Latest CVE Feed
-
7.5
HIGHCVE-2006-2579
Unspecified vulnerability in HP OpenView Storage Data Protector 5.1 and 5.5 allows remote attackers to execute arbitrary code via unknown vectors.... Read more
Affected Products : openview_storage_data_protector- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-2578
admin/cron.php in eSyndicat Directory 1.2, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files and possibly execute arbitrary PHP code via a null-terminated value in the path_to_config para... Read more
Affected Products : esyndicat_directory- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-2573
SQL injection vulnerability in index.php in DGBook 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) homepage, (4) address, (5) comment, and (6) ip parameters. NOTE: the proven... Read more
Affected Products : dgbook- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2572
Cross-site scripting (XSS) vulnerability in index.php in DGBook 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) homepage, (3) email, and (4) address parameters.... Read more
Affected Products : dgbook- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2580
Multiple unspecified vulnerabilities in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allow remote attackers to gain privileged access, execute arbitrary commands, or create arbitrary files via unknown vectors.... Read more
Affected Products : openview_network_node_manager- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2564
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AlstraSoft E-Friends allow remote attackers to inject arbitrary web script or HTML by (1) posting a blog, (2) posting a listing, (3) posting an event, (4) adding comments, or (5) sending ... Read more
Affected Products : e-friends- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2566
Alstrasoft Article Manager Pro 1.6 allows remote attackers to obtain sensitive information via (1) a quote character or possibly an invalid value in the action parameter in a request to mrarticles.php or (2) a login QUERY_STRING to admin.php without any a... Read more
Affected Products : article_manager_pro- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2565
SQL injection vulnerability in Alstrasoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via (1) the author_id parameter in profile.php and (2) the aut_id parameter in userarticles.php. NOTE: the aut_id vector can produ... Read more
Affected Products : article_manager_pro- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2567
Cross-site scripting (XSS) vulnerability in submit_article.php in Alstrasoft Article Manager Pro 1.6 allows remote attackers to inject arbitrary web script or HTML when submitting an article, as demonstrated using a javascript URI in a Cascading Style She... Read more
Affected Products : article_manager_pro- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-1862
The virtual memory implementation in Linux kernel 2.6.x allows local users to cause a denial of service (panic) by running lsof a large number of times in a way that produces a heavy system load.... Read more
- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2313
PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications via invalid encodings of multibyte characters, ... Read more
Affected Products : postgresql- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2314
PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "\"... Read more
Affected Products : postgresql- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-1466
Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service.... Read more
- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-2557
PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newsportal (TRanx rebuilded), allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter.... Read more
Affected Products : newsportal- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2553
Cross-site scripting (XSS) vulnerability in Jemscripts DownloadControl 1.0 allows remote attackers to inject arbitrary HTML or web script via the dcid parameter to dc.php. NOTE: the provenance of this information is unknown; the details are obtained sole... Read more
Affected Products : downloadcontrol- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-2558
Cross-site scripting (XSS) vulnerability in IpLogger 1.7 and earlier allows remote attackers to inject arbitrary HTML or web script via the User-Agent (useragent) header in an HTTP request, which is not filtered when the log files are viewed.... Read more
Affected Products : iplogger- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-2556
Cross-site scripting (XSS) vulnerability in Florian Amrhein NewsPortal before 0.37, and possibly TR Newsportal (TRanx rebuilded), allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : newsportal- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2552
Jemscripts DownloadControl 1.0 allows remote attackers to obtain sensitive information via an invalid dcid parameter to dc.php, which leaks the pathname in an error message. NOTE: this was originally claimed to be SQL injection, but it is probably result... Read more
Affected Products : downloadcontrol- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2559
Linksys WRT54G Wireless-G Broadband Router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMappi... Read more
- Published: May. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2555
The parse_command function in Genecys 0.2 and earlier allows remote attackers to cause a denial of service (crash) via a command with a missing ":" (colon) separator, which triggers a null dereference.... Read more
Affected Products : genecys- Published: May. 24, 2006
- Modified: Apr. 03, 2025