VYPR

CVEs

381,115 total · page 7225 of 7,623

  • CVE-2006-4890Sep 19, 2006
    risk 0.04cvss —epss 0.08

    Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the dirroot parameter to (1) fckeditor/editor/filemanager/browser/default/connectors/php/connector.php or (2)…

  • CVE-2006-4891Sep 19, 2006
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in ArticlesTableview.asp in Techno Dreams Articles & Papers Package 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the key parameter.

  • CVE-2006-4892Sep 19, 2006
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in faqview.asp in Techno Dreams FAQ Manager Package 1.0 allows remote attackers to execute arbitrary SQL commands via the key parameter.

  • CVE-2006-4893Sep 19, 2006
    risk 0.00cvss —epss 0.03

    PHP remote file inclusion vulnerability in bb_usage_stats/includes/bb_usage_stats.php in phpBB XS 0.58 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter, a different vector than CVE-2006-4780.

  • CVE-2006-4894Sep 19, 2006
    risk 0.03cvss —epss 0.04

    Cross-site scripting (XSS) vulnerability in forms/lostpassword.php in iDevSpot NixieAffiliate 1.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter.

  • CVE-2006-4895Sep 19, 2006
    risk 0.00cvss —epss 0.03

    IDevSpot NexieAffiliate 1.9 and earlier allows remote attackers to delete arbitrary affiliates via a modified id parameter to delete.php.

  • CVE-2006-4897Sep 19, 2006
    risk 0.04cvss —epss 0.08

    CMtextS 1.0 and earlier stores users_logins/admin.txt under the web document root with insufficient access control, which allows remote attackers to obtain the administrator password.

  • CVE-2006-4898Sep 19, 2006
    risk 0.04cvss —epss 0.06

    PHP remote file inclusion vulnerability in include/phpxd/phpXD.php in guanxiCRM 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the appconf[rootpath] parameter.

  • CVE-2006-2191Sep 19, 2006
    risk 0.00cvss —epss 0.03

    Format string vulnerability in Mailman before 2.1.9 allows attackers to execute arbitrary code via unspecified vectors. NOTE: the vendor has disputed this vulnerability, stating that it is "unexploitable.

  • CVE-2006-4334Sep 19, 2006
    risk 0.00cvss —epss 0.04

    Unspecified vulnerability in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (crash) via a crafted GZIP (gz) archive, which results in a NULL dereference.

  • CVE-2006-4335Sep 19, 2006
    risk 0.00cvss —epss 0.06

    Array index error in the make_table function in unlzh.c in the LZH decompression component in gzip 1.3.5, when running on certain platforms, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GZIP archive…

  • CVE-2006-4336Sep 19, 2006
    risk 0.00cvss —epss 0.06

    Buffer underflow in the build_tree function in unpack.c in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted leaf count table that causes a write to a negative index.

  • CVE-2006-4337Sep 19, 2006
    risk 0.00cvss —epss 0.06

    Buffer overflow in the make_table function in the LHZ component in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted decoding table in a GZIP archive.

  • CVE-2006-4338Sep 19, 2006
    risk 0.00cvss —epss 0.04

    unlzh.c in the LHZ component in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted GZIP archive.

  • CVE-2006-4871Sep 19, 2006
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in search_run.asp in Keyvan1 (aka Keyvan Janghorbani) EShoppingPro 1.0 allows remote attackers to execute arbitrary SQL commands via the order parameter.

  • CVE-2006-4872Sep 19, 2006
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in search.asp in Keyvan1 (aka Keyvan Janghorbani) ECardPro 2.0 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.

  • CVE-2006-4873Sep 19, 2006
    risk 0.00cvss —epss 0.02

    Jupiter CMS allows remote attackers to obtain sensitive information via a direct request for (1) includes/functions.php, (2) modules/register.php, (3) modules/poll.php, (4) modules/panel.php, (5) modules/pm.php, (6) modules/news.php, (7) modules/templates_change.php, (8)…

  • CVE-2006-4874Sep 19, 2006
    risk 0.03cvss —epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in Jupiter CMS allow remote attackers to inject arbitrary web script or HTML via the (1) language[Admin name] and (2) language[Admin back] parameters in (a) modules/blocks.php; the (3) language[Register title] and (4)…

  • CVE-2006-4875Sep 19, 2006
    risk 0.04cvss —epss 0.07

    Unrestricted file upload vulnerability in modules/galleryuploadfunction.php in Jupiter CMS allows remote attackers to upload picture files, and possibly files with arbitrary extensions, to gallery/albums/public.

