| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2006-0732 | 0.00 | — | 0.03 | Feb 16, 2006 | Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullName parameter to (1) sapbc/SAP/chopSAPLog.dsp or (2) invoke/sap.monitor.rfcTrace/deleteSingle. Details will be updated after the… | |||
| CVE-2006-0733 | 0.03 | — | 0.05 | Feb 16, 2006 | Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the "author's website" field. NOTE: followup comments to the researcher's web log suggest… | |||
| CVE-2006-0734 | 0.03 | — | 0.03 | Feb 16, 2006 | The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.6 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a backslash character at the end of a connection string to UDP port… | |||
| CVE-2006-0735 | 0.03 | — | 0.03 | Feb 16, 2006 | Cross-site scripting (XSS) vulnerability in BBcode.pm in M. Blom HTML::BBCode 1.04 and earlier, as used in products such as My Blog before 1.65, allows remote attackers to inject arbitrary Javascript via a javascript URI in an (1) img or (2) url BBcode tag. | |||
| CVE-2006-0455 | 0.03 | — | 0.01 | Feb 15, 2006 | gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded. … | |||
| CVE-2006-0719 | 0.03 | — | 0.01 | Feb 15, 2006 | SQL injection vulnerability in member_login.php in PHP Classifieds 6.18 through 6.20 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter, which is used by the E-mail address field, and (2) password parameter. | |||
| CVE-2006-0718 | 0.00 | — | 0.02 | Feb 15, 2006 | The Internet Key Exchange version 1 (IKEv1) implementation in Avaya VSU 100, 2000, 7500, 10000, and CSU 5000, when running IPSec, allows remote attackers to cause a denial of service (crash) via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.… | |||
| CVE-2006-0666 | 0.00 | — | 0.00 | Feb 15, 2006 | Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 through 5.3.0.33 allows local users to cause a denial of service (system crash) via unknown vectors related to EMULATE_VMX. | |||
| CVE-2006-0688 | 0.03 | — | 0.04 | Feb 15, 2006 | PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter. | |||
| CVE-2006-0689 | 0.00 | — | 0.01 | Feb 15, 2006 | Cross-site scripting (XSS) vulnerability in the Registration Form in TTS Time Tracking Software 3.0 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter. | |||
| CVE-2006-0690 | 0.00 | — | 0.01 | Feb 15, 2006 | Multiple SQL injection vulnerabilities in TTS Time Tracking Software 3.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||
| CVE-2006-0691 | 0.03 | — | 0.03 | Feb 15, 2006 | edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbitrary data belonging to any account. | |||
| CVE-2006-0692 | 0.00 | — | 0.01 | Feb 15, 2006 | Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php. | |||
| CVE-2006-0693 | 0.00 | — | 0.01 | Feb 15, 2006 | Multiple SQL injection vulnerabilities in rb_auth.php in Roberto Butti CALimba 0.99.2 beta and earlier allow remote attackers to execute arbitrary SQL commands and bypass login authentication via the (1) login and (2) password parameters. | |||
| CVE-2006-0694 | 0.00 | — | 0.01 | Feb 15, 2006 | Unspecified vulnerability in the loaders (load_*.php) in Ansilove before 1.03 allows remote attackers to read arbitrary files via unspecified vectors involving "converting files accessible by the webserver". | |||
| CVE-2006-0695 | 0.00 | — | 0.03 | Feb 15, 2006 | Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them directly in the upload directory. | |||
| CVE-2006-0696 | 0.00 | — | 0.01 | Feb 15, 2006 | SQL injection vulnerability in Zen Cart before 1.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||
| CVE-2006-0697 | 0.00 | — | 0.05 | Feb 15, 2006 | Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests. | |||
| CVE-2006-0698 | 0.00 | — | 0.02 | Feb 15, 2006 | Unspecified vulnerabilities in Zen Cart before 1.2.7 allow remote attackers to cause unknown impact via unspecified vectors related to "other attempted exploits" other than SQL injection. | |||
| CVE-2006-0699 | 0.03 | — | 0.02 | Feb 15, 2006 | Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |||
| CVE-2006-0700 | 0.04 | — | 0.07 | Feb 15, 2006 | imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions. | |||
| CVE-2006-0701 | 0.04 | — | 0.08 | Feb 15, 2006 | readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters. | |||
| CVE-2006-0702 | 0.04 | — | 0.07 | Feb 15, 2006 | admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter. NOTE: due to the lack of details, the specific vulnerability type cannot be determined, although it might be due to… | |||
| CVE-2006-0703 | 0.03 | — | 0.04 | Feb 15, 2006 | Unspecified vulnerability in index.php in imageVue 16.1 has unknown impact, probably a cross-site scripting (XSS) vulnerability involving the query string that is not quoted when inserted into style and body tags, as demonstrated using a bgcol parameter. | |||
| CVE-2006-0704 | 0.00 | — | 0.01 | Feb 15, 2006 | iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory, which results in an error message that displays the… | |||
| CVE-2006-0705 | 0.01 | — | 0.10 | Feb 15, 2006 | Format string vulnerability in a logging function as used by various SFTP servers, including (1) AttachmateWRQ Reflection for Secure IT UNIX Server before 6.0.0.9, (2) Reflection for Secure IT Windows Server before 6.0 build 38, (3) F-Secure SSH Server for Windows before 5.3… | |||
