Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2007-02-22 CVE-2007-1064 Multiple vulnerability in Cisco 802.1X Authentication Deployment Products
Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client do not drop privileges when the help facility in the supplicant GUI is invoked, which allows local users to gain privileges, aka CSCsf14120.
local
low complexity
cisco meetinghouse
6.8
2007-02-22 CVE-2007-1061 SQL Injection vulnerability in PHP-Nuke
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" block is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header (HTTP_REFERER variable).
network
francisco-burzi
6.8
2007-02-22 CVE-2007-1060 Remote File Include vulnerability in Interspire SendStudio
Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl are enabled, allow remote attackers to execute arbitrary PHP code via a URL in the ROOTDIR parameter to (1) createemails.inc.php and (2) send_emails.inc.php in /admin/includes/.
network
interspire
6.8
2007-02-22 CVE-2007-1059 Remote File Include vulnerability in Ultimate FUN Book Ultimate FUN Book 1.02
PHP remote file inclusion vulnerability in function.php in Ultimate Fun Book 1.02 allows remote attackers to execute arbitrary PHP code via a URL in the gbpfad parameter.
6.8
2007-02-21 CVE-2007-1057 Local Privilege Escalation vulnerability in Nortel SSL VPN Net Direct Client
The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 1000 extracts and executes files with insecure permissions, which allows local users to exploit a race condition to replace a world-writable file in /tmp/NetClient and cause another user to execute arbitrary code when attempting to execute this client, as demonstrated by replacing /tmp/NetClient/client.
local
nortel
6.9
2007-02-21 CVE-2007-1055 Code Injection vulnerability in Mediawiki
Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.9.x before 1.9.0rc2, and 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the rs parameter.
network
mediawiki CWE-94
6.8
2007-02-21 CVE-2007-1054 Cross-Site Scripting vulnerability in Mediawiki
Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.6.x through 1.9.2, when $wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded value of the rs parameter, which is processed by Internet Explorer.
network
mediawiki
6.8
2007-02-21 CVE-2007-1051 Local Security vulnerability in Comodo Firewall Pro
Comodo Firewall Pro (formerly Comodo Personal Firewall) 2.4.17.183 and earlier uses a weak cryptographic hashing function (CRC32) to identify trusted modules, which allows local users to bypass security protections by substituting modified modules that have the same CRC32 value.
local
low complexity
comodo
4.6
2007-02-21 CVE-2007-1050 Cross-Site Scripting vulnerability in Abledesign Mycalendar
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inject arbitrary web script or HTML via (1) the go parameter, (2) the keyword parameter in the search menu (go=search), or (3) the username or (4) the password in a go=Login action.
network
abledesign CWE-79
4.3
2007-02-21 CVE-2007-1049 Cross-Site Scripting vulnerability in Wordpress
Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.
network
wordpress gentoo
4.3