| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2006-0756 | 0.00 | — | 0.02 | Feb 18, 2006 | dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allows remote attackers to obtain sensitive configuration information. NOTE: the vendor disputes this issue, saying that it could only occur if… | |||
| CVE-2006-0757 | 0.03 | — | 0.03 | Feb 18, 2006 | Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in… | |||
| CVE-2006-0758 | 0.03 | — | 0.02 | Feb 18, 2006 | Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via a URL encoded expression in the query string in (1) index.php and (2) possibly certain other scripts, which is not properly cleansed… | |||
| CVE-2006-0759 | 0.03 | — | 0.02 | Feb 18, 2006 | Multiple SQL injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in… | |||
| CVE-2006-0760 | 0.00 | — | 0.02 | Feb 18, 2006 | LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP when the configuration… | |||
| CVE-2006-0761 | 0.00 | — | 0.03 | Feb 18, 2006 | Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1… | |||
| CVE-2006-0762 | 0.00 | — | 0.00 | Feb 18, 2006 | WinAbility Folder Guard 4.11 allows local users to gain unauthorized access to certain capabilities of the application by renaming or moving the password file (FGuard.FGP), which disables the password requirement. | |||
| CVE-2006-0763 | 0.00 | — | 0.01 | Feb 18, 2006 | Cross-site scripting (XSS) vulnerability in dowebmailforward.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via a URL encoded value in the fwd parameter. | |||
| CVE-2006-0764 | 0.00 | — | 0.02 | Feb 18, 2006 | The Authentication, Authorization, and Accounting (AAA) capability in versions 5.0(1) and 5.0(3) of the software used by multiple Cisco Anomaly Detection and Mitigation products, when running with an incomplete TACACS+ configuration without a "tacacs-server host" command, allows… | |||
| CVE-2006-0765 | 0.00 | — | 0.01 | Feb 18, 2006 | GUI display truncation vulnerability in ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions, bypass Windows security warnings via a filename that is all… | |||
| CVE-2006-0766 | 0.00 | — | 0.01 | Feb 18, 2006 | ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions and bypass Windows security warnings via a filename that ends in an assumed-safe extension such as JPG,… | |||
| CVE-2006-0460 | 0.08 | — | 0.68 | Feb 17, 2006 | Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error messages. | |||
| CVE-2006-0737 | 0.03 | — | 0.03 | Feb 17, 2006 | eStara SIP softphone allows remote attackers to cause a denial of service (crash) via a SIP OPTIONS request with a negative Expires field. | |||
| CVE-2006-0738 | 0.03 | — | 0.03 | Feb 17, 2006 | Multiple format string vulnerabilities in eStara SIP softphone allow remote attackers to cause a denial of service (hang) via SIP INVITE requests with format string specifiers in the SDP session description, as demonstrated using (1) the field name, (2) the o field… | |||
| CVE-2006-0739 | 0.00 | — | 0.02 | Feb 17, 2006 | eStara SIP softphone allows remote attackers to cause a denial of service (crash) via an INVITE request with a Content-Length field that has more than 9 digits. | |||
| CVE-2006-0679 | 0.00 | — | 0.04 | Feb 16, 2006 | SQL injection vulnerability in index.php in the Your_Account module in PHP-Nuke 7.8 and earlier allows remote attackers to execute arbitrary SQL commands via the username variable (Nickname field). | |||
| CVE-2006-0721 | 0.03 | — | 0.02 | Feb 16, 2006 | SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_userid parameter. | |||
| CVE-2006-0722 | 0.00 | — | 0.01 | Feb 16, 2006 | settings.php in Reamday Enterprises Magic Downloads 1.1.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5)… | |||
| CVE-2006-0723 | 0.00 | — | 0.02 | Feb 16, 2006 | PHP remote file inclusion vulnerability in preview.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the php_script_path parameter. | |||
