Latest CVE Feed
-
5.0
MEDIUMCVE-2006-3413
The privoxy configuration file in Tor before 0.1.1.20, when run on Apple OS X, logs all data via the "logfile", which allows attackers to obtain potentially sensitive information.... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-3412
Tor before 0.1.1.20 does not sufficiently obey certain firewall options, which allows remote attackers to bypass intended access restrictions for dirservers, direct connections, or proxy servers.... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3430
SQL injection vulnerability in checkprofile.asp in (1) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (2) Novell ZENworks 6.2 SR1 and earlier, allows remote attackers to execute arbitrary SQL commands via the agentid paramete... Read more
- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3425
FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/proxyreg.asp, which allows remote attackers to list, add, or delete PatchLi... Read more
- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-3423
WebEx Downloader ActiveX Control and WebEx Downloader Java before 2.1.0.0 do not validate downloaded components, which allows remote attackers to execute arbitrary code via a website that activates the GpcUrlRoot and GpcIniFileName ActiveX controls to cau... Read more
- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-3406
Directory traversal vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to modify arbitrary files via a .. (dot dot) sequence in the edit parameter.... Read more
Affected Products : qtofilemanager- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3420
Cross-site request forgery (CSRF) vulnerability in editpost.php in MyBulletinBoard (MyBB) before 1.1.5 allows remote attackers to perform unauthorized actions as a logged in user and delete arbitrary forum posts via a bbcode IMG tag with a modified delete... Read more
Affected Products : mybulletinboard- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3428
Cross-site scripting (XSS) vulnerability in TigerTom TTCalc 1.0 allows remote attackers to inject arbitrary web script or HTML via the year parameter in (1) loan.php and (2) mortgage.php.... Read more
Affected Products : ttcalc_script- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3422
PHP remote file inclusion vulnerability in WonderEdit Pro CMS allows remote attackers to execute arbitrary PHP code via the config[template_path] parameter in user_bottom.php, as used by multiple templates including (1) rwb (template/rwb/user_bottom.php),... Read more
Affected Products : wonderedit_pro_cms- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3416
Tor before 0.1.1.20 kills the circuit when it receives an unrecognized relay command, which causes network circuits to be disbanded. NOTE: while this item is listed under the "Security fixes" section of the developer changelog, the developer clarified on... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-3411
TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier for remote attackers to conduct brute force attacks on the encryption keys.... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3408
Unspecified vulnerability in the directory server (dirserver) in Tor before 0.1.1.20 allows remote attackers to cause an unspecified denial of service via unknown vectors.... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3397
Multiple cross-site scripting (XSS) vulnerabilities in Taskjitsu before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters, including the (1) title and (2) description parameters when creating a task.... Read more
Affected Products : taskjitsu- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-3378
passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or reso... Read more
Affected Products : ubuntu_linux- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-3377
Cross-site scripting (XSS) vulnerability in JMB Software AutoRank PHP 3.02 and earlier, and AutoRank Pro 5.01 and earlier, allows remote attackers to inject arbitrary web script or HTML via the (1) Keyword parameter in search.php and the (2) Username para... Read more
Affected Products : autorank- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3396
PHP remote file inclusion vulnerability in galleria.html.php in Galleria Mambo Module 1.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.... Read more
Affected Products : galleria- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3370
Blueboy 1.0.3 stores bb_news_config.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information, including the database configuration.... Read more
Affected Products : blueboy- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3367
Mp3 JudeBox Server (Mp3NetBox) Beta 1 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information, including the database configuration.... Read more
Affected Products : mp3netbox- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3361
PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the (1) _PHPLIB[libdir] parameter in studip-phplib/oohforms.inc and (2) ABSOLUTE_PATH_STUDI... Read more
- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3404
Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS... Read more
Affected Products : gimp- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025