Latest CVE Feed
-
6.8
MEDIUMCVE-2006-1121
Cross-site scripting (XSS) vulnerability in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the query string to index.php.... Read more
Affected Products : cutenews- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1123
SQL injection vulnerability in D2KBlog 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the memName parameter in a cookie.... Read more
Affected Products : d2kblog- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-1122
Cross-site scripting (XSS) vulnerability in Default.asp in D2KBlog 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.... Read more
Affected Products : d2kblog- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1120
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 6.1.1 and earlier, with register_globals enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) its_url parameter in the documents page and (2) url parameter in ... Read more
Affected Products : dcp-portal- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1124
Buffer overflow in RevilloC MailServer and Proxy 1.21 allows remote attackers to execute arbitrary code via a long USER command.... Read more
Affected Products : revilloc_mailserver- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0743
Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.... Read more
Affected Products : log4net- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-1119
fantastico in Cpanel does not properly handle when it has insufficient permissions to perform certain file operations, which allows remote authenticated users to obtain the full pathname, which is leaked in a PHP error message.... Read more
- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1113
SQL injection vulnerability in podcast.php in Loudblog before 0.42 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : loudblog- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1108
SQL injection vulnerability in news.php in NMDeluxe before 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : nmdeluxe- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1100
Buffer overflow in the sgetstr function in shared/cube.h in Sauerbraten 2006_02_28 and earlier, as derived from the Cube engine, allows remote attackers to execute arbitrary code via long streams of input data.... Read more
- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1097
Multiple cross-site scripting (XSS) vulnerabilities in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allow remote attackers to inject arbitrary web script or HTML via the fileid parameter to (1) info_db.php or (2) database.php.... Read more
Affected Products : datenbank_module- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1104
Multiple SQL injection vulnerabilities in Pixelpost 1.5 beta 1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the showimage parameter in index.php; and the (2) USER_AGENT, (3) HTTP_REFERER, and (4) HTTP_HOST HTTP header field... Read more
Affected Products : pixelpost- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1094
SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) database.php.... Read more
- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1103
engine/server.cpp in Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial of service (segmentation fault) via a client that does not completely join the game and times out, which results in a null pointer dere... Read more
- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1089
Cross-site scripting (XSS) vulnerability in header.php in PunBB 1.2.10 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly handled when the PHP_SELF variable is used to handle a pun_page tag.... Read more
Affected Products : punbb- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1105
Pixelpost 1.5 beta 1 and earlier allows remote attackers to obtain configuration information via a direct request to includes/phpinfo.php, which calls the phpinfo function. NOTE: the vendor has disputed some issues from the original disclosure, but due t... Read more
Affected Products : pixelpost- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1098
Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers to execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php. NOTE: the vendor has disputed this issue in a comment on the researcher... Read more
Affected Products : nz_ecommerce- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-1092
Unspecified vulnerability in the pagedata subsystem of the process file system (/proc) in Solaris 8 through 10 allows local users to cause a denial of service (system hang or panic) via unknown attack vectors that cause cause the kmem_oversize arena to al... Read more
- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1099
PHP remote file include vulnerability in logIT 1.3 and 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party informat... Read more
Affected Products : logit- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1118
SQL injection vulnerability in bmail before Aardvark PR9.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving GBK character sets.... Read more
Affected Products : bmail- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025