| CVE-2006-0724 | 0.00 | — | 0.01 | Feb 16, 2006 | profile.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5)… | |||
| CVE-2006-0725 | 0.03 | — | 0.03 | Feb 16, 2006 | PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the _PX_config[manager_path] parameter. NOTE: this is a different executable and affected version than… | |||
| CVE-2006-0726 | 0.00 | — | 0.02 | Feb 16, 2006 | Cross-site scripting (XSS) vulnerability in linking.php in CPG-Nuke Dragonfly CMS 9.0.6.1 allows remote attackers to inject arbitrary web script or HTML via a URI that is generated when creating a list of online users. | |||
| CVE-2006-0727 | 0.00 | — | 0.02 | Feb 16, 2006 | SQL injection vulnerability in mstrack.php in MusOX DF MSAnalysis (DFMSA), as used in some environments that use CPG-Nuke Dragonfly CMS, allows remote attackers to trigger path disclosure from a SQL syntax error, and possibly execute arbitrary SQL commands, via certain query… | |||
| CVE-2006-0728 | 0.03 | — | 0.01 | Feb 16, 2006 | SQL injection vulnerability in search.php in webSPELL 4.01.00 and earlier allows remote attackers to inject arbitrary SQL commands via the title_op parameter. | |||
| CVE-2006-0729 | 0.00 | — | 0.01 | Feb 16, 2006 | SQL injection vulnerability in functions.php in Teca Diary PE 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) yy, (2) mm, and (3) dd parameters. | |||
| CVE-2006-0730 | 0.00 | — | 0.02 | Feb 16, 2006 | Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3)… | |||
| CVE-2006-0731 | 0.03 | — | 0.03 | Feb 16, 2006 | WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter, which loads the URL inside a frame. | |||
| CVE-2006-0732 | 0.00 | — | 0.03 | Feb 16, 2006 | Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullName parameter to (1) sapbc/SAP/chopSAPLog.dsp or (2) invoke/sap.monitor.rfcTrace/deleteSingle. Details will be updated after the… | |||
| CVE-2006-0733 | 0.03 | — | 0.05 | Feb 16, 2006 | Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the "author's website" field. NOTE: followup comments to the researcher's web log suggest… | |||
| CVE-2006-0734 | 0.03 | — | 0.03 | Feb 16, 2006 | The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.6 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a backslash character at the end of a connection string to UDP port… | |||
| CVE-2006-0735 | 0.03 | — | 0.03 | Feb 16, 2006 | Cross-site scripting (XSS) vulnerability in BBcode.pm in M. Blom HTML::BBCode 1.04 and earlier, as used in products such as My Blog before 1.65, allows remote attackers to inject arbitrary Javascript via a javascript URI in an (1) img or (2) url BBcode tag. | |||
| CVE-2006-0455 | 0.03 | — | 0.01 | Feb 15, 2006 | gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded. … | |||
| CVE-2006-0719 | 0.03 | — | 0.01 | Feb 15, 2006 | SQL injection vulnerability in member_login.php in PHP Classifieds 6.18 through 6.20 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter, which is used by the E-mail address field, and (2) password parameter. | |||
| CVE-2006-0718 | 0.00 | — | 0.02 | Feb 15, 2006 | The Internet Key Exchange version 1 (IKEv1) implementation in Avaya VSU 100, 2000, 7500, 10000, and CSU 5000, when running IPSec, allows remote attackers to cause a denial of service (crash) via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.… | |||
| CVE-2006-0666 | 0.00 | — | 0.00 | Feb 15, 2006 | Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 through 5.3.0.33 allows local users to cause a denial of service (system crash) via unknown vectors related to EMULATE_VMX. | |||
| CVE-2006-0688 | 0.03 | — | 0.04 | Feb 15, 2006 | PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter. | |||
