VYPR

CVEs

380,829 total · page 7255 of 7,617

  • CVE-2006-2995Jun 13, 2006
    risk 0.04cvss —epss 0.08

    Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the INCDIR parameter in (1) include/nav.php and (2) include/lang.php.

  • CVE-2006-2996Jun 13, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in inc/design.inc.php in LoveCompass aePartner 0.8.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the dir[data] parameter.

  • CVE-2006-2997Jun 13, 2006
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in ZMS 2.9 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the raw parameter in the search field.

  • CVE-2006-2998Jun 13, 2006
    risk 0.04cvss —epss 0.07

    PHP remote file inclusion vulnerability in board/post.php in free QBoard 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the qb_path parameter.

  • CVE-2006-2999Jun 13, 2006
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in search.php in OkScripts QuickLinks 1.1 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

  • CVE-2006-3000Jun 13, 2006
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in search.php in OkScripts OkArticles 1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

  • CVE-2006-3001Jun 13, 2006
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in search.php in OkScripts OkMall 1.0 allow remote attackers to inject arbitrary web script or HTML via the page parameter. NOTE: this might be resultant from another vulnerability, since the XSS is reflected in an error message.

  • CVE-2006-3002Jun 13, 2006
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in details.php in Easy Ad-Manager allows remote attackers to inject arbitrary web script or HTML via the mbid parameter, which is reflected in an error message. NOTE: on 20060829, the vendor notified CVE that this issue has been fixed.

  • CVE-2006-3003Jun 13, 2006
    risk 0.00cvss —epss 0.02

    details.php in Easy Ad-Manager allows remote attackers to obtain the full installation path via an invalid mbid parameter, which leaks the path in an error message. NOTE: this might be resultant from another vulnerability, since this vector also produces cross-site scripting…

  • CVE-2006-3004Jun 13, 2006
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Ez Ringtone Manager allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in player.php and (2) keyword parameter when performing a search.

  • CVE-2006-2981Jun 12, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in vs_search.php in Arantius Vice Stats before 1.0.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors, a different issue than CVE-2006-2972.

  • CVE-2006-2972Jun 12, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in vs_resource.php in Arantius Vice Stats 0.5b and 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

  • CVE-2006-2973Jun 12, 2006
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in month.php in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) catid and (2) cid parameter. NOTE: this might be a duplicate of CVE-2005-4009.c.

  • CVE-2006-2974Jun 12, 2006
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 6.1.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) errCode and (2) uid parameter in (a) default.asp and (3) dname parameter in (b) /admin/dns.asp and (c)…

  • CVE-2006-2975Jun 12, 2006
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in pblguestbook.php in PBL Guestbook 1.31 allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of IMG tags in the (1) name, (2) email, and (3) website parameter, which bypasses XSS…

  • CVE-2006-2976Jun 12, 2006
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in usermgr.php in Coppermine Photo Gallery before 1.4.7 has unknown impact and remote attack vectors, possibly related to authorization/authentication errors.

  • CVE-2006-2977Jun 12, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in big.php in Mafia Moblog 0.6M1 and earlier allows remote attackers to execute arbitrary SQL commands via the img parameter.

  • CVE-2006-2978Jun 12, 2006
    risk 0.00cvss —epss 0.01

    Mafia Moblog 0.6M1 and earlier allows remote attackers to obtain the installation path in an error message via a direct request to (1) big.php and (2) upgrade.php.

  • CVE-2006-2979Jun 12, 2006
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Free 2.5.5, and possibly other distributions including Light, Standard, and Enterprise, allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter in forum.php, which is not…

  • CVE-2006-2980Jun 12, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in block_forum_topic_new.php in ViArt Shop Free 2.5.5, and possibly other distributions including Light, Standard, and Enterprise, might allow remote attackers to execute arbitrary SQL commands via unknown vectors, probably involving the forum_id…

  • CVE-2006-2943Jun 12, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in CGI-RESCUE WebFORM 4.1 and earlier allows remote attackers to inject email headers, which facilitates sending spam messages. NOTE: the details for this issue are obtained from third party information.

  • CVE-2006-2944Jun 12, 2006
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in CGI-RESCUE FORM2MAIL 1.21 and earlier allows remote attackers to inject email headers, which facilitates sending spam messages. NOTE: the details for this issue are obtained from third party information.

  • CVE-2006-2945Jun 12, 2006
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the user profile change functionality in DokuWiki, when Access Control Lists are enabled, allows remote authenticated users to read unauthorized files via unknown attack vectors.

  • CVE-2006-2946Jun 12, 2006
    risk 0.03cvss —epss 0.03

    Dmx Forum 2.1a stores _includes/bd.inc under the web root with insufficient access control, which allows remote attackers to obtain database username and password information.

  • CVE-2006-2947Jun 12, 2006
    risk 0.03cvss —epss 0.03

    Dmx Forum 2.1a allows remote attackers to obtain username and password information via a direct request to pops/edit.php with a modified membre parameter.

  • CVE-2006-2948Jun 12, 2006
    risk 0.00cvss —epss 0.02

    A-CART 2.0 stores the acart2_0.mdb file under the web document root with insufficient access control, which allows remote attackers to obtain username and password information.

