Latest CVE Feed
-
4.3
MEDIUMCVE-2006-0676
Cross-site scripting (XSS) vulnerability in header.php in PHP-Nuke 6.0 to 7.8 allows remote attackers to inject arbitrary web script or HTML via the pagetitle parameter.... Read more
Affected Products : php-nuke- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-0672
Unspecified vulnerability in HP PSC 1210 All-in-One Drivers before 1.0.06 has unknown impact and attack vectors.... Read more
Affected Products : psc_1210_all-in-one- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0668
SQL injection vulnerability in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly in message.php in the espace_membre module. NOTE: the provenance of this information is unknown; the details... Read more
Affected Products : pwsphp- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0673
Multiple SQL injection vulnerabilities in cms/index.php in Magic Calendar Lite 1.02, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) $total_login and (2) $total_password parameter.... Read more
Affected Products : magic_calendar_lite- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0675
Cross-site scripting (XSS) vulnerability in search.php in Siteframe 5.0.1 allows remote attackers to inject arbitrary web script or HTML via the q parameter.... Read more
Affected Products : siteframe- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0662
Cross-site scripting (XSS) vulnerability in Lotus Domino iNotes Client 6.5.4 allows remote attackers to inject arbitrary web script or HTML via email with attached html files, which are directly rendered in the browser.... Read more
- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0663
Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java script:"... Read more
- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0650
Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in multiple scripts, allows remote attackers to inject arbitrary web script or HTML via the cpaint_response_type parameter, which is displayed in a res... Read more
Affected Products : cpaint- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0648
Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to include arbitrary files via the (1) getdate and possibly other parameters used in the replace_files function in search.php and (2) $file variable a... Read more
Affected Products : php_icalendar- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-0659
Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote attackers to execute arbitrary code via the bbPath[path] parameter in (1) class.forumposts.php and (2) forumpollren... Read more
Affected Products : runcms- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2006-0657
Cross-site scripting (XSS) vulnerability in Softcomplex PHP Event Calendar 1.5 allows remote authenticated users to inject arbitrary web script or HTML, and corrupt data, via the (1) username and (2) password parameters, which are not sanitized before bei... Read more
Affected Products : php_event_calendar- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0658
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Confi... Read more
Affected Products : fckeditor- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0598
Buffer overflow in elogd.c in elog before 2.5.7 r1558-4 allows attackers to execute code via unspecified variables, when writing to the log file.... Read more
Affected Products : elog_web_logbook- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0056
Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code ... Read more
Affected Products : pam-mysql- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0600
elog before 2.5.7 r1558-4 allows remote attackers to cause a denial of service (infinite redirection) via a request with the fail parameter set to 1, which redirects to the same request.... Read more
Affected Products : elog_web_logbook- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0597
Multiple stack-based buffer overflows in elogd.c in elog before 2.5.7 r1558-4 allow attackers to cause a denial of service (application crash) and possibly execute code via long "revision attributes".... Read more
Affected Products : elog_web_logbook- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0664
Cross-site scripting (XSS) vulnerability in config_defaults_inc.php in Mantis before 1.0 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtai... Read more
Affected Products : mantis- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-0652
WHMCompleteSolution (WHMCS) before 2.3 assigns incorrect permissions to "resellers", which allows remote authenticated users to perform privileged actions or obtain sensitive information. NOTE: this report is based on a vendor bug report that identified ... Read more
Affected Products : whmcompletesolution- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0651
SQL injection vulnerability in index.php in vwdev allows remote attackers to execute arbitrary SQL commands via the UID parameter in the definition Page.... Read more
Affected Products : vwdev- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0654
check.php in Hinton Design phpht Topsites 1.3 does not validate passwords when using cookies, which allows remote attackers to bypass authentication via unspecified cookies.... Read more
Affected Products : phpht_topsites- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025