Latest CVE Feed
-
7.5
HIGHCVE-2006-0716
SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.... Read more
Affected Products : snews- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0694
Unspecified vulnerability in the loaders (load_*.php) in Ansilove before 1.03 allows remote attackers to read arbitrary files via unspecified vectors involving "converting files accessible by the webserver".... Read more
Affected Products : ansilove- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-0666
Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 through 5.3.0.33 allows local users to cause a denial of service (system crash) via unknown vectors related to EMULATE_VMX.... Read more
Affected Products : aix- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0711
The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled.... Read more
Affected Products : neomail- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0715
Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field.... Read more
Affected Products : snews- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0690
Multiple SQL injection vulnerabilities in TTS Time Tracking Software 3.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : time_tracking_software- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0702
admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter. NOTE: due to the lack of details, the specific vulnerability type cannot be determined, altho... Read more
Affected Products : imagevue- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0710
Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code via a crafted LDAP request, as demonstrated by ProtoVer Sample LDAP.... Read more
Affected Products : m-vault_server- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0713
Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) lang parameter in docs/index.php and the language parameter in (2) install/install.php, (3) install/sec_stage_install.... Read more
Affected Products : linpha- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0717
IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.... Read more
Affected Products : tivoli_directory_server- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-0697
Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.... Read more
Affected Products : zen_cart- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-0698
Unspecified vulnerabilities in Zen Cart before 1.2.7 allow remote attackers to cause unknown impact via unspecified vectors related to "other attempted exploits" other than SQL injection.... Read more
Affected Products : zen_cart- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0692
Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php.... Read more
Affected Products : php_mysql_timesheet- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0700
imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions.... Read more
Affected Products : imagevue- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0714
Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the adodbpath parameter.... Read more
Affected Products : flyspray- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0688
PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.... Read more
Affected Products : indexu- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0701
readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters.... Read more
Affected Products : imagevue- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0693
Multiple SQL injection vulnerabilities in rb_auth.php in Roberto Butti CALimba 0.99.2 beta and earlier allow remote attackers to execute arbitrary SQL commands and bypass login authentication via the (1) login and (2) password parameters.... Read more
Affected Products : calimba- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0696
SQL injection vulnerability in Zen Cart before 1.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : zen_cart- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0699
Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter.... Read more
Affected Products : qwikiwiki- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025