Latest CVE Feed
-
7.5
HIGHCVE-2006-0916
Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domai... Read more
Affected Products : bugzilla- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0908
PHP-Nuke 7.8 Patched 3.2 allows remote attackers to bypass SQL injection protection mechanisms via /%2a (/*) sequences with the "ad_click" word in the query string, as demonstrated via the kala parameter.... Read more
Affected Products : php-nuke- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0906
SQL injection vulnerability in D3Jeeb Pro 3 allows remote attackers to execute arbitrary SQL commands via the catid parameter in (1) fastlinks.php and (2) catogary.php.... Read more
Affected Products : d3jeeb_pro- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0907
SQL injection vulnerability in PHP-Nuke before 7.8 Patched 3.2 allows remote attackers to execute arbitrary SQL commands via encoded /%2a (/*) sequences in the query string, which bypasses regular expressions that are intended to protect against SQL injec... Read more
Affected Products : php-nuke- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-0903
MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function. NOTE: this issue was originally reported for the mysql_query functi... Read more
- Published: Feb. 27, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-0736
Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
- Published: Feb. 27, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-0900
nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demonstrated by the ProtoVer NFS test suite.... Read more
Affected Products : freebsd- Published: Feb. 27, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0899
Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot dot) sequences in the template parameter.... Read more
Affected Products : image_gallery_management_system- Published: Feb. 27, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-0901
Unspecified vulnerability in the hsfs filesystem in Solaris 8, 9, and 10 allows unspecified attackers to cause a denial of service (panic) or execute arbitrary code.... Read more
- Published: Feb. 27, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0897
SQL injection vulnerability in VCS Virtual Program Management Intranet (VPMi) Enterprise 3.3 allows remote attackers to execute arbitrary SQL commands via the UpdateID0 parameter to Service_Requests.asp. NOTE: the provenance of this information is unknow... Read more
Affected Products : vpmi_enterprise- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0889
Cross-site scripting (XSS) vulnerability in Calcium 3.10.1 allows remote attackers to inject arbitrary web script or HTML via the EventText parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party i... Read more
Affected Products : calcium- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0887
Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib distribution is available on the server, allows remote attackers to execute arbitrary PHP code by including a base64-encoded representat... Read more
Affected Products : phplib- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0891
Multiple directory traversal vulnerabilities in NOCC Webmail 1.0 allow remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing NULL (%00) byte in (1) the _SESSION['nocc_theme'] parameter in (a) html/footer.php; and (2) the la... Read more
Affected Products : nocc- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0892
NOCC Webmail 1.0 stores e-mail attachments in temporary files with predictable filenames, which makes it easier for remote attackers to execute arbitrary code by accessing the e-mail attachment via directory traversal vulnerabilities.... Read more
Affected Products : nocc- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0895
NOCC Webmail 1.0 allows remote attackers to obtain the installation path via a direct request to html/header.php.... Read more
Affected Products : nocc- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0898
Crypt::CBC Perl module 2.16 and earlier, when running in RandomIV mode, uses an initialization vector (IV) of 8 bytes, which results in weaker encryption when used with a cipher that requires a larger block size than 8 bytes, such as Rijndael.... Read more
Affected Products : crypt_cbc- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0893
NOCC Webmail 1.0 allows remote attackers to obtain sensitive information via a direct request to (1) the profiles directory, which leaks e-mail addresses contained in filenames of profiles, and (2) the tmp directory, which lists names of uploaded attachme... Read more
Affected Products : nocc- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0894
Multiple cross-site scripting (XSS) vulnerabilities in NOCC Webmail 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the html_error_occurred parameter in error.php, (2) html_filter_select parameter in filter_prefs.php, (3) html_no... Read more
Affected Products : nocc- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0896
Cross-site scripting (XSS) vulnerability in Sources/Register.php in Simple Machine Forum (SMF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For HTTP header field.... Read more
Affected Products : simple_machines_forum- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0888
index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unspecified denial of service by registering a large number of users.... Read more
Affected Products : invision_power_board- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025