| CVE-2006-0706 | 0.03 | — | 0.02 | Feb 15, 2006 | Cross-site scripting vulnerability in eintrag.php in Gästebuch (Gastebuch) before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the URL, which is used in the homepage parameter. | |||
| CVE-2006-0707 | 0.00 | — | 0.01 | Feb 15, 2006 | PyBlosxom before 1.3.2, when running on certain webservers, allows remote attackers to read arbitrary files via an HTTP request with multiple leading / (slash) characters, which is accessed using the PATH_INFO variable. | |||
| CVE-2006-0708 | 0.01 | — | 0.07 | Feb 15, 2006 | Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containing a long URL ending in .wma, (2) a pls file containing a File1 field with a long URL ending in .wma, or (3) an m3u file with a long… | |||
| CVE-2006-0709 | 0.01 | — | 0.06 | Feb 15, 2006 | Buffer overflow in Metamail 2.7-50 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via e-mail messages with a long boundary attribute, a different vulnerability than CVE-2004-0105. | |||
| CVE-2006-0710 | 0.03 | — | 0.04 | Feb 15, 2006 | Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code via a crafted LDAP request, as demonstrated by ProtoVer Sample LDAP. | |||
| CVE-2006-0711 | 0.00 | — | 0.01 | Feb 15, 2006 | The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled. | |||
| CVE-2006-0712 | 0.00 | — | 0.02 | Feb 15, 2006 | mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, which allows remote attackers to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability. | |||
| CVE-2006-0713 | 0.03 | — | 0.03 | Feb 15, 2006 | Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) lang parameter in docs/index.php and the language parameter in (2) install/install.php, (3) install/sec_stage_install.php, (4)… | |||
| CVE-2006-0714 | 0.04 | — | 0.08 | Feb 15, 2006 | Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the adodbpath parameter. | |||
| CVE-2006-0715 | 0.03 | — | 0.02 | Feb 15, 2006 | Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field. | |||
| CVE-2006-0716 | 0.00 | — | 0.01 | Feb 15, 2006 | SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters. | |||
| CVE-2006-0717 | 0.04 | — | 0.09 | Feb 15, 2006 | IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite. | |||
| CVE-2006-0680 | 0.00 | — | 0.01 | Feb 15, 2006 | Unspecified vulnerability in WebGUI before 6.8.6-gamma allows remote attackers to create an account, when anonymous registration is disabled, via a certain URL. | |||
| CVE-2006-0681 | 0.03 | — | 0.04 | Feb 15, 2006 | Format string vulnerability in powerd.c in Power Daemon (powerd) 2.0.2 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the WHATIDO variable. | |||
| CVE-2006-0682 | 0.00 | — | 0.01 | Feb 15, 2006 | Multiple cross-site scripting (XSS) vulnerabilities in bbcodes system in e107 before 0.7.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | |||
| CVE-2006-0683 | 0.00 | — | 0.01 | Feb 15, 2006 | Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled when the administrator… | |||
| CVE-2006-0684 | 0.03 | — | 0.03 | Feb 15, 2006 | change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not verify the old password when a user changes the password, which may allow remote attackers to gain unauthorized access. | |||
| CVE-2006-0685 | 0.03 | — | 0.05 | Feb 15, 2006 | The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allows remote attackers to gain unauthorized access. | |||
| CVE-2006-0686 | 0.00 | — | 0.03 | Feb 15, 2006 | add_user.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not check user privileges when adding a new administrative user, which allows remote attackers to gain unauthorized access. | |||
| CVE-2006-0687 | 0.03 | — | 0.03 | Feb 15, 2006 | process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows remote attackers to include arbitrary local files or possibly remote files via a modified includeModule and siteModInfo variable. | |||
| CVE-2006-0006 | 0.07 | — | 0.54 | Feb 14, 2006 | Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap… | |||
| CVE-2006-0382 | 0.00 | — | 0.00 | Feb 14, 2006 | Apple Mac OS X 10.4.5 and allows local users to cause a denial of service (crash) via an undocumented system call. | |||
| CVE-2006-0451 | 0.00 | — | 0.02 | Feb 14, 2006 | Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was allocated during the ber_scanf… | |||
| CVE-2006-0452 | 0.00 | — | 0.02 | Feb 14, 2006 | dn2ancestor in the LDAP component in Fedora Directory Server 1.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via a ModDN operation with a DN that contains a large number of "," (comma) characters, which results in a large amount of… |
- CVE-2006-0732Feb 16, 2006risk 0.00cvss —epss 0.03
Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullName parameter to (1) sapbc/SAP/chopSAPLog.dsp or (2) invoke/sap.monitor.rfcTrace/deleteSingle. Details will be updated after the…
- CVE-2006-0733Feb 16, 2006risk 0.03cvss —epss 0.05
Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the "author's website" field. NOTE: followup comments to the researcher's web log suggest…
- CVE-2006-0734Feb 16, 2006risk 0.03cvss —epss 0.03
The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.6 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a backslash character at the end of a connection string to UDP port…
- CVE-2006-0735Feb 16, 2006risk 0.03cvss —epss 0.03
Cross-site scripting (XSS) vulnerability in BBcode.pm in M. Blom HTML::BBCode 1.04 and earlier, as used in products such as My Blog before 1.65, allows remote attackers to inject arbitrary Javascript via a javascript URI in an (1) img or (2) url BBcode tag.
