Weekly Vulnerabilities Reports > March 27 to April 2, 2006
Overview
127 new vulnerabilities reported during this period, including 4 critical vulnerabilities and 31 high severity vulnerabilities. This weekly summary report vulnerabilities in 111 products from 92 vendors including Vscripts, Microsoft, Fusionzone, Debian, and Veritas. Vulnerabilities are notably categorized as "SQL Injection", "Code Injection", "Numeric Errors", "Improper Restriction of Operations within the Bounds of a Memory Buffer", and "Cross-site Scripting".
- 117 reported vulnerabilities are remotely exploitables.
- 7 reported vulnerabilities have public exploit available.
- 4 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 120 reported vulnerabilities are exploitable by an anonymous user.
- Vscripts has the most reported vulnerabilities, with 6 reported vulnerabilities.
- Veritas has the most reported critical vulnerabilities, with 2 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
4 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2006-03-30 | CVE-2006-1540 | Microsoft | Code Injection vulnerability in Microsoft Office MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll; (2) an Excel .xlw document, which triggers an access violation in excel.exe; (3) a Word document, which triggers an access violation in mso.dll in winword.exe; and (4) a PowerPoint document, which triggers an access violation in powerpnt.txt. | 9.3 |
2006-03-30 | CVE-2006-1545 | Vscripts | Remote Security vulnerability in Vscripts Vnews 1.2 Direct static code injection vulnerability in admin/config.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allows remote authenticated administrators to execute code by inserting the code into variables that are stored in admin/config.php. | 9.0 |
2006-03-28 | CVE-2006-0990 | Veritas | Remote Buffer Overflow vulnerability in VERITAS NetBackup Stack-based buffer overflow in the NetBackup Catalog daemon (bpdbm) in Veritas NetBackup Enterprise Server 5.0 through 6.0 and DataCenter and BusinesServer 4.5FP and 4.5MP allows attackers to execute arbitrary code via unknown vectors. | 9.0 |
2006-03-28 | CVE-2006-0989 | Veritas | Remote Buffer Overflow vulnerability in VERITAS NetBackup Stack-based buffer overflow in the volume manager daemon (vmd) in Veritas NetBackup Enterprise Server 5.0 through 6.0 and DataCenter and BusinesServer 4.5FP and 4.5MP allows attackers to execute arbitrary code via unknown vectors. | 9.0 |
31 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2006-03-30 | CVE-2006-1541 | Ezaspsite | SQL Injection vulnerability in EzASPSite Default.ASP SQL injection vulnerability in Default.asp in EzASPSite 2.0 RC3 and earlier allows remote attackers to execute arbitrary SQL commands and obtain the SHA1 hash of the admin password via the Scheme parameter. | 7.8 |
2006-03-28 | CVE-2006-1403 | Csdoom | Buffer Overflow and Format String vulnerability in Csdoom 2005 0.7 Format string vulnerability in the PrintString function in c_console.cpp in client/server Doom (csDoom) 0.7 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via format string specifiers in strings passed to the console. | 7.8 |
2006-03-31 | CVE-2006-1563 | Vscripts | Remote Security vulnerability in Vscripts Vbook 2.0 Direct static code injection vulnerability in config.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allows remote administrators to execute arbitrary PHP code into the config file, which is included other [V]Book scripts. | 7.6 |
2006-03-30 | CVE-2006-1550 | DIA | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in DIA Multiple buffer overflows in the xfig import code (xfig-import.c) in Dia 0.87 and later before 0.95-pre6 allow user-assisted attackers to have an unknown impact via a crafted xfig file, possibly involving an invalid (1) color index, (2) number of points, or (3) depth. | 7.6 |
