Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2006-03-03 CVE-2006-0988 Denial-Of-Service vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows NT
The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
network
low complexity
microsoft
7.8
2006-03-03 CVE-2006-0973 SQL Injection vulnerability in PHPWebSite Topics.PHP
SQL injection vulnerability in topics.php in Appalachian State University phpWebSite 0.10.2 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter.
network
low complexity
phpwebsite
7.5
2006-03-03 CVE-2006-0970 Remote Security vulnerability in SupportTrio
PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter.
network
low complexity
activecampaign
7.5
2006-03-03 CVE-2006-0969 Remote Security vulnerability in Top Sites
PHP remote file inclusion vulnerability in index.php in Top sites de PixelArtKingdom allows remote attackers to include and execute arbitrary files via the page parameter.
network
low complexity
pixelartkingdom
7.5
2006-03-02 CVE-2006-0968 Multiple vulnerability in NCP Network Communications Secure Client 8.11Build146
The ncprwsnt service in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to execute arbitrary code by modifying the connect.bat script, which is automatically executed by the service after a connection is established.
local
low complexity
ncp-network-communications
7.2
2006-03-02 CVE-2006-0962 SQL Injection vulnerability in Vubb 0.2
SQL injection vulnerability in vuBB 0.2 allows remote attackers to execute arbitrary SQL commands via the pass parameter in a cookie.
network
low complexity
vubb
7.5
2006-03-02 CVE-2006-0961 SQL Injection vulnerability in Cilem Haber 1.1
SQL injection vulnerability in yazdir.asp in Cilem Hiber 1.1 allows remote attackers to execute arbitrary SQL commands via the haber_id parameter.
network
low complexity
cilem CWE-89
7.5
2006-03-02 CVE-2006-0959 SQL Injection vulnerability in Mybulletinboard 1.0.3/1.0.4
SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands by setting the comma variable value via the comma parameter in a cookie.
network
low complexity
mybulletinboard CWE-89
7.5
2006-03-02 CVE-2006-0957 Remote PHP Script Code Injection vulnerability in freeForum
Direct static code injection vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to execute arbitrary PHP code via the (1) X-Forwarded-For and (2) Client-Ip HTTP headers, which are stored in Data/flood.db.php.
network
low complexity
zoneo-soft
7.5
2006-03-02 CVE-2006-0384 Multiple vulnerability in Apple Mac OS X Security Update 2006-001
automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via unspecified vectors that cause automount to "mount file systems with reserved names".
network
low complexity
apple
7.5