Latest CVE Feed
-
5.0
MEDIUMCVE-2006-3837
delcookie.php in Professional Home Page Tools Guestbook changes the expiration date of a cookie instead of deleting the cookie's value, which makes it easier for attackers to steal the cookie and obtain the administrator's password hash after logout.... Read more
Affected Products : professional_home_page_tools_guestbook- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3815
heartbeat.c in heartbeat before 2.0.6 sets insecure permissions in a shmget call for shared memory, which allows local users to cause an unspecified denial of service via unknown vectors, possibly during a short time window on startup.... Read more
Affected Products : heartbeat- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3823
SQL injection vulnerability in index.php in GeodesicSolutions (1) GeoAuctions Premier 2.0.3 and (2) GeoClassifieds Basic 2.0.3 allows remote attackers to execute arbitrary SQL commands via the b parameter.... Read more
- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-3828
Incomplete blacklist vulnerability in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to bypass SQL injection protection mechanisms by using commas, quote characters, pound sign (#) characters, "UNI... Read more
Affected Products : boastmachine- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3825
The IPv4 implementation in Sun Solaris 10 before 20060721 allows local users to select routes that differ from the routing table, possibly facilitating firewall bypass or unauthorized network communication.... Read more
Affected Products : solaris- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3816
Krusader 1.50-beta1 up to 1.70.0 stores passwords for remote connections in cleartext in the bookmark file (krbookmarks.xml), which allows attackers to steal passwords by obtaining the file.... Read more
Affected Products : krusader- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3780
Keyifweb Keyif Portal 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) ANKET/anket.mdb, (2) HABER/keyifweb.mdb, (3) ASP/download.mdb, or... Read more
Affected Products : keyif_portal- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3676
admin/gallery_admin.php in planetGallery before 14.07.2006 allows remote attackers to execute arbitrary PHP code by uploading files with a double extension and directly accessing the file in the images directory, which bypasses a regular expression check ... Read more
Affected Products : planetgallery- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3800
Cross-site scripting (XSS) vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the "new review" text box.... Read more
Affected Products : afcommerce_shopping_cart- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3790
The decode_stringmap function in server_transport.cpp for UFO2000 svn 1057 allows remote attackers to cause a denial of service (daemon termination) via a keysize or valsize that is inconsistent with the packet size, which leads to a buffer over-read.... Read more
Affected Products : ufo2000- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3785
Symantec pcAnywhere 12.5 obfuscates the passwords in a GUI textbox with asterisks but does not encrypt them in the associated .cif (aka caller or CallerID) file, which allows local users to obtain the passwords from the window using tools such as Nirsoft ... Read more
Affected Products : pcanywhere- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-3779
Citrix MetaFrame up to XP 1.0 Feature 1, except when running on Windows Server 2003, installs a registry key with an insecure ACL, which allows remote authenticated users to gain privileges.... Read more
- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2006-3786
Symantec pcAnywhere 12.5 uses weak integrity protection for .cif (aka caller or CallerID) files, which allows local users to generate a custom .cif file and modify the superuser flag.... Read more
Affected Products : pcanywhere- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3788
Multiple buffer overflows in multiplay.cpp in UFO2000 svn 1057 allow remote attackers to execute arbitrary code via (1) a long unit name in Net::recv_add_unit,; (2) large values to Net::recv_rules, Net::recv_select_unit, Net::recv_options, and Net::recv_u... Read more
Affected Products : ufo2000- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3775
SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote attackers to execute arbitrary SQL commands via the CLIENT-IP HTTP header ($_SERVER['HTTP_CLIENT_IP'] variable), as utilized by index.p... Read more
Affected Products : mybulletinboard- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-3781
Unspecified vulnerability in Sun Solaris 10 allows context-dependent attackers to cause a denial of service (panic) via unspecified vectors involving the event port API.... Read more
Affected Products : solaris- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3771
Multiple PHP remote file inclusion vulnerabilities in component.php in iManage CMS 4.0.12 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) articles.php, (2) contact.php, (3) displaypage.php, ... Read more
Affected Products : imanage_cms- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3791
The decode_stringmap function in server_transport.cpp for UFO2000 svn 1057 allows remote attackers to cause a denial of service (daemon termination) via a large keysize or valsize, which causes a crash when the resize function cannot allocate sufficient m... Read more
Affected Products : ufo2000- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3798
DeluxeBB 1.07 and earlier allows remote attackers to overwrite the (1) _GET, (2) _POST, (3) _ENV, and (4) _SERVER variables via the _COOKIE (aka COOKIE) variable, which can overwrite the other variables during an extract function call, probably leading to... Read more
Affected Products : deluxebb- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-3782
Unspecified vulnerability in the kernel debugger (kmdb) in Sun Solaris 10, when running on x86, allows local users to cause a denial of service (system hang) via unspecified vectors.... Read more
Affected Products : solaris- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025