Latest CVE Feed
-
7.5
HIGHCVE-2006-1994
PHP remote file inclusion vulnerability in dForum 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DFORUM_PATH parameter to (1) about.php, (2) admin.php, (3) anmelden.php, (4) losethread.php, (5) config.php, (6) delpo... Read more
Affected Products : dforum- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2003
Cross-site scripting (XSS) vulnerability in cgi-bin/guest in Community Architect Guestbook allows remote attackers to inject arbitrary web script or HTML by signing the guestbook, which is displayed by fsguestbook.html. NOTE: the provenance of this infor... Read more
Affected Products : community_architect_guestbook- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-1993
Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain Javascript that is not properly handled by the contentWindow.focus method in an iframe, which causes ... Read more
Affected Products : firefox- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2001
Cross-site scripting (XSS) vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this is a different vulnerability than the directory traversal vector.... Read more
Affected Products : scry_gallery- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2010
Multiple SQL injection vulnerabilities in check_login.asp in Bloggage allow remote attackers to execute arbitrary SQL commands via the (1) acc_name and (2) password parameter.... Read more
Affected Products : bloggage- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2014
Directory traversal vulnerability in gallerie.php in SL_site 1.0 allows remote attackers to list images in arbitrary directories via ".." sequences in the rep parameter, which is used to construct a directory name in admin/config.inc.php. NOTE: this issu... Read more
Affected Products : sl_site- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2007
Heap-based buffer overflow in Winny 2.0 b7.1 and earlier allows remote attackers to execute arbitrary code via long strings to certain commands sent to the file transfer port.... Read more
Affected Products : winny- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2017
Dnsmasq 2.29 allows remote attackers to cause a denial of service (application crash) via a DHCP client broadcast reply request.... Read more
Affected Products : dnsmasq- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2012
Format string vulnerability in Skulltag 0.96f and earlier allows remote attackers to cause a denial of service via the version string.... Read more
Affected Products : skulltag- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1999
The multiplayer menu in OpenTTD 0.4.7 allows remote attackers to cause a denial of service via a UDP packet with an incorrect size, which causes the client to return to the main menu.... Read more
Affected Products : openttd- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2005
Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an "include" statement that is injected into the eval statement. NOTE: this issue ... Read more
Affected Products : clansys- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2004
Multiple SQL injection vulnerabilities in RI Blog 1.1 allow remote attackers to execute arbitrary SQL command via the (1) username or (2) password fields.... Read more
Affected Products : ri_blog- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1995
Directory traversal vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to read arbitrary files via ".." sequences in the p parameter, which is not properly sanitized due to an rtrim function call with the arguments in the wrong order.... Read more
Affected Products : scry_gallery- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2008
PHP remote file inclusion vulnerability in movie_cls.php in Built2Go PHP Movie Review 2B and earlier allows remote attackers to execute arbitrary PHP code via a URL in the full_path parameter.... Read more
Affected Products : movie_review- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2002
PHP remote file inclusion vulnerability in stats.php in MyGamingLadder 7.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir[base] parameter.... Read more
Affected Products : mygamingladder- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2011
Cross-site scripting (XSS) vulnerability in member.php in 4images 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the nickname, probably involving the user_name parameter in register.php.... Read more
Affected Products : 4images- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1992
mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid pointer dereferences including NULL dereferences. NOTE: the possibility of code ... Read more
Affected Products : internet_explorer- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0232
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with insufficient access control, which allows remote attackers to obtain the information via direct requests.... Read more
Affected Products : antivirus_scan_engine- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-0230
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses a client-side check to verify a password, which allows remote attackers to gain administrator privileges via a modified client that sends certain XML requests.... Read more
Affected Products : antivirus_scan_engine- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-0231
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses the same private DSA key for each installation, which allows remote attackers to conduct man-in-the-middle attacks and decrypt communications.... Read more
Affected Products : antivirus_scan_engine- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025