VYPR

CVEs

381,306 total · page 7243 of 7,627

  • CVE-2006-4074Aug 11, 2006
    risk 0.03cvss —epss 0.06

    PHP remote file inclusion vulnerability in lib/tpl/default/main.php in the JD-Wiki Component (com_jd-wiki) 1.0.2 and earlier for Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2006-4075Aug 11, 2006
    risk 0.04cvss —epss 0.17

    Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the INIT_PATH parameter to (1) lib/folder.class.php, (2) lib/email.inc.php, (3)…

  • CVE-2006-4076Aug 11, 2006
    risk 0.00cvss —epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 allow remote attackers to execute arbitrary PHP code via a URL in the INIT_PATH parameter to (1) lib/access.inc.php, (2) lib/folders.inc.php, (3) lib/init.inc.php or…

  • CVE-2006-4077Aug 11, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in CheckUpload.php in Vincenzo Valvano Comet WebFileManager (CWFM) 0.9.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the Language parameter.

  • CVE-2006-4078Aug 11, 2006
    risk 0.00cvss —epss 0.02

    pm.php (aka the PM system) in DeluxeBB 1.08, and possibly earlier, allows remote attackers to bypass authentication by providing an arbitrary username in the membercookie cookie parameter.

  • CVE-2006-4079Aug 11, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in newpost.php in DeluxeBB 1.08, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the subject parameter (aka the topic title field).

  • CVE-2006-4080Aug 11, 2006
    risk 0.00cvss —epss 0.01

    DeluxeBB 1.08, and possibly earlier, uses cookies that include the MD5 hash of a password, which allows remote attackers to gain privileges by sniffing or cross-site scripting (XSS) and conduct password guessing attacks.

  • CVE-2006-4071Aug 10, 2006
    risk 0.05cvss —epss 0.24

    Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.

  • CVE-2006-4050Aug 10, 2006
    risk 0.03cvss —epss 0.04

    PHP remote file inclusion vulnerability in auto_check_renewals.php in phpAutoMembersArea (phpAMA) 3.2.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter.

  • CVE-2006-4051Aug 10, 2006
    risk 0.04cvss —epss 0.08

    PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter.

  • CVE-2006-4052Aug 10, 2006
    risk 0.04cvss —epss 0.16

    Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Simple Shop 2.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) admin/index.php, (2) admin/adminindex.php, (3) admin/adminglobal.php, (4)…

  • CVE-2006-4053Aug 10, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in templates/header.php in ME Download System 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the Vb8878b936c2bd8ae0cab parameter.

  • CVE-2006-4054Aug 10, 2006
    risk 0.00cvss —epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in ME Download System 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) Vb8878b936c2bd8ae0cab parameter to (a) inc/sett_style.php or (b) inc/sett_smilies.php; or the (2) Vb6c4d0e18a204a63b38f, (3)…

  • CVE-2006-4055Aug 10, 2006
    risk 0.03cvss —epss 0.04

    Multiple PHP remote file inclusion vulnerabilities in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the tsep_config[absPath] parameter to (1) include/colorswitch.php, (2)…

  • CVE-2006-4056Aug 10, 2006
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in the authentication process in katzlbt (a) The Address Book 1.04e and earlier and (b) The Address Book Reloaded before 2.0-rc4 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters. …

  • CVE-2006-4057Aug 10, 2006
    risk 0.00cvss —epss 0.03

    Buffer overflow in the preview_create function in gui.cpp in Mitch Murray Eremove 1.4 allows remote attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via a large email attachment.

  • CVE-2006-4058Aug 10, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in archive.php in Simplog 0.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyw parameter when performing a search. NOTE: some details are obtained from third party information.

  • CVE-2006-4059Aug 10, 2006
    risk 0.04cvss —epss 0.16

    Multiple PHP remote file inclusion vulnerabilities in USOLVED NEWSolved Lite 1.9.2, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) newsscript_lyt.php, (2) newsticker/newsscript_get.php, (3)…

  • CVE-2006-4060Aug 10, 2006
    risk 0.03cvss —epss 0.04

    PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_dir parameter.

  • CVE-2006-4061Aug 10, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in index.php in Thomas Pequet phpPrintAnalyzer 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep_par_rapport_racine parameter. NOTE: this issue has been disputed by third…

  • CVE-2006-4062Aug 10, 2006
    risk 0.03cvss —epss 0.04

    PHP remote file inclusion vulnerability in usr/extensions/get_tree.inc.php in Dmitry Sheiko SAPID Shop 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[root_path] parameter.

  • CVE-2006-4063Aug 10, 2006
    risk 0.03cvss —epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in Csaba Godor SAPID Blog Beta 2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_blog_infochannel.inc.php, (b)…

  • CVE-2006-4064Aug 10, 2006
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in default.asp in YenerTurk Haber Script 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it was later reported reported that 2.0 is also affected.

