Latest CVE Feed
-
5.0
MEDIUMCVE-2006-0872
Directory traversal vulnerability in init.inc.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the lang parameter.... Read more
Affected Products : coppermine_photo_gallery- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0879
SQL injection vulnerability in the search tool in Noah's Classifieds 1.3 allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors.... Read more
Affected Products : noahs_classifieds- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-0871
Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read and include arbitrary files via the mos_change_template parameter. NOTE: CVE-2006-1794 has been assigned ... Read more
Affected Products : mambo- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0881
Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demons... Read more
Affected Products : noahs_classifieds- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0876
POPFile before 0.22.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving character sets within e-mail messages.... Read more
Affected Products : popfile- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0880
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) inf parameter; or, when register_globals is enabled, the (2) upperTemplate and (3) lowerTe... Read more
Affected Products : noahs_classifieds- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0877
Cross-site scripting vulnerability in Easy Forum 2.5 allows remote attackers to inject arbitrary web script or HTML via the image variable.... Read more
Affected Products : easy_forum- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0873
Absolute path traversal vulnerability in docs/showdocs.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via the f parameter, and possibly remote files using UNC share pathnames.... Read more
- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-0813
Heap-based buffer overflow in WinACE 2.60 allows user-assisted attackers to execute arbitrary code via a large header block in an ARJ archive.... Read more
Affected Products : winace- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-0874
Multiple unspecified vulnerabilities in Intensive Point iUser Ecommerce before 2.2 have unspecified vectors and impact, as addressed by "Urgent secure fixes". NOTE: this might be a duplicate of CVE-2006-0854, but the vendor announcement for this issue (f... Read more
Affected Products : iuser_ecommerce- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0195
Interpretation conflict in the MagicHTML filter in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via style sheet specifiers with invalid (1) "/*" and "*/" comments, or (2) a newline in a "url" specifier,... Read more
Affected Products : squirrelmail- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0377
CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka "IMAP injection."... Read more
Affected Products : squirrelmail- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0188
webmail.php in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary web pages into the right frame via a URL in the right_frame parameter. NOTE: this has been called a cross-site scripting (XSS) issue, but it is different than what is ... Read more
Affected Products : squirrelmail- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-0300
Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.... Read more
Affected Products : tar- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0865
PunBB 1.2.10 and earlier allows remote attackers to cause a denial of service (resource consumption) by registering many user accounts quickly.... Read more
Affected Products : punbb- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0859
Michael Salzer Guestbox 0.6, and other versions before 0.8, allows remote attackers to post an admin comment to a guestbook entry via a certain modified form, possibly related to the nummer parameter.... Read more
Affected Products : guestbox- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0862
Unspecified vulnerability in InfoVista PortalSE 2.0 Build 20087 on Solaris 8 without the IV00038969 hotfix allows remote attackers to read arbitrary files via a crafted URL.... Read more
Affected Products : portalse- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0866
PunBB 1.2.10 and earlier allows remote attackers to conduct brute force guessing attacks for an account's password, which may be as short as 4 characters.... Read more
Affected Products : punbb- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0860
Multiple cross-site scripting (XSS) vulnerabilities in Michael Salzer Guestbox 0.6, and other versions before 0.8, allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags that follow a "http://" string, which bypasses a regular exp... Read more
Affected Products : guestbox- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-0864
filescan in Global Hauri ViRobot 2.0 20050817 does not verify the Cookie HTTP header, which allows remote attackers to gain administrative privileges via an arbitrary cookie value.... Read more
Affected Products : virobot- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025