Latest CVE Feed
-
6.8
MEDIUMCVE-2006-3020
Multiple cross-site scripting (XSS) vulnerabilities in FullPhoto.asp in WS-Album 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) image and (2) PublisedDate parameters.... Read more
Affected Products : ws-album- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3023
Multiple cross-site scripting (XSS) vulnerabilities in thumbnails.asp in Uapplication Uphotogallery 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) s and (2) block parameters.... Read more
Affected Products : uphotogallery- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3033
Cross-site scripting (XSS) vulnerability in MyScrapbook 3.1 allows remote attackers to inject arbitrary web script or HTML via the input box in singlepage.php when submitting scrapbook pages.... Read more
Affected Products : myscrapbook- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-2449
KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for login.... Read more
- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3025
Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea Lucid Calendar 0.22 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: the provenance of this information is unknown; the details are obtained... Read more
Affected Products : lucid_calendar- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3027
Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) CAT_ID parameter in (a) subphotos.asp and (b) subLevel2.asp, the (2) AL_ID parameter in (c) photo.asp, and ... Read more
Affected Products : ephotos- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3022
Cross-site scripting (XSS) vulnerability in zoom.php in fipsGallery 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the path parameter.... Read more
Affected Products : fipsgallery- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3034
MyScrapbook 3.1 allows remote attackers to obtain sensitive information via a direct request to files in the txt-db-api directory such as txt-db-api/sql.php, which reveals the path in an error message.... Read more
Affected Products : myscrapbook- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3021
Multiple cross-site scripting (XSS) vulnerabilities in BlueCollar i-Gallery 4.1 PLUS and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) n and (2) d parameters in (a) login.asp and the d parameter in (b) igallery.asp.... Read more
Affected Products : i-gallery- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-2916
artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping pri... Read more
- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3019
Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPCMS_INCLUDEPATH parameter to files in parser/include/ including (1) class.parser_phpcms.php, (2) class.session_p... Read more
Affected Products : phpcms- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3038
Cross-site scripting (XSS) vulnerability in index.php in Cescripts Realty Room Rent allows remote attackers to inject arbitrary web script or HTML via the sel_menu parameter. NOTE: the vendor notified CVE on 20060823 that "All issues concerning this scri... Read more
Affected Products : realty_room_rent- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3037
Multiple cross-site scripting (XSS) vulnerabilities in publish.php in ST AdManager Lite allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, (3) article, (4) bio, and (5) name parameters.... Read more
Affected Products : st_admanager_lite- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3030
Multiple cross-site scripting (XSS) vulnerabilities in DwZone Shopping Cart 1.1.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ToCategory and (2) FromCategory parameters to (a) ProductDetailsForm.asp and (3) UserNa... Read more
Affected Products : dwzone_shopping_cart- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3024
Multiple cross-site scripting (XSS) vulnerabilities in EvGenius Counter 3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) monthly.php and (2) daily.php.... Read more
Affected Products : evgenius_counter- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-3016
Unspecified vulnerability in session.c in PHP before 5.1.3 has unknown impact and attack vectors, related to "certain characters in session names," including special characters that are frequently associated with CRLF injection, SQL injection, cross-site ... Read more
Affected Products : php- Published: Jun. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3018
Unspecified vulnerability in the session extension functionality in PHP before 5.1.3 has unknown impact and attack vectors related to heap corruption.... Read more
Affected Products : php- Published: Jun. 14, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-3017
zend_hash_del_key_or_index in zend_hash.c in PHP before 4.4.3 and 5.x before 5.1.3 can cause zend_hash_del to delete the wrong element, which prevents a variable from being unset even when the PHP unset function is called, which might cause the variable's... Read more
Affected Products : php- Published: Jun. 14, 2006
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2006-3015
Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI.... Read more
Affected Products : winscp- Published: Jun. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3010
Multiple SQL injection vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to execute arbitrary SQL commands via the (1) new_order and (2) order_dir parameters to (a) index.php, (b) group/group_index.php, (c) user/user_index... Read more
Affected Products : open_business_management- Published: Jun. 13, 2006
- Modified: Apr. 03, 2025