2006-04-02 | CVE-2006-1586 | Internet Solutions Professionals | SQL Injection vulnerability in ISP Site Man Admin_Login.ASP SQL injection vulnerability in admin_login.asp in ISP of Egypt SiteMan allows remote attackers to execute arbitrary SQL commands via the pass parameter. | 7.5 |
2006-04-02 | CVE-2006-1579 | Dbbs | SQL Injection vulnerability in DbbS Topics.PHP SQL injection vulnerability in topics.php in Dynamic Bulletin Board System (DbbS) 2.0-alpha and earlier allows remote attackers to execute arbitrary SQL commands via the limite parameter. | 7.5 |
2006-04-02 | CVE-2006-1576 | Vscripts PL | Input Validation vulnerability in Vscripts.Pl Qlnews 1.2 Direct static code injection vulnerability in QLnews 1.2 allows remote authenticated administrators to execute arbitrary PHP code by modifying config.php. | 7.5 |
2006-04-01 | CVE-2006-1573 | Mediaslash COM | Remote File Include vulnerability in Mediaslash.Com Mediaslash Gallery 0 PHP remote file inclusion vulnerability in index.php in MediaSlash Gallery allows remote attackers to execute arbitrary PHP code via a URL in the rub parameter (part of the $page_menu variable). | 7.5 |
2006-03-31 | CVE-2006-1560 | Skintech | SQL Injection vulnerability in Skintech PHPnewsmanager 1.48 Multiple SQL injection vulnerabilities in SkinTech phpNewsManager 1.48 allow remote attackers to execute arbitrary SQL commands via unspecified parameters, possibly (1) id and (2) topicid, in (a) browse.php, (b) category.php, (c) gallery.php, (d) poll.php, and (e) possibly other unspecified scripts. | 7.5 |
2006-03-31 | CVE-2006-1559 | PHP | SQL-Injection vulnerability in PHP Script Index SQL injection vulnerability in PHP Script Index allows remote attackers to execute arbitrary SQL commands via the search parameter. | 7.5 |
2006-03-31 | CVE-2006-1557 | Skintech | SQL Injection vulnerability in Skintech X-Changer 0.20 Multiple SQL injection vulnerabilities in X-Changer 0.2 allow remote attackers to execute arbitrary SQL commands via the (1) from and (2) into parameters in a calculate action, and the (3) id parameter in an edit action to index.php. | 7.5 |
2006-03-31 | CVE-2006-1555 | Tachyon | Authentication Bypass vulnerability in Tachyon Vsns Lemon 3.2.0 VSNS Lemon 3.2.0 allows remote attackers to bypass authentication and access password-protected articles by setting the vsns[topic_id] cookie to the targeted topic. | 7.5 |
2006-03-30 | CVE-2006-1547 | Apache | Unspecified vulnerability in Apache Commons Beanutils and Struts ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils. | 7.5 |
2006-03-30 | CVE-2006-1543 | Vscripts | SQL Injection vulnerability in Vscripts Vnews 1.2 Multiple SQL injection vulnerabilities in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) loginvar parameter in (a) admin/admin.php, and the (2) news and (3) nom parameters in (b) news.php. | 7.5 |
2006-03-30 | CVE-2006-1539 | BSD Games | Local Privilege Escalation vulnerability in Bsd-Games Tetris-Bsd Gold Multiple buffer overflows in the checkscores function in scores.c in tetris-bsd in bsd-games before 2.17-r1 in Gentoo Linux might allow local users with games group membership to gain privileges by modifying tetris-bsd.scores to contain crafted executable content, which is executed when another user launches tetris-bsd. | 7.5 |
2006-03-30 | CVE-2006-1536 | Phoetux NET | SQL Injection vulnerability in Phxcontacts 0.93/0.93.1 Multiple SQL injection vulnerabilities in Phoetux.net PhxContacts 0.93.1 beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) motclef and (2) nbr_line_view parameters in (a) carnet.php, and the (3) id_contact parameter in (b) contact_view.php. | 7.5 |
2006-03-30 | CVE-2006-1534 | Null News | SQL Injection vulnerability in Null News Multiple SQL injection vulnerabilities in Null news allow remote attackers to execute arbitrary SQL commands via (1) the user_email parameter in (a) lostpass.php, and the (2) user_email and (3) user_username parameters in (b) sub.php and (c) unsub.php. | 7.5 |
