Latest CVE Feed
-
6.5
MEDIUMCVE-2006-1853
Multiple SQL injection vulnerabilities in ModernBill 4.3.2 and earlier allow remote attackers or administrators to execute arbitrary SQL commands via the (1) id parameter in (a) user.php, or (2) where and (3) order parameters to (b) admin.php.... Read more
Affected Products : modernbill- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2006-1753
A cron job in fcheck before 2.7.59 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.... Read more
Affected Products : debian_linux- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1827
Integer signedness error in format_jpeg.c in Asterisk 1.2.6 and earlier allows remote attackers to execute arbitrary code via a length value that passes a length check as a negative number, but triggers a buffer overflow when it is used as an unsigned len... Read more
Affected Products : asterisk- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-0744
Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the w... Read more
Affected Products : linux_kernel- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-1820
Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this might be resultant from the directory traversal vulnerability.... Read more
Affected Products : modxcms- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-1822
Cross-site scripting (XSS) vulnerability in search.php in FarsiNews 2.5.3 Pro and earlier allows remote attackers to inject arbitrary web script or HTML via the selected_search_arch parameter.... Read more
Affected Products : farsinews- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1823
Directory traversal vulnerability in FarsiNews 2.5.3 Pro and earlier allows remote attackers to obtain the installation path via ".." sequences in the archive parameter to index.php, which leaks the full pathname in an error message.... Read more
Affected Products : farsinews- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-1814
NetBSD 1.6, 2.0, 2.1 and 3.0 allows local users to cause a denial of service (memory exhaustion) by using the sysctl system call to lock a large buffer into physical memory.... Read more
Affected Products : netbsd- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1801
Cross-site scripting (XSS) vulnerability in planetsearchplus.php in planetSearch+ allows remote attackers to inject arbitrary web script or HTML via the search_exp parameter.... Read more
Affected Products : planetsearch\+- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1803
Cross-site scripting (XSS) vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to inject arbitrary web script or HTML via the sql_query parameter.... Read more
Affected Products : phpmyadmin- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1798
SQL injection vulnerability in rateit.php in RateIt 2.2 allows remote attackers to execute arbitrary SQL commands via the rateit_id parameter.... Read more
Affected Products : rateit- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1812
phpWebFTP 3.2 and earlier stores script.js under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.... Read more
Affected Products : phpwebftp- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1804
SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter.... Read more
Affected Products : phpmyadmin- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1813
Directory traversal vulnerability in index.php in phpWebFTP 3.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter.... Read more
Affected Products : phpwebftp- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1806
Cross-site scripting (XSS) vulnerability in index.php in Musicbox 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter in a search action.... Read more
Affected Products : musicbox- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1811
Multiple SQL injection vulnerabilities in FlexBB 0.5.5 BETA allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) forumid, or (3) threadid parameter to index.php; the (4) ICQ, (5) AIM, (6) MSN, (7) Google Talk, (8) Website Name, (9)... Read more
Affected Products : flexbb- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-1825
Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.... Read more
Affected Products : phplinks- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1800
Directory traversal vulnerability in posts.php in SimpleBBS 1.0.6 through 1.1 allows remote attackers to include and execute arbitrary files via ".." sequences in the language cookie, as demonstrated by by injecting the code into the gl_session cookie of ... Read more
Affected Products : simplebbs- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1819
Directory traversal vulnerability in the loadConfig function in index.php in phpWebSite 0.10.2 and earlier allows remote attackers to include arbitrary local files and execute arbitrary PHP code via the hub_dir parameter, as demonstrated by including acce... Read more
Affected Products : phpwebsite- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1802
Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the twg_album parameter.... Read more
Affected Products : tinywebgallery- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025