Vulnerabilities
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-05-19 | CVE-2006-2486 | SQL Injection vulnerability in Yapbb 1.1/1.2/1.2Beta2 SQL injection vulnerability in find.php in YapBB 1.2 Beta2 and earlier allows remote attackers to execute arbitrary SQL commands via the userID parameter. | 6.4 |
2006-05-19 | CVE-2006-2485 | Remote File Include vulnerability in Quezza BB 1.1.0 PHP remote file inclusion vulnerability in includes/class_template.php in Quezza 1.0 and earlier, and possibly 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the quezza_root_path parameter. | 7.5 |
2006-05-19 | CVE-2006-2484 | Cross-Site Scripting vulnerability in IceWarp Universal WebMail PHPSESSID Parameter Cross-site scripting (XSS) vulnerability in index.html in IceWarp WebMail 5.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the PHPSESSID parameter. network icewarp | 4.3 |
2006-05-19 | CVE-2006-1856 | Unspecified vulnerability in Linux Kernel Certain modifications to the Linux kernel 2.6.16 and earlier do not add the appropriate Linux Security Modules (LSM) file_permission hooks to the (1) readv and (2) writev functions, which might allow attackers to bypass intended access restrictions. | 7.5 |
2006-05-19 | CVE-2006-2480 | USE of Externally-Controlled Format String vulnerability in DIA 0.94 Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename. | 5.1 |
2006-05-19 | CVE-2006-0059 | Remote Heap Overflow vulnerability in Livedata Iccp Server 5.00.045 Heap-based buffer overflow in the ISO Transport Service over TCP (RFC 1006) implementation of LiveData ICCP Server before 5.00.035 allows remote attackers to cause a denial of service or execute arbitrary code via malformed packets. | 7.5 |
2006-05-19 | CVE-2006-2479 | Information Disclosure vulnerability in Bitrix Site Manager The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allows remote attackers to obtain sensitive information and ultimately execute arbitrary PHP code via DNS cache poisoning that redirects the user to a malicious site. | 5.0 |
2006-05-19 | CVE-2006-2478 | Cross-Site Scripting vulnerability in Bitrix Site Manager Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a HTTP POST request. | 5.0 |
2006-05-19 | CVE-2006-2477 | Cross-Site Scripting vulnerability in Bitrix Site Manager Cross-site scripting (XSS) vulnerability in the administrative interface Bitrix Site Manager 4.1.x allows remote attackers to inject arbitrary web script or HTML via unspecified inputs. network bitrix | 4.9 |
2006-05-19 | CVE-2006-2476 | Information Disclosure vulnerability in Bitrix Site Manager Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information. | 5.0 |