Latest CVE Feed
-
4.3
MEDIUMCVE-2006-0511
Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle, which allows subsequent users to log in as the previous user and gain privileges. NOTE: the vendor has disputed this issue, s... Read more
- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0507
Multiple cross-site scripting (XSS) vulnerabilities in Easy CMS allow remote attackers to inject arbitrary web script or HTML via (1) unknown attack vectors in the administrative interface and (2) input fields of the contact form.... Read more
Affected Products : easy_cms- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0510
SQL injection vulnerability in userlogin.jsp in Daffodil CRM 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified parameters in a login action.... Read more
Affected Products : daffodil_crm- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0509
Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web script or HTML via (1) the contact_search parameter and (2) unspecified url fields.... Read more
Affected Products : cerberus_helpdesk- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0505
zbattle.net Zbattle client 1.09 SR-1 beta allows remote attackers to cause an unspecified denial of service by rapidly creating and closing a game.... Read more
Affected Products : zbattle_client- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0506
Cross-site scripting (XSS) vulnerability in index.php in Nuked-klaN 1.7 allows remote attackers to inject arbitrary web script or HTML via the letter parameter.... Read more
Affected Products : nuked-klan- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0500
MyCO Guestbook 1.0 stores the admin directory under the web document root with insufficient access control, which allows remote attackers to perform unspecified privileged actions by directly accessing files via a URL.... Read more
Affected Products : myco_guestbook- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0499
Cross-site scripting (XSS) vulnerability in rlink.php in Rlink 1.0.0 module for phpBB allows remote attackers to inject arbitrary web script or HTML via the url parameter. NOTE: the provenance of this information is unknown; the details are obtained sole... Read more
Affected Products : rlink- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0502
PHP remote file inclusion vulnerability in loginout.php in FarsiNews 2.1 Beta 2 and earlier, with register_globals enabled, allows remote attackers to include arbitrary files via a URL in the cutepath parameter.... Read more
Affected Products : farsinews- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0504
Unspecified vulnerability in MailEnable Enterprise Edition before 1.2 allows remote attackers to cause a denial of service (CPU utilization) by viewing "formatted quoted-printable emails" via webmail.... Read more
Affected Products : mailenable_enterprise- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0501
Cross-site scripting (XSS) vulnerability in MyCO Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the Name field, when registering a user.... Read more
Affected Products : myco_guestbook- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0503
IMAP service in MailEnable Professional Edition before 1.72 allows remote attackers to cause a denial of service (service crash) via unspecified vectors involving the EXAMINE command.... Read more
Affected Products : mailenable_professional- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0497
Multiple SQL injection vulnerabilities in PHP GEN before 1.4 allow remote attackers to inject arbitrary SQL commands via unknown attack vectors.... Read more
Affected Products : php_gen- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0498
Multiple cross-site scripting (XSS) vulnerabilities in PHP GEN before 1.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more
Affected Products : php_gen- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0487
Multiple unspecified vulnerabilities in Tumbleweed MailGate Email Firewall (EMF) 6.x allow remote attackers to (1) trigger temporarily incorrect processing of an e-mail message under "extremely heavy loads" and (2) cause an "increased number of missed spa... Read more
Affected Products : mailgate_email_firewall- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0492
Multiple SQL injection vulnerabilities in Calendarix allow remote attackers to execute arbitrary SQL commands via (1) the catview parameter in cal_functions.inc.php and (2) the login parameter in cal_login.php. NOTE: the catview vector might overlap CVE-... Read more
Affected Products : calendarix- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-0485
The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain other releases before 25 January 2006 does not perform Authentication, Authorization, and Accounting (AAA) command authorization checks, which may allow loc... Read more
Affected Products : ios- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0490
SQL injection vulnerability in login.asp in ASPThai.Net ASPThai Forums 8.0 and earlier allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the password field.... Read more
Affected Products : aspthai_forums- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0491
SQL injection vulnerability in SZUserMgnt.class.php in SZUserMgnt 1.4 allows remote attackers to execute arbitrary SQL commands via the username parameter.... Read more
Affected Products : szusermgnt- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-0488
The VDM (Virtual DOS Machine) emulation environment for MS-DOS applications in Windows 2000, Windows XP SP2, and Windows Server 2003 allows local users to read the first megabyte of memory and possibly obtain sensitive information, as demonstrated by dump... Read more
- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025