Weekly Vulnerabilities Reports > February 27 to March 5, 2006
Overview
85 new vulnerabilities reported during this period, including 2 critical vulnerabilities and 26 high severity vulnerabilities. This weekly summary report vulnerabilities in 75 products from 60 vendors including Apple, NCP Network Communications, Mozilla, Argosoft, and Microsoft. Vulnerabilities are notably categorized as "Resource Management Errors", "SQL Injection", "Path Traversal", "Code Injection", and "Cross-site Scripting".
- 72 reported vulnerabilities are remotely exploitables.
- 6 reported vulnerabilities have public exploit available.
- 5 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 75 reported vulnerabilities are exploitable by an anonymous user.
- Apple has the most reported vulnerabilities, with 6 reported vulnerabilities.
- Novell has the most reported critical vulnerabilities, with 1 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
2 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2006-03-03 | CVE-2006-0979 | Nidelven IT | Information Disclosure vulnerability in Nidelven IT Issue Dealer 0.9.95 Unspecified vulnerability in the local weblog publisher in Nidelven IT Issue Dealer before 0.9.96 has unknown impact and attack vectors. | 10.0 |
2006-02-27 | CVE-2006-0736 | Novell | Remote Buffer Overflow vulnerability in Novell Linux Desktop and Open Enterprise Server Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors. | 10.0 |
26 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2006-03-03 | CVE-2006-0988 | Microsoft | Denial-Of-Service vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows NT The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses. | 7.8 |
2006-02-27 | CVE-2006-0900 | Freebsd | Remote NFS RPC Request Denial of Service vulnerability in Freebsd 6.0 nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demonstrated by the ProtoVer NFS test suite. | 7.8 |
2006-03-03 | CVE-2006-0973 | Phpwebsite | SQL Injection vulnerability in PHPWebSite Topics.PHP SQL injection vulnerability in topics.php in Appalachian State University phpWebSite 0.10.2 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter. | 7.5 |
2006-03-03 | CVE-2006-0970 | Activecampaign | Remote Security vulnerability in SupportTrio PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter. | 7.5 |
2006-03-03 | CVE-2006-0969 | Pixelartkingdom | Remote Security vulnerability in Top Sites PHP remote file inclusion vulnerability in index.php in Top sites de PixelArtKingdom allows remote attackers to include and execute arbitrary files via the page parameter. | 7.5 |
2006-03-02 | CVE-2006-0962 | Vubb | SQL Injection vulnerability in Vubb 0.2 SQL injection vulnerability in vuBB 0.2 allows remote attackers to execute arbitrary SQL commands via the pass parameter in a cookie. | 7.5 |
2006-03-02 | CVE-2006-0961 | Cilem | SQL Injection vulnerability in Cilem Haber 1.1 SQL injection vulnerability in yazdir.asp in Cilem Hiber 1.1 allows remote attackers to execute arbitrary SQL commands via the haber_id parameter. | 7.5 |
2006-03-02 | CVE-2006-0959 | Mybulletinboard | SQL Injection vulnerability in Mybulletinboard 1.0.3/1.0.4 SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands by setting the comma variable value via the comma parameter in a cookie. | 7.5 |
2006-03-02 | CVE-2006-0957 | Zoneo Soft | Remote PHP Script Code Injection vulnerability in freeForum Direct static code injection vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to execute arbitrary PHP code via the (1) X-Forwarded-For and (2) Client-Ip HTTP headers, which are stored in Data/flood.db.php. | 7.5 |
2006-03-02 | CVE-2006-0384 | Apple | Multiple vulnerability in Apple Mac OS X Security Update 2006-001 automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via unspecified vectors that cause automount to "mount file systems with reserved names". | 7.5 |
