Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2006-02-13 CVE-2006-0664 Cross-Site Scripting vulnerability in Mantis Config_Defaults_Inc.PHP
Cross-site scripting (XSS) vulnerability in config_defaults_inc.php in Mantis before 1.0 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
network
mantis
4.3
2006-02-13 CVE-2006-0663 Cross-Site Scripting vulnerability in IBM Lotus Domino Inotes Client 6.5.4/7.0
Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java
script:"; or (3) when the Domino Web Access ActiveX control is not installed, via an email attachment filename.
network
ibm CWE-79
4.3
2006-02-13 CVE-2006-0662 HTML and Script Injection vulnerability in IBM Lotus Domino Inotes Client 6.5.4
Cross-site scripting (XSS) vulnerability in Lotus Domino iNotes Client 6.5.4 allows remote attackers to inject arbitrary web script or HTML via email with attached html files, which are directly rendered in the browser.
network
ibm
4.3
2006-02-13 CVE-2006-0661 Unspecified vulnerability in Scriptme SME Blog Host and SME GB Host
Cross-site scripting (XSS) vulnerability in Scriptme SmE GB Host 1.21 and SmE Blog Host allows remote attackers to inject arbitrary web script or HTML via the BBcode url tag.
network
scriptme
4.3
2006-02-13 CVE-2006-0660 Directory Traversal and Local File Include vulnerability in Farsinews 2.1/2.1Beta2/2.5
Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary files or trigger an error message path disclosure via ".." or invalid names in the archive parameter to index.php, or (2) include arbitrary files via the template parameter to show_archives.php.
network
low complexity
farsinews
6.4
2006-02-13 CVE-2006-0659 Code Injection vulnerability in Runcms 1.1/1.1A
Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote attackers to execute arbitrary code via the bbPath[path] parameter in (1) class.forumposts.php and (2) forumpollrenderer.php.
network
runcms CWE-94
6.8
2006-02-13 CVE-2006-0658 Remote Security vulnerability in Fckeditor 2.0/2.2
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt.
network
low complexity
fckeditor
5.0
2006-02-13 CVE-2006-0656 Directory Traversal vulnerability in HP Systems Insight Manager 4.2/5.0
Directory traversal vulnerability in HP Systems Insight Manager 4.2 through 5.0 SP3 for Windows allows remote attackers to access arbitrary files via unspecified vectors, a different vulnerability than CVE-2005-2006.
network
low complexity
hp
5.0
2006-02-13 CVE-2006-0655 Input Validation vulnerability in Hinton Design PHPht Topsites 1.3
Multiple cross-site scripting (XSS) vulnerabilities in (1) link_edited.php and (2) link_added.php in Hinton Design phpht Topsites 1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
hinton-design
4.3
2006-02-13 CVE-2006-0652 Information Disclosure vulnerability in Whmcompletesolution 2.0/2.1/2.2
WHMCompleteSolution (WHMCS) before 2.3 assigns incorrect permissions to "resellers", which allows remote authenticated users to perform privileged actions or obtain sensitive information.
network
low complexity
whmcompletesolution
6.5