Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2006-11-06 CVE-2006-5728 Resource Management Errors vulnerability in Dxmsoft XM Easy Personal FTP Server 4.2/4.3
XM Easy Personal FTP Server 5.2.1 and earlier allows remote authenticated users to cause a denial of service via a long argument to the NLST command, possibly involving the -al flags.
network
low complexity
dxmsoft CWE-399
4.0
2006-11-06 CVE-2006-5727 Remote File Include vulnerability in Sazcart 1.5
PHP remote file inclusion vulnerability in admin/controls/cart.php in sazcart 1.5 allows remote attackers to execute arbitrary PHP code via the (1) _saz[settings][shippingfolder] and (2) _saz[settings][taxfolder] parameters.
network
high complexity
sazcart
5.1
2006-11-06 CVE-2006-5726 Local Denial of Service vulnerability in SUN Solaris 10.0
alloccgblk in the UFS filesystem in Solaris 10 allows local users to cause a denial of service (memory corruption) by mounting crafted UFS filesystems with malformed data structures.
local
low complexity
sun
4.9
2006-11-06 CVE-2006-5466 Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assisted attackers to execute arbitrary code via crafted RPM packages.
network
high complexity
rpm ubuntu
5.4
2006-11-04 CVE-2006-5725 Information Exposure vulnerability in AEP Networks Smartgate SSL Server 4.3B
The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request for a directory URI, which returns different HTTP status codes for existing and non-existing directories.
network
low complexity
aep-networks CWE-200
5.0
2006-11-04 CVE-2006-5722 Remote Security vulnerability in Middlebury College Segue CMS 1.3.5/1.5.7/1.5.8
Multiple PHP remote file inclusion vulnerabilities in Segue CMS 1.5.9 and earlier, when magic_quotes_gpc is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the theme parameter to (1) themesettings.php or (2) index.php, a different vector than CVE-2006-5497.
network
high complexity
middlebury-college
5.1
2006-11-04 CVE-2006-5721 Local Denial of Service vulnerability in Agnitum Outpost Firewall 4.0
The \Device\SandBox driver in Outpost Firewall PRO 4.0 (964.582.059) allows local users to cause a denial of service (system crash) via an invalid argument to the DeviceIoControl function that triggers an invalid memory operation.
local
low complexity
agnitum
4.9
2006-11-04 CVE-2006-5718 Cross-Site Scripting vulnerability in PHPMyAdmin UTF-7 Encoding
Cross-site scripting (XSS) vulnerability in error.php in phpMyAdmin 2.6.4 through 2.9.0.2 allows remote attackers to inject arbitrary web script or HTML via UTF-7 or US-ASCII encoded characters, which are injected into an error message, as demonstrated by a request with a utf7 charset parameter accompanied by UTF-7 data.
network
phpmyadmin
4.3
2006-11-04 CVE-2006-5717 Cross-Site Scripting vulnerability in Zend Google Data Client Library Preview 0.2.0
Multiple cross-site scripting (XSS) vulnerabilities in Zend Google Data Client Library (ZendGData) Preview 0.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) basedemo.php and (2) calenderdemo.php in samples/, and other unspecified files.
network
zend
4.3
2006-11-04 CVE-2006-5716 Remote File Include vulnerability in Freenews 2.1
Directory traversal vulnerability in aff_news.php in FreeNews 2.1 allows remote attackers to include local files via a ..
network
low complexity
freenews
5.0