2006-03-01 | CVE-2006-0947 | Thomson | Cross-Site Scripting vulnerability in Thomson SpeedTouch 500 Series Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the "31" parameter in a NewUser function, which is not filtered by the modem when creating the account, but cannot be deleted by the administrator, possibly due to cleansing that occurs in the administrator interface. | 7.5 |
2006-03-01 | CVE-2006-0944 | Archangelmgt | Authentication Bypass vulnerability in Archangelmgt Weblog 0.90.02 Archangel Weblog 0.90.02 allows remote attackers to bypass authentication by setting the ba_admin cookie to 1. | 7.5 |
2006-03-01 | CVE-2006-0943 | Pwsphp | SQL-Injection vulnerability in Pwsphp 1.2.3 SQL injection vulnerability in the sondages module in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | 7.5 |
2006-03-01 | CVE-2006-0942 | Pwsphp | SQL Injection vulnerability in PwsPHP SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the aff_news_form parameter, a different vulnerability than CVE-2005-1509. | 7.5 |
2006-03-01 | CVE-2006-0940 | Cynical Games | Input Validation vulnerability in Cynical Games Shoutlive 1.1.0 Multiple direct static code injection vulnerabilities in savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to execute arbitrary PHP code via variables that are written to settings.php. | 7.5 |
2006-03-01 | CVE-2006-0939 | DCI Designs | SQL Injection vulnerability in Dci-Designs Dci-Taskeen 1.03 SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id or (2) action parameter to (a) basket.php, or (3) id or (4) page parameter to (b) cat.php. | 7.5 |
2006-02-28 | CVE-2006-0919 | OI | SQL-Injection vulnerability in OI Email Marketing System 3.0 SQL injection vulnerability in index.php (aka the login page) in Oi! Email Marketing System 3.0 (aka Oi! 3) allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields. | 7.5 |
2006-02-28 | CVE-2006-0918 | Ritlabs | Remote Buffer Overflow vulnerability in Ritlabs the BAT 3.60.07 Buffer overflow in RITLabs The Bat! 3.60.07 allows remote attackers to execute arbitrary code via a long Subject field. | 7.5 |
2006-02-28 | CVE-2006-0916 | Mozilla | Information Disclosure vulnerability in Bugzilla User Credentials Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domain. | 7.5 |
2006-02-28 | CVE-2006-0915 | Mozilla | Unspecified vulnerability in Mozilla Bugzilla 2.16.10 Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which allows remote attackers to trigger a SQL error. | 7.5 |
2006-02-28 | CVE-2006-0908 | Francisco Burzi | SQL-Injection vulnerability in Francisco Burzi PHP-Nuke 7.8Patched3.2 PHP-Nuke 7.8 Patched 3.2 allows remote attackers to bypass SQL injection protection mechanisms via /%2a (/*) sequences with the "ad_click" word in the query string, as demonstrated via the kala parameter. | 7.5 |
2006-02-28 | CVE-2006-0907 | Francisco Burzi | SQL-Injection vulnerability in Francisco Burzi PHP-Nuke 7.8 SQL injection vulnerability in PHP-Nuke before 7.8 Patched 3.2 allows remote attackers to execute arbitrary SQL commands via encoded /%2a (/*) sequences in the query string, which bypasses regular expressions that are intended to protect against SQL injection, as demonstrated via the kala parameter. | 7.5 |
2006-02-28 | CVE-2006-0906 | TOP Line | SQL Injection vulnerability in TOP Line D3Jeeb PRO 3 SQL injection vulnerability in D3Jeeb Pro 3 allows remote attackers to execute arbitrary SQL commands via the catid parameter in (1) fastlinks.php and (2) catogary.php. | 7.5 |
2006-02-27 | CVE-2006-0899 | 4Images | Remote File Include vulnerability in 4images Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot dot) sequences in the template parameter. | 7.5 |
