| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2006-0373 | 0.00 | — | 0.01 | Jan 22, 2006 | Cross-site scripting (XSS) vulnerability in register.aspx in Douran FollowWeb allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |||
| CVE-2006-0374 | 0.00 | — | 0.02 | Jan 22, 2006 | Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-system data, by directly… | |||
| CVE-2006-0375 | 0.00 | — | 0.01 | Jan 22, 2006 | Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 on VxWorks uses a hardcoded Network Time Protocol (NTP) server in Taiwan, which could allow remote attackers to provide false time information, block access to time information, or conduct… | |||
| CVE-2006-0376 | 0.01 | — | 0.18 | Jan 22, 2006 | The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user when (1) it establishes an association with a station in ad hoc (aka peer-to-peer) mode or (2) a station in ad hoc mode establishes an… | |||
| CVE-2006-0353 | 0.00 | — | 0.00 | Jan 22, 2006 | unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed information that could be used to… | |||
| CVE-2006-0345 | 0.03 | — | 0.01 | Jan 21, 2006 | Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the search parameter to search.php. NOTE: the id/viewprofile.php issue is already covered by CVE-2005-4058. | |||
| CVE-2006-0346 | 0.00 | — | 0.01 | Jan 21, 2006 | Cross-site scripting (XSS) vulnerability in SaralBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via a website field in a new comment to view.php, which is not properly handled in the comment function in functions.php. | |||
| CVE-2006-0347 | 0.00 | — | 0.02 | Jan 21, 2006 | Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access arbitrary files outside of the elog directory via "../" (dot dot) sequences in the URL. | |||
| CVE-2006-0348 | 0.00 | — | 0.02 | Jan 21, 2006 | Format string vulnerability in the write_logfile function in ELOG before 2.6.1 allows remote attackers to cause a denial of service (server crash) via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |||
| CVE-2006-0349 | 0.03 | — | 0.01 | Jan 21, 2006 | SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to blog.php. | |||
| CVE-2006-0350 | 0.03 | — | 0.02 | Jan 21, 2006 | Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.php. | |||
| CVE-2006-0351 | 0.00 | — | 0.03 | Jan 21, 2006 | Unspecified "critical denial-of-service vulnerability" in MyDNS before 1.1.0 has unknown impact and attack vectors. | |||
| CVE-2006-0352 | 0.00 | — | 0.01 | Jan 21, 2006 | The default configuration of Fluffington FLog 1.01 installs users.0.dat under the web document root with insufficient access control, which might allow remote attackers to obtain sensitive information (login credentials) via a direct request. NOTE: It was later reported that… | |||
| CVE-2006-0327 | 0.00 | — | 0.02 | Jan 21, 2006 | TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which causes them to incorrectly define a variable and reveal the path in an error message when a require function call fails. | |||
| CVE-2006-0328 | 0.04 | — | 0.07 | Jan 21, 2006 | Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request. | |||
| CVE-2006-0329 | 0.00 | — | 0.01 | Jan 21, 2006 | SQL injection vulnerability in HITSENSER Data Mart Server BS, BS-S, BS-M, BS-L, and EX allows remote attackers to execute arbitrary SQL commands via unknown attack vectors. | |||
| CVE-2006-0330 | 0.00 | — | 0.02 | Jan 21, 2006 | Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname). | |||
| CVE-2006-0331 | 0.03 | — | 0.01 | Jan 21, 2006 | Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments. | |||
| CVE-2006-0332 | 0.00 | — | 0.01 | Jan 21, 2006 | Pantomime in Ecartis 1.0.0 snapshot 20050909 stores e-mail attachments in a publicly accessible directory, which may allow remote attackers to upload arbitrary files. | |||
| CVE-2006-0333 | 0.00 | — | 0.01 | Jan 21, 2006 | Cross-site scripting (XSS) vulnerability in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) month or (2) year parameter to index.php. | |||
| CVE-2006-0334 | 0.00 | — | 0.01 | Jan 21, 2006 | Cross-site scripting (XSS) vulnerability in search.php in My Amazon Store Manager 1.0 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter. NOTE: some sources claim that the affected parameter is "q", but the only public archive of the… | |||
