Latest CVE Feed
-
4.3
MEDIUMCVE-2006-3319
Cross-site scripting (XSS) vulnerability in rss/index.php in PHP iCalendar 2.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the cal parameter.... Read more
Affected Products : php_icalendar- Published: Jun. 30, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-1467
Integer overflow in the AAC file parsing code in Apple iTunes before 6.0.5 on Mac OS X 10.2.8 or later, and Windows XP and 2000, allows remote user-assisted attackers to execute arbitrary code via an AAC (M4P, M4A, or M4B) file with a sample table size (S... Read more
Affected Products : itunes- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3316
Multiple PHP remote file inclusion vulnerabilities in phpRaid 3.0.5 allow remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (1) logs.php and (2) users.php, a different set of vectors than CVE-2006-3116.... Read more
Affected Products : phpraid- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3318
SQL injection vulnerability in register.php for phpRaid 3.0.6 and possibly other versions, when the authorization type is phpraid, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) email parameters.... Read more
Affected Products : phpraid- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3317
PHP remote file inclusion vulnerability in phpRaid 3.0.6 allows remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (1) announcements.php and (2) rss.php, a different set of vectors and affected versions than CVE-2006-3316... Read more
Affected Products : phpraid- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3116
Multiple PHP remote file inclusion vulnerabilities in phpRaid 3.0.4 and 3.0.5 allow remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (1) configuration.php, (3) guilds.php, (4) index.php, (5) locations.php, (6) login.php... Read more
Affected Products : phpraid- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3115
SQL injection vulnerability in view.php in phpRaid 3.0.4, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the raid_id parameter.... Read more
Affected Products : phpraid- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3312
Multiple cross-site scripting (XSS) vulnerabilities in ashmans and Bill Echlin QaTraq 6.5 RC and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) link_print, (2) link_upgrade, (3) link_sql, (4) link_next, (5) link_prev, an... Read more
Affected Products : qatraq- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3313
Cross-site scripting (XSS) vulnerability in search.jsp in Netsoft smartNet 2.0 allows remote attackers to inject arbitrary web script or HTML via the keyWord parameter.... Read more
Affected Products : smartnet- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3314
PHP remote file inclusion vulnerability in page.php in an unspecified RahnemaCo.com product, possibly eShop, allows remote attackers to execute arbitrary PHP code via a URL in the pageid parameter.... Read more
Affected Products : rahnemaco- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3315
PHP remote file inclusion vulnerability in page.php in an unspecified RahnemaCo.com product, possibly eShop, allows remote attackers to execute arbitrary PHP code via a URL in the osCsid parameter.... Read more
Affected Products : rahnemaco- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3268
Unspecified vulnerability in the Windows Client API in Novell GroupWise 5.x through 7 might allow users to obtain "random programmatic access" to other email within the same post office.... Read more
Affected Products : groupwise- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3302
PHP remote file inclusion vulnerability in mod_cbsms.php in CBSMS Mambo Module 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosC_a_path parameter. NOTE: the provenance of this i... Read more
Affected Products : mambo_module- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3295
Cross-site scripting (XSS) vulnerability in header.php in Open Guestbook 0.5 allows remote attackers to inject arbitrary web script or HTML via the title parameter.... Read more
Affected Products : open_guestbook- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3297
Cross-site scripting (XSS) vulnerability in error.php in UebiMiau Webmail 2.7.10 and earlier allows remote attackers to inject arbitrary web script or HTML via the icq parameter. NOTE: the provenance of this information is unknown; the details are obtain... Read more
Affected Products : uebimiau- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-3308
Unspecified vulnerability in the wpprop code for Project EROS bbsengine before 20060622-0315 has unknown impact and remote attack vectors via [img] tags, possibly cross-site scripting (XSS).... Read more
Affected Products : project_eros_bbsengine- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3296
SQL injection vulnerability in view.php in Open Guestbook 0.5 allows remote attackers to execute arbitrary SQL commands via the offset parameter.... Read more
Affected Products : open_guestbook- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3301
Multiple cross-site scripting (XSS) vulnerabilities in phpQLAdmin 2.2.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the domain parameter in (1) user_add.php or (2) unit_add.php.... Read more
Affected Products : phpqladmin- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3305
Multiple cross-site scripting (XSS) vulnerabilities in UebiMiau Webmail 2.7.10, and 2.7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) f_user parameter in index.php, the (2) pag parameter in messages.php, or the (3... Read more
Affected Products : uebimiau- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3304
SQL injection vulnerability in cp.php in DeluxeBB 1.07 and earlier allows remote attackers to execute arbitrary SQL commands via the xmsn parameter.... Read more
Affected Products : deluxebb- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025