Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2006-05-15 CVE-2006-2368 Cross-Site Scripting vulnerability in Clansys 1.1
Cross-site scripting (XSS) vulnerability in index.php in Clansys (aka Clanpage System) 1.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
network
clansys
5.8
2006-05-15 CVE-2006-2367 Cross-Site Scripting vulnerability in Clansys 1.0/1.1
Cross-site scripting (XSS) vulnerability in index.php in Clansys (aka Clanpage System) 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the func parameter in a search function.
network
clansys
4.3
2006-05-15 CVE-2006-2366 Unspecified vulnerability in Openobex 1.2
ircp_io.c in libopenobex for ircp 1.2, when ircp is run with the -r option, does not prompt the user when overwriting files, which allows user-assisted remote attackers to overwrite dangerous files via an arbitrary destination file name in an OBEX File Transfer session.
network
high complexity
openobex
2.6
2006-05-15 CVE-2006-2365 Cross-Site Scripting vulnerability in Vizra
Cross-site scripting (XSS) vulnerability in a_login.php in Vizra allows remote attackers to inject arbitrary web script or HTML via the message parameter.
network
vizra
5.8
2006-05-15 CVE-2006-2364 Cross-Site Scripting vulnerability in Macromedia Coldfusion 5.0
Cross-site scripting (XSS) vulnerability in the validation feature in Macromedia ColdFusion 5 and earlier allows remote attackers to inject arbitrary web script or HTML via a "_required" field when the associated normal field is missing or empty, which is not sanitized before being presented in an error message.
network
macromedia
5.8
2006-05-15 CVE-2006-2363 SQL Injection vulnerability in Limbo CMS Limbo CMS 1.0.4.2
SQL injection vulnerability in the weblinks option (weblinks.html.php) in Limbo CMS allows remote attackers to execute arbitrary SQL commands via the catid parameter.
network
high complexity
limbo-cms CWE-89
5.1
2006-05-15 CVE-2006-2361 Remote File Include vulnerability in PAFileDB Pafiledb_Constants.PHP
PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
network
low complexity
mxbb php-arena
7.5
2006-05-15 CVE-2006-2360 Input Validation vulnerability in Chart Mod
SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
phpbb-group
7.5
2006-05-15 CVE-2006-2359 Input Validation vulnerability in Chart Mod
Cross-site scripting (XSS) vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter.
network
phpbb-group
4.3
2006-05-15 CVE-2006-2358 Cross-Site Scripting vulnerability in Web-Labs CMS
Multiple cross-site scripting (XSS) vulnerabilities in various scripts in Web-Labs CMS allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter and (2) unspecified fields related to e-mail alerts.
network
web-labs
4.3