Latest CVE Feed
-
6.8
MEDIUMCVE-2006-1779
Cross-site scripting (XSS) vulnerability in login.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the btag parameter.... Read more
Affected Products : simplog- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1781
PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. NOTE: It was later reported that 1.4.2 and earlier are affected.... Read more
Affected Products : monster_top_list- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1767
Multiple PHP remote file inclusion vulnerabilities in nicecoder.com INDEXU 5.0.0 and 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the theme_path parameter in (1) index.php, (2) become_editor.php, (3) add.php, (4) bad_link.php, (... Read more
Affected Products : indexu- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-1765
Cross-site scripting (XSS) vulnerability in index.php in JBook 1.3 allows remote attackers to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : jbook- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1774
HP System Management Homepage (SMH) 2.1.3.132, when running on CompaqHTTPServer/9.9 on Windows, Linux, or Tru64 UNIX, and when "Trust by Certificates" is not enabled, allows remote attackers to bypass authentication via a crafted URL.... Read more
- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1773
SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands via the contentid parameter, possibly involving content/news.php.... Read more
Affected Products : phpkit- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1775
Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.19 allow remote attackers to inject arbitrary web script or HTML via the (1) Site Description field in (a) admin_board.php, the (2) Group name and (3) Group description fields in (b) admin_g... Read more
Affected Products : phpbb- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1771
Directory traversal vulnerability in misc in pbcs.dll in SAXoTECH SAXoPRESS, aka Saxotech Online (formerly Publicus) allows remote attackers to read arbitrary files and possibly execute arbitrary programs via a .. (dot dot) in the url parameter.... Read more
Affected Products : saxopress- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-1780
The Bourne shell (sh) in Solaris 8, 9, and 10 allows local users to cause a denial of service (sh crash) via an unspecified attack vector that causes sh processes to crash during creation of temporary files.... Read more
- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1777
Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the s parameter, as demonstrated by injecting PHP seq... Read more
Affected Products : simplog- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-1772
debconf in Debian GNU/Linux, when configuring mnogosearch in the mnogosearch-common 3.2.31-1 package, uses the world-readable config.dat file instead of the restricted passwords.dat for storing the cleartext database administrator password in the mnogosea... Read more
Affected Products : debian_linux- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1783
Cross-site scripting (XSS) vulnerability in PatroNet CMS allows remote attackers to inject arbitrary web script or HTML via the URI.... Read more
Affected Products : cms- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1759
Cross-site scripting (XSS) vulnerability in allgemein_transfer.php in SWSoft Confixx 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the jahr parameter.... Read more
Affected Products : confixx- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1755
SQL injection vulnerability in admin.php in MD News 1 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : md_news- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-1764
Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as user name and password credentials. NOTE: the provenance of this informat... Read more
Affected Products : hosting_controller- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1761
Cross-site scripting vulnerability in index.php in blur6ex 0.3.452 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter, which is not sanitized in the error message. NOTE: the vector in the shard parameter is not XSS a... Read more
Affected Products : blur6ex- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1762
Directory traversal vulnerability in index.php in blur6ex 0.3.452 allows remote attackers to include arbitrary files via the shard parameter. NOTE: this issue can be exploited to produce resultant XSS when the parameter has XSS manipulations, and path di... Read more
Affected Products : blur6ex- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1763
Multiple SQL injection vulnerabilities in index.php in blur6ex 0.3.452 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a (1) g_reply or (2) g_permaPost action to the blog shard (engine/shards/blog.php), or a (3) g_viewCon... Read more
Affected Products : blur6ex- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1760
Multiple cross-site scripting (XSS) vulnerabilities in JetPhoto allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) Classic.view/thumbnail.php, (2) Classic.view/gallery.php, (3) Classic.view/detail.php, or (4) Orang... Read more
Affected Products : jetphoto- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1758
SQL injection vulnerability in index.php in Vegadns 0.99 allows remote attackers to execute arbitrary SQL commands via the cid parameter.... Read more
Affected Products : vegadns- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025