Latest CVE Feed
-
7.5
HIGHCVE-2006-0918
Buffer overflow in RITLabs The Bat! 3.60.07 allows remote attackers to execute arbitrary code via a long Subject field.... Read more
Affected Products : the_bat- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0910
Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to list directory contents via a direct request to multiple directories, including (1) sources/loginauth/convert/, (2) sources/portal_plugins/, (3) cache/skin_cache/cacheid_2/, (4) ips_k... Read more
Affected Products : invision_power_board- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0915
Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which allows remote attackers to trigger a SQL error.... Read more
Affected Products : bugzilla- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2006-0914
Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote attackers to trigger a SQL error.... Read more
Affected Products : bugzilla- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2006-0913
SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows remote authenticated users with administrative privileges to execute arbitrary SQL commands via the whinedays parameter, as accessible from editparams.cgi.... Read more
Affected Products : bugzilla- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0922
CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results in an absolute path traversal vulnerability in FileUpload in connector.php (aka upload.php) that allows r... Read more
Affected Products : cubecart- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0916
Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domai... Read more
Affected Products : bugzilla- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0908
PHP-Nuke 7.8 Patched 3.2 allows remote attackers to bypass SQL injection protection mechanisms via /%2a (/*) sequences with the "ad_click" word in the query string, as demonstrated via the kala parameter.... Read more
Affected Products : php-nuke- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0906
SQL injection vulnerability in D3Jeeb Pro 3 allows remote attackers to execute arbitrary SQL commands via the catid parameter in (1) fastlinks.php and (2) catogary.php.... Read more
Affected Products : d3jeeb_pro- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0907
SQL injection vulnerability in PHP-Nuke before 7.8 Patched 3.2 allows remote attackers to execute arbitrary SQL commands via encoded /%2a (/*) sequences in the query string, which bypasses regular expressions that are intended to protect against SQL injec... Read more
Affected Products : php-nuke- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-0903
MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function. NOTE: this issue was originally reported for the mysql_query functi... Read more
- Published: Feb. 27, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-0736
Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
- Published: Feb. 27, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-0900
nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demonstrated by the ProtoVer NFS test suite.... Read more
Affected Products : freebsd- Published: Feb. 27, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0899
Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot dot) sequences in the template parameter.... Read more
Affected Products : image_gallery_management_system- Published: Feb. 27, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-0901
Unspecified vulnerability in the hsfs filesystem in Solaris 8, 9, and 10 allows unspecified attackers to cause a denial of service (panic) or execute arbitrary code.... Read more
- Published: Feb. 27, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0897
SQL injection vulnerability in VCS Virtual Program Management Intranet (VPMi) Enterprise 3.3 allows remote attackers to execute arbitrary SQL commands via the UpdateID0 parameter to Service_Requests.asp. NOTE: the provenance of this information is unknow... Read more
Affected Products : vpmi_enterprise- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0889
Cross-site scripting (XSS) vulnerability in Calcium 3.10.1 allows remote attackers to inject arbitrary web script or HTML via the EventText parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party i... Read more
Affected Products : calcium- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0887
Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib distribution is available on the server, allows remote attackers to execute arbitrary PHP code by including a base64-encoded representat... Read more
Affected Products : phplib- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0891
Multiple directory traversal vulnerabilities in NOCC Webmail 1.0 allow remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing NULL (%00) byte in (1) the _SESSION['nocc_theme'] parameter in (a) html/footer.php; and (2) the la... Read more
Affected Products : nocc- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0892
NOCC Webmail 1.0 stores e-mail attachments in temporary files with predictable filenames, which makes it easier for remote attackers to execute arbitrary code by accessing the e-mail attachment via directory traversal vulnerabilities.... Read more
Affected Products : nocc- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025