Vulnerabilities > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-10-20 | CVE-2006-5413 | Remote File Include vulnerability in Supermod 3.0.0 Multiple PHP remote file inclusion vulnerabilities in SuperMod 3.0.0 for YABB (YaBBSM) allow remote attackers to execute arbitrary PHP code via a URL in the sourcedir parameter to (1) Offline.php, (2) Sources/Admin.php, (3) Sources/Offline.php, or (4) content/portalshow.php. | 7.5 |
2006-10-20 | CVE-2006-5411 | Remote Command Execution vulnerability in FreeWPS Upload.PHP Unrestricted file upload vulnerability in upload.php for Free Web Publishing System (FreeWPS), possibly 2.11 and earlier, allows remote attackers to upload and execute arbitrary PHP programs. | 7.5 |
2006-10-20 | CVE-2006-5409 | Products Management Interface Multiple Input Validation vulnerability in Highwall Multiple SQL injection vulnerabilities in the wireless IDS management interface for Highwall Enterprise and Highwall Endpoint 4.0.2.11045 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | 7.5 |
2006-10-19 | CVE-2006-5407 | Unspecified vulnerability in Osticket PHP remote file inclusion vulnerability in open_form.php in osTicket allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter. | 7.5 |
2006-10-18 | CVE-2006-5402 | Code Injection vulnerability in PHPmybibli Multiple PHP remote file inclusion vulnerabilities in PHPmybibli 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) class_path, (2) javascript_path, and (3) include_path parameters in (a) cart.php; the (4) class_path parameter in (b) index.php; the (5) javascript_path parameter in (c) edit.php; the (6) include_path parameter in (d) circ.php; unspecified parameters in (e) select.php; and unspecified parameters in other files. | 7.5 |
2006-10-18 | CVE-2006-5401 | Remote File Include vulnerability in Aroundme 0.5.1 PHP remote file inclusion vulnerability in template/barnraiser_01/p_new_password.tpl.php in AROUNDMe 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the templatePath parameter. | 7.5 |
2006-10-18 | CVE-2006-5399 | Code Injection vulnerability in PHPrecipebook 2.36 PHP remote file inclusion vulnerability in classes/Import_MM.class.php in PHPRecipeBook 2.36, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the g_rb_basedir parameter. | 7.5 |
2006-10-18 | CVE-2006-5398 | SQL Injection vulnerability in Simplog 0.9.3.1 SQL injection vulnerability in comments.php in Simplog 0.9.3.1 allows remote attackers to execute arbitrary SQL commands via the cid parameter. | 7.5 |
2006-10-18 | CVE-2006-5395 | Local Buffer Overflow vulnerability in Microsoft Class Package Export Tool 5.0.2752 Buffer overflow in Microsoft Class Package Export Tool (aka clspack.exe) allows context-dependent attackers to execute arbitrary code via a long string. | 7.5 |
2006-10-18 | CVE-2006-5392 | Remote File Include vulnerability in OpenDock FullCore Multiple PHP remote file inclusion vulnerabilities in OpenDock FullCore 4.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) sw/index_sw.php; (2) cart.php, (3) lib_cart.php, (4) lib_read_cart.php, (5) lib_sys_cart.php, and (6) txt_info_cart.php in sw/lib_cart/; (7) comment.php, (8) find_comment.php, and (9) lib_comment.php in sw/lib_comment/; (10) sw/lib_find/find.php; and other unspecified PHP scripts. | 7.5 |