Latest CVE Feed
-
4.0
MEDIUMCVE-2006-2644
AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the L... Read more
- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-2633
Absolute path traversal vulnerability in the copy action in index.php in Andrew Godwin ByteHoard 2.1 and earlier allows remote authenticated users to create or overwrite files in other users' directories by specifying the absolute path of the directory in... Read more
Affected Products : bytehoard- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2650
SQL injection vulnerability in cosmicshop/search.php in CosmicShoppingCart allows remote attackers to execute arbitrary SQL commands via the max parameter.... Read more
Affected Products : cosmicshoppingcart- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-2640
Cross-site scripting (XSS) vulnerability in OmegaMw7a.ASP in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allows remote attackers to inject arbitrary web script or HTML via the WCE parameter.... Read more
Affected Products : interneserviceslosungen- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2646
Buffer overflow in Alt-N MDaemon, possibly 9.0.1 and earlier, allows remote attackers to execute arbitrary code via a long A0001 argument that begins with a '"' (double quote).... Read more
Affected Products : mdaemon- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2648
Cross-site scripting (XSS) vulnerability in perform_search.asp for ASPBB 0.52 and earlier allows remote attackers to inject arbitrary HTML or web script via the search parameter.... Read more
Affected Products : aspbb- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2643
Cross-site scripting (XSS) vulnerability in index.php in Monster Top List (MTL) 1.4 allows remote attackers to inject arbitrary web script or HTML via the user_error_message parameter.... Read more
Affected Products : monster_top_list- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2651
Cross-site scripting (XSS) vulnerability in index.php in Vacation Rental Script 1.0 allows remote attackers to inject arbitrary web script or HTML via the obj parameter.... Read more
Affected Products : vacation_rental_script- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2635
Multiple cross-site scripting (XSS) vulnerabilities in Tikiwiki (aka Tiki CMS/Groupware) 1.9.x allow remote attackers to inject arbitrary web script or HTML via malformed nested HTML tags such as "<scr<script>ipt>" in (1) offset and (2) days parameters in... Read more
Affected Products : tikiwiki_cms\/groupware- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2006-2632
Cross-site scripting (XSS) vulnerability in Andrew Godwin ByteHoard 2.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via file descriptions.... Read more
Affected Products : bytehoard- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2653
Cross-site scripting (XSS) vulnerability in login_error.shtml for D-Link DSA-3100 allows remote attackers to inject arbitrary HTML or web script via an encoded uname parameter.... Read more
Affected Products : dsa-3100_airspot_gateway- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-2647
Untrusted search path vulnerability in update_flash for IBM AIX 5.1, 5.2 and 5.3 allows local users to execute arbitrary commands via unknown vectors involving lsmcode and possibly other commands.... Read more
Affected Products : aix- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2636
newsadmin.asp in Katy Whitton NewsCMSLite allows remote attackers to bypass authentication and gain administrative access by setting the loggedIn cookie to "xY1zZoPQ".... Read more
Affected Products : newscmslite- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-2563
The cURL library (libcurl) in PHP 4.4.2 and 5.1.4 allows attackers to bypass safe mode and read files via a file:// request containing null characters.... Read more
Affected Products : php- Published: May. 29, 2006
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2006-1174
useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly ... Read more
Affected Products : shadow- Published: May. 28, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2453
Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-2006-2480.... Read more
- Published: May. 28, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-2631
phpFoX allows remote authenticated users to modify arbitrary accounts via a modified NATIO cookie value, possibly the phpfox_user parameter.... Read more
Affected Products : phpfox- Published: May. 27, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-2630
Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack vectors.... Read more
- Published: May. 27, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-2629
Race condition in Linux kernel 2.6.15 to 2.6.17, when running on SMP platforms, allows local users to cause a denial of service (crash) by creating and exiting a large number of tasks, then accessing the /proc entry of a task that is exiting, which causes... Read more
Affected Products : linux_kernel- Published: May. 27, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2618
Cross-site scripting (XSS) vulnerability in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, might allow remote attackers to inject arbitrary web script or HTML via the "write a review" box. NOTE: since user reviews do not ... Read more
Affected Products : webhost_directory- Published: May. 26, 2006
- Modified: Apr. 03, 2025