Vulnerabilities > Zend

DATE CVE VULNERABILITY TITLE RISK
2006-11-15 CVE-2006-5900 Cross-Site Scripting vulnerability in Zend Framework Preview 0.2.0
Cross-site scripting (XSS) vulnerability in the incubator/tests/Zend/Http/_files/testRedirections.php sample code in Zend Framework Preview 0.2.0 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters.
network
zend
6.8
2006-11-04 CVE-2006-5717 Cross-Site Scripting vulnerability in Zend Google Data Client Library Preview 0.2.0
Multiple cross-site scripting (XSS) vulnerabilities in Zend Google Data Client Library (ZendGData) Preview 0.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) basedemo.php and (2) calenderdemo.php in samples/, and other unspecified files.
network
zend
4.3
2006-08-29 CVE-2006-4432 Directory Traversal vulnerability in Zend Platform
Directory traversal vulnerability in Zend Platform 2.2.1 and earlier allows remote attackers to overwrite arbitrary files via a ..
network
low complexity
zend
7.5
2006-08-29 CVE-2006-4431 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Zend Platform
Multiple buffer overflows in the (a) Session Clustering Daemon and the (b) mod_cluster module in the Zend Platform 2.2.1 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a (1) empty or (2) crafted PHP session identifier (PHPSESSID).
network
low complexity
zend CWE-119
7.5