| CVE-2006-0689 | 0.00 | — | 0.01 | Feb 15, 2006 | Cross-site scripting (XSS) vulnerability in the Registration Form in TTS Time Tracking Software 3.0 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter. | |||
| CVE-2006-0690 | 0.00 | — | 0.01 | Feb 15, 2006 | Multiple SQL injection vulnerabilities in TTS Time Tracking Software 3.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||
| CVE-2006-0691 | 0.03 | — | 0.03 | Feb 15, 2006 | edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbitrary data belonging to any account. | |||
| CVE-2006-0692 | 0.00 | — | 0.01 | Feb 15, 2006 | Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php. | |||
| CVE-2006-0693 | 0.00 | — | 0.01 | Feb 15, 2006 | Multiple SQL injection vulnerabilities in rb_auth.php in Roberto Butti CALimba 0.99.2 beta and earlier allow remote attackers to execute arbitrary SQL commands and bypass login authentication via the (1) login and (2) password parameters. | |||
| CVE-2006-0694 | 0.00 | — | 0.01 | Feb 15, 2006 | Unspecified vulnerability in the loaders (load_*.php) in Ansilove before 1.03 allows remote attackers to read arbitrary files via unspecified vectors involving "converting files accessible by the webserver". | |||
| CVE-2006-0695 | 0.00 | — | 0.03 | Feb 15, 2006 | Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them directly in the upload directory. | |||
| CVE-2006-0696 | 0.00 | — | 0.01 | Feb 15, 2006 | SQL injection vulnerability in Zen Cart before 1.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||
| CVE-2006-0697 | 0.00 | — | 0.05 | Feb 15, 2006 | Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests. | |||
| CVE-2006-0698 | 0.00 | — | 0.02 | Feb 15, 2006 | Unspecified vulnerabilities in Zen Cart before 1.2.7 allow remote attackers to cause unknown impact via unspecified vectors related to "other attempted exploits" other than SQL injection. | |||
| CVE-2006-0699 | 0.03 | — | 0.02 | Feb 15, 2006 | Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |||
| CVE-2006-0700 | 0.04 | — | 0.07 | Feb 15, 2006 | imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions. | |||
| CVE-2006-0701 | 0.04 | — | 0.08 | Feb 15, 2006 | readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters. | |||
| CVE-2006-0702 | 0.04 | — | 0.07 | Feb 15, 2006 | admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter. NOTE: due to the lack of details, the specific vulnerability type cannot be determined, although it might be due to… |
- CVE-2006-0756Feb 18, 2006risk 0.00cvss —epss 0.02
dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allows remote attackers to obtain sensitive configuration information. NOTE: the vendor disputes this issue, saying that it could only occur if…
- CVE-2006-0757Feb 18, 2006risk 0.03cvss —epss 0.03
Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in…
- CVE-2006-0758Feb 18, 2006risk 0.03cvss —epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via a URL encoded expression in the query string in (1) index.php and (2) possibly certain other scripts, which is not properly cleansed…
- CVE-2006-0759Feb 18, 2006risk 0.03cvss —epss 0.02
Multiple SQL injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in…
- CVE-2006-0760Feb 18, 2006risk 0.00cvss —epss 0.02
LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP when the configuration…
- CVE-2006-0761Feb 18, 2006risk 0.00cvss —epss 0.03
Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1…
- CVE-2006-0762Feb 18, 2006risk 0.00cvss —epss 0.00
WinAbility Folder Guard 4.11 allows local users to gain unauthorized access to certain capabilities of the application by renaming or moving the password file (FGuard.FGP), which disables the password requirement.
- CVE-2006-0763Feb 18, 2006risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in dowebmailforward.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via a URL encoded value in the fwd parameter.
