Latest CVE Feed
-
7.5
HIGHCVE-2006-0868
Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before 1.3.0r4, allow remote attackers to "falsify authentication credentials," related to the "underlying storage containers."... Read more
- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0860
Multiple cross-site scripting (XSS) vulnerabilities in Michael Salzer Guestbox 0.6, and other versions before 0.8, allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags that follow a "http://" string, which bypasses a regular exp... Read more
Affected Products : guestbox- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0866
PunBB 1.2.10 and earlier allows remote attackers to conduct brute force guessing attacks for an account's password, which may be as short as 4 characters.... Read more
Affected Products : punbb- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0862
Unspecified vulnerability in InfoVista PortalSE 2.0 Build 20087 on Solaris 8 without the IV00038969 hotfix allows remote attackers to read arbitrary files via a crafted URL.... Read more
Affected Products : portalse- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2006-0720
Stack-based buffer overflow in Nullsoft Winamp 5.12 and 5.13 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted .m3u file that causes an incorrect strncpy function call when the player pau... Read more
Affected Products : winamp- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-0855
Stack-based buffer overflow in the fullpath function in misc.c for zoo 2.10 and earlier, as used in products such as Barracuda Spam Firewall, allows user-assisted attackers to execute arbitrary code via a crafted ZOO file that causes the combine function ... Read more
Affected Products : zoo- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0803
The signature verification functionality in the YaST Online Update (YOU) script handling relies on a gpg feature that is not intended for signature verification, which prevents YOU from detecting malicious scripts or code that do not pass the signature ch... Read more
- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-0812
The VisNetic AntiVirus Plug-in (DKAVUpSch.exe) for Mail Server 4.6.0.4, 4.6.1.1, and possibly other versions before 4.6.1.2, does not drop privileges before executing other programs, which allows local users to gain privileges.... Read more
Affected Products : visnetic_antivirus_plug-in_for_mail_server- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0850
SQL injection vulnerability in include/includes/user/login.php in ilchClan before 1.05g allows remote attackers to execute arbitrary SQL commands via the login_name parameter. NOTE: the provenance of this information is unknown; the details are obtained ... Read more
Affected Products : ilchclan- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0851
SQL injection vulnerability in the forum module of ilchClan 1.05g and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter, when creating a newpost.... Read more
Affected Products : ilchclan- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0854
PHP remote file inclusion vulnerability in common.php in Intensive Point iUser Ecommerce allows remote attackers to include arbitrary files via a URL in the include_path variable, which is not initialized before being used.... Read more
Affected Products : iuser_ecommerce- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-0853
Buffer overflow in the IMAP service of TrueNorth Internet Anywhere (IA) eMailserver 5.3.4 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long SEARCH argument.... Read more
Affected Products : ia_emailserver- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0852
Direct static code injection vulnerability in write.php in Admbook 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via the X-Forwarded-For HTTP header field, which is inserted into content-data.php.... Read more
Affected Products : admbook- Published: Feb. 23, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-0848
The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to execute arbitrary commands by tricking a user into downloading a __MACOSX folder that contains metadata (resource fork) that invokes the ... Read more
- Published: Feb. 22, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-0838
IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 stores cleartext passwords in the (1) CMS_DBPASS, (2) CMSM_DBPASS, and (3) RPT_DBPASS fields in /etc/neusecure.conf, and in (4) /opt/NeuSecure/bin/ns_archiver.log, which allows local users to gain privileges.... Read more
Affected Products : netcool_neusecure- Published: Feb. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0835
SQL injection vulnerability in dropbase.php in MitriDAT Web Calendar Pro allows remote attackers to modify internal SQL queries and cause a denial of service (inaccessible database) via the tabls parameter.... Read more
Affected Products : web_calendar_pro- Published: Feb. 22, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-0845
Leif M. Wright's Blog 3.5 allows remote authenticated users with administrative privileges to execute arbitrary programs, including shell commands, by configuring the sendmail path to a malicious pathname.... Read more
Affected Products : web_blog- Published: Feb. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0834
Uniden UIP1868P VoIP Telephone and Router has a default password of admin for the web-based configuration utility, which allows remote attackers to obtain sensitive information on the device such as telephone numbers called, and possibly connect to other ... Read more
Affected Products : uip1868p- Published: Feb. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0844
Leif M. Wright's Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, probably by setting the blogAdmin cookie.... Read more
Affected Products : web_blog- Published: Feb. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0846
Multiple cross-site scripting (XSS) vulnerabilities in Leif M. Wright's Blog 3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Referer and (2) User-Agent HTTP headers, which are stored in a log file and not sanitized when the a... Read more
Affected Products : web_blog- Published: Feb. 22, 2006
- Modified: Apr. 03, 2025