Latest CVE Feed
-
4.3
MEDIUMCVE-2006-0254
Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed ... Read more
Affected Products : geronimo- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0252
SQL injection vulnerability in Benders Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by the (1) year, (2) month, and (3) day parameters.... Read more
Affected Products : benders_calendar- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0251
Cross-site scripting (XSS) vulnerability in fom.cgi in Faq-O-Matic 2.711 allows remote attackers to inject arbitrary web script or HTML via the (1) _duration, (2) file, and (3) cmd parameters.... Read more
Affected Products : faq-o-matic- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0246
Cross-site scripting (XSS) vulnerability in down.pl in Widexl Download Tracker 1.06 allows remote attackers to inject arbitrary web script or HTML via the ID parameter.... Read more
Affected Products : download_tracker- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0249
SQL injection vulnerability in viewcat.php in BitDamaged geoBlog MOD_1.0 allows remote attackers to execute arbitrary SQL commands, then steal credentials and upload files, via the cat parameter ($tmpCategory variable).... Read more
Affected Products : geoblog- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0247
Cross-site scripting (XSS) vulnerability in anyboard.cgi in Netbula Anyboard 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the tK parameter in a find command.... Read more
Affected Products : anyboard- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-0250
Format string vulnerability in the snmp_input function in snmptrapd in CMU SNMP utilities (cmu-snmp) allows remote attackers to execute arbitrary code by sending crafted SNMP messages to UDP port 162.... Read more
Affected Products : snmptrapd- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0238
SQL injection vulnerability in wp-stats.php in GaMerZ WP-Stats 2.0 allows remote attackers to execute arbitrary SQL commands via the author parameter.... Read more
Affected Products : wp-stats- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0237
Cross-site scripting (XSS) vulnerability in index.php in GTP iCommerce allows remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) subcat parameters. NOTE: the provenance of this information is unknown; the details are obtained... Read more
Affected Products : icommerce- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-0236
GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an attachment with a filename containing a large number of spaces ending with a dangerous extension that is no... Read more
Affected Products : thunderbird- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0241
Cross-site scripting vulnerability in WBNews 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the Name field.... Read more
Affected Products : wbnews- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-0242
Cross-site scripting vulnerability in index.php in PHP Fusebox 4.0.6 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter.... Read more
Affected Products : php_fusebox- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-0239
Multiple cross-site scripting (XSS) vulnerabilities in Simple Blog 2.1 allow remote attackers to inject arbitrary web script or HTML via (1) a comment to comments.asp and (2) possibly certain other fields in unspecified scripts.... Read more
Affected Products : simple_blog- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0240
Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote attackers to execute arbitrary SQL commands via the month parameter in an archives view operation and possibly certain other parameters in unspecified scripts.... Read more
Affected Products : simple_blog- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0235
SQL injection vulnerability in WhiteAlbum 2.5 allows remote attackers to execute arbitrary SQL commands via the dir parameter to pictures.php.... Read more
Affected Products : white_album- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0233
Cross-site scripting (XSS) vulnerability in functions.php in microBlog 2.0 RC-10 allows remote attackers to inject arbitrary web script and HTML via a javascript: URI in a [url] BBcode tag.... Read more
Affected Products : microblog- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0234
SQL injection vulnerability in index.php in microBlog 2.0 RC-10 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters.... Read more
Affected Products : microblog- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-0228
The RBAC functionality in grsecurity before 2.1.8 does not properly handle when the admin role creates a service and then exits the shell without unauthenticating, which causes the service to be restarted with the admin role still active.... Read more
Affected Products : grsecurity_kernel_patch- Published: Jan. 17, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-0229
Unquoted Windows search path vulnerability in Wehntrust might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run when Wehntrust creates the autostart key.... Read more
Affected Products : wehntrust- Published: Jan. 17, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0227
Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to delete arbitrary files or disable the LP print service via unknown attack vectors.... Read more
- Published: Jan. 17, 2006
- Modified: Apr. 03, 2025