VYPR

CVEs

380,747 total · page 7260 of 7,615

  • CVE-2006-2642May 30, 2006
    risk 0.00cvss —epss 0.01

    ** UNVERIFIABLE ** NOTE: this issue does not contain any verifiable or actionable details. Cross-site scripting (XSS) vulnerability in Marco M. F. De Santis Php-residence 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via "any of its input." …

  • CVE-2006-2643May 30, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in Monster Top List (MTL) 1.4 allows remote attackers to inject arbitrary web script or HTML via the user_error_message parameter.

  • CVE-2006-2644May 30, 2006
    risk 0.00cvss —epss 0.03

    AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive.

  • CVE-2006-2645May 30, 2006
    risk 0.03cvss —epss 0.06

    PHP remote file inclusion vulnerability in manager/frontinc/prepend.php for Plume 1.0.3 allows remote attackers to execute arbitrary code via a URL in the _PX_config[manager_path] parameter. NOTE: this is a different executable and affected version than CVE-2006-0725.

  • CVE-2006-2646May 30, 2006
    risk 0.03cvss —epss 0.05

    Buffer overflow in Alt-N MDaemon, possibly 9.0.1 and earlier, allows remote attackers to execute arbitrary code via a long A0001 argument that begins with a '"' (double quote).

  • CVE-2006-2647May 30, 2006
    risk 0.00cvss —epss 0.00

    Untrusted search path vulnerability in update_flash for IBM AIX 5.1, 5.2 and 5.3 allows local users to execute arbitrary commands via unknown vectors involving lsmcode and possibly other commands.

  • CVE-2006-2648May 30, 2006
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in perform_search.asp for ASPBB 0.52 and earlier allows remote attackers to inject arbitrary HTML or web script via the search parameter.

  • CVE-2006-2649May 30, 2006
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in (a) search.php, (b) search_cat.php, (c) search_price.php, and (d) product_details.php in the cosmicshop directory for CosmicShoppingCart allow remote attackers to inject arbitrary web script or HTML via multiple unspecified…

  • CVE-2006-2650May 30, 2006
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in cosmicshop/search.php in CosmicShoppingCart allows remote attackers to execute arbitrary SQL commands via the max parameter.

  • CVE-2006-2651May 30, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in Vacation Rental Script 1.0 allows remote attackers to inject arbitrary web script or HTML via the obj parameter.

  • CVE-2006-2652May 30, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in WikiNi 0.4.2 and earlier allows remote attackers to inject arbitrary HTML and web script by editing a Wiki page to contain the script.

  • CVE-2006-2653May 30, 2006
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in login_error.shtml for D-Link DSA-3100 allows remote attackers to inject arbitrary HTML or web script via an encoded uname parameter.

  • CVE-2006-2563May 29, 2006
    risk 0.00cvss —epss 0.00

    The cURL library (libcurl) in PHP 4.4.2 and 5.1.4 allows attackers to bypass safe mode and read files via a file:// request containing null characters.

  • CVE-2006-1174May 28, 2006
    risk 0.00cvss —epss 0.00

    useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read…

  • CVE-2006-2453May 28, 2006
    risk 0.00cvss —epss 0.02

    Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-2006-2480.

  • CVE-2006-2630May 27, 2006
    risk 0.09cvss —epss 0.74

    Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack vectors.

  • CVE-2006-2631May 27, 2006
    risk 0.00cvss —epss 0.01

    phpFoX allows remote authenticated users to modify arbitrary accounts via a modified NATIO cookie value, possibly the phpfox_user parameter.

  • CVE-2006-2629May 27, 2006
    risk 0.00cvss —epss 0.01

    Race condition in Linux kernel 2.6.15 to 2.6.17, when running on SMP platforms, allows local users to cause a denial of service (crash) by creating and exiting a large number of tasks, then accessing the /proc entry of a task that is exiting, which causes memory corruption that…

  • CVE-2006-2608May 26, 2006
    risk 0.03cvss —epss 0.03

    artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the logfile parameter in a direct request to log.php, which causes the $logfile variable to be redefined to…

  • CVE-2006-2609May 26, 2006
    risk 0.00cvss —epss 0.01

    artmedic newsletter 4.1.2 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the email parameter to newsletter_log.php. NOTE: the provenance of this information is unknown; the…

  • CVE-2006-2610May 26, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in view.php in phpRaid 2.9.5 allows remote attackers to inject arbitrary web script or HTML via the (1) URL query string and the (2) Sort parameter.

  • CVE-2006-2611May 26, 2006
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in includes/Sanitizer.php in the variable handler in MediaWiki 1.6.x before r14349 allows remote attackers to inject arbitrary Javascript via unspecified vectors, possibly involving the usage of the | (pipe) character.

  • CVE-2006-2612May 26, 2006
    risk 0.00cvss —epss 0.00

    Novell Client for Windows 4.8 and 4.9 does not restrict access to the clipboard contents while a machine is locked, which allows users with physical access to read the current clipboard contents by pasting them into the "User Name" field on the login prompt.

