Latest CVE Feed
-
5.0
MEDIUMCVE-2006-2692
Multiple unspecified vulnerabilities in aMuleWeb for AMule before 2.1.2 allow remote attackers to read arbitrary image, HTML, or PHP files via unknown vectors, probably related to directory traversal.... Read more
Affected Products : amule- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-2684
Cross-site scripting (XSS) vulnerability in the search module in CMS Mundo 1.0 allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter.... Read more
Affected Products : cms_mundo- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2006-2693
Directory traversal vulnerability in admin/admin_hacks_list.php in Nivisec Hacks List 1.20 and earlier for phpBB, when register_globals is enabled, allows remote attackers to read arbitrary files via a ".." in the phpEx parameter.... Read more
Affected Products : hacks_list- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-2679
Unspecified vulnerability in the VPN Client for Windows Graphical User Interface (GUI) (aka the VPN client dialer) in Cisco VPN Client for Windows 4.8.00.* and earlier, except for 4.7.00.0533, allows local authenticated, interactive users to gain privileg... Read more
Affected Products : vpn_client- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2702
vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which vars.php uses to redefine $_SERVER['REMOTE_ADDR'].... Read more
Affected Products : wordpress- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-2696
Cross-site scripting (XSS) vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) startletter parameter in userview.asp and the (2) catid parameter in topics.asp.... Read more
Affected Products : easy-content_forums- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2694
Multiple PHP remote file inclusion vulnerabilities in EzUpload Pro 2.10 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) form.php, (2) customize.php, and (3) initialize.php.... Read more
Affected Products : ezupload_pro- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-2688
SQL injection vulnerability in the employees node (class.employee.inc) in Achievo 1.1.0 and earlier and 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the atkselector parameter.... Read more
Affected Products : achievo- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-2698
Geeklog 1.4.0sr2 and earlier allows remote attackers to obtain the full installation path via a direct request and possibly invalid arguments to (1) layout/professional/functions.php or (2) getimage.php.... Read more
Affected Products : geeklog- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-2683
PHP remote file inclusion vulnerability in 404.php in open-medium.CMS 0.25 allows remote attackers to execute arbitrary PHP code via a URL in the REDSYS[MYPATH][TEMPLATES] parameter.... Read more
Affected Products : open-medium_cms- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-2697
Multiple SQL injection vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) startletter parameter in userview.asp and the (2) forumname parameter in topics.asp.... Read more
Affected Products : easy-content_forums- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-1175
The WeOnlyDo! SFTP (wodSFTP) ActiveX control is marked as safe for scripting, which allows remote attackers to read and write files in arbitrary locations by accessing the control from a web page.... Read more
Affected Products : weonlydo_sftp- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-2700
SQL injection vulnerability in admin/auth.inc.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via the loginname parameter.... Read more
Affected Products : geeklog- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2691
Unspecified "information leakage" vulnerabilities in aMuleWeb for AMule before 2.1.2 allow remote attackers to access arbitrary images, including dynamically generated images, via unknown vectors.... Read more
Affected Products : amule- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-2678
Multiple cross-site scripting (XSS) vulnerabilities in Pre News Manager 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) index.php, and the (2) nid parameter to (b) news_detail.php, (c) email_story.php, (d)... Read more
Affected Products : pre_news_manager- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-2699
Cross-site scripting (XSS) vulnerability in getimage.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to inject arbitrary HTML or web script via the image argument in a show action.... Read more
Affected Products : geeklog- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-2685
PHP remote file inclusion vulnerability in Basic Analysis and Security Engine (BASE) 1.2.4 and earlier, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via a URL in the BASE_path parameter to (1) base_qry_common.php, (... Read more
Affected Products : basic_analysis_and_security_engine- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-2664
Cross-site scripting (XSS) vulnerability in iFdate 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) password fields, or certain other input text boxes.... Read more
Affected Products : ifdate- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2667
Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into fi... Read more
Affected Products : wordpress- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2669
Multiple cross-site scripting (XSS) vulnerabilities in Pre Shopping Mall 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter in search.php (the "search box"), (2) the prodid parameter in detail.php, and the (3) c... Read more
Affected Products : pre_shopping_mall- Published: May. 30, 2006
- Modified: Apr. 03, 2025