Latest CVE Feed
-
5.0
MEDIUMCVE-2006-3413
The privoxy configuration file in Tor before 0.1.1.20, when run on Apple OS X, logs all data via the "logfile", which allows attackers to obtain potentially sensitive information.... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3421
PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the root parameter in (1) comment.php, (2) admin/comedit.php, (3) admin/test.php, (4) admi... Read more
Affected Products : smartsitecms- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3428
Cross-site scripting (XSS) vulnerability in TigerTom TTCalc 1.0 allows remote attackers to inject arbitrary web script or HTML via the year parameter in (1) loan.php and (2) mortgage.php.... Read more
Affected Products : ttcalc_script- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3429
Cross-site scripting (XSS) vulnerability in TigerTom TTCalc 1.0 allows remote attackers to inject arbitrary web script or HTML via the currency parameter in (1) loan.php and (2) mortgage.php. NOTE: the provenance of this information is unknown; the detai... Read more
Affected Products : ttcalc_script- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3416
Tor before 0.1.1.20 kills the circuit when it receives an unrecognized relay command, which causes network circuits to be disbanded. NOTE: while this item is listed under the "Security fixes" section of the developer changelog, the developer clarified on... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-3406
Directory traversal vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to modify arbitrary files via a .. (dot dot) sequence in the edit parameter.... Read more
Affected Products : qtofilemanager- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3420
Cross-site request forgery (CSRF) vulnerability in editpost.php in MyBulletinBoard (MyBB) before 1.1.5 allows remote attackers to perform unauthorized actions as a logged in user and delete arbitrary forum posts via a bbcode IMG tag with a modified delete... Read more
Affected Products : mybulletinboard- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3422
PHP remote file inclusion vulnerability in WonderEdit Pro CMS allows remote attackers to execute arbitrary PHP code via the config[template_path] parameter in user_bottom.php, as used by multiple templates including (1) rwb (template/rwb/user_bottom.php),... Read more
Affected Products : wonderedit_pro_cms- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3427
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declaring the sourceURL attribute on an uninitialized DirectAnimation.StructuredGraphicsControl ActiveX Object, which triggers a null dereference.... Read more
Affected Products : internet_explorer- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3414
Tor before 0.1.1.20 supports server descriptors that contain hostnames instead of IP addresses, which allows remote attackers to arbitrarily group users by providing preferential address resolution.... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-3415
Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITM) attack via unspecified vectors.... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-3423
WebEx Downloader ActiveX Control and WebEx Downloader Java before 2.1.0.0 do not validate downloaded components, which allows remote attackers to execute arbitrary code via a website that activates the GpcUrlRoot and GpcIniFileName ActiveX controls to cau... Read more
- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3430
SQL injection vulnerability in checkprofile.asp in (1) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (2) Novell ZENworks 6.2 SR1 and earlier, allows remote attackers to execute arbitrary SQL commands via the agentid paramete... Read more
- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3425
FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/proxyreg.asp, which allows remote attackers to list, add, or delete PatchLi... Read more
- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3359
Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) topmenuitem, and (4) cat_id parameters in (a) index.php; and the (5) category parameter in... Read more
Affected Products : newsphp- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3398
The "change password forms" in Taskjitsu before 2.0.1 includes password hashes in hidden form fields, which allows remote attackers to obtain sensitive information from the (1) Category Editor and (2) User Information editor.... Read more
Affected Products : taskjitsu- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3392
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes su... Read more
- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3404
Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS... Read more
Affected Products : gimp- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3386
index.php in Vincent Leclercq News 5.2 allows remote attackers to obtain sensitive information, such as the installation path, via a mail[] parameter with invalid values.... Read more
Affected Products : news- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3363
PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the pa parameter.... Read more
Affected Products : xoops_glossaire_module- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025