Vulnerabilities > Zend
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-11-15 | CVE-2006-5900 | Cross-Site Scripting vulnerability in Zend Framework Preview 0.2.0 Cross-site scripting (XSS) vulnerability in the incubator/tests/Zend/Http/_files/testRedirections.php sample code in Zend Framework Preview 0.2.0 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters. network zend | 6.8 |
2006-11-04 | CVE-2006-5717 | Cross-Site Scripting vulnerability in Zend Google Data Client Library Preview 0.2.0 Multiple cross-site scripting (XSS) vulnerabilities in Zend Google Data Client Library (ZendGData) Preview 0.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) basedemo.php and (2) calenderdemo.php in samples/, and other unspecified files. network zend | 4.3 |
2006-08-29 | CVE-2006-4432 | Directory Traversal vulnerability in Zend Platform Directory traversal vulnerability in Zend Platform 2.2.1 and earlier allows remote attackers to overwrite arbitrary files via a .. | 7.5 |
2006-08-29 | CVE-2006-4431 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Zend Platform Multiple buffer overflows in the (a) Session Clustering Daemon and the (b) mod_cluster module in the Zend Platform 2.2.1 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a (1) empty or (2) crafted PHP session identifier (PHPSESSID). | 7.5 |