2006-03-30 | CVE-2006-1533 | Sourceworkshop | SQL Injection vulnerability in Sourceworkshop Newsletter 1.0 SQL injection vulnerability in newsletter.php in Sourceworkshop newsletter 1.0 allows remote attackers to execute arbitrary SQL commands via the newsletteremail parameter. | 7.5 |
2006-03-30 | CVE-2006-1501 | Oneorzero | SQL Injection vulnerability in Oneorzero 1.6.3.0 SQL injection vulnerability in index.php in OneOrZero 1.6.3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly in the kans action. | 7.5 |
2006-03-30 | CVE-2006-1500 | Tilde | SQL Injection vulnerability in Tilde CMS 3.0 SQL injection vulnerability in index.php in Tilde CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 7.5 |
2006-03-30 | CVE-2006-1499 | Source Workshop | SQL Injection vulnerability in Source Workshop Vcounter 1.0 SQL injection vulnerability in vCounter.php in vCounter 1.0 allows remote attackers to execute arbitrary SQL commands via the URI (_SERVER[REQUEST_URI] variable). | 7.5 |
2006-03-30 | CVE-2006-1495 | Netoffice Phpcollab | SQL Injection vulnerability in PhpCollab Sendpassword.PHP SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remote attackers to execute arbitrary SQL commands via the loginForm parameter in the "forgotten password" option. | 7.5 |
2006-03-29 | CVE-2006-1491 | Horde | Code Injection vulnerability in Horde Application Framework Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer. | 7.5 |
2006-03-29 | CVE-2006-1489 | Fusionzone | SQL Injection vulnerability in Fusionzone Couponzone 4.2 Multiple SQL injection vulnerabilities in FusionZONE CouponZONE local.cfm in 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) companyid, (2) scat, and (3) coid parameters. | 7.5 |
2006-03-29 | CVE-2006-1478 | Turnkey WEB Tools | File-Upload vulnerability in Turnkey web Tools PHP Live Helper 1.8 Directory traversal vulnerability in (1) initiate.php and (2) possibly other PHP scripts in Turnkey Web Tools PHP Live Helper 1.8, and possibly later versions, allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the language cookie, as demonstrated by uploading PHP code in a gl_session cookie to users.php, which causes the code to be stored in error.log, which is then included by initiate.php. | 7.5 |
2006-03-29 | CVE-2006-1477 | Turnkey WEB Tools | Remote File Include vulnerability in Turnkey web Tools PHP Live Helper 1.8 Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Live Helper 1.8 allow remote attackers to include and execute arbitrary PHP code via the abs_path parameter in (1) initiate.php, (2) waiting.php, (3) welcome.php, (4) admin/index.php, (5) javascript.php, (6) checkchat.php, and (7) blank.php. | 7.5 |
2006-03-28 | CVE-2006-1426 | Pixel Motion | SQL Injection vulnerability in Pixel Motion Multiple SQL injection vulnerabilities in Pixel Motion Blog allow remote attackers to execute arbitrary SQL commands via the (1) date parameter in index.php or bypass authentication via the (2) password parameter in admin/index.php. | 7.5 |
2006-03-28 | CVE-2006-1402 | Csdoom | Buffer Overflow and Format String vulnerability in Csdoom 20050.7 Buffer overflow in client/server Doom (csDoom) 0.7 and earlier allows remote attackers to (1) cause a denial of service via a long nickname or teamname to the SV_SetupUserInfo function or (2) execute arbitrary code via a long string sent when joining a match or a long chat message to the SV_BroadcastPrintf function. | 7.5 |
2006-03-30 | CVE-2006-1506 | SUN | Local Security vulnerability in Grid Engine Unspecified vulnerability in rsh in Sun Microsystems Sun Grid Engine 5.3 before 20060327 and N1 Grid Engine 6.0 before 20060327 allows local users to gain root privileges. | 7.2 |
2006-03-29 | CVE-2006-1484 | KYE | Local Privilege Escalation vulnerability in Genius VideoCAM NB Genius VideoCAM NB Driver does not drop privileges when saving files, which allows local users to gain privileges by opening arbitrary files via the "save as" dialog. | 7.2 |
