Latest CVE Feed
-
6.8
MEDIUMCVE-2006-1324
Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter when a SQL error is generated.... Read more
Affected Products : burning_board- Published: Mar. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1061
Heap-based buffer overflow in cURL and libcURL 7.15.0 through 7.15.2 allows remote attackers to execute arbitrary commands via a TFTP URL (tftp://) with a valid hostname and a long path.... Read more
- Published: Mar. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1327
SQL injection vulnerability in reg.php in SoftBB 0.1 allows remote attackers to execute arbitrary SQL commands via the mail parameter.... Read more
Affected Products : softbb- Published: Mar. 21, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-1331
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) method or (2) list parameter.... Read more
Affected Products : noahs_classifieds- Published: Mar. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1326
Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board 2.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) result_type, (2) search_in, (3) nav, (4) forums, and (5) s parameters in the Search action to index... Read more
Affected Products : invision_power_board- Published: Mar. 21, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1334
Multiple SQL injection vulnerabilities in Maian Weblog 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) entry and (2) email parameters to (a) print.php and (b) mail.php.... Read more
Affected Products : maian_weblog- Published: Mar. 21, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-1325
Cross-site scripting (XSS) vulnerability in Streber 0.055 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more
Affected Products : streber- Published: Mar. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1328
SQL injection vulnerability in count.php in Skull-Splitter PHP Downloadcounter for Wallpapers 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) count_fieldname, (2) url_fieldname, or (3) url parameter.... Read more
Affected Products : download_counter_wallpaper- Published: Mar. 21, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1333
Multiple SQL injection vulnerabilities in BetaParticle Blog 6.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to template_permalink.asp or (2) fldGalleryID parameter to template_gallery_detail.asp.... Read more
Affected Products : betaparticle_blog- Published: Mar. 21, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-1323
Directory traversal vulnerability in WinHKI 1.6 and earlier allows user-assisted attackers to overwrite arbitrary files via a (1) RAR, (2) TAR, (3) ZIP, or (4) TAR.GZ archive with a file whose file name contains ".." sequences.... Read more
Affected Products : winhki- Published: Mar. 20, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1322
Novell Netware NWFTPD 5.06.05 allows remote attackers to cause a denial of service (ABEND) via an MDTM command that uses a long path for the target file, possibly due to a buffer overflow.... Read more
- Published: Mar. 20, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1320
util.c in rssh 2.3.0 in Debian GNU/Linux does not use braces to make a block, which causes a check for CVS to always succeed and allows rsync and rdist to bypass intended access restrictions in rssh.conf.... Read more
Affected Products : rssh- Published: Mar. 20, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1321
Cross-site scripting (XSS) vulnerability in webcheck before 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the (1) url, (2) title, or (3) author name in a crawled page, which is not properly sanitized in the tooltips of a report.... Read more
Affected Products : webcheck- Published: Mar. 20, 2006
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2006-1319
chpst in runit 1.3.3-1 for Debian GNU/Linux, when compiled on little endian i386 machines against dietlibc, does not properly handle when multiple groups are specified in the -u option, which causes chpst to assign permissions for the root group due to in... Read more
Affected Products : runit- Published: Mar. 20, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-1287
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060130 allows remote attackers to steal cookies and probably conduct other activities when the victim is using Internet Explorer.... Read more
Affected Products : invision_power_board- Published: Mar. 19, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-1284
The installation of SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, includes a default administrator login account and password, which allows local users to gain privileges or modify tasks.... Read more
- Published: Mar. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1293
Cross-site scripting (XSS) vulnerability in index.php in Contrexx CMS 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF).... Read more
Affected Products : contrexx- Published: Mar. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1288
Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060105 allow remote attackers to execute arbitrary SQL commands via cookies, related to (1) arrays of id/stamp pairs and (2) the keys in arrays of key/value pair... Read more
Affected Products : invision_power_board- Published: Mar. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1291
publish.ical.php in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier does not require authentication for write access to the calendars directory, which allows remote attackers to upload and execute arbitrary PHP scripts via a WebDAV PUT request with ... Read more
Affected Products : php_icalendar- Published: Mar. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1296
Untrusted search path vulnerability in Beagle 0.2.2.1 might allow local users to gain privileges via a malicious beagle-info program in the current working directory, or possibly directories specified in the PATH.... Read more
Affected Products : beagle- Published: Mar. 19, 2006
- Modified: Apr. 03, 2025