- CVE-2006-0764Feb 18, 2006risk 0.00cvss —epss 0.02
The Authentication, Authorization, and Accounting (AAA) capability in versions 5.0(1) and 5.0(3) of the software used by multiple Cisco Anomaly Detection and Mitigation products, when running with an incomplete TACACS+ configuration without a "tacacs-server host" command, allows…
- CVE-2006-0765Feb 18, 2006risk 0.00cvss —epss 0.01
GUI display truncation vulnerability in ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions, bypass Windows security warnings via a filename that is all…
- CVE-2006-0766Feb 18, 2006risk 0.00cvss —epss 0.01
ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions and bypass Windows security warnings via a filename that ends in an assumed-safe extension such as JPG,…
- CVE-2006-0460Feb 17, 2006risk 0.08cvss —epss 0.68
Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error messages.
- CVE-2006-0737Feb 17, 2006risk 0.03cvss —epss 0.03
eStara SIP softphone allows remote attackers to cause a denial of service (crash) via a SIP OPTIONS request with a negative Expires field.
- CVE-2006-0738Feb 17, 2006risk 0.03cvss —epss 0.03
Multiple format string vulnerabilities in eStara SIP softphone allow remote attackers to cause a denial of service (hang) via SIP INVITE requests with format string specifiers in the SDP session description, as demonstrated using (1) the field name, (2) the o field…
- CVE-2006-0739Feb 17, 2006risk 0.00cvss —epss 0.02
eStara SIP softphone allows remote attackers to cause a denial of service (crash) via an INVITE request with a Content-Length field that has more than 9 digits.
- CVE-2006-0679Feb 16, 2006risk 0.00cvss —epss 0.04
SQL injection vulnerability in index.php in the Your_Account module in PHP-Nuke 7.8 and earlier allows remote attackers to execute arbitrary SQL commands via the username variable (Nickname field).
- CVE-2006-0721Feb 16, 2006risk 0.03cvss —epss 0.02
SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_userid parameter.
- CVE-2006-0722Feb 16, 2006risk 0.00cvss —epss 0.01
settings.php in Reamday Enterprises Magic Downloads 1.1.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5)…
- CVE-2006-0723Feb 16, 2006risk 0.00cvss —epss 0.02
PHP remote file inclusion vulnerability in preview.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the php_script_path parameter.
- CVE-2006-0724Feb 16, 2006risk 0.00cvss —epss 0.01
profile.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5)…
- CVE-2006-0725Feb 16, 2006risk 0.03cvss —epss 0.03
PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the _PX_config[manager_path] parameter. NOTE: this is a different executable and affected version than…
- CVE-2006-0726Feb 16, 2006risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in linking.php in CPG-Nuke Dragonfly CMS 9.0.6.1 allows remote attackers to inject arbitrary web script or HTML via a URI that is generated when creating a list of online users.
- CVE-2006-0727Feb 16, 2006risk 0.00cvss —epss 0.02
SQL injection vulnerability in mstrack.php in MusOX DF MSAnalysis (DFMSA), as used in some environments that use CPG-Nuke Dragonfly CMS, allows remote attackers to trigger path disclosure from a SQL syntax error, and possibly execute arbitrary SQL commands, via certain query…
- CVE-2006-0728Feb 16, 2006risk 0.03cvss —epss 0.01
SQL injection vulnerability in search.php in webSPELL 4.01.00 and earlier allows remote attackers to inject arbitrary SQL commands via the title_op parameter.
- CVE-2006-0729Feb 16, 2006risk 0.00cvss —epss 0.01
SQL injection vulnerability in functions.php in Teca Diary PE 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) yy, (2) mm, and (3) dd parameters.
- CVE-2006-0730Feb 16, 2006risk 0.00cvss —epss 0.02
Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3)…
- CVE-2006-0731Feb 16, 2006risk 0.03cvss —epss 0.03
WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter, which loads the URL inside a frame.
