Latest CVE Feed
-
7.5
HIGHCVE-2006-1805
SQL injection vulnerability in member.php in PowerClan 1.14 allows remote attackers to execute arbitrary SQL commands via the memberid parameter.... Read more
Affected Products : powerclan- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1803
Cross-site scripting (XSS) vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to inject arbitrary web script or HTML via the sql_query parameter.... Read more
Affected Products : phpmyadmin- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-1820
Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this might be resultant from the directory traversal vulnerability.... Read more
Affected Products : modxcms- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1826
Multiple cross-site scripting (XSS) vulnerabilities in Snipe Gallery 3.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in view.php, (2) keyword parameter in search.php, and (3) image_id parame... Read more
Affected Products : snipe_gallery- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1816
PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers to execute arbitrary code via a URL in the systempath parameter to (1) ImpExModule.php, (2) ImpExController.php, and (3) ImpExDisplay.php.... Read more
Affected Products : vbulletin- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1818
Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly including the (1) first_name and (2) last_name parameter in myaccounts.php. NOTE: por... Read more
Affected Products : warforge.news- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1799
censtore.cgi in Censtore 7.3.002 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.... Read more
Affected Products : censtore- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1801
Cross-site scripting (XSS) vulnerability in planetsearchplus.php in planetSearch+ allows remote attackers to inject arbitrary web script or HTML via the search_exp parameter.... Read more
Affected Products : planetsearch\+- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1823
Directory traversal vulnerability in FarsiNews 2.5.3 Pro and earlier allows remote attackers to obtain the installation path via ".." sequences in the archive parameter to index.php, which leaks the full pathname in an error message.... Read more
Affected Products : farsinews- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-1814
NetBSD 1.6, 2.0, 2.1 and 3.0 allows local users to cause a denial of service (memory exhaustion) by using the sysctl system call to lock a large buffer into physical memory.... Read more
Affected Products : netbsd- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-1822
Cross-site scripting (XSS) vulnerability in search.php in FarsiNews 2.5.3 Pro and earlier allows remote attackers to inject arbitrary web script or HTML via the selected_search_arch parameter.... Read more
Affected Products : farsinews- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1798
SQL injection vulnerability in rateit.php in RateIt 2.2 allows remote attackers to execute arbitrary SQL commands via the rateit_id parameter.... Read more
Affected Products : rateit- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-0744
Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the w... Read more
Affected Products : linux_kernel- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1812
phpWebFTP 3.2 and earlier stores script.js under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.... Read more
Affected Products : phpwebftp- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1804
SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter.... Read more
Affected Products : phpmyadmin- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-1796
Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other versions before 2.0.1, allows remote attackers to inject arbitrary web script or HTML to Internet Explorer us... Read more
Affected Products : wordpress- Published: Apr. 17, 2006
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2006-1794
SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function... Read more
Affected Products : mambo- Published: Apr. 17, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1795
Cross-site scripting (XSS) vulnerability in tablepublisher.cgi in UPDI Network Enterprise @1 Table Publisher 2006-03-23 allows remote attackers to inject arbitrary web script or HTML via the Title of Table field.... Read more
Affected Products : at1_event_publisher- Published: Apr. 17, 2006
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2006-1793
Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) class.forumposts.php and (2) forumpollrenderer.php. NOTE: this issue is closely related to CVE-2006-0659.... Read more
Affected Products : runcms- Published: Apr. 17, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1436
Multiple cross-site scripting (XSS) vulnerabilities in UPOINT @1 Event Publisher allow remote attackers to inject arbitrary web script or HTML via the (1) Event, (2) Description, (3) Time, (4) Website, and (5) Public Remarks fields to (a) eventpublisher_a... Read more
Affected Products : at1_event_publisher- Published: Apr. 15, 2006
- Modified: Apr. 03, 2025