| CVE-2006-0335 | 0.00 | — | 0.03 | Jan 21, 2006 | Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service via multiple unspecified vectors involving (1) long strings received from Active Directory and (2) the filtering of HTML. | |||
| CVE-2006-0336 | 0.00 | — | 0.02 | Jan 21, 2006 | Kerio WinRoute Firewall before 6.1.4 Patch 2 allows attackers to cause a denial of service (CPU consumption and hang) via unknown vectors involving "browsing the web". | |||
| CVE-2006-0337 | 0.00 | — | 0.06 | Jan 21, 2006 | Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote attackers to execute… | |||
| CVE-2006-0338 | 0.00 | — | 0.03 | Jan 21, 2006 | Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allow remote attackers to hide arbitrary files and data… | |||
| CVE-2006-0339 | 0.00 | — | 0.05 | Jan 21, 2006 | Buffer overflow in BitComet Client 0.60 allows remote attackers to execute arbitrary code, when the publisher's name link is clicked, via a long publisher URI in a torrent file. | |||
| CVE-2006-0340 | 0.00 | — | 0.03 | Jan 21, 2006 | Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote attackers on the local network to cause a denial of service (device hang and network traffic loss) via a… | |||
| CVE-2006-0342 | 0.00 | — | 0.02 | Jan 21, 2006 | RockLiffe MailSite HTTP Mail management agent (httpma) 7.0.3.1 allows remote attackers to cause a denial of service (CPU consumption and crash) via a malformed query string containing special characters such as "|". | |||
| CVE-2006-0343 | 0.00 | — | 0.02 | Jan 21, 2006 | Unspecified vulnerability in the Port Discovery Standard and Advanced features in Hitachi JP1/NetInsight II allows attackers to stop the Port Discovery service via unknown vectors involving "invalid format data". | |||
| CVE-2006-0344 | 0.00 | — | 0.02 | Jan 21, 2006 | Directory traversal vulnerability in Intervations FileCOPA FTP Server 1.01 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the (1) STOR and (2) RETR commands. | |||
| CVE-2006-0019 | 0.00 | — | 0.06 | Jan 20, 2006 | Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI. | |||
| CVE-2006-0045 | 0.00 | — | 0.00 | Jan 20, 2006 | crawl before 4.0.0 does not securely call programs when saving and loading games, which allows local users to gain privileges. | |||
| CVE-2006-0325 | 0.00 | — | 0.03 | Jan 20, 2006 | Etomite Content Management System 0.6, and possibly earlier versions, when downloaded from the web site in January 2006 after January 10, contains a back door in manager/includes/todo.inc.php, which allows remote attackers to execute arbitrary commands via the "cij" parameter. | |||
| CVE-2006-0322 | 0.00 | — | 0.02 | Jan 19, 2006 | Unspecified vulnerability the edit comment formatting functionality in MediaWiki 1.5.x before 1.5.6 and 1.4.x before 1.4.14 allows attackers to cause a denial of service (infinite loop) via "certain malformed links." | |||
| CVE-2006-0324 | 0.03 | — | 0.03 | Jan 19, 2006 | SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter to login.php. | |||
| CVE-2006-0226 | 0.00 | — | 0.06 | Jan 19, 2006 | Integer overflow in IEEE 802.11 network subsystem (ieee80211_ioctl.c) in FreeBSD before 6.0-STABLE, while scanning for wireless networks, allows remote attackers to execute arbitrary code by broadcasting crafted (1) beacon or (2) probe response frames. | |||
| CVE-2006-0309 | 0.00 | — | 0.01 | Jan 19, 2006 | Linksys BEFVP41 VPN Router 2.0 with firmware 1.01.04 allows remote attackers on the local network, to cause a denial of service via IP packets with a null IP option length. | |||
| CVE-2006-0310 | 0.03 | — | 0.02 | Jan 19, 2006 | Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag. | |||
| CVE-2006-0311 | 0.03 | — | 0.02 | Jan 19, 2006 | SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |||
| CVE-2006-0312 | 0.03 | — | 0.03 | Jan 19, 2006 | create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1. | |||
| CVE-2006-0313 | 0.00 | — | 0.02 | Jan 19, 2006 | Multiple SQL injection vulnerabilities in PDFdirectory before 1.0 allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors involving (1) util.php, (2) userpref.php, (3) user.php, (4) uploadfrm.php, (5) title.php, (6) team.php, (7) stats.php, (8)… | |||
