Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2006-04-21 CVE-2006-1971 Cross-Site Scripting vulnerability in ContentBoxx Login.PHP
Cross-site scripting (XSS) vulnerability in login.php in KRANKIKOM ContentBoxX allows remote attackers to inject arbitrary web script or HTML via the action parameter.
network
krankikom
4.3
2006-04-21 CVE-2006-1970 Cross-Site Scripting vulnerability in Portal Pack
Cross-site scripting (XSS) vulnerability in classifieds/viewcat.cgi in KCScripts Classifieds, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.
network
kcscripts
4.3
2006-04-21 CVE-2006-1969 Cross-Site Scripting vulnerability in Portal Pack
Cross-site scripting (XSS) vulnerability in search/search.cgi in an unspecified KCScripts script, probably Search Engine or Site Search, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the q parameter.
network
high complexity
kcscripts
2.6
2006-04-21 CVE-2006-1968 Cross-Site Scripting vulnerability in Portal Pack
Cross-site scripting (XSS) vulnerability in news/NsVisitor.cgi in KCScripts News Publisher, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter.
network
kcscripts
5.8
2006-04-21 CVE-2006-1967 Cross-Site Scripting vulnerability in Kcscripts Calendar and Portal Pack
Cross-site scripting (XSS) vulnerability in calendar/Visitor.cgi in KCScripts Calendar, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter.
network
high complexity
kcscripts
2.6
2006-04-21 CVE-2006-1966 Denial-Of-Service vulnerability in Fortinet28
An unspecified Fortinet product, possibly Fortinet28, allows remote attackers to cause a denial of service via a "small synflood" to the SMTP port (TCP port 25), as demonstrated by a 10-microsecond wait between sending packets.
network
low complexity
fortinet
5.0
2006-04-21 CVE-2006-1965 Cross-Site Scripting vulnerability in Aasi Media NET Clubs PRO 4.0
Multiple cross-site scripting (XSS) vulnerabilities in aasi media Net Clubs Pro 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) onuser, (2) pass, (3) chatsys, (4) room, (5) username, and (6) to parameters in (a) sendim.cgi; the (7) username parameter in (b) imessage.cgi; the (8) password parameter in (c) login.cgi; and the (9) cat_id parameter in (d) viewcat.cgi.
network
aasi-media
5.8
2006-04-21 CVE-2006-1964 SQL Injection vulnerability in Aspsitem 1.83
SQL injection vulnerability in Haberler.asp in ASPSitem 1.83 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
aspsitem
7.5
2006-04-21 CVE-2006-1963 SQL Injection vulnerability in PCPIN Chat Main.PHP
Directory traversal vulnerability in main.php in PCPIN Chat 5.0.4 and earlier allows remote authenticated users to include and execute arbitrary PHP code via a ".." (dot dot) in a language cookie, as demonstrated by uploading then accessing a smiliefile image that actually contains PHP code.
network
low complexity
pcpin
5.5
2006-04-21 CVE-2006-1962 SQL Injection vulnerability in Pcpin Chat
SQL injection vulnerability in PCPIN Chat 5.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (login parameter) to main.php.
network
low complexity
pcpin CWE-89
7.5