Latest CVE Feed
-
7.5
HIGHCVE-2006-1890
Multiple PHP remote file inclusion vulnerabilities in myWebland myEvent 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter in (1) event.php and (2) initialize.php. NOTE: vector 2 was later reported to affect ... Read more
Affected Products : myevent- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1894
Cross-site scripting (XSS) vulnerability in RevoBoard 1.8, as derived from PunBB, allows remote attackers to inject arbitrary web script or HTML via a substitution cipher of the email tag, which is transformed when the application's e-mail address obfusca... Read more
Affected Products : revoboard- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1878
Cross-site scripting (XSS) vulnerability in index.php in phpFaber TopSites allows remote attackers to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : topsites- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1887
Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Security Server 8.95.J1 has unknown impact and attack vectors, aka Vuln# JDE01.... Read more
Affected Products : enterpriseone- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-1889
Cross-site scripting (XSS) vulnerability in the search action handler in index.php in Nils Asmussen (aka SCRIPTSOLUTION) Boardsolution 1.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the "Search for" item (keyword param... Read more
Affected Products : boardsolution- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1880
Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, as identified by Vuln# (1) APPS01 in the (a) Application Install component; (2) APPS09 in the (b) Oracle Diagnostics Interf... Read more
Affected Products : e-business_suite- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1906
Cross-site scripting (XSS) vulnerability in index.php in jjgan852 phpLister 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : phplister- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-1871
SQL injection vulnerability in Oracle Database Server 9.2.0.7 and 10.1.0.5 allows remote attackers to execute arbitrary SQL commands via the DELETE_FROM_TABLE function in the DBMS_LOGMNR_SESSION (Log Miner) package, aka Vuln# DB06.... Read more
Affected Products : database_server- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1883
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite and Applications 11.5.10CU1 has unknown impact and attack vectors, aka Vuln# APPS05.... Read more
Affected Products : e-business_suite- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1872
Unspecified vulnerability in Oracle Database Server 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors in the Oracle Enterprise Manager Intelligent Agent component, aka Vuln# DB07.... Read more
Affected Products : database_server- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1901
Mozilla Camino 1.0 and earlier allow remote attackers to cause a denial of service (null dereference and application crash or hang) via HTML with certain improperly nested elements. NOTE: this might be the same issue as CVE-2006-1724.... Read more
Affected Products : camino- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1867
Unspecified vulnerability in Oracle Database Server 9.2.0.6 has unknown impact and attack vectors in the Advanced Replication component, aka Vuln# DB02.... Read more
Affected Products : database_server- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2006-1873
Unspecified vulnerability in Oracle Database Server 9.2.0.7, 10.1.0.4, and 10.2.0.1 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB08.... Read more
Affected Products : database_server- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
9.7
HIGHCVE-2006-1866
Multiple unspecified vulnerabilities in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and other versions have unknown impact and attack vectors in the (1) Advanced Replication component, as identified by Vuln# DB01, and (2) Oracle Spatial co... Read more
Affected Products : database_server- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1874
Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, and 9.2.0.6 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB09. NOTE: Oracle has not disputed reliable claims that this issue is SQL injection in MDS... Read more
Affected Products : database_server- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2006-1876
Unspecified vulnerability in Oracle Database Server 9.2.0.7 and 10.1.0.4 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB12. NOTE: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed... Read more
Affected Products : database_server- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1886
Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise 8.46.12 and 8.47.04 has unknown impact and attack vectors, aka Vuln# PSE01.... Read more
Affected Products : peoplesoft_enterprise- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1904
Cross-site scripting (XSS) vulnerability in index.php in AnimeGenesis Gallery allows remote attackers to inject arbitrary web script or HTML via the cat parameter.... Read more
Affected Products : gallery- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1884
Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01.... Read more
- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
6.0
MEDIUMCVE-2006-1896
Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature values, possibly involving the highlight functiona... Read more
Affected Products : phpbb- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025