  • CVE-2006-4876Sep 19, 2006
    risk 0.03cvss —epss 0.02

    Multiple SQL injection vulnerabilities in Jupiter CMS allow remote attackers to execute arbitrary SQL commands via (1) the user name during login, or the (2) key or (3) fpwusername parameters in modules/register.

  • CVE-2006-4877Sep 19, 2006
    risk 0.04cvss —epss 0.09

    Variable overwrite vulnerability in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to overwrite arbitrary program variables via multiple vectors that use the extract function, as demonstrated by the table_prefix parameter in (1) index.php, (2) profile.php,…

  • CVE-2006-4878Sep 19, 2006
    risk 0.00cvss —epss 0.06

    Directory traversal vulnerability in footer.php in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to read and include arbitrary local files via a .. (dot dot) sequence in the template parameter. NOTE: this was later reported to affect 1.0.1, and…

  • CVE-2006-4879Sep 19, 2006
    risk 0.00cvss —epss 0.02

    SQL injection vulnerability in profile.php in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.

  • CVE-2006-4880Sep 19, 2006
    risk 0.00cvss —epss 0.02

    David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to obtain sensitive information via a direct request for (1) footer.php, (2) template.php, or (3) lastvisit.php, which reveals the installation path in various error messages.

  • CVE-2006-4881Sep 19, 2006
    risk 0.03cvss —epss 0.05

    Multiple cross-site scripting (XSS) vulnerabilities in David Bennett PHP-Post (PHPp) 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the replyuser parameter in (a) pm.php; (2) the txt_jumpto parameter in (b) dropdown.php; the (3) txt_error…

  • CVE-2006-4882Sep 19, 2006
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in Review.asp in Julian Roberts Charon Cart 3 allows remote attackers to execute arbitrary SQL commands via the ProductID parameter.

  • CVE-2006-4883Sep 19, 2006
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot BizDirectory allow remote attackers to inject arbitrary web script or HTML via (1) the stylesheet parameter in Feed.php or (2) the message parameter in status.php.

  • CVE-2006-4884Sep 19, 2006
    risk 0.03cvss —epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 allow remote attackers to inject arbitrary web script or HTML via (1) the suser parameter in support/rightbar.php, (2) the ticket_id parameter in support/open_tickets.php, and (3) the cons_page_title…

  • CVE-2006-4885Sep 19, 2006
    risk 0.04cvss —epss 0.07

    PHP remote file inclusion vulnerability in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) footer.php and (2) header.php. NOTE: the provenance of this information is unknown; the details are obtained…

  • CVE-2006-4886Sep 19, 2006
    risk 0.00cvss —epss 0.00

    The VirusScan On-Access Scan component in McAfee VirusScan Enterprise 7.1.0 and Scan Engine 4.4.00 allows local privileged users to bypass security restrictions and disable the On-Access Scan option by opening the program via the task bar and quickly clicking the Disable button,…

  • CVE-2006-4887Sep 19, 2006
    risk 0.00cvss —epss 0.00

    Apple Remote Desktop (ARD) for Mac OS X 10.2.8 and later does not drop privileges on the remote machine while installing certain applications, which allows local users to bypass authentication and gain privileges by selecting the icon during installation. NOTE: it could be…

  • CVE-2006-4888Sep 19, 2006
    risk 0.01cvss —epss 0.17

    Microsoft Internet Explorer 6 and earlier allows remote attackers to cause a denial of service (application hang) via a CSS-formatted HTML INPUT element within a DIV element that has a larger size than the INPUT.