| CVE-2006-0314 | 0.00 | — | 0.01 | Jan 19, 2006 | PDFdirectory before 1.0 stores sensitive data in plaintext, which allows remote attackers to obtain arbitrary users' passwords by direct queries to the database, possibly via one of the SQL injection vulnerabilities. | |||
| CVE-2006-0315 | 0.03 | — | 0.05 | Jan 19, 2006 | index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) and path disclosure. | |||
| CVE-2006-0316 | 0.01 | — | 0.10 | Jan 19, 2006 | Buffer overflow in YGPPicFinder.DLL in AOL You've Got Pictures (YGP) Picture Finder Tool ActiveX Control, as used in AOL 8.0, 8.0 Plus, and 9.0 Classic, allows remote attackers to execute arbitrary code via unspecified vectors. | |||
| CVE-2006-0317 | 0.03 | — | 0.02 | Jan 19, 2006 | Cross-site scripting (XSS) vulnerability in rkrt_stats.php in RedKernel Referrer Tracker 1.1.0-3 allows remote attackers to inject arbitrary web script or HTML via a query string value as a GET, which is stored in the $QUERY_STRING variable. NOTE: the provenance of this… | |||
| CVE-2006-0318 | 0.03 | — | 0.01 | Jan 19, 2006 | SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action. | |||
| CVE-2006-0319 | 0.04 | — | 0.07 | Jan 19, 2006 | Directory traversal vulnerability in the FTP server (port 22003/tcp) in Farmers WIFE 4.4 SP1 allows remote attackers to create arbitrary files via ".." (dot dot) sequences in a (1) PUT, (2) SIZE, and possibly other commands. | |||
| CVE-2006-0320 | 0.03 | — | 0.01 | Jan 19, 2006 | SQL injection vulnerability in admin/processlogin.php in Bit 5 Blog 8.01 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameter. | |||
| CVE-2006-0302 | 0.00 | — | 0.01 | Jan 19, 2006 | ZyXel P2000W VoIP 802.11b Wireless Phone running firmware WV.00.02 allows remote attackers to obtain sensitive information, such as MAC address and software version, by directly accessing UDP port 9090. | |||
| CVE-2006-0303 | 0.00 | — | 0.01 | Jan 19, 2006 | Multiple unspecified vulnerabilities in the (1) publishing component, (2) Contact Component, (3) TinyMCE Compressor, and (4) other components in Joomla! 1.0.5 and earlier have unknown impact and attack vectors. |
- CVE-2006-0373Jan 22, 2006risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in register.aspx in Douran FollowWeb allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
- CVE-2006-0374Jan 22, 2006risk 0.00cvss —epss 0.02
Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-system data, by directly…
- CVE-2006-0375Jan 22, 2006risk 0.00cvss —epss 0.01
Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 on VxWorks uses a hardcoded Network Time Protocol (NTP) server in Taiwan, which could allow remote attackers to provide false time information, block access to time information, or conduct…
- CVE-2006-0376Jan 22, 2006risk 0.01cvss —epss 0.18
The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user when (1) it establishes an association with a station in ad hoc (aka peer-to-peer) mode or (2) a station in ad hoc mode establishes an…
- CVE-2006-0353Jan 22, 2006risk 0.00cvss —epss 0.00
unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed information that could be used to…
- CVE-2006-0345Jan 21, 2006risk 0.03cvss —epss 0.01
Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the search parameter to search.php. NOTE: the id/viewprofile.php issue is already covered by CVE-2005-4058.
- CVE-2006-0346Jan 21, 2006risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in SaralBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via a website field in a new comment to view.php, which is not properly handled in the comment function in functions.php.
- CVE-2006-0347Jan 21, 2006risk 0.00cvss —epss 0.02
Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access arbitrary files outside of the elog directory via "../" (dot dot) sequences in the URL.
- CVE-2006-0348Jan 21, 2006risk 0.00cvss —epss 0.02
Format string vulnerability in the write_logfile function in ELOG before 2.6.1 allows remote attackers to cause a denial of service (server crash) via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
- CVE-2006-0349Jan 21, 2006risk 0.03cvss —epss 0.01
SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to blog.php.