  • CVE-2006-2613May 26, 2006
    risk 0.00cvss —epss 0.02

    Mozilla Suite 1.7.13, Mozilla Firefox 1.5.0.3 and possibly other versions before before 1.8.0, and Netscape 7.2 and 8.1, and possibly other versions and products, allows remote user-assisted attackers to obtain information such as the installation path by causing exceptions to…

  • CVE-2006-2614May 26, 2006
    risk 0.00cvss —epss 0.00

    Sun N1 System Manager 1.1 for Solaris 10 before patch 121161-01 records system passwords in the world-readable scripts (1) /cr/hd_jobs_db.sh, (2) /cr/hd_plan_checkin.sh, and (3) /cr/oracle_plan_checkin.sh, which allows local users to obtain System Manager passwords.

  • CVE-2006-2615May 26, 2006
    risk 0.00cvss —epss 0.02

    ping.php in Russcom.Ping allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter.

  • CVE-2006-2616May 26, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in the search script in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to execute arbitrary SQL commands via the uri parameter.

  • CVE-2006-2617May 26, 2006
    risk 0.00cvss —epss 0.02

    (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to obtain the installation path via an invalid entry in the Username field on the login page, which causes the path to be displayed in an SQL error. NOTE: this issue might be…

  • CVE-2006-2618May 26, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, might allow remote attackers to inject arbitrary web script or HTML via the "write a review" box. NOTE: since user reviews do not require administrator…

  • CVE-2006-2607May 25, 2006
    risk 0.00cvss —epss 0.01

    do_command.c in Vixie cron (vixie-cron) 4.1 does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits, as originally demonstrated by a program that exceeds the process…

  • CVE-2006-2444May 25, 2006
    risk 0.00cvss —epss 0.22

    The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attackers to cause a denial of service (crash) via unspecified remote attack vectors that cause failures in snmp_trap_decode that trigger (1) frees of random memory or (2) frees…

  • CVE-2006-2581May 25, 2006
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in Wiki content in RWiki 2.1.0pre1 through 2.1.0 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

  • CVE-2006-2582May 25, 2006
    risk 0.00cvss —epss 0.02

    The editing form in RWiki 2.1.0pre1 through 2.1.0 allows remote attackers to execute arbitrary Ruby code via unknown attack vectors.

  • CVE-2006-2583May 25, 2006
    risk 0.04cvss —epss 0.07

    PHP remote file inclusion vulnerability in nucleus/libs/PLUGINADMIN.php in Nucleus 3.22 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[DIR_LIBS] parameter.

  • CVE-2006-2584May 25, 2006
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in post.php in SkyeBox 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) message parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from…

  • CVE-2006-2585May 25, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in Destiney Links Script 2.1.2 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2006-2586May 25, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in IpLogger 1.7 and earlier allows remote attackers to inject arbitrary HTML or web script via the HTTP_REFERER header in an HTTP request.

  • CVE-2006-2587May 25, 2006
    risk 0.03cvss —epss 0.05

    Buffer overflow in the WebTool HTTP server component in (1) PunkBuster before 1.229, as used by multiple products including (2) America's Army 1.228 and earlier, (3) Battlefield 1942 1.158 and earlier, (4) Battlefield 2 1.184 and earlier, (5) Battlefield Vietnam 1.150 and…

  • CVE-2006-2588May 25, 2006
    risk 0.00cvss —epss 0.01

    Russcom PHPImages allows remote attackers to upload files of arbitrary types by uploading a file with a .gif extension. NOTE: due to lack of specific information about attack vectors do not depend on the existence of another vulnerability, it is not clear whether this is a…

  • CVE-2006-2589May 25, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in rss.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter. NOTE: it is not clear from the original report how this attack can succeed, since the demonstration URL uses a variable…

  • CVE-2006-2590May 25, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in e107 before 0.7.5 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

  • CVE-2006-2591May 25, 2006
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in e107 before 0.7.5 has unknown impact and remote attack vectors related to an "emailing exploit".

  • CVE-2006-2592May 25, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in DSChat 1.0 allows remote attackers to execute arbitrary PHP code via the Nickname field, which is not sanitized before creating a file in a user directory. NOTE: the provenance of this information is unknown; the details are obtained solely from…

  • CVE-2006-2605May 25, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in DSChat 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the chatbox, probably involving the ctext parameter to send.php.

  • CVE-2006-2606May 25, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Chatty, possibly 1.0.2 and other versions, allows remote attackers to inject arbitrary web script or HTML via the username.

  • CVE-2006-2549May 24, 2006
    risk 0.00cvss —epss 0.04

    Stack-based buffer overflow in PDF Form Filling and Flattening Tool before 3.1.0.12 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long field names.

  • CVE-2006-2568May 24, 2006
    risk 0.04cvss —epss 0.08

    PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute arbitrary PHP code via a URL in the thispath parameter.

  • CVE-2006-2569May 24, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows remote attackers to execute arbitrary SQL commands via the cat parameter.

  • CVE-2006-2570May 24, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS["CLPath"] parameter to (1) reconfig.php and (2) srxclr.php. NOTE: this might be due to a globals overwrite issue.

  • CVE-2006-2571May 24, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in search.html in Alkacon OpenCms 6.0.0, 6.0.2, and 6.0.3 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search action.