Latest CVE Feed
-
5.0
MEDIUMCVE-2006-0348
Format string vulnerability in the write_logfile function in ELOG before 2.6.1 allows remote attackers to cause a denial of service (server crash) via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained s... Read more
Affected Products : elog_web_logbook- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0347
Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access arbitrary files outside of the elog directory via "../" (dot dot) sequences in the URL.... Read more
Affected Products : elog_web_logbook- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0351
Unspecified "critical denial-of-service vulnerability" in MyDNS before 1.1.0 has unknown impact and attack vectors.... Read more
Affected Products : mydns- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0350
Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.php.... Read more
Affected Products : eggblog- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0345
Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the search parameter to search.php. NOTE: the id/viewprofile.php issue is already covered by CVE-2005-4058.... Read more
Affected Products : saralblog- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0346
Cross-site scripting (XSS) vulnerability in SaralBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via a website field in a new comment to view.php, which is not properly handled in the comment function in functions.php.... Read more
Affected Products : saralblog- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0352
The default configuration of Fluffington FLog 1.01 installs users.0.dat under the web document root with insufficient access control, which might allow remote attackers to obtain sensitive information (login credentials) via a direct request. NOTE: It wa... Read more
Affected Products : flog- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0327
TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which causes them to incorrectly define a variable and reveal the path in an error message when a require funct... Read more
Affected Products : typo3- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-0332
Pantomime in Ecartis 1.0.0 snapshot 20050909 stores e-mail attachments in a publicly accessible directory, which may allow remote attackers to upload arbitrary files.... Read more
Affected Products : ecartis- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0334
Cross-site scripting (XSS) vulnerability in search.php in My Amazon Store Manager 1.0 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter. NOTE: some sources claim that the affected parameter is "q", but the only pub... Read more
Affected Products : my_amazon_store_manager- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0329
SQL injection vulnerability in HITSENSER Data Mart Server BS, BS-S, BS-M, BS-L, and EX allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.... Read more
Affected Products : hitsenser_data_mart_server- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2006-0340
Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote attackers on the local network to cause a denial of service (device hang and net... Read more
Affected Products : ios- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0328
Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request.... Read more
Affected Products : tftpd32- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0338
Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allow remote attackers to hide a... Read more
Affected Products : f-secure_anti-virus internet_gatekeeper f-secure_internet_security f-secure_personal_express- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-0331
Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments.... Read more
Affected Products : change_passwd- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0335
Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service via multiple unspecified vectors involving (1) long strings received from Active Directory and (2) the filtering of HT... Read more
Affected Products : winroute_firewall- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-0342
RockLiffe MailSite HTTP Mail management agent (httpma) 7.0.3.1 allows remote attackers to cause a denial of service (CPU consumption and crash) via a malformed query string containing special characters such as "|".... Read more
Affected Products : mailsite- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-0344
Directory traversal vulnerability in Intervations FileCOPA FTP Server 1.01 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the (1) STOR and (2) RETR commands.... Read more
Affected Products : filecopa- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0330
Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname).... Read more
Affected Products : gallery- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0337
Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote... Read more
- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025