2006-03-02 | CVE-2006-0968 | NCP Network Communications | Multiple vulnerability in NCP Network Communications Secure Client 8.11Build146 The ncprwsnt service in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to execute arbitrary code by modifying the connect.bat script, which is automatically executed by the service after a connection is established. | 7.2 |
2006-02-27 | CVE-2006-0901 | SUN | Local Denial Of Service vulnerability in Sun Solaris HSFS Filesystem Unspecified vulnerability in the hsfs filesystem in Solaris 8, 9, and 10 allows unspecified attackers to cause a denial of service (panic) or execute arbitrary code. | 7.2 |
45 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2006-03-01 | CVE-2006-0945 | Archangelmgt | Code Injection vulnerability in Archangelmgt Weblog 0.90.02 PHP remote file include vulnerability in admin/index.php in Archangel Weblog 0.90.02 allows remote authenticated administrators to execute arbitrary PHP code via a URL ending in a NULL (%00) in the index parameter. | 6.5 |
2006-02-28 | CVE-2006-0936 | Free Host Shop | Unspecified vulnerability in Free Host Shop Website Generator 3.3 Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a dangerous file extension and a trailing %00. | 6.5 |
2006-02-28 | CVE-2006-0921 | Fckeditor | Unspecified vulnerability in Fckeditor 2.0Fc Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackers to list and create arbitrary directories via a .. | 6.4 |
2006-02-28 | CVE-2006-0914 | Mozilla | Improper Input Validation vulnerability in Mozilla Bugzilla Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote attackers to trigger a SQL error. | 5.5 |
2006-02-28 | CVE-2006-0913 | Mozilla | SQL Injection vulnerability in Bugzilla Whinedays SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows remote authenticated users with administrative privileges to execute arbitrary SQL commands via the whinedays parameter, as accessible from editparams.cgi. | 5.5 |
2006-03-03 | CVE-2006-0995 | EMC Dantz | Remote Denial of Service vulnerability in EMC Dantz Retrospect Backup Client EMC Dantz Retrospect 7 backup client 7.0.107, and other versions before 7.0.109, and 6.5 before 6.5.138 allows remote attackers to cause a denial of service (client termination and loss of backup service) via a malformed packet to TCP port 497, which triggers an assert error. | 5.0 |
2006-03-03 | CVE-2006-0987 | ISC | Denial-Of-Service vulnerability in ISC Bind 9.3.2 The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses. | 5.0 |
2006-03-03 | CVE-2006-0986 | Wordpress | Information Disclosure vulnerability in WordPress WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) default-filters.php, (2) template-loader.php, (3) rss-functions.php, (4) locale.php, (5) wp-db.php, and (6) kses.php in the wp-includes/ directory; and (7) edit-form-advanced.php, (8) admin-functions.php, (9) edit-link-form.php, (10) edit-page-form.php, (11) admin-footer.php, and (12) menu.php in the wp-admin directory; and possibly (13) list directory contents of the wp-includes directory. | 5.0 |
2006-03-03 | CVE-2006-0982 | Mcafee | Security Bypass vulnerability in Mcafee Virex 7.7 The on-access scanner for McAfee Virex 7.7 for Macintosh, in some circumstances, might not activate when malicious content is accessed from the web browser, and might not prevent the content from being saved, which allows remote attackers to bypass virus protection, as demonstrated using the EICAR test file. | 5.0 |
2006-03-03 | CVE-2006-0977 | Craig Morrison | Unspecified vulnerability in Craig Morrison MTS PRO Craig Morrison Mail Transport System Professional (aka MTS Pro) acts as an open relay when configured to relay all mail through an external SMTP server, which allows remote attackers to relay mail by connecting to the MTS Pro server, then sending a MAIL FROM that specifies a domain that is local to the server. | 5.0 |
