Latest CVE Feed
-
7.5
HIGHCVE-2006-1852
SQL injection vulnerability in category.php in Article Publisher Pro 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cname parameter.... Read more
Affected Products : article_publisher_pro- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1854
Multiple cross-site scripting (XSS) vulnerabilities in BluePay Manager 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML during a login action via the (1) Account Name and (2) Username field. NOTE: the vendor has disputed this... Read more
Affected Products : bluepay_manager- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-1836
Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program.... Read more
- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1849
Multiple SQL injection vulnerabilities in members_only/index.cgi in xFlow 5.46.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) position and (2) id parameter.... Read more
Affected Products : xflow- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-1844
The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pppoeconf passwords, which might allow local users to gain privileges.... Read more
- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-1829
EAServer Manager in Sybase EAServer 5.2 and 5.3 allows remote authenticated users, possibly guests, to obtain password credentials of arbitrary users via unspecified vectors involving (1) connection caches, (2) open password prompts, and (3) stored custom... Read more
Affected Products : easerver- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1846
Cross-site scripting (XSS) vulnerability in the Your_Account module in PHP-Nuke 7.8 might allows remote attackers to inject arbitrary HTML and web script via the ublock parameter, which is saved in the user's personal menu. NOTE: the provenance of this i... Read more
Affected Products : php-nuke- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1837
SQL injection vulnerability in archiv2.php in Fuju News 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.... Read more
Affected Products : fuju_news- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1832
sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action.... Read more
Affected Products : sysinfo- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-1853
Multiple SQL injection vulnerabilities in ModernBill 4.3.2 and earlier allow remote attackers or administrators to execute arbitrary SQL commands via the (1) id parameter in (a) user.php, or (2) where and (3) order parameters to (b) admin.php.... Read more
Affected Products : modernbill- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2006-1753
A cron job in fcheck before 2.7.59 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.... Read more
Affected Products : debian_linux- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1827
Integer signedness error in format_jpeg.c in Asterisk 1.2.6 and earlier allows remote attackers to execute arbitrary code via a length value that passes a length check as a negative number, but triggers a buffer overflow when it is used as an unsigned len... Read more
Affected Products : asterisk- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-0744
Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the w... Read more
Affected Products : linux_kernel- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-1820
Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this might be resultant from the directory traversal vulnerability.... Read more
Affected Products : modxcms- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-1822
Cross-site scripting (XSS) vulnerability in search.php in FarsiNews 2.5.3 Pro and earlier allows remote attackers to inject arbitrary web script or HTML via the selected_search_arch parameter.... Read more
Affected Products : farsinews- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1823
Directory traversal vulnerability in FarsiNews 2.5.3 Pro and earlier allows remote attackers to obtain the installation path via ".." sequences in the archive parameter to index.php, which leaks the full pathname in an error message.... Read more
Affected Products : farsinews- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-1814
NetBSD 1.6, 2.0, 2.1 and 3.0 allows local users to cause a denial of service (memory exhaustion) by using the sysctl system call to lock a large buffer into physical memory.... Read more
Affected Products : netbsd- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1801
Cross-site scripting (XSS) vulnerability in planetsearchplus.php in planetSearch+ allows remote attackers to inject arbitrary web script or HTML via the search_exp parameter.... Read more
Affected Products : planetsearch\+- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1803
Cross-site scripting (XSS) vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to inject arbitrary web script or HTML via the sql_query parameter.... Read more
Affected Products : phpmyadmin- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1798
SQL injection vulnerability in rateit.php in RateIt 2.2 allows remote attackers to execute arbitrary SQL commands via the rateit_id parameter.... Read more
Affected Products : rateit- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025