VYPR

CVEs

379,993 total · page 7281 of 7,600

  • CVE-2006-0756Feb 18, 2006
    risk 0.00cvss epss 0.02

    dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allows remote attackers to obtain sensitive configuration information. NOTE: the vendor disputes this issue, saying that it could only occur if…

  • CVE-2006-0757Feb 18, 2006
    risk 0.03cvss epss 0.03

    Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in…

  • CVE-2006-0758Feb 18, 2006
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via a URL encoded expression in the query string in (1) index.php and (2) possibly certain other scripts, which is not properly cleansed…

  • CVE-2006-0759Feb 18, 2006
    risk 0.03cvss epss 0.02

    Multiple SQL injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in…

  • CVE-2006-0760Feb 18, 2006
    risk 0.00cvss epss 0.02

    LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP when the configuration…

  • CVE-2006-0761Feb 18, 2006
    risk 0.00cvss epss 0.03

    Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1…

  • CVE-2006-0762Feb 18, 2006
    risk 0.00cvss epss 0.00

    WinAbility Folder Guard 4.11 allows local users to gain unauthorized access to certain capabilities of the application by renaming or moving the password file (FGuard.FGP), which disables the password requirement.

  • CVE-2006-0763Feb 18, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in dowebmailforward.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via a URL encoded value in the fwd parameter.

  • CVE-2006-0764Feb 18, 2006
    risk 0.00cvss epss 0.02

    The Authentication, Authorization, and Accounting (AAA) capability in versions 5.0(1) and 5.0(3) of the software used by multiple Cisco Anomaly Detection and Mitigation products, when running with an incomplete TACACS+ configuration without a "tacacs-server host" command, allows…

  • CVE-2006-0765Feb 18, 2006
    risk 0.00cvss epss 0.01

    GUI display truncation vulnerability in ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions, bypass Windows security warnings via a filename that is all…

  • CVE-2006-0766Feb 18, 2006
    risk 0.00cvss epss 0.01

    ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions and bypass Windows security warnings via a filename that ends in an assumed-safe extension such as JPG,…

  • CVE-2006-0460Feb 17, 2006
    risk 0.08cvss epss 0.68

    Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error messages.

  • CVE-2006-0737Feb 17, 2006
    risk 0.03cvss epss 0.03

    eStara SIP softphone allows remote attackers to cause a denial of service (crash) via a SIP OPTIONS request with a negative Expires field.

  • CVE-2006-0738Feb 17, 2006
    risk 0.03cvss epss 0.03

    Multiple format string vulnerabilities in eStara SIP softphone allow remote attackers to cause a denial of service (hang) via SIP INVITE requests with format string specifiers in the SDP session description, as demonstrated using (1) the field name, (2) the o field…

  • CVE-2006-0739Feb 17, 2006
    risk 0.00cvss epss 0.02

    eStara SIP softphone allows remote attackers to cause a denial of service (crash) via an INVITE request with a Content-Length field that has more than 9 digits.

  • CVE-2006-0679Feb 16, 2006
    risk 0.00cvss epss 0.04

    SQL injection vulnerability in index.php in the Your_Account module in PHP-Nuke 7.8 and earlier allows remote attackers to execute arbitrary SQL commands via the username variable (Nickname field).

  • CVE-2006-0721Feb 16, 2006
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_userid parameter.

  • CVE-2006-0722Feb 16, 2006
    risk 0.00cvss epss 0.01

    settings.php in Reamday Enterprises Magic Downloads 1.1.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5)…

  • CVE-2006-0723Feb 16, 2006
    risk 0.00cvss epss 0.02

    PHP remote file inclusion vulnerability in preview.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the php_script_path parameter.

  • CVE-2006-0724Feb 16, 2006
    risk 0.00cvss epss 0.01

    profile.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5)…

  • CVE-2006-0725Feb 16, 2006
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the _PX_config[manager_path] parameter. NOTE: this is a different executable and affected version than…

  • CVE-2006-0726Feb 16, 2006
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in linking.php in CPG-Nuke Dragonfly CMS 9.0.6.1 allows remote attackers to inject arbitrary web script or HTML via a URI that is generated when creating a list of online users.