- CVE-2006-0455Feb 15, 2006risk 0.03cvss —epss 0.01
gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded. …
- CVE-2006-0719Feb 15, 2006risk 0.03cvss —epss 0.01
SQL injection vulnerability in member_login.php in PHP Classifieds 6.18 through 6.20 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter, which is used by the E-mail address field, and (2) password parameter.
- CVE-2006-0718Feb 15, 2006risk 0.00cvss —epss 0.02
The Internet Key Exchange version 1 (IKEv1) implementation in Avaya VSU 100, 2000, 7500, 10000, and CSU 5000, when running IPSec, allows remote attackers to cause a denial of service (crash) via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.…
- CVE-2006-0666Feb 15, 2006risk 0.00cvss —epss 0.00
Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 through 5.3.0.33 allows local users to cause a denial of service (system crash) via unknown vectors related to EMULATE_VMX.
- CVE-2006-0688Feb 15, 2006risk 0.03cvss —epss 0.04
PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.
- CVE-2006-0689Feb 15, 2006risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in the Registration Form in TTS Time Tracking Software 3.0 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter.
- CVE-2006-0690Feb 15, 2006risk 0.00cvss —epss 0.01
Multiple SQL injection vulnerabilities in TTS Time Tracking Software 3.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
- CVE-2006-0691Feb 15, 2006risk 0.03cvss —epss 0.03
edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbitrary data belonging to any account.
- CVE-2006-0692Feb 15, 2006risk 0.00cvss —epss 0.01
Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php.
- CVE-2006-0693Feb 15, 2006risk 0.00cvss —epss 0.01
Multiple SQL injection vulnerabilities in rb_auth.php in Roberto Butti CALimba 0.99.2 beta and earlier allow remote attackers to execute arbitrary SQL commands and bypass login authentication via the (1) login and (2) password parameters.
- CVE-2006-0694Feb 15, 2006risk 0.00cvss —epss 0.01
Unspecified vulnerability in the loaders (load_*.php) in Ansilove before 1.03 allows remote attackers to read arbitrary files via unspecified vectors involving "converting files accessible by the webserver".
- CVE-2006-0695Feb 15, 2006risk 0.00cvss —epss 0.03
Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them directly in the upload directory.
- CVE-2006-0696Feb 15, 2006risk 0.00cvss —epss 0.01
SQL injection vulnerability in Zen Cart before 1.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
- CVE-2006-0697Feb 15, 2006risk 0.00cvss —epss 0.05
Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.
- CVE-2006-0698Feb 15, 2006risk 0.00cvss —epss 0.02
Unspecified vulnerabilities in Zen Cart before 1.2.7 allow remote attackers to cause unknown impact via unspecified vectors related to "other attempted exploits" other than SQL injection.
- CVE-2006-0699Feb 15, 2006risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter.
- CVE-2006-0700Feb 15, 2006risk 0.04cvss —epss 0.07
imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions.
- CVE-2006-0701Feb 15, 2006risk 0.04cvss —epss 0.08
readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters.
- CVE-2006-0702Feb 15, 2006risk 0.04cvss —epss 0.07
admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter. NOTE: due to the lack of details, the specific vulnerability type cannot be determined, although it might be due to…
- CVE-2006-0703Feb 15, 2006risk 0.03cvss —epss 0.04
Unspecified vulnerability in index.php in imageVue 16.1 has unknown impact, probably a cross-site scripting (XSS) vulnerability involving the query string that is not quoted when inserted into style and body tags, as demonstrated using a bgcol parameter.
