Latest CVE Feed
-
6.8
MEDIUMCVE-2006-3751
PHP remote file inclusion vulnerability in popups/ImageManager/config.inc.php in the HTMLArea3 Addon Component (com_htmlarea3_xtd-c) for ImageManager 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parame... Read more
Affected Products : htmlarea3- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3733
jmx-console/HtmlAdaptor in the jmx-console in the JBoss web application server, as shipped with Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allows remote attackers to gain privileges as the CS-MARS administrator and exe... Read more
Affected Products : security_monitoring_analysis_and_response_system- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3748
PHP remote file inclusion vulnerability in includes/abbc/abbc.class.php in the LoudMouth Component for Mambo 4.0j, and possibly other versions including 4.1, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path pa... Read more
Affected Products : loudmouth- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2006-3699
Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5 and 9.2.0.6 has unknown impact and attack vectors, aka Oracle Vuln# DB02.... Read more
Affected Products : database_server- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3759
Unspecified vulnerability in MyBB (aka MyBulletinBoard) 1.1.4, related has unspecified impact and attack vectors related to "user group manipulation."... Read more
Affected Products : mybulletinboard- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3682
awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode or (3) month parameters.... Read more
- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3731
Mozilla Firefox 1.5.0.4 and earlier allows remote user-assisted attackers to cause a denial of service (crash) via a form with a multipart/form-data encoding and a user-uploaded file. NOTE: a third party has claimed that this issue might be related to th... Read more
Affected Products : firefox- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2006-3701
Unspecified vulnerability in the Dictionary component in Oracle Database 8.1.7.4, 9.0.1.5, and 9.2.0.6 has unknown impact and attack vectors, aka Oracle Vuln# DB05.... Read more
Affected Products : database_server- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3684
PHP remote file inclusion vulnerability in calendar.php in SoftComplex PHP Event Calendar 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_calendar parameter, which overwrites the $path_to_calendar variable from an extrac... Read more
Affected Products : php_event_calendar- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3766
Darren's $5 Script Archive osDate 1.1.7 and earlier allows users to boost their own ratings via a txtrating parameter with a score greater than the intended maximum of 10.... Read more
Affected Products : osdate- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-3693
Rocks Clusters 4.1 and earlier allows local users to gain privileges via commands enclosed with escaped backticks (\`) in an argument to the (1) mount-loop (mount-loop.c) or (2) umount-loop (umount-loop.c) command, which is not filtered in a system functi... Read more
Affected Products : rocks_clusters- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3691
Multiple SQL injection vulnerabilities in VBZooM 1.11 and earlier allow remote attackers to execute arbitrary SQL commands via the UserID parameter to (1) ignore-pm.php, (2) sendmail.php, (3) reply.php or (4) sub-join.php.... Read more
Affected Products : vbzoom- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3688
SQL injection vulnerability in Room.php in Francisco Charrua Photo-Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : photo-gallery- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3749
PHP remote file inclusion vulnerability in sitemap.xml.php in Sitemap component (com_sitemap) 2.0.0 for Mambo 4.5.1 CMS, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path param... Read more
Affected Products : sitemap- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3702
Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB06 in Export; (2) DB08, (3) DB09, (4) DB10, (5) DB11, (6) DB12, (7) DB13, (8) DB14, an... Read more
Affected Products : database_server- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3704
Unspecified vulnerability in the Oracle ODBC Driver for Oracle Database 10.1.0.4 has unknown impact and attack vectors, aka Oracle Vuln# 10.1.0.4.... Read more
Affected Products : database_server- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3698
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB01 for Change Data Capture (CDC) component and (2) DB03 for Data Pump Metadata API. NOTE: as of 20060719, Oracle has not dispu... Read more
Affected Products : database_server- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-3713
Unspecified vulnerability in OC4J for Oracle Application Server 10.1.3.0 has unknown impact and attack vectors, aka Oracle Vuln# AS09.... Read more
Affected Products : application_server- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3714
Unspecified vulnerability in OC4J for Oracle Application Server 10.1.2.0.2 and 10.1.2.1 has unknown impact and attack vectors, aka Oracle Vuln# AS10.... Read more
Affected Products : application_server- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-3468
Linux kernel 2.6.x, when using both NFS and EXT3, allows remote attackers to cause a denial of service (file system panic) via a crafted UDP packet with a V2 lookup procedure that specifies a bad file handle (inode number), which triggers an error and cau... Read more
- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025