Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-5031 | 1 Cakefoundation | 1 Cakephp | 2017-07-19 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, followed by a filename ending with "%00" and a .js filename. | |||||
CVE-2006-5033 | 1 Paul Smith Computer Services | 1 Vcap | 2017-07-19 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in StoresAndCalendarsList.cgi in Paul Smith Computer Services vCAP 1.9.0 Beta and earlier allows remote attackers to cause a denial of service via the session parameter, possibly related to format string specifiers or malformed URL encoding. | |||||
CVE-2006-5034 | 1 Paul Smith Computer Services | 1 Vcap | 2017-07-19 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in Paul Smith Computer Services vCAP 1.9.0 Beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | |||||
CVE-2006-5038 | 1 Fiwin | 1 Ss28s Wifi Voip Sip Skype Phone | 2017-07-19 | 7.5 HIGH | N/A |
The FiWin SS28S WiFi VoIP SIP/Skype Phone, firmware version 01_02_07, has a hard-coded username and password, which allows remote attackers to gain administrative access via telnet. | |||||
CVE-2006-5045 | 1 Joomlaxt | 1 Com Pollxt | 2017-07-19 | 6.8 MEDIUM | N/A |
Unspecified vulnerability in PollXT component (com_pollxt) 1.22.07 and earlier for Joomla! has unspecified impact and attack vectors, probably related to PHP remote file inclusion in the mosConfig_absolute_path to conf.pollxt.php. | |||||
CVE-2006-5058 | 1 Activision | 3 Call Of Duty, Call Of Duty 2, Call Of Duty United Offensive | 2017-07-19 | 7.5 HIGH | N/A |
Buffer overflow in (1) Call of Duty 1.5b and earlier, (2) Call of Duty United Offensive 1.51b and earlier, and (3) Call of Duty 2 1.3 and earlier allows remote attackers to execute arbitrary code via a long map argument to the "callvote map" command. | |||||
CVE-2006-5063 | 1 Stefan Ritt | 1 Elog Web Logbook | 2017-07-19 | 5.1 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Elog 2.6.1 allows remote attackers to inject arbitrary web script or HTML by editing log entries in HTML mode. | |||||
CVE-2006-5071 | 1 Eyeos Project | 1 Eyeos | 2017-07-19 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in eyeOS before 0.9.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) eyeNav and (2) system/baixar.php. | |||||
CVE-2006-5072 | 1 Mono | 1 Mono | 2017-07-19 | 6.2 MEDIUM | N/A |
The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite arbitrary files or execute arbitrary code via a symlink attack. | |||||
CVE-2006-5075 | 1 Sun | 1 Solaris | 2017-07-19 | 7.8 HIGH | N/A |
The Kernel SSL Proxy service (svc:/network/ssl/proxy) in Sun Solaris 10 before 20060926 allows remote attackers to cause a denial of service (system crash) via unspecified vectors related to an SSL client. | |||||
CVE-2006-5080 | 1 Six Apart | 1 Movable Type | 2017-07-19 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the search function in Six Apart Movable Type 3.3 to 3.32, and Movable Type Enterprise 1.01 and 1.02, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2006-5082 | 1 Sugarcrm | 1 Sugar Suite | 2017-07-19 | 7.5 HIGH | N/A |
Unspecified vulnerability in Sugar Suite Open Source (SugarCRM) before 4.2.1 Patch C (20060917) has unspecified impact, related to code execution, and unspecified attack vectors. | |||||
CVE-2006-5105 | 1 Forum One | 1 Syntaxcms | 2017-07-19 | 7.5 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in SyntaxCMS 1.1.1 through 1.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the init_path parameter to admin/testing/tests/0030_init_syntax.php, or (2) an unspecified parameter to admin/testing/index.php. NOTE: the 0004_init_urls.php vector is already covered by CVE-2006-5055. | |||||
CVE-2006-5110 | 1 Php Invoice | 1 Php Invoice | 2017-07-19 | 6.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in home.php in PHP Invoice 2.2 allows remote attackers to inject arbitrary web script or HTML via the msg parameter, a different vector than CVE-2006-5074. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |||||
CVE-2006-5111 | 1 Libksba Library | 1 Libksba Library | 2017-07-19 | 5.0 MEDIUM | N/A |
The libksba library 0.9.12 and possibly other versions, as used by gpgsm in the newpg package on SUSE LINUX, allows attackers to cause a denial of service (application crash) via a malformed X.509 certificate in a signature. | |||||
CVE-2006-5113 | 1 Yuuki Yoshizawa | 1 Exporia | 2017-07-19 | 7.5 HIGH | N/A |
Directory traversal vulnerability in common.php in Yuuki Yoshizawa Exporia 0.3.0 allows remote attackers to include and execute local files via a .. (dot dot) in the lan parameter to includes.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2006-5132 | 1 Phpmyagenda | 1 Phpmyagenda | 2017-07-19 | 7.5 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in phpMyAgenda 3.0 Final and earlier allow remote attackers to execute arbitrary PHP code via a URL in the rootagenda parameter to (1) agendaplace.php3, (2) agendaplace2.php3, (3) infoevent.php3, and (4) agenda2.php3, different vectors than CVE-2006-2009. | |||||
CVE-2006-5150 | 1 Openbiblio | 1 Openbiblio | 2017-07-19 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the reports system in OpenBiblio before 0.5.2 allows remote attackers with report privileges to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2006-5154 | 1 Deluxebb | 1 Deluxebb | 2017-07-19 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in cp/sig.php in DeluxeBB 1.09 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the templatefolder parameter. | |||||
CVE-2006-5156 | 1 Mcafee | 2 Epolicy Orchestrator, Protectionpilot | 2017-07-19 | 10.0 HIGH | N/A |
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header. |