- CVE-2006-0350Jan 21, 2006risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.php.
- CVE-2006-0351Jan 21, 2006risk 0.00cvss —epss 0.03
Unspecified "critical denial-of-service vulnerability" in MyDNS before 1.1.0 has unknown impact and attack vectors.
- CVE-2006-0352Jan 21, 2006risk 0.00cvss —epss 0.01
The default configuration of Fluffington FLog 1.01 installs users.0.dat under the web document root with insufficient access control, which might allow remote attackers to obtain sensitive information (login credentials) via a direct request. NOTE: It was later reported that…
- CVE-2006-0327Jan 21, 2006risk 0.00cvss —epss 0.02
TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which causes them to incorrectly define a variable and reveal the path in an error message when a require function call fails.
- CVE-2006-0328Jan 21, 2006risk 0.04cvss —epss 0.07
Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request.
- CVE-2006-0329Jan 21, 2006risk 0.00cvss —epss 0.01
SQL injection vulnerability in HITSENSER Data Mart Server BS, BS-S, BS-M, BS-L, and EX allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
- CVE-2006-0330Jan 21, 2006risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname).
- CVE-2006-0331Jan 21, 2006risk 0.03cvss —epss 0.01
Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments.
- CVE-2006-0332Jan 21, 2006risk 0.00cvss —epss 0.01
Pantomime in Ecartis 1.0.0 snapshot 20050909 stores e-mail attachments in a publicly accessible directory, which may allow remote attackers to upload arbitrary files.
- CVE-2006-0333Jan 21, 2006risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) month or (2) year parameter to index.php.
- CVE-2006-0334Jan 21, 2006risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in search.php in My Amazon Store Manager 1.0 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter. NOTE: some sources claim that the affected parameter is "q", but the only public archive of the…
- CVE-2006-0335Jan 21, 2006risk 0.00cvss —epss 0.03
Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service via multiple unspecified vectors involving (1) long strings received from Active Directory and (2) the filtering of HTML.
- CVE-2006-0336Jan 21, 2006risk 0.00cvss —epss 0.02
Kerio WinRoute Firewall before 6.1.4 Patch 2 allows attackers to cause a denial of service (CPU consumption and hang) via unknown vectors involving "browsing the web".
- CVE-2006-0337Jan 21, 2006risk 0.00cvss —epss 0.06
Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote attackers to execute…
- CVE-2006-0338Jan 21, 2006risk 0.00cvss —epss 0.03
Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allow remote attackers to hide arbitrary files and data…
- CVE-2006-0339Jan 21, 2006risk 0.00cvss —epss 0.05
Buffer overflow in BitComet Client 0.60 allows remote attackers to execute arbitrary code, when the publisher's name link is clicked, via a long publisher URI in a torrent file.
- CVE-2006-0340Jan 21, 2006risk 0.00cvss —epss 0.03
Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote attackers on the local network to cause a denial of service (device hang and network traffic loss) via a…
- CVE-2006-0342Jan 21, 2006risk 0.00cvss —epss 0.02
RockLiffe MailSite HTTP Mail management agent (httpma) 7.0.3.1 allows remote attackers to cause a denial of service (CPU consumption and crash) via a malformed query string containing special characters such as "|".
- CVE-2006-0343Jan 21, 2006risk 0.00cvss —epss 0.02
Unspecified vulnerability in the Port Discovery Standard and Advanced features in Hitachi JP1/NetInsight II allows attackers to stop the Port Discovery service via unknown vectors involving "invalid format data".
- CVE-2006-0344Jan 21, 2006risk 0.00cvss —epss 0.02
Directory traversal vulnerability in Intervations FileCOPA FTP Server 1.01 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the (1) STOR and (2) RETR commands.
- CVE-2006-0019Jan 20, 2006risk 0.00cvss —epss 0.06
Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.
- CVE-2006-0045Jan 20, 2006risk 0.00cvss —epss 0.00
crawl before 4.0.0 does not securely call programs when saving and loading games, which allows local users to gain privileges.
