Latest CVE Feed
-
7.5
HIGHCVE-2006-3727
Multiple SQL injection vulnerabilities in Eskolar CMS 0.9.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) gr_1_id, (2) gr_2_id, (3) gr_3_id, and (4) doc_id parameters in (a) index.php; the (5) uid and (6) pwd parameters in (b) php... Read more
Affected Products : eskolar_cms- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-3753
setcookie.php for the administration login in Professional Home Page Tools Guestbook records the hash of the administrator password in a cookie, which allows attackers to conduct brute force password guessing attacks after obtaining the hash.... Read more
Affected Products : professional_home_page_tools_guestbook- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3764
Till Gerken phpPolls 1.0.3 allows remote attackers to create a new poll via a direct request to phpPollAdmin.php3 with the poll_action parameter set to create.... Read more
Affected Products : phppolls- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3736
PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.... Read more
Affected Products : videodb- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3759
Unspecified vulnerability in MyBB (aka MyBulletinBoard) 1.1.4, related has unspecified impact and attack vectors related to "user group manipulation."... Read more
Affected Products : mybulletinboard- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3763
SQL injection vulnerability in category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : diesel_joke_site- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3766
Darren's $5 Script Archive osDate 1.1.7 and earlier allows users to boost their own ratings via a txtrating parameter with a score greater than the intended maximum of 10.... Read more
Affected Products : osdate- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3748
PHP remote file inclusion vulnerability in includes/abbc/abbc.class.php in the LoudMouth Component for Mambo 4.0j, and possibly other versions including 4.1, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path pa... Read more
Affected Products : loudmouth- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3735
Multiple PHP remote file inclusion vulnerabilities in Mail2Forum (module for phpBB) 1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the m2f_root_path parameter to (1) m2f/m2f_phpbb204.php, (2) m2f/m2f_forum.php, (3) m2f/m... Read more
Affected Products : mail2forum- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3725
Norton Personal Firewall 2006 9.1.0.33 allows local users to cause a denial of service (crash) via certain RegSaveKey, RegRestoreKey and RegDeleteKey operations on the (1) HKLM\SYSTEM\CurrentControlSet\Services\SNDSrvc and (2) HKLM\SYSTEM\CurrentControlSe... Read more
Affected Products : norton_personal_firewall- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-3726
Buffer overflow in FileCOPA FTP Server before 1.01 released on 18th July 2006, allows remote authenticated attackers to execute arbitrary code via a long argument to the LIST command.... Read more
Affected Products : filecopa- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3710
Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3, 9.0.3.1, 9.0.4.2, and 10.1.2.0.0 has unknown impact and attack vectors, aka Oracle Vuln# (1) AS05 and (2) AS08.... Read more
Affected Products : application_server- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3733
jmx-console/HtmlAdaptor in the jmx-console in the JBoss web application server, as shipped with Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allows remote attackers to gain privileges as the CS-MARS administrator and exe... Read more
Affected Products : security_monitoring_analysis_and_response_system- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3714
Unspecified vulnerability in OC4J for Oracle Application Server 10.1.2.0.2 and 10.1.2.1 has unknown impact and attack vectors, aka Oracle Vuln# AS10.... Read more
Affected Products : application_server- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-3468
Linux kernel 2.6.x, when using both NFS and EXT3, allows remote attackers to cause a denial of service (file system panic) via a crafted UDP packet with a V2 lookup procedure that specifies a bad file handle (inode number), which triggers an error and cau... Read more
- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3700
Multiple unspecified vulnerabilities in Oracle Database 9.2.0.6 and 10.1.0.4 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB04 for Web Distributed Authoring and Versioning (DAV) and (2) DB23 for XMLDB.... Read more
Affected Products : database_server- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3717
Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.9 have unknown impact and attack vectors, aka Oracle Vuln# (1) APPS03 and (2) APPS04 for Oracle Application Object Library; and (3) APPS20 for Oracle XML Gateway.... Read more
Affected Products : e-business_suite- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3762
The Touch Control ActiveX control 2.0.0.55 allows remote attackers to read and possibly execute arbitrary files via a "file///" URI in the sPath parameter to the Execute function.... Read more
Affected Products : activex_control- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3724
Unspecified vulnerability in JD Edwards HTML Server for Oracle OneWorld Tools EnterpriseOne Tools 8.95 and 8.96 has unknown impact and attack vectors, aka Oracle Vuln# JDE01.... Read more
Affected Products : enterpriseone- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2006-3707
Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3 and 9.0.3.1 has unknown impact and attack vectors, aka Oracle Vuln# AS02.... Read more
Affected Products : application_server- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025