2006-03-03 | CVE-2006-0976 | Spid | Path Traversal vulnerability in Spid 1.3.1 Directory traversal vulnerability in scan_lang_insert.php in Boris Herbiniere-Seve SPiD 1.3.1 allows remote attackers to read arbitrary files via the lang parameter. | 5.0 |
2006-03-03 | CVE-2006-0972 | Fscripts | SQL Injection vulnerability in Fscripts Fantastic News 2.1.1 SQL injection vulnerability in news.php in Tony Baird Fantastic News 2.1.1 allows remote attackers to execute arbitrary SQL commands via the page parameter. | 5.0 |
2006-03-03 | CVE-2006-0971 | Lionel Reyero | Directory Traversal vulnerability in Lionel Reyero Directcontact 0.3B Directory traversal vulnerability in Lionel Reyero DirectContact 0.3b allows remote attackers to read arbitrary files via a .. | 5.0 |
2006-03-02 | CVE-2006-0960 | Compex | Denial Of Service vulnerability in Compex NetPassage WPE54G uConfig agent in Compex NetPassage WPE54G router allows remote attackers to cause a denial of service (unresposiveness) via crafted datagrams to UDP port 7778. | 5.0 |
2006-03-02 | CVE-2006-0383 | Apple | Multiple vulnerability in Apple Mac OS X Security Update 2006-001 IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving the "incorrect handling of error conditions". | 5.0 |
2006-02-28 | CVE-2006-0937 | UNU Networks | Information Disclosure vulnerability in UNU Networks Mailgust 1.9 U.N.U. | 5.0 |
2006-02-28 | CVE-2006-0932 | Pear | Directory Traversal vulnerability in Pear Archive ZIP 1.1 Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a ZIP archive. | 5.0 |
2006-02-28 | CVE-2006-0931 | Pear | Path Traversal vulnerability in Pear Archive TAR Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a TAR archive. | 5.0 |
2006-02-28 | CVE-2006-0928 | Argosoft | Remote Information Disclosure vulnerability in Argosoft Mail Server 1.8 The POP3 Server in ArGoSoft Mail Server Pro 1.8 allows remote attackers to obtain sensitive information via the _DUMP command, which reveals the operating system, registered user, and registration code. | 5.0 |
2006-02-28 | CVE-2006-0925 | ALT N | Remote Format String vulnerability in Alt-N MDaemon IMAP Server Format string vulnerability in the IMAP4rev1 server in Alt-N MDaemon 8.1.1 and possibly 8.1.4 allows remote attackers to cause a denial of service (CPU consumption) by creating and then listing folders whose names contain format string specifiers. | 5.0 |
2006-02-28 | CVE-2006-0922 | Devellion | Unspecified vulnerability in Devellion Cubecart CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results in an absolute path traversal vulnerability in FileUpload in connector.php (aka upload.php) that allows remote attackers to upload arbitrary files via a modified CurrentFolder parameter in a direct request to admin/filemanager/upload.php. | 5.0 |
2006-02-28 | CVE-2006-0912 | Oreka | Remote Denial of Service vulnerability in Oreka RTP Packet Handling Oreka before 0.5 allows remote attackers to cause a denial of service (application crash) via a "certain RTP sequence." | 5.0 |
2006-02-28 | CVE-2006-0911 | Ipswitch | Resource Management Errors vulnerability in Ipswitch Whatsup Professional2006 NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumption) via crafted requests to Login.asp, possibly involving the (1) "In]" and (2) "b;tnLogIn" parameters, or (3) malformed btnLogIn parameters, possibly involving missing "[" (open bracket) or "[" (closing bracket) characters, as demonstrated by "&btnLogIn=[Log&In]=&" or "&b;tnLogIn=[Log&In]=&" in the URL. | 5.0 |
2006-02-28 | CVE-2006-0910 | Invision Power Services | Remote Security vulnerability in Invision Power Board Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to list directory contents via a direct request to multiple directories, including (1) sources/loginauth/convert/, (2) sources/portal_plugins/, (3) cache/skin_cache/cacheid_2/, (4) ips_kernel/PEAR/, (5) ips_kernel/PEAR/Text/, (6) ips_kernel/PEAR/Text/Diff/, (7) ips_kernel/PEAR/Text/Diff/Renderer/, (8) style_images/1/folder_rte_files/, (9) style_images/1/folder_js_skin/, (10) style_images/1/folder_rte_images/, and (11) upgrade/ and its subdirectories. | 5.0 |
