Latest CVE Feed
-
7.5
HIGHCVE-2006-3758
inc/init.php in Archive Mode (Light) in MyBB (aka MyBulletinBoard) 1.1.4 calls the extract function with EXTR_OVERWRITE on HTTP POST and GET variables, which allows remote attackers to overwrite arbitrary variables, as demonstrated via an SQL injection us... Read more
Affected Products : mybulletinboard- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3696
filtnt.sys in Outpost Firewall Pro before 3.51.759.6511 (462) allows local users to cause a denial of service (crash) via long arguments to mshta.exe.... Read more
Affected Products : outpost_firewall- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3631
Unspecified vulnerability in the SSH dissector in Wireshark (aka Ethereal) 0.9.10 to 0.99.0 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.... Read more
- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3754
PHP remote file inclusion vulnerability in Include/editor/rich_files/class.rich.php in FlushCMS 1.0.0-pre2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the class_path parameter.... Read more
Affected Products : flushcms- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3765
Multiple cross-site scripting (XSS) vulnerabilities in Huttenlocher Webdesign hwdeGUEST 2.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, as demonstrated by the "name input" field in new_entry.php.... Read more
Affected Products : hwdeguest- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3767
Cross-site scripting (XSS) vulnerability in showprofile.php in Darren's $5 Script Archive osDate 1.1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the onerror attribute in an HTML IMG tag with a non-existent source file ... Read more
Affected Products : osdate- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3762
The Touch Control ActiveX control 2.0.0.55 allows remote attackers to read and possibly execute arbitrary files via a "file///" URI in the sPath parameter to the Execute function.... Read more
Affected Products : activex_control- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3724
Unspecified vulnerability in JD Edwards HTML Server for Oracle OneWorld Tools EnterpriseOne Tools 8.95 and 8.96 has unknown impact and attack vectors, aka Oracle Vuln# JDE01.... Read more
Affected Products : enterpriseone- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2006-3707
Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3 and 9.0.3.1 has unknown impact and attack vectors, aka Oracle Vuln# AS02.... Read more
Affected Products : application_server- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-3734
Multiple unspecified vulnerabilities in the Command Line Interface (CLI) for Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allow local CS-MARS administrators to execute arbitrary commands as root.... Read more
Affected Products : cs-mars- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3685
PHP remote file inclusion vulnerability in CzarNews 1.12 through 1.14 allows remote attackers to execute arbitrary PHP code via a URL in the tpath parameter to cn_config.php. NOTE: the news.php vector is already covered by CVE-2005-0859.... Read more
Affected Products : czarnews- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2006-3589
vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the S... Read more
- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2006-3703
Unspecified vulnerability in InterMedia for Oracle Database 9.0.1.5, 9.2.0.6, and 10.1.0.4 has unknown impact and attack vectors, aka oracle Vuln# DB07.... Read more
Affected Products : database_server- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3757
index.php in Zen Cart 1.3.0.2 allows remote attackers to obtain sensitive information via empty (1) _GET[], (2) _SESSION[], (3) _POST[], (4) _COOKIE[], or (5) _SESSION[] array parameters, which reveals the installation path in an error message. NOTE: thi... Read more
- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2006-3720
Unspecified vulnerability in Enterprise Config Management for Oracle Enterprise Manager 10.1.0.3 has unknown impact and attack vectors, aka Oracle Vuln# EM02.... Read more
Affected Products : enterprise_manager- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3692
PHP remote file inclusion vulnerability in enduser/listmessenger.php in ListMessenger 0.9.3 allows remote attackers to execute arbitrary PHP code via a URL in the lm_path parameter. NOTE: the vendor has disputed this issue to SecurityTracker, stating tha... Read more
Affected Products : listmessenger- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3728
Unspecified vulnerability in the kernel in Solaris 10 with patch 118822-29 (118844-29 on x86) and without patch 118833-11 (118855-08) allows remote authenticated users to cause a denial of service via unspecified vectors that lead to "kernel data structur... Read more
- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3683
PHP remote file inclusion vulnerability in poll.php in Flipper Poll 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.... Read more
Affected Products : flipper_poll- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3732
Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1 ships with an Oracle database that contains several default accounts and passwords, which allows attackers to obtain sensitive information.... Read more
Affected Products : cs-mars- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3717
Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.9 have unknown impact and attack vectors, aka Oracle Vuln# (1) APPS03 and (2) APPS04 for Oracle Application Object Library; and (3) APPS20 for Oracle XML Gateway.... Read more
Affected Products : e-business_suite- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025