Latest CVE Feed
-
2.6
LOWCVE-2006-0888
index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unspecified denial of service by registering a large number of users.... Read more
Affected Products : invision_power_board- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0886
Cross-site scripting (XSS) vulnerability in register.php in DEV web management system 1.5 allows remote attackers to inject arbitrary web script or HTML via the "City/Region" field (mesto variable). NOTE: the provenance of this information is unknown; th... Read more
Affected Products : dev_web_management_system- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0890
Directory traversal vulnerability in SpeedProject Squeez 5.1, as used in (1) ZipStar 5.1 and (2) SpeedCommander 11.01.4450, allows remote attackers to overwrite arbitrary files via unspecified manipulations in a (1) JAR or (2) ZIP archive.... Read more
- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0885
Cross-site scripting (XSS) vulnerability in show_news.php in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the show parameter.... Read more
Affected Products : cutenews- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-0884
The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in... Read more
Affected Products : thunderbird- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0878
Noah's Classifieds 1.3 allows remote attackers to obtain the installation path via a direct request to include files, as demonstrated by classifieds/gorum/category.php.... Read more
Affected Products : noahs_classifieds- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0875
Cross-site scripting vulnerability in ratefile.php in RunCMS 1.3a5 allows remote attackers to inject arbitrary web script or HTML via the lid parameter.... Read more
Affected Products : runcms- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0882
Directory traversal vulnerability in include.php in Noah's Classifieds 1.3 allows remote attackers to include arbitrary local files via the otherTemplate parameter to index.php.... Read more
Affected Products : noahs_classifieds- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0872
Directory traversal vulnerability in init.inc.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the lang parameter.... Read more
Affected Products : coppermine_photo_gallery- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0879
SQL injection vulnerability in the search tool in Noah's Classifieds 1.3 allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors.... Read more
Affected Products : noahs_classifieds- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-0871
Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read and include arbitrary files via the mos_change_template parameter. NOTE: CVE-2006-1794 has been assigned ... Read more
Affected Products : mambo- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0881
Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demons... Read more
Affected Products : noahs_classifieds- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0876
POPFile before 0.22.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving character sets within e-mail messages.... Read more
Affected Products : popfile- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0880
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) inf parameter; or, when register_globals is enabled, the (2) upperTemplate and (3) lowerTe... Read more
Affected Products : noahs_classifieds- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0877
Cross-site scripting vulnerability in Easy Forum 2.5 allows remote attackers to inject arbitrary web script or HTML via the image variable.... Read more
Affected Products : easy_forum- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0873
Absolute path traversal vulnerability in docs/showdocs.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via the f parameter, and possibly remote files using UNC share pathnames.... Read more
- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-0813
Heap-based buffer overflow in WinACE 2.60 allows user-assisted attackers to execute arbitrary code via a large header block in an ARJ archive.... Read more
Affected Products : winace- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-0874
Multiple unspecified vulnerabilities in Intensive Point iUser Ecommerce before 2.2 have unspecified vectors and impact, as addressed by "Urgent secure fixes". NOTE: this might be a duplicate of CVE-2006-0854, but the vendor announcement for this issue (f... Read more
Affected Products : iuser_ecommerce- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0195
Interpretation conflict in the MagicHTML filter in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via style sheet specifiers with invalid (1) "/*" and "*/" comments, or (2) a newline in a "url" specifier,... Read more
Affected Products : squirrelmail- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0377
CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka "IMAP injection."... Read more
Affected Products : squirrelmail- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025