Latest CVE Feed
-
2.6
LOWCVE-2006-3174
Cross-site scripting (XSS) vulnerability in search.php in SquirrelMail 1.5.1 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary HTML via the mailbox parameter.... Read more
Affected Products : squirrelmail- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3162
PHP remote file inclusion vulnerability in include/inc_foot.php in SmartSiteCMS 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.... Read more
Affected Products : smartsitecms- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3141
Cross-site scripting (XSS) vulnerability in details.cfm in Tradingeye Shop R4 and earlier allows remote attackers to inject arbitrary web script or HTML via the image parameter.... Read more
Affected Products : tradingeye_shop- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3165
SQL injection vulnerability in propview.php in Free Realty 2.9-0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the sort parameter.... Read more
Affected Products : free_realty- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3153
Cross-site scripting (XSS) vulnerability in index.pl in Ultimate Estate 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.... Read more
Affected Products : ultimate_estate- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3158
index.php in Eduha Meeting does not properly restrict file extensions before permitting a file upload, which allows remote attackers to bypass security checks and upload or execute arbitrary php code via the add action.... Read more
Affected Products : eduha_meeting- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3163
Multiple SQL injection vulnerabilities in galeria.php in IMGallery 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start or (2) sort parameters.... Read more
Affected Products : imgallery- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3151
Cross-site scripting (XSS) vulnerability in index.php in AssoCIateD (aka ACID) 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the menu parameter.... Read more
Affected Products : associated_cms- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-3143
Cross-site scripting (XSS) vulnerability in icue_login.asp in Maximus SchoolMAX 4.0.1 and earlier iCue and iParent applications allows remote attackers to inject arbitrary web script or HTML via the error_msg parameter.... Read more
Affected Products : schoolmax- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3159
pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built May 14 2003) allows local users to read portions of restricted files via a symlink attack on msg.conf in a directory identified by the CONFIGROOT environment variable, which returns th... Read more
- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3146
The TOSRFBD.SYS driver for Toshiba Bluetooth Stack 4.00.29 and earlier on Windows allows remote attackers to cause a denial of service (reboot) via a L2CAP echo request that triggers an out-of-bounds memory access, similar to "Ping o' Death" and as demons... Read more
- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3140
SQL injection vulnerability in index.php in openCI 1.0 BETA 0.20.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : openci- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3167
Free Realty before 2.9 allows remote attackers to obtain the full path and other sensitive information via unspecified manipulations that produce an error message.... Read more
Affected Products : free_realty- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3150
SQL injection vulnerability in index.php in CavoxCms 1.0.16 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.... Read more
Affected Products : cavoxcms- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2006-3136
Multiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LIBS parameter in (1) path/action.php, and to files in path/nucleus including (2) media.php, (3) /xmlrpc/server.php, ... Read more
Affected Products : nucleus_cms- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3155
Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in (a) emailtofriend.pl or (b) violation.pl, (2) seller parameter in (c) vsoa.... Read more
Affected Products : ultimate_estate- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3142
SQL injection vulnerability in forum.php in VBZooM 1.11 allows remote attackers to execute arbitrary SQL commands via the MainID parameter.... Read more
Affected Products : vbzoom- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3164
SQL injection vulnerability in category.php in TPL Design tplShop 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the first_row parameter.... Read more
Affected Products : tplshop- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3154
SQL injection vulnerability in index.pl in Ultimate Estate 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : ultimate_estate- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3139
Multiple SQL injection vulnerabilities in war.php in Virtual War (VWar) 1.5.0 R14 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) showgame, (3) sortorder, and (4) sortby parameters.... Read more
Affected Products : virtual_war- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025