VYPR

CVEs

343,267 total · page 6547 of 6,866

  • CVE-2006-0732Feb 16, 2006
    risk 0.00cvss epss 0.03

    Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullName parameter to (1) sapbc/SAP/chopSAPLog.dsp or (2) invoke/sap.monitor.rfcTrace/deleteSingle. Details will be updated after the…

  • CVE-2006-0733Feb 16, 2006
    risk 0.03cvss epss 0.05

    Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the "author's website" field. NOTE: followup comments to the researcher's web log suggest…

  • CVE-2006-0734Feb 16, 2006
    risk 0.03cvss epss 0.03

    The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.6 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a backslash character at the end of a connection string to UDP port…

  • CVE-2006-0735Feb 16, 2006
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in BBcode.pm in M. Blom HTML::BBCode 1.04 and earlier, as used in products such as My Blog before 1.65, allows remote attackers to inject arbitrary Javascript via a javascript URI in an (1) img or (2) url BBcode tag.

  • CVE-2006-0455Feb 15, 2006
    risk 0.03cvss epss 0.01

    gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded. …

  • CVE-2006-0719Feb 15, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in member_login.php in PHP Classifieds 6.18 through 6.20 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter, which is used by the E-mail address field, and (2) password parameter.

  • CVE-2006-0718Feb 15, 2006
    risk 0.00cvss epss 0.02

    The Internet Key Exchange version 1 (IKEv1) implementation in Avaya VSU 100, 2000, 7500, 10000, and CSU 5000, when running IPSec, allows remote attackers to cause a denial of service (crash) via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.…

  • CVE-2006-0666Feb 15, 2006
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 through 5.3.0.33 allows local users to cause a denial of service (system crash) via unknown vectors related to EMULATE_VMX.

  • CVE-2006-0688Feb 15, 2006
    risk 0.03cvss epss 0.04

    PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.

  • CVE-2006-0689Feb 15, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Registration Form in TTS Time Tracking Software 3.0 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter.

  • CVE-2006-0690Feb 15, 2006
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in TTS Time Tracking Software 3.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2006-0691Feb 15, 2006
    risk 0.03cvss epss 0.03

    edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbitrary data belonging to any account.

  • CVE-2006-0692Feb 15, 2006
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php.

  • CVE-2006-0693Feb 15, 2006
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in rb_auth.php in Roberto Butti CALimba 0.99.2 beta and earlier allow remote attackers to execute arbitrary SQL commands and bypass login authentication via the (1) login and (2) password parameters.

  • CVE-2006-0694Feb 15, 2006
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in the loaders (load_*.php) in Ansilove before 1.03 allows remote attackers to read arbitrary files via unspecified vectors involving "converting files accessible by the webserver".

  • CVE-2006-0695Feb 15, 2006
    risk 0.00cvss epss 0.03

    Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them directly in the upload directory.

  • CVE-2006-0696Feb 15, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in Zen Cart before 1.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2006-0697Feb 15, 2006
    risk 0.00cvss epss 0.05

    Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.

  • CVE-2006-0698Feb 15, 2006
    risk 0.00cvss epss 0.02

    Unspecified vulnerabilities in Zen Cart before 1.2.7 allow remote attackers to cause unknown impact via unspecified vectors related to "other attempted exploits" other than SQL injection.

  • CVE-2006-0699Feb 15, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter.

  • CVE-2006-0700Feb 15, 2006
    risk 0.04cvss epss 0.07

    imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions.

  • CVE-2006-0701Feb 15, 2006
    risk 0.04cvss epss 0.08

    readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters.

  • CVE-2006-0702Feb 15, 2006
    risk 0.04cvss epss 0.07

    admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter. NOTE: due to the lack of details, the specific vulnerability type cannot be determined, although it might be due to…

  • CVE-2006-0703Feb 15, 2006
    risk 0.03cvss epss 0.04

    Unspecified vulnerability in index.php in imageVue 16.1 has unknown impact, probably a cross-site scripting (XSS) vulnerability involving the query string that is not quoted when inserted into style and body tags, as demonstrated using a bgcol parameter.