2006-02-28 | CVE-2006-0909 | Invision Power Services | Information Disclosure vulnerability in Invision Power Board Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to view sensitive information via a direct request to multiple PHP scripts that include the full path in error messages, including (1) PEAR/Text/Diff/Renderer/inline.php, (2) PEAR/Text/Diff/Renderer/unified.php, (3) PEAR/Text/Diff3.php, (4) class_db.php, (5) class_db_mysql.php, and (6) class_xml.php in the ips_kernel/ directory; (7) mysql_admin_queries.php, (8) mysql_extra_queries.php, (9) mysql_queries.php, and (10) mysql_subsm_queries.php in the sources/sql directory; (11) sources/acp_loaders/acp_pages_components.php; (12) sources/action_admin/member.php and (13) sources/action_admin/paysubscriptions.php; (14) login.php, (15) messenger.php, (16) moderate.php, (17) paysubscriptions.php, (18) register.php, (19) search.php, (20) topics.php, (21) and usercp.php in the sources/action_public directory; (22) bbcode/class_bbcode.php, (23) bbcode/class_bbcode_legacy.php, (24) editor/class_editor_rte.php, (25) editor/class_editor_std.php, (26) post/class_post.php, (27) post/class_post_edit.php, (28) post/class_post_new.php, (29) and post/class_post_reply.php in the sources/classes directory; (30) sources/components_acp/registration_DEPR.php; (31) sources/handlers/han_paysubscriptions.php; (32) func_usercp.php; (33) search_mysql_ftext.php, and (34) search_mysql_man.php in the sources/lib/ directory; and (35) convert/auth.php.bak, (36) external/auth.php, and (37) ldap/auth.php in the sources/loginauth directory. | 5.0 |
2006-03-02 | CVE-2006-0965 | NCP Network Communications | Multiple vulnerability in NCP Network Communications Secure Client 8.11Build146 NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to bypass security protections and configure privileged options via a long argument to ncpmon.exe, which provides access to alternate privileged menus, possibly due to a buffer overflow. | 4.6 |
2006-03-02 | CVE-2006-0964 | NCP Network Communications | Multiple vulnerability in NCP Network Communications Secure Client 8.11Build146 Client Firewall in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to bypass firewall program execution rules by replacing an allowed program with an arbitrary program. | 4.6 |
2006-03-02 | CVE-2006-0963 | Stlport Project | Classic Buffer Overflow vulnerability in Stlport Project Stlport 5.0.2 Multiple buffer overflows in STLport 5.0.2 might allow local users to execute arbitrary code via (1) long locale environment variables to a strcpy function call in c_locale_glibc2.c and (2) long arguments to unspecified functions in num_put_float.cpp. | 4.6 |
2006-03-03 | CVE-2006-0985 | Wordpress | Cross-Site Scripting vulnerability in WordPress Multiple cross-site scripting (XSS) vulnerabilities in the "post comment" functionality of WordPress 2.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) website, and (3) comment parameters. | 4.3 |
2006-03-03 | CVE-2006-0984 | EJ3 | Cross-Site Scripting vulnerability in EJ3 Topo 2.2.178 Cross-site scripting (XSS) vulnerability in inc_header.php in EJ3 TOPo 2.2.178 allows remote attackers to inject arbitrary web script or HTML via the gTopNombre parameter. | 4.3 |
2006-03-03 | CVE-2006-0983 | David Barrett | Cross-Site Scripting vulnerability in David Barrett Qwikiwiki 1.4 Cross-site scripting (XSS) vulnerability in index.php in QwikiWiki 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | 4.3 |
