Latest CVE Feed
-
4.3
MEDIUMCVE-2006-3321
Multiple cross-site scripting (XSS) vulnerabilities in openforum.asp in OpenForum 1.2 Beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ofdisp and (2) ofmsgid parameters.... Read more
Affected Products : openforum- Published: Jun. 30, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3320
Cross-site scripting (XSS) vulnerability in command.php in SiteBar 3.3.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the command parameter.... Read more
Affected Products : sitebar- Published: Jun. 30, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3319
Cross-site scripting (XSS) vulnerability in rss/index.php in PHP iCalendar 2.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the cal parameter.... Read more
Affected Products : php_icalendar- Published: Jun. 30, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-1467
Integer overflow in the AAC file parsing code in Apple iTunes before 6.0.5 on Mac OS X 10.2.8 or later, and Windows XP and 2000, allows remote user-assisted attackers to execute arbitrary code via an AAC (M4P, M4A, or M4B) file with a sample table size (S... Read more
Affected Products : itunes- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3115
SQL injection vulnerability in view.php in phpRaid 3.0.4, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the raid_id parameter.... Read more
Affected Products : phpraid- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3316
Multiple PHP remote file inclusion vulnerabilities in phpRaid 3.0.5 allow remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (1) logs.php and (2) users.php, a different set of vectors than CVE-2006-3116.... Read more
Affected Products : phpraid- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3318
SQL injection vulnerability in register.php for phpRaid 3.0.6 and possibly other versions, when the authorization type is phpraid, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) email parameters.... Read more
Affected Products : phpraid- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3116
Multiple PHP remote file inclusion vulnerabilities in phpRaid 3.0.4 and 3.0.5 allow remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (1) configuration.php, (3) guilds.php, (4) index.php, (5) locations.php, (6) login.php... Read more
Affected Products : phpraid- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3317
PHP remote file inclusion vulnerability in phpRaid 3.0.6 allows remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (1) announcements.php and (2) rss.php, a different set of vectors and affected versions than CVE-2006-3316... Read more
Affected Products : phpraid- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3314
PHP remote file inclusion vulnerability in page.php in an unspecified RahnemaCo.com product, possibly eShop, allows remote attackers to execute arbitrary PHP code via a URL in the pageid parameter.... Read more
Affected Products : rahnemaco- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3313
Cross-site scripting (XSS) vulnerability in search.jsp in Netsoft smartNet 2.0 allows remote attackers to inject arbitrary web script or HTML via the keyWord parameter.... Read more
Affected Products : smartnet- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3312
Multiple cross-site scripting (XSS) vulnerabilities in ashmans and Bill Echlin QaTraq 6.5 RC and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) link_print, (2) link_upgrade, (3) link_sql, (4) link_next, (5) link_prev, an... Read more
Affected Products : qatraq- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3315
PHP remote file inclusion vulnerability in page.php in an unspecified RahnemaCo.com product, possibly eShop, allows remote attackers to execute arbitrary PHP code via a URL in the osCsid parameter.... Read more
Affected Products : rahnemaco- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3268
Unspecified vulnerability in the Windows Client API in Novell GroupWise 5.x through 7 might allow users to obtain "random programmatic access" to other email within the same post office.... Read more
Affected Products : groupwise- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3306
Cross-site scripting (XSS) vulnerability in the preparestring function in lib/common.php in Project EROS bbsengine before 20060501-0142-jam, and possibly earlier versions dating back to 2006-02-23, might allow remote attackers to inject arbitrary web scri... Read more
Affected Products : project_eros_bbsengine- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3298
Yahoo! Messenger 7.5.0.814 and 7.0.438 allows remote attackers to cause a denial of service (crash) via messages that contain non-ASCII characters, which triggers the crash in jscript.dll.... Read more
Affected Products : messenger- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3294
PHP remote file inclusion vulnerability in mod_cbsms_messages.php in CBSMS Mambo Module 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.... Read more
Affected Products : mambo_module- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3307
Multiple SQL injection vulnerabilities in Project EROS bbsengine before bbsengine-20060429-1550-jam allow remote attackers to execute arbitrary SQL commands via (1) unspecified parameters in the php/comment.php and (2) the getpartialmatches method in php/... Read more
Affected Products : project_eros_bbsengine- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3300
PHP remote file inclusion vulnerability in sms_config/gateway.php in PhpMySms 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter.... Read more
Affected Products : phpmysms- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3299
Cross-site scripting (XSS) vulnerability in index.php in Usenet Script 0.5 allows remote attackers to inject arbitrary web script or HTML via the group parameter.... Read more
Affected Products : usenet- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025