Latest CVE Feed
-
5.0
MEDIUMCVE-2006-1118
SQL injection vulnerability in bmail before Aardvark PR9.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving GBK character sets.... Read more
Affected Products : bmail- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1110
Cross-site scripting (XSS) vulnerability in Aztek Forum 4.0 allows remote attackers to inject arbitrary web script or HTML via the message body in a new message.... Read more
Affected Products : aztek_forum- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1111
Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a "*/*" in the msg parameter to index.php, which reveals usernames and passwords in a MySQL error message, possibly due to a forced SQL error or SQL injection.... Read more
Affected Products : aztek_forum- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1089
Cross-site scripting (XSS) vulnerability in header.php in PunBB 1.2.10 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly handled when the PHP_SELF variable is used to handle a pun_page tag.... Read more
Affected Products : punbb- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-1091
Kaspersky Antivirus 5.0.5 and 5.5.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via unknown attack vectors.... Read more
Affected Products : kaspersky_anti-virus- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-1090
register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations.... Read more
Affected Products : punbb- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1116
The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a message when the implementation uses a non-zero IV, which allows remote attackers to bypass integrity checks and modify messages withou... Read more
Affected Products : ncore- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1096
Cross-site scripting (XSS) vulnerability in index.php in NZ Ecommerce allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by... Read more
Affected Products : nz_ecommerce- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1076
SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execute arbitrary SQL commands via the st parameter.... Read more
Affected Products : invision_power_board- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1085
admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileges, and execute arbitrary PHP code by modifying the option[admin_pass] parameter and setting the pass_cookie to the MD5 hash of the spe... Read more
Affected Products : php-stats- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1074
Jason Boettcher Liero Xtreme 0.62b and earlier allow remote attackers to cause a denial of service (application crash or hang) via a long argument to the connect command.... Read more
Affected Products : liero_xtreme- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1083
Multiple directory traversal vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to read and possibly execute arbitrary files via a .. (dot dot) in the (1) option[language] and (2) option[template] parameters, and (3) possibly other pa... Read more
Affected Products : php-stats- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1077
Multiple cross-site scripting (XSS) vulnerabilities in the commentary in Evo-Dev evoBlog allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter and (2) other unspecified parameters.... Read more
Affected Products : evoblog- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1075
Format string vulnerability in the visualization function in Jason Boettcher Liero Xtreme 0.62b and earlier allows remote attackers to execute arbitrary code via format string specifiers in (1) a nickname, (2) a dedicated server name, or (3) a mapname in ... Read more
Affected Products : liero_xtreme- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0746
Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-dependent attackers to exploit vulnerabilities that were present in CVE-2005-3627.... Read more
- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
8.4
HIGHCVE-2006-1078
Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normal... Read more
Affected Products : thttpd- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1084
Multiple SQL injection vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the option[prefix] parameter in admin.php and other unspecified PHP scripts, and (2) the PC_REMOTE_ADDR HTTP header to... Read more
Affected Products : php-stats- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1081
SQL injection vulnerability in forgotten_password.php in Jonathan Beckett PluggedOut Nexus 0.1 allows remote attackers to execute arbitrary SQL commands via the email parameter.... Read more
Affected Products : pluggedout_nexus- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1080
Cross-site scripting (XSS) vulnerability in login.php in Game-Panel 2.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter, possibly requiring a URL encoded value.... Read more
Affected Products : game-panel- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1088
PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request to checktables.php, which lists the database table_prefix.... Read more
Affected Products : php-stats- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025