Latest CVE Feed
-
5.0
MEDIUMCVE-2006-2337
Directory traversal vulnerability in webcm in the D-Link DSL-G604T Wireless ADSL Router Modem allows remote attackers to read arbitrary files via an absolute path in the getpage parameter.... Read more
Affected Products : dsl-g604t- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2338
PlaNet Concept plaNetStat 20050127 allows remote attackers to gain administrative privileges, and view and configure log files, via a direct request to the (1) admin.php or (2) settings.php page.... Read more
Affected Products : planetstat- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-2323
Multiple PHP remote file inclusion vulnerabilities in SmartISoft phpListPro 2.01 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the returnpath parameter in (1) editsite.php, (2) addsite.php, and (3) in.php. NOTE: The config... Read more
Affected Products : phplistpro- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-2333
Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) 1.1.1 allow remote attackers to execute arbitrary SQL commands via the e-mail address when registering for a forum that requires e-mail verification, which is not properly handled in (1)... Read more
Affected Products : mybulletinboard- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2317
Unspecified vulnerability in Ideal Science Ideal BB 1.5.4a and earlier allows remote attackers to read arbitrary files under the web root via unspecified attack vectors related to the OpenTextFile method in Scripting.FileSystemObject.... Read more
Affected Products : idealbb- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2318
Incomplete blacklist vulnerability in Ideal Science Ideal BB 1.5.4a and earlier allows remote attackers to upload and execute an ASP script via a ".asa" file, which bypasses the check for the ".asp" extension but is executable on the server.... Read more
Affected Products : idealbb- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-2334
The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in Microsoft Windows 2000 SP4 and XP SP2 does not properly convert DOS style paths with trailing spaces into NT style paths, which allows context-dependent attackers to create files that cannot be... Read more
- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-2324
180solutions Zango downloads "required Adware components" without checking integrity or authenticity, which might allow context-dependent attackers to execute arbitrary code by subverting the DNS resolution of static.zangocash.com.... Read more
Affected Products : zango- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2319
Ideal Science Ideal BB 1.5.4a and earlier does not properly check file extensions before permitting an upload, which allows remote attackers to upload and execute an ASP script via a 0x00 character before the ".asp" portion of the filename.... Read more
Affected Products : idealbb- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-2331
Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via (1) a .. (dot dot) in the settings[locale] parameter in infusions/last_seen_users_panel/last_seen_users_panel.php, ... Read more
Affected Products : php_fusion- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-2316
S24EvMon.exe in the Intel PROset/Wireless software, possibly 10.1.0.33, uses a S24EventManagerSharedMemory shared memory section with weak permissions, which allows local users to read or modify passwords or other data, or cause a denial of service.... Read more
Affected Products : proset_wireless- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-2325
Cross-site scripting (XSS) vulnerability in index.php in OnlyScript.info Online Universal Payment System Script allows remote attackers to inject arbitrary web script or HTML via the read parameter. NOTE: the provenance of this information is unknown; th... Read more
Affected Products : online_universal_payment_system_script- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2315
PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the go_info[server][classes_root] parameter. NOTE: the vendor has disputed this vulnerability, sa... Read more
Affected Products : ispconfig- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-2327
Multiple integer overflows in the DPRPC library (DPRPCNLM.NLM) NDPS/iPrint module in Novell Distributed Print Services in Novell NetWare 6.5 SP3, SP4, and SP5 allow remote attackers to execute arbitrary code via an XDR encoded array with a field that spec... Read more
Affected Products : netware- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-2322
The transparent proxy feature of the Cisco Application Velocity System (AVS) 3110 5.0 and 4.0 and earlier, and 3120 5.0.0 and earlier, has a default configuration that allows remote attackers to proxy arbitrary TCP connections, aka Bug ID CSCsd32143.... Read more
- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-2335
Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrators to gain shell access by uploading a CSS file that contains PHP code, then selecting the file via the style choose... Read more
Affected Products : vbulletin- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-2336
SQL injection vulnerability in showthread.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter.... Read more
Affected Products : mybulletinboard- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2329
AngelineCMS 0.6.5 and earlier allow remote attackers to obtain sensitive information via a direct request for (1) adodb-access.inc.php, (2) adodb-ado.inc.php, (3) adodb-ado_access.inc, (4) adodb-ado_mssql.inc.php, (5) adodb-borland_ibase, (6) adodb-csv.in... Read more
Affected Products : angelinecms- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2326
Directory traversal vulnerability in index.php in OnlyScript.info Online Universal Payment System Script allows remote attackers to read arbitrary files via directory traversal sequences in the read parameter. NOTE: the provenance of this information is ... Read more
Affected Products : online_universal_payment_system_script- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2301
SQL injection vulnerability in admin_default.asp in OzzyWork Galeri allows remote attackers to execute arbitrary SQL commands via the (1) Login or (2) password fields.... Read more
Affected Products : galeri- Published: May. 11, 2006
- Modified: Apr. 03, 2025