  • CVE-2006-2949Jun 12, 2006
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in private.php in MyBB 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the do parameter.

  • CVE-2006-2950Jun 12, 2006
    risk 0.00cvss —epss 0.02

    Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) header.php, (2) contact.php, or (3) forum_extender.php, which reveals the path in an error message.

  • CVE-2006-2951Jun 12, 2006
    risk 0.00cvss —epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in Net Portal Dynamic System (NPDS) 5.10 and earlier allow remote attackers to inject arbitrary web script and HTML via the (1) Titlesitename or (2) sitename parameter to (a) header.php, (3) nuke_url parameter to (b)…

  • CVE-2006-2952Jun 12, 2006
    risk 0.00cvss —epss 0.03

    Directory traversal vulnerability in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the (1) Default_Theme parameter to header.php or (2) ModPath parameter to…

  • CVE-2006-2953Jun 12, 2006
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in default.asp in OfficeFlow 2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the sqlType parameter.

  • CVE-2006-2954Jun 12, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in files.asp in OfficeFlow 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the Project parameter.

  • CVE-2006-2955Jun 12, 2006
    risk 0.03cvss —epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice 7.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) New Category (newcategory) or (2) apage parameter to (a) edtalbum.asp, or the (3) cat or (4) albumid parameter to (b)…

  • CVE-2006-2956Jun 12, 2006
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in i.List 1.5 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) searchword parameter to search.php or (2) siteurl parameter to add.php.

  • CVE-2006-2957Jun 12, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in i.List 1.5 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the banurl parameter to add.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

  • CVE-2006-2958Jun 12, 2006
    risk 0.00cvss —epss 0.01

    Directory traversal vulnerability in FilZip 3.05 allows remote attackers to write arbitrary files via a .. (dot dot) in a (1) .rar, (2) .tar, (3) .jar, or (4) .gz file. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

  • CVE-2006-2959Jun 12, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in inc_header.asp in Snitz Forum 3.4.05 and earlier allows remote attackers to execute arbitrary SQL commands via the %strCookieURL%.GROUP parameter in a cookie.

  • CVE-2006-2960Jun 12, 2006
    risk 0.00cvss —epss 0.02

    PHP remote file inclusion vulnerability in includes/joomla.php in Joomla! 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the includepath parameter.

  • CVE-2006-2961Jun 12, 2006
    risk 0.08cvss —epss 0.62

    Stack-based buffer overflow in CesarFTP 0.99g and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MKD command. NOTE: the provenance of this information is unknown; the details are obtained from…

  • CVE-2006-2962Jun 12, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in sql_fcnsOLD.php in Emergenices Personnel Information System (Empris) 20020923 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phormationdir parameter.

  • CVE-2006-2963Jun 12, 2006
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in Suchergebnisse.asp in Cabacos Web CMS 3.8.498 and earlier allows remote attackers to inject arbitrary web script or HTML via the suchtext parameter.

  • CVE-2006-2964Jun 12, 2006
    risk 0.00cvss —epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in Xtreme Scripts Download Manager (aka Xtreme Downloads) 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) download.php, (2) manager.php, (3) admin/scripts/category.php, (4)…

  • CVE-2006-2965Jun 12, 2006
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Particle Soft Particle Whois 1.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the target parameter in index.php and (2) the "input box."

  • CVE-2006-2966Jun 12, 2006
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in Particle Soft Particle Wiki 1.0.2 allows remote attackers to inject arbitrary web script or HTML via a BR element with an extraneous IMG tag and a STYLE attribute that contains "/**/" comment sequences, which bypasses the XSS…

  • CVE-2006-2967Jun 12, 2006
    risk 0.00cvss —epss 0.00

    Syworks SafeNET allows local users to bypass restrictions on network resource consumption by editing the policy.dat file.

  • CVE-2006-2968Jun 12, 2006
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in search.php in PHP Labware LabWiki 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input box (query parameter).

  • CVE-2006-2969Jun 12, 2006
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in L0j1k tinyMuw 0.1.0 allow remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element in the input box in quickchat.php, and possibly other manipulations.

  • CVE-2006-2970Jun 12, 2006
    risk 0.00cvss —epss 0.01

    videoPage.php in L0j1k tinyMuw 0.1.0 allows remote attackers to obtain sensitive information via a certain id parameter, probably with an invalid value, which reveals the path in an error message.

  • CVE-2006-2971Jun 12, 2006
    risk 0.03cvss —epss 0.05

    Integer overflow in the recv_packet function in 0verkill 0.16 allows remote attackers to cause a denial of service (daemon crash) via a UDP packet with fewer than 12 bytes, which results in a long length value to the crc32 function.

  • CVE-2006-2452Jun 9, 2006
    risk 0.00cvss —epss 0.00

    GNOME GDM 2.8, 2.12, 2.14, and 2.15, when the "face browser" feature is enabled, allows local users to access the "Configure Login Manager" functionality using their own password instead of the root password, which can be leveraged to gain additional privileges.