- CVE-2006-0704Feb 15, 2006risk 0.00cvss —epss 0.01
iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory, which results in an error message that displays the…
- CVE-2006-0705Feb 15, 2006risk 0.01cvss —epss 0.10
Format string vulnerability in a logging function as used by various SFTP servers, including (1) AttachmateWRQ Reflection for Secure IT UNIX Server before 6.0.0.9, (2) Reflection for Secure IT Windows Server before 6.0 build 38, (3) F-Secure SSH Server for Windows before 5.3…
- CVE-2006-0706Feb 15, 2006risk 0.03cvss —epss 0.02
Cross-site scripting vulnerability in eintrag.php in Gästebuch (Gastebuch) before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the URL, which is used in the homepage parameter.
- CVE-2006-0707Feb 15, 2006risk 0.00cvss —epss 0.01
PyBlosxom before 1.3.2, when running on certain webservers, allows remote attackers to read arbitrary files via an HTTP request with multiple leading / (slash) characters, which is accessed using the PATH_INFO variable.
- CVE-2006-0708Feb 15, 2006risk 0.01cvss —epss 0.07
Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containing a long URL ending in .wma, (2) a pls file containing a File1 field with a long URL ending in .wma, or (3) an m3u file with a long…
- CVE-2006-0709Feb 15, 2006risk 0.01cvss —epss 0.06
Buffer overflow in Metamail 2.7-50 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via e-mail messages with a long boundary attribute, a different vulnerability than CVE-2004-0105.
- CVE-2006-0710Feb 15, 2006risk 0.03cvss —epss 0.04
Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code via a crafted LDAP request, as demonstrated by ProtoVer Sample LDAP.
- CVE-2006-0711Feb 15, 2006risk 0.00cvss —epss 0.01
The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled.
- CVE-2006-0712Feb 15, 2006risk 0.00cvss —epss 0.02
mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, which allows remote attackers to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability.
- CVE-2006-0713Feb 15, 2006risk 0.03cvss —epss 0.03
Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) lang parameter in docs/index.php and the language parameter in (2) install/install.php, (3) install/sec_stage_install.php, (4)…
- CVE-2006-0714Feb 15, 2006risk 0.04cvss —epss 0.08
Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the adodbpath parameter.
- CVE-2006-0715Feb 15, 2006risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field.
- CVE-2006-0716Feb 15, 2006risk 0.00cvss —epss 0.01
SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.
- CVE-2006-0717Feb 15, 2006risk 0.04cvss —epss 0.09
IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.
- CVE-2006-0680Feb 15, 2006risk 0.00cvss —epss 0.01
Unspecified vulnerability in WebGUI before 6.8.6-gamma allows remote attackers to create an account, when anonymous registration is disabled, via a certain URL.
- CVE-2006-0681Feb 15, 2006risk 0.03cvss —epss 0.04
Format string vulnerability in powerd.c in Power Daemon (powerd) 2.0.2 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the WHATIDO variable.
- CVE-2006-0682Feb 15, 2006risk 0.00cvss —epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in bbcodes system in e107 before 0.7.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
- CVE-2006-0683Feb 15, 2006risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled when the administrator…
- CVE-2006-0684Feb 15, 2006risk 0.03cvss —epss 0.03
change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not verify the old password when a user changes the password, which may allow remote attackers to gain unauthorized access.
- CVE-2006-0685Feb 15, 2006risk 0.03cvss —epss 0.05
The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allows remote attackers to gain unauthorized access.
- CVE-2006-0686Feb 15, 2006risk 0.00cvss —epss 0.03
add_user.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not check user privileges when adding a new administrative user, which allows remote attackers to gain unauthorized access.
- CVE-2006-0687Feb 15, 2006risk 0.03cvss —epss 0.03
process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows remote attackers to include arbitrary local files or possibly remote files via a modified includeModule and siteModInfo variable.
- CVE-2006-0006Feb 14, 2006risk 0.07cvss —epss 0.54
Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap…
- CVE-2006-0382Feb 14, 2006risk 0.00cvss —epss 0.00
Apple Mac OS X 10.4.5 and allows local users to cause a denial of service (crash) via an undocumented system call.
- CVE-2006-0451Feb 14, 2006risk 0.00cvss —epss 0.02
Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was allocated during the ber_scanf…
- CVE-2006-0452Feb 14, 2006risk 0.00cvss —epss 0.02
dn2ancestor in the LDAP component in Fedora Directory Server 1.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via a ModDN operation with a DN that contains a large number of "," (comma) characters, which results in a large amount of…