- CVE-2006-0732Feb 16, 2006risk 0.00cvss —epss 0.03
Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullName parameter to (1) sapbc/SAP/chopSAPLog.dsp or (2) invoke/sap.monitor.rfcTrace/deleteSingle. Details will be updated after the…
- CVE-2006-0733Feb 16, 2006risk 0.03cvss —epss 0.05
Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the "author's website" field. NOTE: followup comments to the researcher's web log suggest…
- CVE-2006-0734Feb 16, 2006risk 0.03cvss —epss 0.03
The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.6 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a backslash character at the end of a connection string to UDP port…
- CVE-2006-0735Feb 16, 2006risk 0.03cvss —epss 0.03
Cross-site scripting (XSS) vulnerability in BBcode.pm in M. Blom HTML::BBCode 1.04 and earlier, as used in products such as My Blog before 1.65, allows remote attackers to inject arbitrary Javascript via a javascript URI in an (1) img or (2) url BBcode tag.
- CVE-2006-0455Feb 15, 2006risk 0.03cvss —epss 0.01
gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded. …
- CVE-2006-0719Feb 15, 2006risk 0.03cvss —epss 0.01
SQL injection vulnerability in member_login.php in PHP Classifieds 6.18 through 6.20 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter, which is used by the E-mail address field, and (2) password parameter.
- CVE-2006-0718Feb 15, 2006risk 0.00cvss —epss 0.02
The Internet Key Exchange version 1 (IKEv1) implementation in Avaya VSU 100, 2000, 7500, 10000, and CSU 5000, when running IPSec, allows remote attackers to cause a denial of service (crash) via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.…
- CVE-2006-0666Feb 15, 2006risk 0.00cvss —epss 0.00
Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 through 5.3.0.33 allows local users to cause a denial of service (system crash) via unknown vectors related to EMULATE_VMX.
- CVE-2006-0688Feb 15, 2006risk 0.03cvss —epss 0.04
PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.
- CVE-2006-0689Feb 15, 2006risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in the Registration Form in TTS Time Tracking Software 3.0 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter.
- CVE-2006-0690Feb 15, 2006risk 0.00cvss —epss 0.01
Multiple SQL injection vulnerabilities in TTS Time Tracking Software 3.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
- CVE-2006-0691Feb 15, 2006risk 0.03cvss —epss 0.03
edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbitrary data belonging to any account.
- CVE-2006-0692Feb 15, 2006risk 0.00cvss —epss 0.01
Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php.
- CVE-2006-0693Feb 15, 2006risk 0.00cvss —epss 0.01
Multiple SQL injection vulnerabilities in rb_auth.php in Roberto Butti CALimba 0.99.2 beta and earlier allow remote attackers to execute arbitrary SQL commands and bypass login authentication via the (1) login and (2) password parameters.
- CVE-2006-0694Feb 15, 2006risk 0.00cvss —epss 0.01
Unspecified vulnerability in the loaders (load_*.php) in Ansilove before 1.03 allows remote attackers to read arbitrary files via unspecified vectors involving "converting files accessible by the webserver".
- CVE-2006-0695Feb 15, 2006risk 0.00cvss —epss 0.03
Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them directly in the upload directory.
- CVE-2006-0696Feb 15, 2006risk 0.00cvss —epss 0.01
SQL injection vulnerability in Zen Cart before 1.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
- CVE-2006-0697Feb 15, 2006risk 0.00cvss —epss 0.05
Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.
- CVE-2006-0698Feb 15, 2006risk 0.00cvss —epss 0.02
Unspecified vulnerabilities in Zen Cart before 1.2.7 allow remote attackers to cause unknown impact via unspecified vectors related to "other attempted exploits" other than SQL injection.
- CVE-2006-0699Feb 15, 2006risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter.
- CVE-2006-0700Feb 15, 2006risk 0.04cvss —epss 0.07
imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions.
- CVE-2006-0701Feb 15, 2006risk 0.04cvss —epss 0.08
readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters.
- CVE-2006-0702Feb 15, 2006risk 0.04cvss —epss 0.07
admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter. NOTE: due to the lack of details, the specific vulnerability type cannot be determined, although it might be due to…