Latest CVE Feed
-
5.0
MEDIUMCVE-2006-0875
Cross-site scripting vulnerability in ratefile.php in RunCMS 1.3a5 allows remote attackers to inject arbitrary web script or HTML via the lid parameter.... Read more
Affected Products : runcms- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0882
Directory traversal vulnerability in include.php in Noah's Classifieds 1.3 allows remote attackers to include arbitrary local files via the otherTemplate parameter to index.php.... Read more
Affected Products : noahs_classifieds- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0872
Directory traversal vulnerability in init.inc.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the lang parameter.... Read more
Affected Products : coppermine_photo_gallery- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0879
SQL injection vulnerability in the search tool in Noah's Classifieds 1.3 allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors.... Read more
Affected Products : noahs_classifieds- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-0871
Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read and include arbitrary files via the mos_change_template parameter. NOTE: CVE-2006-1794 has been assigned ... Read more
Affected Products : mambo- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0881
Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demons... Read more
Affected Products : noahs_classifieds- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0876
POPFile before 0.22.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving character sets within e-mail messages.... Read more
Affected Products : popfile- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0880
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) inf parameter; or, when register_globals is enabled, the (2) upperTemplate and (3) lowerTe... Read more
Affected Products : noahs_classifieds- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0877
Cross-site scripting vulnerability in Easy Forum 2.5 allows remote attackers to inject arbitrary web script or HTML via the image variable.... Read more
Affected Products : easy_forum- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0873
Absolute path traversal vulnerability in docs/showdocs.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via the f parameter, and possibly remote files using UNC share pathnames.... Read more
- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-0813
Heap-based buffer overflow in WinACE 2.60 allows user-assisted attackers to execute arbitrary code via a large header block in an ARJ archive.... Read more
Affected Products : winace- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-0874
Multiple unspecified vulnerabilities in Intensive Point iUser Ecommerce before 2.2 have unspecified vectors and impact, as addressed by "Urgent secure fixes". NOTE: this might be a duplicate of CVE-2006-0854, but the vendor announcement for this issue (f... Read more
Affected Products : iuser_ecommerce- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0195
Interpretation conflict in the MagicHTML filter in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via style sheet specifiers with invalid (1) "/*" and "*/" comments, or (2) a newline in a "url" specifier,... Read more
Affected Products : squirrelmail- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0377
CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka "IMAP injection."... Read more
Affected Products : squirrelmail- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0188
webmail.php in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary web pages into the right frame via a URL in the right_frame parameter. NOTE: this has been called a cross-site scripting (XSS) issue, but it is different than what is ... Read more
Affected Products : squirrelmail- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-0300
Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.... Read more
Affected Products : tar- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0865
PunBB 1.2.10 and earlier allows remote attackers to cause a denial of service (resource consumption) by registering many user accounts quickly.... Read more
Affected Products : punbb- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0859
Michael Salzer Guestbox 0.6, and other versions before 0.8, allows remote attackers to post an admin comment to a guestbook entry via a certain modified form, possibly related to the nummer parameter.... Read more
Affected Products : guestbox- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0862
Unspecified vulnerability in InfoVista PortalSE 2.0 Build 20087 on Solaris 8 without the IV00038969 hotfix allows remote attackers to read arbitrary files via a crafted URL.... Read more
Affected Products : portalse- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0866
PunBB 1.2.10 and earlier allows remote attackers to conduct brute force guessing attacks for an account's password, which may be as short as 4 characters.... Read more
Affected Products : punbb- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025