Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2006-09-01 CVE-2006-4522 Local Privilege Escalation vulnerability in IBM AIX Dtterm
Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code with root privileges via unspecified vectors.
local
low complexity
ibm
7.2
2006-08-31 CVE-2006-4505 Unspecified vulnerability in NX5 Nx5Linx 1.0
CRLF injection vulnerability in links.php in NX5Linx 1.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a CRLF sequence in the url parameter.
network
low complexity
nx5
7.5
2006-08-31 CVE-2006-4504 SQL Injection vulnerability in NX5 Nx5Linx 1.0
SQL injection vulnerability in NX5Linx 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) c and (2) l parameters.
network
low complexity
nx5
7.5
2006-08-31 CVE-2006-4502 Input Validation vulnerability in Ztml Ezportal Ztml CMS 1.0
ezPortal/ztml CMS 1.0 allows remote attackers to bypass authentication controls via a direct request to the "Administration Area" script.
network
low complexity
ztml
7.5
2006-08-31 CVE-2006-4501 Input Validation vulnerability in Ztml Ezportal Ztml CMS 1.0
SQL injection vulnerability in index.php in ezPortal/ztml CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) about, (2) album, (3) id, (4) use, (5) desc, (6) doc, (7) mname, (8) max, and possibly other parameters.
network
low complexity
ztml
7.5
2006-08-31 CVE-2006-4498 Remote File Include vulnerability in PHPalbum.Net PHPalbum 0.2.3
PHP remote file inclusion vulnerability in sommaire_admin.php in PhpAlbum (mod_phpalbum) 2.15 for PortailPHP allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter, a different vector than CVE-2006-3922.
network
low complexity
phpalbum-net
7.5
2006-08-31 CVE-2006-4497 SQL Injection vulnerability in Iwebnegar 1.1
SQL injection vulnerability in comments.php in IwebNegar 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
iwebnegar
7.5
2006-08-31 CVE-2006-4495 COM Object Instantiation Code Execution vulnerability in Microsoft Windows 2000
Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.
network
low complexity
microsoft
7.5
2006-08-31 CVE-2006-4494 Denial of Service vulnerability in Microsoft Visual Studio 6.0
Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Visual Studio 6.0 ActiveX COM Objects in Internet Explorer, including (1) tcprops.dll, (2) fp30wec.dll, (3) mdt2db.dll, (4) mdt2qd.dll, and (5) vi30aut.dll.
network
low complexity
microsoft
7.5
2006-08-31 CVE-2006-4489 Remote File Include vulnerability in MiniBill Config[Plugin_Dir] Parameter
Multiple PHP remote file inclusion vulnerabilities in MiniBill 2006-07-14 (1.2.2) allow remote attackers to execute arbitrary PHP code via (1) a URL in the config[include_dir] parameter in actions/ipn.php or (2) an FTP path in the config[plugin_dir] parameter in include/initPlugins.php.
network
low complexity
ultrize
7.5