain the full installation path via a crafted fDocumentId parameter, which displays the path in the resulting error message. NOTE: this might be resultant from another v... Read more
Affected Products : knowledgetree_open_source- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-2894
Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by tricking a user into typing the char... Read more
- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2879
SQL injection vulnerability in newscomments.php in Alex News-Engine 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the newsid parameter.... Read more
Affected Products : news-engine- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2883
Cross-site scripting (XSS) vulnerability in search.php in Kmita FAQ 1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.... Read more
Affected Products : kmita_faq- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-2889
Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL commands, and leverage them to gain administrator privileges, via the (1) category or (2) archivedate parameter.... Read more
Affected Products : pixelpost- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2896
profile.php in FunkBoard CF0.71 allows remote attackers to change arbitrary passwords via a modified uid hidden form field in an Edit Profile action.... Read more
Affected Products : funkboard- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-2880
Cross-site scripting (XSS) vulnerability in the Contributed Packages for PyBlosxom 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the Comments plugin in the (1) url and (2) author fields.... Read more
Affected Products : pyblosxom- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2888
PHP remote file inclusion vulnerability in _wk/wk_lang.php in Wikiwig 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the WK[wkPath] parameter.... Read more
Affected Products : wikiwig- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2892
Cross-site scripting (XSS) vulnerability in index.php in GANTTy 1.0.3 allows remote attackers to inject arbitrary HTML and web script via the message parameter in a login action.... Read more
Affected Products : gantty- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2882
Multiple cross-site scripting (XSS) vulnerabilities submit.asp in ASPScriptz Guest Book 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) GBOOK_UNAME, (2) GBOOK_EMAIL, (3) GBOOK_CITY, (4) GBOOK_COU, (5) GBOOK_WWW, a... Read more
Affected Products : aspscriptz_guest_book- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2891
Cross-site scripting (XSS) vulnerability in admin/index.php for Pixelpost 1-5rc1-2 and earlier allows remote attackers to inject arbitrary HTML or web script via the loginmessage parameter.... Read more
Affected Products : pixelpost- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2885
Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree Open Source 3.0.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) fDocumentId parameter in view.php and the (2) fSearchableText parameter in /search... Read more
Affected Products : knowledgetree- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2884
SQL injection vulnerability in index.php in Kmita FAQ 1.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter.... Read more
Affected Products : kmita_faq- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2895
Cross-site scripting (XSS) vulnerability in MediaWiki 1.6.0 up to versions before 1.6.7 allows remote attackers to inject arbitrary HTML and web script via the edit form.... Read more
Affected Products : mediawiki- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2893
index.php in GANTTy 1.0.3 allows remote attackers to obtain the full path of the web server via an invalid lang parameter in an authenticate action.... Read more
Affected Products : gantty- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-2899
Unspecified vulnerability in ESTsoft InternetDISK versions before 2006/04/20 allows remote authenticated users to execute arbitrary code, possibly by uploading a file with multiple extensions into the WebLink directory.... Read more
Affected Products : internetdisk- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2898
The IAX2 channel driver (chan_iax2) for Asterisk 1.2.x before 1.2.9 and 1.0.x before 1.0.11 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via truncated IAX 2 (IAX2) video frames, which bypasses a length check and ... Read more
Affected Products : asterisk- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025