Latest CVE Feed
-
5.0
MEDIUMCVE-2006-0702
admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter. NOTE: due to the lack of details, the specific vulnerability type cannot be determined, altho... Read more
Affected Products : imagevue- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0710
Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code via a crafted LDAP request, as demonstrated by ProtoVer Sample LDAP.... Read more
Affected Products : m-vault_server- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0713
Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) lang parameter in docs/index.php and the language parameter in (2) install/install.php, (3) install/sec_stage_install.... Read more
Affected Products : linpha- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0715
Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field.... Read more
Affected Products : snews- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0690
Multiple SQL injection vulnerabilities in TTS Time Tracking Software 3.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : time_tracking_software- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0694
Unspecified vulnerability in the loaders (load_*.php) in Ansilove before 1.03 allows remote attackers to read arbitrary files via unspecified vectors involving "converting files accessible by the webserver".... Read more
Affected Products : ansilove- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0703
Unspecified vulnerability in index.php in imageVue 16.1 has unknown impact, probably a cross-site scripting (XSS) vulnerability involving the query string that is not quoted when inserted into style and body tags, as demonstrated using a bgcol parameter.... Read more
Affected Products : imagevue- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0716
SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.... Read more
Affected Products : snews- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0707
PyBlosxom before 1.3.2, when running on certain webservers, allows remote attackers to read arbitrary files via an HTTP request with multiple leading / (slash) characters, which is accessed using the PATH_INFO variable.... Read more
Affected Products : pyblosxom- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0704
iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory, which results in an error messa... Read more
Affected Products : ie_integrator- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-0697
Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.... Read more
Affected Products : zen_cart- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0699
Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter.... Read more
Affected Products : qwikiwiki- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0706
Cross-site scripting vulnerability in eintrag.php in Gästebuch (Gastebuch) before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the URL, which is used in the homepage parameter.... Read more
Affected Products : gastebuch- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0695
Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them directly in the upload directory.... Read more
Affected Products : ansilove- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0696
SQL injection vulnerability in Zen Cart before 1.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : zen_cart- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0693
Multiple SQL injection vulnerabilities in rb_auth.php in Roberto Butti CALimba 0.99.2 beta and earlier allow remote attackers to execute arbitrary SQL commands and bypass login authentication via the (1) login and (2) password parameters.... Read more
Affected Products : calimba- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0691
edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbitrary data belonging to any account.... Read more
Affected Products : time_tracking_software- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0689
Cross-site scripting (XSS) vulnerability in the Registration Form in TTS Time Tracking Software 3.0 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter.... Read more
Affected Products : time_tracking_software- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-0666
Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 through 5.3.0.33 allows local users to cause a denial of service (system crash) via unknown vectors related to EMULATE_VMX.... Read more
Affected Products : aix- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0712
mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, which allows remote attackers to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability.... Read more
Affected Products : squishdot- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025