Latest CVE Feed
-
4.3
MEDIUMCVE-2006-1077
Multiple cross-site scripting (XSS) vulnerabilities in the commentary in Evo-Dev evoBlog allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter and (2) other unspecified parameters.... Read more
Affected Products : evoblog- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1075
Format string vulnerability in the visualization function in Jason Boettcher Liero Xtreme 0.62b and earlier allows remote attackers to execute arbitrary code via format string specifiers in (1) a nickname, (2) a dedicated server name, or (3) a mapname in ... Read more
Affected Products : liero_xtreme- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0746
Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-dependent attackers to exploit vulnerabilities that were present in CVE-2005-3627.... Read more
- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
8.4
HIGHCVE-2006-1078
Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normal... Read more
Affected Products : thttpd- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1084
Multiple SQL injection vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the option[prefix] parameter in admin.php and other unspecified PHP scripts, and (2) the PC_REMOTE_ADDR HTTP header to... Read more
Affected Products : php-stats- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1081
SQL injection vulnerability in forgotten_password.php in Jonathan Beckett PluggedOut Nexus 0.1 allows remote attackers to execute arbitrary SQL commands via the email parameter.... Read more
Affected Products : pluggedout_nexus- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1080
Cross-site scripting (XSS) vulnerability in login.php in Game-Panel 2.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter, possibly requiring a URL encoded value.... Read more
Affected Products : game-panel- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1088
PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request to checktables.php, which lists the database table_prefix.... Read more
Affected Products : php-stats- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-1087
Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the option_new[compatibility_mode] parameter, which is not f... Read more
Affected Products : php-stats- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-1079
htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is nor... Read more
Affected Products : thttpd- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1082
Multiple cross-site scripting (XSS) vulnerabilities in phpArcadeScript 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the gamename parameter in tellafriend.php, (2) the login_status parameter in loginbox.php, (3) the... Read more
Affected Products : phparcadescript- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1073
Directory traversal vulnerability in index.php in Daverave Simplog 1.0.2 and earlier allows remote attackers to include or read arbitrary .txt files via the (1) act and (2) blogid parameters.... Read more
Affected Products : simplog- Published: Mar. 08, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1072
Cross-site scripting (XSS) vulnerability in Daverave Simplog 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a blog post.... Read more
Affected Products : simplog- Published: Mar. 08, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1071
Cross-site scripting (XSS) vulnerability in index.php in DVguestbook 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : dvguestbook- Published: Mar. 08, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1070
Cross-site scripting (XSS) vulnerability in dv_gbook.php in DVguestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the f parameter.... Read more
Affected Products : dvguestbook- Published: Mar. 08, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1069
Unspecified vulnerability in the session handling for Geeklog 1.4.x before 1.4.0sr2, 1.3.11 before 1.3.11sr5, 1.3.9 before 1.3.9sr5, and possibly earlier versions allows attackers to gain privileges as arbitrary users via unknown vectors.... Read more
Affected Products : geeklog- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-1068
Netgear 614 and 624 routers, possibly running VXWorks, allow remote attackers to cause a denial of service by sending a malformed DCC SEND string to an IRC channel, which causes an IRC connection reset, possibly related to the masquerading code for NAT en... Read more
Affected Products : netgear_router- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1065
SQL injection vulnerability in search.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to execute arbitrary SQL commands via the forums[] parameter.... Read more
Affected Products : mybulletinboard- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1067
Linksys WRT54G routers version 5 (running VXWorks) allow remote attackers to cause a denial of service by sending a malformed DCC SEND string to an IRC channel, which causes an IRC connection reset, possibly related to the masquerading code for NAT enviro... Read more
Affected Products : wrt54g_v5- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1062
Unspecified vulnerability in lurker.cgi for Lurker 2.0 and earlier allows attackers to read arbitrary files via unknown vectors.... Read more
Affected Products : lurker- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025