Latest CVE Feed
-
4.3
MEDIUMCVE-2006-3428
Cross-site scripting (XSS) vulnerability in TigerTom TTCalc 1.0 allows remote attackers to inject arbitrary web script or HTML via the year parameter in (1) loan.php and (2) mortgage.php.... Read more
Affected Products : ttcalc_script- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3429
Cross-site scripting (XSS) vulnerability in TigerTom TTCalc 1.0 allows remote attackers to inject arbitrary web script or HTML via the currency parameter in (1) loan.php and (2) mortgage.php. NOTE: the provenance of this information is unknown; the detai... Read more
Affected Products : ttcalc_script- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-3406
Directory traversal vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to modify arbitrary files via a .. (dot dot) sequence in the edit parameter.... Read more
Affected Products : qtofilemanager- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3420
Cross-site request forgery (CSRF) vulnerability in editpost.php in MyBulletinBoard (MyBB) before 1.1.5 allows remote attackers to perform unauthorized actions as a logged in user and delete arbitrary forum posts via a bbcode IMG tag with a modified delete... Read more
Affected Products : mybulletinboard- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-3377
Cross-site scripting (XSS) vulnerability in JMB Software AutoRank PHP 3.02 and earlier, and AutoRank Pro 5.01 and earlier, allows remote attackers to inject arbitrary web script or HTML via the (1) Keyword parameter in search.php and the (2) Username para... Read more
Affected Products : autorank- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3367
Mp3 JudeBox Server (Mp3NetBox) Beta 1 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information, including the database configuration.... Read more
Affected Products : mp3netbox- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3365
V3 Chat allows remote attackers to obtain the installation path via (1) an invalid id parameter to mail/index.php or (2) membername parameter to messenger/online.php, which displays the path in an error page due to an incorrect SQL statement.... Read more
Affected Products : v3_chat- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3358
Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being returned... Read more
Affected Products : newsphp- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3361
PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the (1) _PHPLIB[libdir] parameter in studip-phplib/oohforms.inc and (2) ABSOLUTE_PATH_STUDI... Read more
- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-3378
passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or reso... Read more
Affected Products : ubuntu_linux- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3397
Multiple cross-site scripting (XSS) vulnerabilities in Taskjitsu before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters, including the (1) title and (2) description parameters when creating a task.... Read more
Affected Products : taskjitsu- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3366
Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2) l... Read more
Affected Products : v3_chat- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3379
Algorithmic complexity vulnerability in Hiki Wiki 0.6.0 through 0.6.5 and 0.8.0 through 0.8.5 allows remote attackers to cause a denial of service (CPU consumption) by performing a diff between large, crafted pages that trigger the worst case.... Read more
Affected Products : hiki_wiki- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3370
Blueboy 1.0.3 stores bb_news_config.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information, including the database configuration.... Read more
Affected Products : blueboy- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3396
PHP remote file inclusion vulnerability in galleria.html.php in Galleria Mambo Module 1.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.... Read more
Affected Products : galleria- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3392
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes su... Read more
- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3356
The TIFFFetchAnyArray function in ImageIO in Apple OS X 10.4.7 and earlier allows remote user-assisted attackers to cause a denial of service (application crash) via an invalid tag value in a TIFF image, possibly triggering a null dereference. NOTE: This... Read more
- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3355
Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not properly terminated before being used with the strncpy function. NOTE: This appears to be the result of an ... Read more
Affected Products : mpg123- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3369
Kamikaze-QSCM 0.1 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information, including the database configuration.... Read more
Affected Products : kamikaze-qscm- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3399
Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki before 1.1.2-20060702 allows remote attackers to inject arbitrary Javascript via the URL, which is reflected back in an error message, a variant of CVE-2004-1632.... Read more
Affected Products : moniwiki- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025