Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2007-02-24 CVE-2006-7057 SQL-Injection vulnerability in Sphider
SQL injection vulnerability in search.php in Sphider before 1.3.1c allows remote attackers to execute arbitrary SQL commands via the category parameter.
network
low complexity
sphider
7.5
2007-02-24 CVE-2006-7054 Denial-Of-Service vulnerability in Fast360
The DNS module in Arkoon FAST360 UTM appliances 3.0 up to 3.0/29, 3.1 through 3.3, and 4.0 allows remote attackers to cause a denial of service (reboot) via a malformed DNS message, as demonstrated by the PROTOS DNS testing suite.
network
low complexity
arkoon
7.8
2007-02-24 CVE-2006-7053 Security Bypass vulnerability in Fast360
Unspecified vulnerability in Arkoon FAST360 UTM appliances 3.0 through 3.0/29, 3.1, 3.2, and 3.3 allows remote attackers to bypass keyword filtering in the FAST HTTP module, and signatures in the IDPS HTTP module, via crafted URLs that are "misinterpreted."
network
low complexity
arkoon
7.5
2007-02-24 CVE-2006-7049 Information Disclosure vulnerability in Wikkawiki Method Function
The Method method in WikkaWiki (Wikka Wiki) before 1.1.6.2 calls the strstr and strrpos functions with the wrong argument order, which allows remote attackers to bypass intended access restrictions and access arbitrary PHP files.
network
low complexity
wikkawiki
7.5
2007-02-24 CVE-2006-7048 Remote Security vulnerability in Claroline 1.7.5
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarolineRepositorySys parameter to (a) atutor.inc.php (b) db-generic.inc.php (c) docebo.inc.php (d) dokeos.1.6.inc.php (e) dokeos.inc.php (f) ganesha.inc.php (g) mambo.inc.php (h) moodle.inc.php (i) phpnuke.inc.php (j) postnuke.inc.php and (k) spip.inc.php in claroline/auth/extauth/drivers/; (2) includePath parameter in mambo.inc.php, postnuke.inc.php, and (l) inc/lib/event/init_event_manager.inc.php; and (3) rootSys parameter in (m) inc/lib/export_exe_tracking.class.php, a different set of vectors than CVE-2006-2284.
network
low complexity
claroline
7.5
2007-02-24 CVE-2006-7045 Remote Security vulnerability in Clan Manager Pro
PHP remote file inclusion vulnerability in Clan Manager Pro (CMPRO) 1.1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the (1) rootpath and possibly (2) sitepath parameters to (a) cmpro.ext/comment.core.inc.php and (b) cmpro.intern/comment.core.inc.php.
network
low complexity
cmpro-team
7.5
2007-02-24 CVE-2006-7044 Remote Security vulnerability in Clan Manager Pro
PHP remote file inclusion vulnerability in comment.core.inc.php in Clan Manager Pro (CMPRO) 1.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sitepath parameter.
network
low complexity
cmpro-team
7.5
2007-02-23 CVE-2007-1089 Local Security vulnerability in IBM DB2 Universal Database 8.0/9.1
IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors.
local
low complexity
linux microsoft ibm
7.2
2007-02-23 CVE-2007-1088 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2
Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows local users to execute arbitrary code via a long string in unspecified environment variables.
local
low complexity
ibm CWE-119
7.2
2007-02-23 CVE-2007-1087 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM DB2
IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.
local
low complexity
ibm CWE-119
7.2