Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2007-03-02 CVE-2006-7081 Remote File Include vulnerability in PHPnews 1.0
Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code via the Include parameter to (1) Include/lib.inc.php3 and (2) Include/variables.php3.
network
low complexity
phpnews
7.5
2007-03-02 CVE-2006-7074 USE of Hard-Coded Credentials vulnerability in Smartsitecms 1.0
admin.php in SmartSiteCMS 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the userName cookie.
network
low complexity
smartsitecms CWE-798
7.5
2007-03-02 CVE-2006-7071 SQL-Injection vulnerability in Invision Power Board
SQL injection vulnerability in classes/class_session.php in Invision Power Board (IPB) 2.1 up to 2.1.6 allows remote attackers to execute arbitrary SQL commands via the CLIENT_IP parameter.
network
low complexity
invision-power-services
7.5
2007-03-02 CVE-2006-7070 Improper Input Validation vulnerability in Etomite 0.6
Unrestricted file upload vulnerability in manager/media/ibrowser/scripts/rfiles.php in Etomite CMS 0.6.1 and earlier allows remote attackers to upload and execute arbitrary files via an nfile[] parameter with a filename that contains a .php extension followed by a valid image extension such as .gif or .jpg, then calling the rename function.
network
low complexity
etomite CWE-20
7.5
2007-03-02 CVE-2006-7069 Remote File Include vulnerability in Socketwiz Bookmarks Smarty_Config.PHP
PHP remote file inclusion vulnerability in smarty_config.php in Socketwiz Bookmarks 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the root_dir parameter.
network
low complexity
socketwiz
7.5
2007-03-02 CVE-2006-7068 Remote File Include vulnerability in CliServ Web Community
PHP remote file inclusion vulnerability in CliServ Web Community 0.65 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cl_headers parameter to (1) menu.php3 and (2) login.php3.
network
low complexity
cliserv
7.5
2007-03-02 CVE-2006-7066 Unspecified vulnerability in Microsoft Internet Explorer 6.0
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating an object inside an iframe, deleting the frame by setting its location.href to about:blank, then accessing a property of the object within the deleted frame, which triggers a NULL pointer dereference.
network
microsoft
7.1
2007-02-27 CVE-2007-1133 Remote File Include vulnerability in Fcring 1.3/1.31
PHP remote file inclusion vulnerability in fcring.php in FCRing 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_fuss parameter.
network
low complexity
scripter-ch
7.5
2007-02-27 CVE-2007-1131 Remote File Include vulnerability in Scripter.Ch Sinapis Forum 2.2
PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.
network
low complexity
scripter-ch
7.5
2007-02-27 CVE-2007-1130 Remote File Include vulnerability in Scipter.Ch Gastebuch 2.2
PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.
network
low complexity
scipter-ch
7.5