Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2006-05-19 CVE-2006-2486 SQL Injection vulnerability in Yapbb 1.1/1.2/1.2Beta2
SQL injection vulnerability in find.php in YapBB 1.2 Beta2 and earlier allows remote attackers to execute arbitrary SQL commands via the userID parameter.
network
low complexity
yapbb
6.4
2006-05-19 CVE-2006-2485 Remote File Include vulnerability in Quezza BB 1.1.0
PHP remote file inclusion vulnerability in includes/class_template.php in Quezza 1.0 and earlier, and possibly 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the quezza_root_path parameter.
network
low complexity
quezza
7.5
2006-05-19 CVE-2006-2484 Cross-Site Scripting vulnerability in IceWarp Universal WebMail PHPSESSID Parameter
Cross-site scripting (XSS) vulnerability in index.html in IceWarp WebMail 5.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the PHPSESSID parameter.
network
icewarp
4.3
2006-05-19 CVE-2006-1856 Unspecified vulnerability in Linux Kernel
Certain modifications to the Linux kernel 2.6.16 and earlier do not add the appropriate Linux Security Modules (LSM) file_permission hooks to the (1) readv and (2) writev functions, which might allow attackers to bypass intended access restrictions.
network
low complexity
linux
7.5
2006-05-19 CVE-2006-2480 USE of Externally-Controlled Format String vulnerability in DIA 0.94
Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename.
network
high complexity
dia CWE-134
5.1
2006-05-19 CVE-2006-0059 Remote Heap Overflow vulnerability in Livedata Iccp Server 5.00.045
Heap-based buffer overflow in the ISO Transport Service over TCP (RFC 1006) implementation of LiveData ICCP Server before 5.00.035 allows remote attackers to cause a denial of service or execute arbitrary code via malformed packets.
network
low complexity
livedata
7.5
2006-05-19 CVE-2006-2479 Information Disclosure vulnerability in Bitrix Site Manager
The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allows remote attackers to obtain sensitive information and ultimately execute arbitrary PHP code via DNS cache poisoning that redirects the user to a malicious site.
network
low complexity
bitrix
5.0
2006-05-19 CVE-2006-2478 Cross-Site Scripting vulnerability in Bitrix Site Manager
Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a HTTP POST request.
network
low complexity
bitrix
5.0
2006-05-19 CVE-2006-2477 Cross-Site Scripting vulnerability in Bitrix Site Manager
Cross-site scripting (XSS) vulnerability in the administrative interface Bitrix Site Manager 4.1.x allows remote attackers to inject arbitrary web script or HTML via unspecified inputs.
network
bitrix
4.9
2006-05-19 CVE-2006-2476 Information Disclosure vulnerability in Bitrix Site Manager
Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.
network
low complexity
bitrix
5.0