Latest CVE Feed
-
7.5
HIGHCVE-2006-1798
SQL injection vulnerability in rateit.php in RateIt 2.2 allows remote attackers to execute arbitrary SQL commands via the rateit_id parameter.... Read more
Affected Products : rateit- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1812
phpWebFTP 3.2 and earlier stores script.js under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.... Read more
Affected Products : phpwebftp- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1804
SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter.... Read more
Affected Products : phpmyadmin- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1813
Directory traversal vulnerability in index.php in phpWebFTP 3.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter.... Read more
Affected Products : phpwebftp- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1806
Cross-site scripting (XSS) vulnerability in index.php in Musicbox 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter in a search action.... Read more
Affected Products : musicbox- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1811
Multiple SQL injection vulnerabilities in FlexBB 0.5.5 BETA allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) forumid, or (3) threadid parameter to index.php; the (4) ICQ, (5) AIM, (6) MSN, (7) Google Talk, (8) Website Name, (9)... Read more
Affected Products : flexbb- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-1825
Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.... Read more
Affected Products : phplinks- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1800
Directory traversal vulnerability in posts.php in SimpleBBS 1.0.6 through 1.1 allows remote attackers to include and execute arbitrary files via ".." sequences in the language cookie, as demonstrated by by injecting the code into the gl_session cookie of ... Read more
Affected Products : simplebbs- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1819
Directory traversal vulnerability in the loadConfig function in index.php in phpWebSite 0.10.2 and earlier allows remote attackers to include arbitrary local files and execute arbitrary PHP code via the hub_dir parameter, as demonstrated by including acce... Read more
Affected Products : phpwebsite- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1802
Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the twg_album parameter.... Read more
Affected Products : tinywebgallery- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1807
Multiple SQL injection vulnerabilities in index.php in Musicbox 2.3.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start parameter in a search action or (2) type parameter in a top action.... Read more
Affected Products : musicbox- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1817
SQL injection vulnerability in authcheck.php in warforge.NEWS 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) authusername and possibly the (2) authpassword cookie.... Read more
Affected Products : warforge.news- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1805
SQL injection vulnerability in member.php in PowerClan 1.14 allows remote attackers to execute arbitrary SQL commands via the memberid parameter.... Read more
Affected Products : powerclan- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-1797
The kernel in NetBSD-current before September 28, 2005 allows local users to cause a denial of service (system crash) by using the SIOCGIFALIAS ioctl to gather information on a non-existent alias of a network interface, which causes a NULL pointer derefer... Read more
Affected Products : netbsd- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1808
Cross-site scripting (XSS) vulnerability in index.php in Lifetype 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the show parameter in a Template operation.... Read more
Affected Products : lifetype- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1809
index.php in Lifetype 1.0.3 allows remote attackers to obtain sensitive information via an invalid show parameter, which reveals the path in an error message.... Read more
Affected Products : lifetype- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
1.9
LOWCVE-2006-1810
Multiple cross-site scripting (XSS) vulnerabilities in FlexBB 0.5.5 BETA allow remote attackers to inject arbitrary web script or HTML via the (1) ICQ, (2) AIM, (3) MSN, (4) Google Talk, (5) Website Name, (6) Website Address, (7) Email Address, (8) Locati... Read more
Affected Products : flexbb- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1821
Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the id parameter.... Read more
Affected Products : modxcms- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1815
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) newuser_realname and (2) newuser_icq parameters, a different vector than ... Read more
Affected Products : tritanium_bulletin_board- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-1824
Multiple cross-site scripting (XSS) vulnerabilities in PhpGuestbook.php in PhpGuestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Website, and (3) Comment parameter.... Read more
Affected Products : phpguestbook- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025