  • CVE-2006-4889Sep 19, 2006
    risk 0.04cvss —epss 0.16

    Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter in (1) index.php, (2) includes/functions.gb.php, (3)…

  • CVE-2006-4535Sep 19, 2006
    risk 0.00cvss —epss 0.00

    The Linux kernel 2.6.17.10 and 2.6.17.11 and 2.6.18-rc5 allows local users to cause a denial of service (crash) via an SCTP socket with a certain SO_LINGER value, possibly related to the patch for CVE-2006-3745. NOTE: older kernel versions for specific Linux distributions are…

  • CVE-2006-4866Sep 19, 2006
    risk 0.03cvss —epss 0.01

    Buffer overflow in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via a long extension argument.

  • CVE-2006-4867Sep 19, 2006
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in mods.php in GNUTurk 2G and earlier allows remote attackers to execute arbitrary SQL commands via the t_id parameter when the go parameter is "Forum."

  • CVE-2006-4868Sep 19, 2006
    risk 0.08cvss —epss 0.61

    Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a…

  • CVE-2006-4869Sep 19, 2006
    risk 0.04cvss —epss 0.07

    PHP remote file inclusion vulnerability in phpunity-postcard.php in phpunity.postcard allows remote attackers to execute arbitrary PHP code via a URL in the gallery_path parameter.

  • CVE-2006-4870Sep 19, 2006
    risk 0.04cvss —epss 0.10

    Multiple PHP remote file inclusion vulnerabilities in AEDating 4.1, and possibly earlier versions, allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) inc/design.inc.php or (2) inc/admin_design.inc.php.

  • CVE-2006-4246Sep 19, 2006
    risk 0.00cvss —epss 0.01

    Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell parameter, which results in changing root's shell instead of the shell of a specified user.

  • CVE-2006-4684Sep 19, 2006
    risk 0.00cvss —epss 0.02

    The docutils module in Zope (Zope2) 2.7.0 through 2.7.9 and 2.8.0 through 2.8.8 does not properly handle web pages with reStructuredText (reST) markup, which allows remote attackers to read arbitrary files via a csv_table directive, a different vulnerability than CVE-2006-3458.

  • CVE-2006-4855Sep 19, 2006
    risk 0.03cvss —epss 0.01

    The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS 1.x, 2.x, 3.0, and 3.1, Symantec AntiVirus Corporate Edition SAVCE 8.x, 9.x,…

  • CVE-2006-4856Sep 19, 2006
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Roller WebLogger 2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, or (3) url parameters; (4) certain content parameters in the preview method; or (5) the q parameter in (a)…

  • CVE-2006-4857Sep 19, 2006
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in default.asp (aka the login page) in ClickTech ClickBlog 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) form_codeword (aka the Password field) parameters.

  • CVE-2006-4858Sep 19, 2006
    risk 0.04cvss —epss 0.07

    PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2006-4859Sep 19, 2006
    risk 0.04cvss —epss 0.07

    Unrestricted file upload vulnerability in contact.html.php in the Contact (com_contact) component in Limbo (aka Lite Mambo) CMS 1.0.4.2L and earlier allows remote attackers to upload PHP code to the images/contact folder via a filename with a double extension in the…

  • CVE-2006-4860Sep 19, 2006
    risk 0.00cvss —epss 0.03

    Multiple unspecified vulnerabilities in (1) index.php, (2) minixml.inc.php, (3) doc.inc.php, (4) element.inc.php, (5) node.inc.php, (6) treecomp.inc.php, (7) forum.html.php, (8) forum.php, (9) antihack.php, (10) content.php, (11) initglobals.php, and (12) imanager.php in Limbo…

  • CVE-2006-4861Sep 19, 2006
    risk 0.00cvss —epss 0.02

    SQL injection vulnerability in loginprocess.asp in Mohammed Mehdi Panjwani Complain Center 1 allows remote attackers to execute arbitrary SQL commands via the (1) TxtUser (aka Username) and (2) TxtPass (aka Password) parameters in login.asp.

  • CVE-2006-4862Sep 19, 2006
    risk 0.00cvss —epss 0.02

    SQL injection vulnerability in default.aspx in easypage allows remote attackers to execute arbitrary SQL commands via the srch parameter in the Search page.

  • CVE-2006-4863Sep 19, 2006
    risk 0.00cvss —epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in Marc Cagninacci mcLinksCounter 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the langfile parameter in (1) login.php, (2) stats.php, (3) detail.php, or (4) erase.php. NOTE: CVE and a third party…