Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2006-01-05 CVE-2006-0088 SQL Injection vulnerability in Intouch 0.5.1Alpha
SQL injection vulnerability in intouch.lib.php in inTouch 0.5.1 Alpha allows remote attackers to execute arbitrary SQL commands via the user parameter.
network
low complexity
intouch
7.5
2006-01-05 CVE-2006-0087 SQL Injection vulnerability in Lizard Cart Lizard Cart CMS 1.0.4
SQL injection vulnerability in (1) pages.php and (2) detail.php in Lizard Cart CMS 1.04 allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
lizard-cart
7.5
2006-01-05 CVE-2006-0085 SQL-Injection vulnerability in Nkads 1.0Alfa2/1.0Alfa3
SQL injection vulnerability in Nkads 1.0 alfa 3 allows remote attackers to execute arbitrary SQL commands via the (1) usuario_nkads_admin or (2) password_nkads_admin parameters.
network
low complexity
nkads
7.5
2006-01-04 CVE-2006-0081 Resource Management Errors vulnerability in Intel Graphics Accelerator Driver 6.14.10.4308
ialmnt5.sys in the ialmrnt5 display driver in Intel Graphics Accelerator Driver 6.14.10.4308 allows attackers to cause a denial of service (crash or screen resolution change) via a long text field, as demonstrated using a long window title.
network
low complexity
intel CWE-399
7.8
2006-01-04 CVE-2006-0079 SQL Injection vulnerability in Scoznet Scozbook 1.1Beta
SQL injection vulnerability in auth.php in ScozNet ScozBook BETA 1.1 allows remote attackers to execute arbitrary SQL commands via the username field (adminname variable).
network
low complexity
scoznet
7.5
2006-01-04 CVE-2006-0076 Remote File Include vulnerability in Oaboard 1.0
PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.
network
low complexity
oaboard
7.5
2006-01-04 CVE-2006-0075 Unspecified vulnerability in GNU PHPbook
Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (mail variable) in a new message, which is written to a PHP file.
network
low complexity
gnu
7.5
2006-01-04 CVE-2006-0074 SQL Injection vulnerability in Jevontech PHPenpals
SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter.
network
low complexity
jevontech CWE-89
7.5
2006-01-04 CVE-2006-0072 Buffer Overflow vulnerability in SCO OpenServer Termsh
Buffer overflow in termsh on SCO OpenServer 5.0.7 allows remote attackers to execute arbitrary code via a long -o command line argument.
network
low complexity
sco
7.5
2006-01-03 CVE-2006-0068 SQL Injection vulnerability in Primo Place Primo Cart
SQL injection vulnerability in Primo Cart 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) q parameter to search.php and (2) email parameter to user.php.
network
low complexity
primo-place
7.5