  • CVE-2006-0727Feb 16, 2006
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in mstrack.php in MusOX DF MSAnalysis (DFMSA), as used in some environments that use CPG-Nuke Dragonfly CMS, allows remote attackers to trigger path disclosure from a SQL syntax error, and possibly execute arbitrary SQL commands, via certain query…

  • CVE-2006-0728Feb 16, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in search.php in webSPELL 4.01.00 and earlier allows remote attackers to inject arbitrary SQL commands via the title_op parameter.

  • CVE-2006-0729Feb 16, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in functions.php in Teca Diary PE 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) yy, (2) mm, and (3) dd parameters.

  • CVE-2006-0730Feb 16, 2006
    risk 0.00cvss epss 0.02

    Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3)…

  • CVE-2006-0731Feb 16, 2006
    risk 0.03cvss epss 0.03

    WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter, which loads the URL inside a frame.

  • CVE-2006-0732Feb 16, 2006
    risk 0.00cvss epss 0.03

    Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullName parameter to (1) sapbc/SAP/chopSAPLog.dsp or (2) invoke/sap.monitor.rfcTrace/deleteSingle. Details will be updated after the…

  • CVE-2006-0733Feb 16, 2006
    risk 0.03cvss epss 0.05

    Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the "author's website" field. NOTE: followup comments to the researcher's web log suggest…

  • CVE-2006-0734Feb 16, 2006
    risk 0.03cvss epss 0.03

    The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.6 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a backslash character at the end of a connection string to UDP port…

  • CVE-2006-0735Feb 16, 2006
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in BBcode.pm in M. Blom HTML::BBCode 1.04 and earlier, as used in products such as My Blog before 1.65, allows remote attackers to inject arbitrary Javascript via a javascript URI in an (1) img or (2) url BBcode tag.

  • CVE-2006-0455Feb 15, 2006
    risk 0.03cvss epss 0.01

    gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded. …

  • CVE-2006-0719Feb 15, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in member_login.php in PHP Classifieds 6.18 through 6.20 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter, which is used by the E-mail address field, and (2) password parameter.

  • CVE-2006-0718Feb 15, 2006
    risk 0.00cvss epss 0.02

    The Internet Key Exchange version 1 (IKEv1) implementation in Avaya VSU 100, 2000, 7500, 10000, and CSU 5000, when running IPSec, allows remote attackers to cause a denial of service (crash) via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.…

  • CVE-2006-0666Feb 15, 2006
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 through 5.3.0.33 allows local users to cause a denial of service (system crash) via unknown vectors related to EMULATE_VMX.

  • CVE-2006-0688Feb 15, 2006
    risk 0.03cvss epss 0.04

    PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.

  • CVE-2006-0689Feb 15, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Registration Form in TTS Time Tracking Software 3.0 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter.

  • CVE-2006-0690Feb 15, 2006
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in TTS Time Tracking Software 3.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2006-0691Feb 15, 2006
    risk 0.03cvss epss 0.03

    edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbitrary data belonging to any account.

  • CVE-2006-0692Feb 15, 2006
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php.

  • CVE-2006-0693Feb 15, 2006
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in rb_auth.php in Roberto Butti CALimba 0.99.2 beta and earlier allow remote attackers to execute arbitrary SQL commands and bypass login authentication via the (1) login and (2) password parameters.

  • CVE-2006-0694Feb 15, 2006
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in the loaders (load_*.php) in Ansilove before 1.03 allows remote attackers to read arbitrary files via unspecified vectors involving "converting files accessible by the webserver".

  • CVE-2006-0695Feb 15, 2006
    risk 0.00cvss epss 0.03

    Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them directly in the upload directory.

  • CVE-2006-0696Feb 15, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in Zen Cart before 1.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2006-0697Feb 15, 2006
    risk 0.00cvss epss 0.05

    Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.

  • CVE-2006-0698Feb 15, 2006
    risk 0.00cvss epss 0.02

    Unspecified vulnerabilities in Zen Cart before 1.2.7 allow remote attackers to cause unknown impact via unspecified vectors related to "other attempted exploits" other than SQL injection.

  • CVE-2006-0699Feb 15, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter.

  • CVE-2006-0700Feb 15, 2006
    risk 0.04cvss epss 0.07

    imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions.

  • CVE-2006-0701Feb 15, 2006
    risk 0.04cvss epss 0.08

    readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters.

  • CVE-2006-0702Feb 15, 2006
    risk 0.04cvss epss 0.07

    admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter. NOTE: due to the lack of details, the specific vulnerability type cannot be determined, although it might be due to…