2006-03-03 | CVE-2006-0980 | JAY Eckles | Cross-Site Scripting vulnerability in JAY Eckles CGI Calendar 2.7 Multiple cross-site scripting (XSS) vulnerabilities in Jay Eckles CGI Calendar 2.7 allow remote attackers to inject arbitrary web script or HTML via the year parameter in (1) index.cgi and (2) viewday.cgi. | 4.3 |
2006-03-03 | CVE-2006-0978 | Argosoft | HTML Injection vulnerability in Argosoft Mail Server 1.8.8.5 Multiple cross-site scripting (XSS) vulnerabilities in the View Headers (aka viewheaders) functionality in ArGoSoft Mail Server Pro 1.8.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the Subject header, (2) the From header, and (3) certain other unspecified headers. | 4.3 |
2006-03-03 | CVE-2006-0974 | Battleaxe Software | Cross-Site Scripting vulnerability in Battleaxe Software Bttlxeforum 2.0 Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML via the err_txt parameter. | 4.3 |
2006-03-02 | CVE-2006-0958 | Zoneo Soft | HTML Injection vulnerability in freeForum Cross-site scripting (XSS) vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) subject parameters. | 4.3 |
2006-03-01 | CVE-2006-0946 | Thomson | Cross-Site Scripting vulnerability in Thomson SpeedTouch 500 Series Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter to the LocalNetwork page. | 4.3 |
2006-03-01 | CVE-2006-0941 | Cynical Games | Input Validation vulnerability in Cynical Games Shoutlive 1.1.0 Multiple cross-site scripting (XSS) vulnerabilities in post.php in ShoutLIVE 1.1.0 allow remote attackers to inject arbitrary web script or HTML via certain variables when posting new messages. | 4.3 |
2006-03-01 | CVE-2006-0938 | EZ | Cross-Site Scripting vulnerability in EZ Publish Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the RefererURL parameter. | 4.3 |
2006-02-28 | CVE-2006-0934 | Limbo CMS | HTML Injection vulnerability in Limbo CMS Limbo CMS 1.0.4.2 Cross-site scripting (XSS) vulnerability in webinsta Limbo 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the message field in the Contact Form. | 4.3 |
2006-02-28 | CVE-2006-0933 | Phpx | HTML Injection vulnerability in PHPx 3.5.9 Cross-site scripting (XSS) vulnerability in PHPX 3.5.9 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a url XCode tag in a posted message. | 4.3 |
2006-02-28 | CVE-2006-0924 | Brown Bear Software | Cross-Site Scripting vulnerability in Brown Bear Software Ical 3.10 Cross-site scripting (XSS) vulnerability in Brown Bear iCal 3.10 allows remote attackers to inject arbitrary web script or HTML via the Calendar Text field when a new event is added. | 4.3 |
2006-02-28 | CVE-2006-0923 | Myphpnuke | Cross-Site Scripting vulnerability in MyPHPNuke Multiple cross-site scripting (XSS) vulnerabilities in MyPHPNuke (MPN) 1.88 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the letter parameter in reviews.php and (2) the dcategory parameter in download.php. | 4.3 |
2006-03-03 | CVE-2006-0981 | E Merge | Remote Directory Traversal vulnerability in E-Merge Winace 2.6 Directory traversal vulnerability in e-merge WinAce 2.6 and earlier allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive. | 4.0 |
2006-02-28 | CVE-2006-0930 | Argosoft | Directory Traversal vulnerability in Argosoft Mail Server 1.8 Directory traversal vulnerability in Webmail in ArGoSoft Mail Server Pro 1.8 allows remote authenticated users to read arbitrary files via a .. | 4.0 |
2006-02-28 | CVE-2006-0929 | Argosoft | Remote Directory Traversal vulnerability in Argosoft Mail Server 1.8.8.1 Directory traversal vulnerability in the IMAP server in ArGoSoft Mail Server Pro 1.8.8.1 allows remote authenticated users to create arbitrary folders via a .. | 4.0 |