  • CVE-2006-0704Feb 15, 2006
    risk 0.00cvss epss 0.01

    iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory, which results in an error message that displays the…

  • CVE-2006-0705Feb 15, 2006
    risk 0.01cvss epss 0.10

    Format string vulnerability in a logging function as used by various SFTP servers, including (1) AttachmateWRQ Reflection for Secure IT UNIX Server before 6.0.0.9, (2) Reflection for Secure IT Windows Server before 6.0 build 38, (3) F-Secure SSH Server for Windows before 5.3…

  • CVE-2006-0706Feb 15, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting vulnerability in eintrag.php in Gästebuch (Gastebuch) before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the URL, which is used in the homepage parameter.

  • CVE-2006-0707Feb 15, 2006
    risk 0.00cvss epss 0.01

    PyBlosxom before 1.3.2, when running on certain webservers, allows remote attackers to read arbitrary files via an HTTP request with multiple leading / (slash) characters, which is accessed using the PATH_INFO variable.

  • CVE-2006-0708Feb 15, 2006
    risk 0.01cvss epss 0.07

    Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containing a long URL ending in .wma, (2) a pls file containing a File1 field with a long URL ending in .wma, or (3) an m3u file with a long…

  • CVE-2006-0709Feb 15, 2006
    risk 0.01cvss epss 0.06

    Buffer overflow in Metamail 2.7-50 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via e-mail messages with a long boundary attribute, a different vulnerability than CVE-2004-0105.

  • CVE-2006-0710Feb 15, 2006
    risk 0.03cvss epss 0.04

    Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code via a crafted LDAP request, as demonstrated by ProtoVer Sample LDAP.

  • CVE-2006-0711Feb 15, 2006
    risk 0.00cvss epss 0.01

    The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled.

  • CVE-2006-0712Feb 15, 2006
    risk 0.00cvss epss 0.02

    mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, which allows remote attackers to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability.

  • CVE-2006-0713Feb 15, 2006
    risk 0.03cvss epss 0.03

    Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) lang parameter in docs/index.php and the language parameter in (2) install/install.php, (3) install/sec_stage_install.php, (4)…

  • CVE-2006-0714Feb 15, 2006
    risk 0.04cvss epss 0.08

    Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the adodbpath parameter.

  • CVE-2006-0715Feb 15, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field.

  • CVE-2006-0716Feb 15, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.

  • CVE-2006-0717Feb 15, 2006
    risk 0.04cvss epss 0.09

    IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.

  • CVE-2006-0680Feb 15, 2006
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in WebGUI before 6.8.6-gamma allows remote attackers to create an account, when anonymous registration is disabled, via a certain URL.

  • CVE-2006-0681Feb 15, 2006
    risk 0.03cvss epss 0.04

    Format string vulnerability in powerd.c in Power Daemon (powerd) 2.0.2 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the WHATIDO variable.

  • CVE-2006-0682Feb 15, 2006
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in bbcodes system in e107 before 0.7.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

  • CVE-2006-0683Feb 15, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled when the administrator…

  • CVE-2006-0684Feb 15, 2006
    risk 0.03cvss epss 0.03

    change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not verify the old password when a user changes the password, which may allow remote attackers to gain unauthorized access.

  • CVE-2006-0685Feb 15, 2006
    risk 0.03cvss epss 0.05

    The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allows remote attackers to gain unauthorized access.

  • CVE-2006-0686Feb 15, 2006
    risk 0.00cvss epss 0.03

    add_user.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not check user privileges when adding a new administrative user, which allows remote attackers to gain unauthorized access.

  • CVE-2006-0687Feb 15, 2006
    risk 0.03cvss epss 0.03

    process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows remote attackers to include arbitrary local files or possibly remote files via a modified includeModule and siteModInfo variable.

  • CVE-2006-0006Feb 14, 2006
    risk 0.07cvss epss 0.54

    Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap…

  • CVE-2006-0382Feb 14, 2006
    risk 0.00cvss epss 0.00

    Apple Mac OS X 10.4.5 and allows local users to cause a denial of service (crash) via an undocumented system call.

  • CVE-2006-0451Feb 14, 2006
    risk 0.00cvss epss 0.02

    Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was allocated during the ber_scanf…

  • CVE-2006-0452Feb 14, 2006
    risk 0.00cvss epss 0.02

    dn2ancestor in the LDAP component in Fedora Directory Server 1.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via a ModDN operation with a DN that contains a large number of "," (comma) characters, which results in a large amount of…