Latest CVE Feed
-
2.6
LOWCVE-2006-3769
Multiple cross-site scripting (XSS) vulnerabilities in Top XL 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) pass and (2) pass2 parameters in (a) add.php or the (3) id parameter in (b) members/index.php.... Read more
Affected Products : top_xl- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3794
SQL injection vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the search field. NOTE: the vendor has disputed this issue, stating "if someone were to type in any sql injection code, th... Read more
Affected Products : afcommerce_shopping_cart- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3795
Multiple cross-site scripting (XSS) vulnerabilities in DeluxeBB before 1.08 allow remote attackers to inject arbitrary web script or HTML via the (1) membercookie cookie in header.php and the (2) redirect parameter in misc.php.... Read more
Affected Products : deluxebb- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3773
PHP remote file inclusion vulnerability in smf.php in the SMF-Forum 1.3.1.3 Bridge Component (com_smf) For Joomla! and Mambo 4.5.3+ allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.... Read more
Affected Products : smf-forum- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3799
DeluxeBB 1.07 and earlier allows remote attackers to bypass SQL injection protection mechanisms via the login variable and certain other variables, by using lowercase "union select" or possibly other statements that do not match the uppercase "UNION SELEC... Read more
Affected Products : deluxebb- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3770
Multiple SQL injection vulnerabilities in index.php in phpFaber TopSites 2.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) i_cat or (2) method parameters.... Read more
Affected Products : topsites- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-3783
Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors involving (1) the /net mount point and (2) the "-hosts" map in a mount point.... Read more
Affected Products : solaris- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3777
PHP remote file inclusion vulnerability in index.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.... Read more
Affected Products : phplinkexchange- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3691
Multiple SQL injection vulnerabilities in VBZooM 1.11 and earlier allow remote attackers to execute arbitrary SQL commands via the UserID parameter to (1) ignore-pm.php, (2) sendmail.php, (3) reply.php or (4) sub-join.php.... Read more
Affected Products : vbzoom- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3759
Unspecified vulnerability in MyBB (aka MyBulletinBoard) 1.1.4, related has unspecified impact and attack vectors related to "user group manipulation."... Read more
Affected Products : mybulletinboard- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3766
Darren's $5 Script Archive osDate 1.1.7 and earlier allows users to boost their own ratings via a txtrating parameter with a score greater than the intended maximum of 10.... Read more
Affected Products : osdate- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3763
SQL injection vulnerability in category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : diesel_joke_site- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-3753
setcookie.php for the administration login in Professional Home Page Tools Guestbook records the hash of the administrator password in a cookie, which allows attackers to conduct brute force password guessing attacks after obtaining the hash.... Read more
Affected Products : professional_home_page_tools_guestbook- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3748
PHP remote file inclusion vulnerability in includes/abbc/abbc.class.php in the LoudMouth Component for Mambo 4.0j, and possibly other versions including 4.1, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path pa... Read more
Affected Products : loudmouth- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3751
PHP remote file inclusion vulnerability in popups/ImageManager/config.inc.php in the HTMLArea3 Addon Component (com_htmlarea3_xtd-c) for ImageManager 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parame... Read more
Affected Products : htmlarea3- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3735
Multiple PHP remote file inclusion vulnerabilities in Mail2Forum (module for phpBB) 1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the m2f_root_path parameter to (1) m2f/m2f_phpbb204.php, (2) m2f/m2f_forum.php, (3) m2f/m... Read more
Affected Products : mail2forum- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3736
PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.... Read more
Affected Products : videodb- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3727
Multiple SQL injection vulnerabilities in Eskolar CMS 0.9.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) gr_1_id, (2) gr_2_id, (3) gr_3_id, and (4) doc_id parameters in (a) index.php; the (5) uid and (6) pwd parameters in (b) php... Read more
Affected Products : eskolar_cms- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3764
Till Gerken phpPolls 1.0.3 allows remote attackers to create a new poll via a direct request to phpPollAdmin.php3 with the poll_action parameter set to create.... Read more
Affected Products : phppolls- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3733
jmx-console/HtmlAdaptor in the jmx-console in the JBoss web application server, as shipped with Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allows remote attackers to gain privileges as the CS-MARS administrator and exe... Read more
Affected Products : security_monitoring_analysis_and_response_system- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025