12 Low Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2006-03-03 | CVE-2006-0389 | Apple | Multiple vulnerability in Apple Mac OS X Security Update 2006-001 Cross-site scripting (XSS) vulnerability in Syndication (Safari RSS) in Mac OS X 10.4 through 10.4.5 allows remote attackers to execute arbitrary JavaScript via unspecified vectors involving RSS feeds. | 2.6 |
2006-03-03 | CVE-2006-0388 | Apple | Code Injection vulnerability in Apple mac OS X and mac OS X Server Safari in Mac OS X 10.3 before 10.3.9 and 10.4 before 10.4.5 allows remote attackers to redirect users to local files and execute arbitrary JavaScript via unspecified vectors involving HTTP redirection to local resources. | 2.6 |
2006-02-28 | CVE-2006-0935 | Microsoft | Denial Of Service vulnerability in Microsoft Word 2003 Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz. | 2.6 |
2006-02-28 | CVE-2006-0927 | JGS XA Woltlab | Cross-Site Scripting vulnerability in JGS-Gallery Module Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b) jgs_galerie_scroll.php, and the (2) katid parameter in (c) jgs_galerie_slideshow.php. | 2.6 |
2006-02-28 | CVE-2006-0926 | Smithmicro | Remote Directory Traversal vulnerability in StuffIt and ZipMagic Multiple directory traversal vulnerabilities in Allume StuffIt Standard and Deluxe 9.0, ZipMagic Deluxe 9.0, and StuffIt Expander 9.0.0.21 Engine 9.0.0.21 allow remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive. | 2.6 |
2006-03-02 | CVE-2006-0967 | NCP Network Communications | Resource Management Errors vulnerability in NCP Network Communications Secure Client 8.11Build146 NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to cause a denial of service (memory usage and cpu utilization) via a flood of arbitrary UDP datagrams to ports 0 to 65000. | 2.1 |
2006-03-02 | CVE-2006-0966 | NCP Network Communications | Resource Management Errors vulnerability in NCP Network Communications Secure Client 8.11Build146 NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to cause a denial of service (CPU consumption) via a large number of arguments to ncprwsnt.exe, possibly due to a buffer overflow. | 2.1 |
2006-02-28 | CVE-2006-0917 | Melange | Information Disclosure vulnerability in Melange Chat System 1.10 Melange Chat Server (aka M-Chat), when accessed via a web browser, automatically sends cookies and other sensitive information for a server to any port specified in the associated link, which allows local users on that server to read the cookies from HTTP headers and possibly gain sensitive information, such as credentials, by setting up a listening port and reading the credentials when the victim clicks on the link. | 2.1 |
2006-03-03 | CVE-2006-0391 | Apple | Multiple vulnerability in Apple Mac OS X Security Update 2006-001 Directory traversal vulnerability in the BOM framework in Mac OS X 10.x before 10.3.9 and 10.4 before 10.4.5 allows user-assisted attackers to overwrite or create arbitrary files via an archive that is handled by BOMArchiveHelper. | 1.7 |
2006-03-03 | CVE-2006-0386 | Apple | Multiple vulnerability in Apple Mac OS X Security Update 2006-001 FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a FileVault image, which allows local users to access protected files when FileVault is enabled. | 1.7 |
2006-03-02 | CVE-2006-0956 | Nufw | Remote TLS Connection Handling Denial of Service vulnerability in Nufw Firewall 1.0.20 nuauth in NuFW before 1.0.21 does not properly handle blocking TLS sockets, which allows remote authenticated users to cause a denial of service (service hang) by flooding packets at the authentication server. | 1.7 |
2006-02-28 | CVE-2006-0920 | OI | SQL Injection vulnerability in OI Email Marketing System 3.0 Oi! Email Marketing System 3.0 (aka Oi! 3) stores the server's FTP password in cleartext on a Configuration web page, which allows local users with superadministrator privileges, or attackers who have obtained access to the web page, to view the password. | 1.7 |