Latest CVE Feed
-
7.5
HIGHCVE-2006-1819
Directory traversal vulnerability in the loadConfig function in index.php in phpWebSite 0.10.2 and earlier allows remote attackers to include arbitrary local files and execute arbitrary PHP code via the hub_dir parameter, as demonstrated by including acce... Read more
Affected Products : phpwebsite- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1800
Directory traversal vulnerability in posts.php in SimpleBBS 1.0.6 through 1.1 allows remote attackers to include and execute arbitrary files via ".." sequences in the language cookie, as demonstrated by by injecting the code into the gl_session cookie of ... Read more
Affected Products : simplebbs- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-1825
Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.... Read more
Affected Products : phplinks- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1811
Multiple SQL injection vulnerabilities in FlexBB 0.5.5 BETA allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) forumid, or (3) threadid parameter to index.php; the (4) ICQ, (5) AIM, (6) MSN, (7) Google Talk, (8) Website Name, (9)... Read more
Affected Products : flexbb- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1806
Cross-site scripting (XSS) vulnerability in index.php in Musicbox 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter in a search action.... Read more
Affected Products : musicbox- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-1796
Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other versions before 2.0.1, allows remote attackers to inject arbitrary web script or HTML to Internet Explorer us... Read more
Affected Products : wordpress- Published: Apr. 17, 2006
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2006-1794
SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function... Read more
Affected Products : mambo- Published: Apr. 17, 2006
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2006-1793
Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) class.forumposts.php and (2) forumpollrenderer.php. NOTE: this issue is closely related to CVE-2006-0659.... Read more
Affected Products : runcms- Published: Apr. 17, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1795
Cross-site scripting (XSS) vulnerability in tablepublisher.cgi in UPDI Network Enterprise @1 Table Publisher 2006-03-23 allows remote attackers to inject arbitrary web script or HTML via the Title of Table field.... Read more
Affected Products : at1_event_publisher- Published: Apr. 17, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1437
UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attackers to read private comments via a direct request to eventpublisher.txt.... Read more
Affected Products : at1_event_publisher- Published: Apr. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1436
Multiple cross-site scripting (XSS) vulnerabilities in UPOINT @1 Event Publisher allow remote attackers to inject arbitrary web script or HTML via the (1) Event, (2) Description, (3) Time, (4) Website, and (5) Public Remarks fields to (a) eventpublisher_a... Read more
Affected Products : at1_event_publisher- Published: Apr. 15, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1792
Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edition before 1.22 has unknown attack vectors and impact related to "authentication exploits". NOTE: this is a diff... Read more
- Published: Apr. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1791
Directory traversal vulnerability in acc.php in QuickBlogger 1.4 allows remote attackers to read or include arbitrary local files via the request parameter. NOTE: this issue can also produce resultant XSS when the associated include statement fails.... Read more
Affected Products : quickblogger- Published: Apr. 14, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-0558
perfmon (perfmon.c) in Linux kernel on IA64 architectures allows local users to cause a denial of service (crash) by interrupting a task while another process is accessing the mm_struct, which triggers a BUG_ON action in the put_page_testzero function.... Read more
Affected Products : linux_kernel- Published: Apr. 14, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1790
A regression fix in Mozilla Firefox 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the InstallTrigger.install method, which leads to memory corruption.... Read more
Affected Products : firefox- Published: Apr. 14, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1738
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) by changing the (1) -moz-grid and (2) -m... Read more
- Published: Apr. 14, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-1737
Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary bytecode via JavaS... Read more
- Published: Apr. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1724
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack ve... Read more
- Published: Apr. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1531
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to th... Read more
- Published: Apr. 14, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1740
Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to spoof secure site indicators such as the locked icon by opening the trusted site in a popup window, then changing the l... Read more
- Published: Apr. 14, 2006
- Modified: Apr. 03, 2025