  • CVE-2006-4065Aug 10, 2006
    risk 0.03cvss —epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in Dmitry Sheiko SAPID Gallery 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_calendar.inc.php or the (2) GLOBALS[root_path] parameter to…

  • CVE-2006-4066Aug 10, 2006
    risk 0.01cvss —epss 0.06

    The Graphical Device Interface Plus library (gdiplus.dll) in Microsoft Windows XP SP2 allows context-dependent attackers to cause a denial of service (application crash) via certain images that trigger a divide-by-zero error, as demonstrated by a (1) .ico file, (2) .png file…

  • CVE-2006-4067Aug 10, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 404 ("Not Found") error page. NOTE: some of these details are obtained from…

  • CVE-2006-4068Aug 10, 2006
    risk 0.03cvss —epss 0.03

    The pswd.js script relies on the client to calculate whether a username and password match hard-coded hashed values for a server, and uses a hashing scheme that creates a large number of collisions, which makes it easier for remote attackers to conduct offline brute force…

  • CVE-2006-4069Aug 10, 2006
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Elaine Aquino Online Zone Journals (OZJournals) 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) m and (2) c parameters in index.php, (3) a search action, and (4) a "submit comment" action.

  • CVE-2006-4070Aug 10, 2006
    risk 0.00cvss —epss 0.02

    Format string vulnerability in Imendio Planner 0.13 allows user-assisted attackers to execute arbitrary code via format string specifiers in a filename.

  • CVE-2006-4040Aug 9, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in myevent.php in myWebland myEvent 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter.

  • CVE-2006-4041Aug 9, 2006
    risk 0.00cvss —epss 0.02

    SQL injection vulnerability in Pike before 7.6.86, when using a Postgres database server, allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors.

  • CVE-2006-4042Aug 9, 2006
    risk 0.03cvss —epss 0.02

    Multiple SQL injection vulnerabilities in trackback.php in myWebland myBloggie 2.1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) title, (2) url, (3) excerpt, or (4) blog_name parameters.

  • CVE-2006-4043Aug 9, 2006
    risk 0.00cvss —epss 0.02

    index.php in myWebland myBloggie 2.1.4 and earlier allows remote attackers to obtain sensitive information via a query that only specifies the viewdate mode, which reveals the table prefix in a SQL error message.

  • CVE-2006-4044Aug 9, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in Beautifier/Core.php in Brad Fears phpCodeCabinet 0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the BEAUT_PATH parameter.

  • CVE-2006-4045Aug 9, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in news.php in Torbstoff News 4 allows remote attackers to execute arbitrary PHP code via a URL in the pfad parameter.

  • CVE-2006-4046Aug 9, 2006
    risk 0.04cvss —epss 0.16

    Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 and earlier for Windows, and 0.1.10_rc5 and earlier on Linux/BSD, allow remote attackers to execute arbitrary code via (1) a large .S3M file handled by the mpLoadS3M function, (2) a crafted .IT file handled by…

  • CVE-2006-4047Aug 9, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in index.php in Netious CMS 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

  • CVE-2006-4048Aug 9, 2006
    risk 0.00cvss —epss 0.02

    Netious CMS 0.4 initializes session IDs based on the client IP address, which allows remote attackers to gain access to the administration section when originating from the same IP address as the administrator. NOTE: the provenance of this information is unknown; the details…

  • CVE-2006-4049Aug 9, 2006
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in the utxconfig utility in Sun Ray Server Software 3.x allows local users to create or overwrite arbitrary files via unknown attack vectors.

  • CVE-2006-3122Aug 9, 2006
    risk 0.00cvss —epss 0.04

    The supersede_lease function in memory.c in ISC DHCP (dhcpd) server 2.0pl5 allows remote attackers to cause a denial of service (application crash) via a DHCPDISCOVER packet with a 32 byte client-identifier, which causes the packet to be interpreted as a corrupt uid and causes…

  • CVE-2006-4031Aug 9, 2006
    risk 0.00cvss —epss 0.02

    MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access a table through a previously created MERGE table, even after the user's privileges are revoked for the original table, which might violate intended security policy.

  • CVE-2006-4032Aug 9, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Cisco IOS CallManager Express (CME) allows remote attackers to gain sensitive information (user names) from the Session Initiation Protocol (SIP) user directory via certain SIP messages, aka bug CSCse92417.

  • CVE-2006-4033Aug 9, 2006
    risk 0.00cvss —epss 0.05

    Heap-based buffer overflow in Lhaplus.exe in Lhaplus 1.52, and possibly earlier versions, allows remote attackers to execute arbitrary code via an LZH archive with a long header, as specified by the extendedHeaderSize.

  • CVE-2006-4034Aug 9, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in include/html/config.php in ModernGigabyte ModernBill 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the DIR parameter.

  • CVE-2006-4035Aug 9, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in counterchaos.php in CounterChaos 0.48c and earlier allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header.

  • CVE-2006-4036Aug 9, 2006
    risk 0.03cvss —epss 0.04

    PHP remote file inclusion vulnerability in includes/usercp_register.php in ZoneMetrics ZoneX Publishers Gold Edition 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

  • CVE-2006-4037Aug 9, 2006
    risk 0.00cvss —epss 0.05

    Unspecified vulnerability in Fenestrae Faxination Server allows remote attackers to execute arbitrary code via a crafted packet.

  • CVE-2006-4038Aug 9, 2006
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in eintragen.php in GaesteChaos 0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gastname or (2) gastwohnort parameters.

  • CVE-2006-4039Aug 9, 2006
    risk 0.00cvss —epss 0.02

    Multiple SQL injection vulnerabilities in eintragen.php in GaesteChaos 0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) gastname, (2) gastwohnort, or (3) gasteintrag parameters.

  • CVE-2006-4028Aug 9, 2006
    risk 0.00cvss —epss 0.04

    Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due to lack of details, it is not clear how these issues are different from CVE-2006-3389 and CVE-2006-3390, although it is likely that 2.0.4 addresses an…