Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2006-06-16 CVE-2006-3045 File Include vulnerability in Foing Remote
PHP remote file inclusion vulnerability in manage_songs.php in Foing 0.7.0e and earlier allows remote attackers to execute arbitrary PHP code via a URL in the foing_root_path parameter.
network
low complexity
teake-nutma
7.5
2006-06-16 CVE-2006-2909 Buffer Overflow vulnerability in Picozip 4.01
Stack-based buffer overflow in the info tip shell extension (zipinfo.dll) in PicoZip 4.01 allows remote attackers to execute arbitrary code via a long filename in an (1) ACE, (2) RAR, or (3) ZIP archive, which is triggered when the user moves the mouse over the archive.
network
low complexity
picozip
7.5
2006-06-15 CVE-2006-3028 Remote File Inclusion vulnerability in Minerva 2.0.8Abuild237
PHP remote file inclusion vulnerability in stat_modules/users_age/module.php in Minerva 2.0.8a Build 237 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
network
low complexity
minerva
7.5
2006-06-15 CVE-2006-3027 SQL Injection vulnerability in Enthrallweb ePhotos SubLevel2.ASP
Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) CAT_ID parameter in (a) subphotos.asp and (b) subLevel2.asp, the (2) AL_ID parameter in (c) photo.asp, and the (3) SUB_ID parameter in (d) subLevel2.asp.
network
low complexity
enthrallweb
7.5
2006-06-15 CVE-2006-3019 Code Injection vulnerability in PHPcms 1.2.1P12
Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPCMS_INCLUDEPATH parameter to files in parser/include/ including (1) class.parser_phpcms.php, (2) class.session_phpcms.php, (3) class.edit_phpcms.php, (4) class.http_indexer_phpcms.php, (5) class.cache_phpcms.php, (6) class.search_phpcms.php, (7) class.lib_indexer_universal_phpcms.php, and (8) class.layout_phpcms.php, (9) parser/plugs/counter.php, and (10) parser/parser.php.
network
low complexity
phpcms CWE-94
7.5
2006-06-15 CVE-2006-2916 Improper Check for Dropped Privileges vulnerability in KDE Arts 1.0/1.2
artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.
local
low complexity
kde CWE-273
7.8
2006-06-14 CVE-2006-3018 Multiple Unspecified vulnerability in PHP
Unspecified vulnerability in the session extension functionality in PHP before 5.1.3 has unknown impact and attack vectors related to heap corruption.
network
low complexity
php-group
7.5
2006-06-13 CVE-2006-3010 Cross-Site Scripting vulnerability in Aliacom Open Business Management 1.0.3Pl1
Multiple SQL injection vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to execute arbitrary SQL commands via the (1) new_order and (2) order_dir parameters to (a) index.php, (b) group/group_index.php, (c) user/user_index.php, (d) list/list_index.php, and (e) company/company_index.php, and the (3) entity and (4) tf_dateafter parameter to company/company_index.php.
network
low complexity
aliacom
7.5
2006-06-13 CVE-2006-2385 Code Injection vulnerability in Microsoft IE and Internet Explorer
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption when it is saved as a multipart HTML (.mht) file.
network
high complexity
microsoft CWE-94
7.6
2006-06-13 CVE-2006-2371 Remote Access RASMAN Registry Remote Code Execution vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Registry Corruption Vulnerability."
network
low complexity
microsoft
7.5