- CVE-2006-0325Jan 20, 2006risk 0.00cvss —epss 0.03
Etomite Content Management System 0.6, and possibly earlier versions, when downloaded from the web site in January 2006 after January 10, contains a back door in manager/includes/todo.inc.php, which allows remote attackers to execute arbitrary commands via the "cij" parameter.
- CVE-2006-0322Jan 19, 2006risk 0.00cvss —epss 0.02
Unspecified vulnerability the edit comment formatting functionality in MediaWiki 1.5.x before 1.5.6 and 1.4.x before 1.4.14 allows attackers to cause a denial of service (infinite loop) via "certain malformed links."
- CVE-2006-0324Jan 19, 2006risk 0.03cvss —epss 0.03
SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter to login.php.
- CVE-2006-0226Jan 19, 2006risk 0.00cvss —epss 0.06
Integer overflow in IEEE 802.11 network subsystem (ieee80211_ioctl.c) in FreeBSD before 6.0-STABLE, while scanning for wireless networks, allows remote attackers to execute arbitrary code by broadcasting crafted (1) beacon or (2) probe response frames.
- CVE-2006-0309Jan 19, 2006risk 0.00cvss —epss 0.01
Linksys BEFVP41 VPN Router 2.0 with firmware 1.01.04 allows remote attackers on the local network, to cause a denial of service via IP packets with a null IP option length.
- CVE-2006-0310Jan 19, 2006risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag.
- CVE-2006-0311Jan 19, 2006risk 0.03cvss —epss 0.02
SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.
- CVE-2006-0312Jan 19, 2006risk 0.03cvss —epss 0.03
create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1.
- CVE-2006-0313Jan 19, 2006risk 0.00cvss —epss 0.02
Multiple SQL injection vulnerabilities in PDFdirectory before 1.0 allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors involving (1) util.php, (2) userpref.php, (3) user.php, (4) uploadfrm.php, (5) title.php, (6) team.php, (7) stats.php, (8)…
- CVE-2006-0314Jan 19, 2006risk 0.00cvss —epss 0.01
PDFdirectory before 1.0 stores sensitive data in plaintext, which allows remote attackers to obtain arbitrary users' passwords by direct queries to the database, possibly via one of the SQL injection vulnerabilities.
- CVE-2006-0315Jan 19, 2006risk 0.03cvss —epss 0.05
index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) and path disclosure.
- CVE-2006-0316Jan 19, 2006risk 0.01cvss —epss 0.10
Buffer overflow in YGPPicFinder.DLL in AOL You've Got Pictures (YGP) Picture Finder Tool ActiveX Control, as used in AOL 8.0, 8.0 Plus, and 9.0 Classic, allows remote attackers to execute arbitrary code via unspecified vectors.
- CVE-2006-0317Jan 19, 2006risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in rkrt_stats.php in RedKernel Referrer Tracker 1.1.0-3 allows remote attackers to inject arbitrary web script or HTML via a query string value as a GET, which is stored in the $QUERY_STRING variable. NOTE: the provenance of this…
- CVE-2006-0318Jan 19, 2006risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action.
- CVE-2006-0319Jan 19, 2006risk 0.04cvss —epss 0.07
Directory traversal vulnerability in the FTP server (port 22003/tcp) in Farmers WIFE 4.4 SP1 allows remote attackers to create arbitrary files via ".." (dot dot) sequences in a (1) PUT, (2) SIZE, and possibly other commands.
- CVE-2006-0320Jan 19, 2006risk 0.03cvss —epss 0.01
SQL injection vulnerability in admin/processlogin.php in Bit 5 Blog 8.01 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameter.
- CVE-2006-0302Jan 19, 2006risk 0.00cvss —epss 0.01
ZyXel P2000W VoIP 802.11b Wireless Phone running firmware WV.00.02 allows remote attackers to obtain sensitive information, such as MAC address and software version, by directly accessing UDP port 9090.
- CVE-2006-0303Jan 19, 2006risk 0.00cvss —epss 0.01
Multiple unspecified vulnerabilities in the (1) publishing component, (2) Contact Component, (3) TinyMCE Compressor, and (4) other components in Joomla! 1.0.5 and earlier have unknown impact and attack vectors.