Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2006-05-02 CVE-2006-2146 Input Validation vulnerability in Harold Bakker Hb-Ns 1.1.6
Multiple cross-site scripting (XSS) vulnerabilities in index.php in HB-NS 1.1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) poster_name, (2) poster_email, (3) poster_homepage, or (4) message parameter.
network
harold-bakker
5.8
2006-05-02 CVE-2006-2145 Input Validation vulnerability in Harold Bakker Hb-Ns 1.1.6
Multiple SQL injection vulnerabilities in index.php in HB-NS 1.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) topic or (2) id parameter.
network
low complexity
harold-bakker
6.4
2006-05-02 CVE-2006-2144 Remote File Include vulnerability in Dmcounter 0.9.2B
PHP remote file inclusion vulnerability in kopf.php in DMCounter 0.9.2-b allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter.
network
low complexity
dmcounter
6.4
2006-05-02 CVE-2006-2143 Tag Script Injection vulnerability in Jcink Textfilebb 1.0.16
Multiple cross-site scripting (XSS) vulnerabilities in TextFileBB 1.0.16 allow remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) color, (2) size, or (3) url bbcode tags.
network
jcink
4.3
2006-05-02 CVE-2006-2142 Remote File Include vulnerability in Limbo CMS 1.0.4/1.0.4.2
PHP remote file inclusion vulnerability in classes/adodbt/sql.php in Limbo CMS 1.04 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter.
network
low complexity
limbo-cms
6.4
2006-05-02 CVE-2006-2141 Cross-Site Scripting vulnerability in Collaborative Portal Server Project Collaborative Portal Server 3.4.0
Cross-site scripting (XSS) vulnerability in popup_image in Collaborative Portal Server (CPS) 3.4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the pos argument.
4.3
2006-05-02 CVE-2006-2140 Cross-Site Scripting vulnerability in Orbitscripts Orbithyip 2.0
Multiple cross-site scripting (XSS) vulnerabilities in OrbitHYIP 2.0 and earlier allow remote attackers to inject arbitrary web script via the (1) referral parameter to signup.php or (2) id parameter to members.php.
network
orbitscripts
5.8
2006-05-02 CVE-2006-2139 SQL Injection vulnerability in Wilsonncareabusinesses PHP Newsfeed 20040723
Multiple SQL injection vulnerabilities in PHP Newsfeed 20040723 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to (a) deltables.php, (2) select, (3) header, (4) url, (5) source, or (6) time parameters to (b) manualsubmit.php, (7) num parameter to (c) delete.php, or (8) tablename parameter to (d) searchnews.php.
network
low complexity
wilsonncareabusinesses
6.4
2006-05-02 CVE-2006-2138 Cross-Site Scripting vulnerability in Neomail 1.29
Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.29 allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter.
network
neomail
4.3
2006-05-02 CVE-2006-2137 Remote File Include vulnerability in OpenPHPnuke
PHP remote file inclusion vulnerability in master.php in OpenPHPNuke and 2.3.3 earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.
network
low complexity
openphpnuke
7.5