2006-03-28 | CVE-2006-0991 | Veritas | Remote Buffer Overflow vulnerability in VERITAS NetBackup Buffer overflow in the NetBackup Sharepoint Services server daemon (bpspsserver) on NetBackup 6.0 for Windows allows remote attackers to execute arbitrary code via crafted "Request Service" packets to the vnetd service (TCP port 13724). | 7.1 |
86 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2006-04-02 | CVE-2006-1577 | Mantis | Cross-Site Scripting vulnerability in Mantis View_All_Set.PHP Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) start_day, (2) start_year, and (3) start_month parameters. | 6.8 |
2006-04-02 | CVE-2006-1575 | Vscripts PL | Input Validation vulnerability in Vscripts.Pl Qlnews 1.2 Multiple cross-site scripting (XSS) vulnerabilities in news.php in QLnews 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) autorx and (2) newsx parameters. | 6.8 |
2006-03-31 | CVE-2006-1562 | Vscripts | Cross-Site Scripting vulnerability in Vscripts Vbook 2.0 Multiple cross-site scripting (XSS) vulnerabilities in index.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) autor, (2) www, (3) temat, and (4) tresc parameters. | 6.8 |
2006-03-31 | CVE-2006-1558 | PHP | Cross-Site Scripting vulnerability in PHP Script Index Search Parameter Cross-site scripting (XSS) vulnerability in search.php in PHP Script Index allows remote attackers to inject arbitrary web script or HTML via the search parameter. | 6.8 |
2006-03-31 | CVE-2006-1556 | AL Caricatier | Cross-Site Scripting vulnerability in Al-Caricatier 2.5 Multiple cross-site scripting (XSS) vulnerabilities in view_caricatier.php in AL-Caricatier 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) CatName, (2) CaricatierID, or (3) CatID parameter. | 6.8 |
2006-03-30 | CVE-2006-1507 | Phpkit | Cross-Site Scripting vulnerability in PHPkit 1.6.03 Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the error parameter to include.php, possibly due to a problem in login/login.php. | 6.8 |
2006-03-29 | CVE-2006-1485 | Greymatter | Unspecified vulnerability in Greymatter gm-upload.cgi in Greymatter 1.3.1 allows remote authenticated users with upload privileges to execute arbitrary programs by uploading files to locations within the web root. | 6.5 |
2006-03-29 | CVE-2006-1481 | PHP Ticket | SQL Injection vulnerability in PHP Ticket PHP Ticket 0.5/0.6 SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL commands and obtain usernames and passwords via the frm_search_in parameter. | 6.5 |
2006-04-02 | CVE-2006-1584 | Juliusz Julas Gonera | Remote File Include vulnerability in Juliusz Julas Gonera Warcraft III Replay Parser PHP 1.8C Unspecified vulnerability in index.php in Warcraft III Replay Parser for PHP 1.8c allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to fopen function calls or file uploads. | 6.4 |
2006-04-02 | CVE-2006-1581 | Blanknberg | Directory Traversal vulnerability in Blanknberg 0.2 Directory traversal vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to read arbitrary files via a .. | 6.4 |
2006-04-02 | CVE-2006-1578 | Index Data APS | SQL-Injection vulnerability in Keystone Digital Library Suite Multiple SQL injection vulnerabilities in Keystone Digital Library Suite (DLS) 1.5.4 and earlier allow remote attackers to execute arbitrary SQL commands via the subject_type_id parameter in (1) the index page and (2) the search module. | 6.4 |
2006-04-02 | CVE-2006-1583 | Juliusz Julas Gonera | Remote File Include vulnerability in Juliusz Julas Gonera Warcraft III Replay Parser PHP 1.8C Cross-site scripting (XSS) vulnerability in index.php in Warcraft III Replay Parser for PHP 1.8c allows remote attackers to inject arbitrary web script or HTML via the page parameter. | 5.8 |
2006-04-02 | CVE-2006-1582 | Blanknberg | Cross-Site Scripting vulnerability in Blanknberg 0.2 Cross-site scripting (XSS) vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to inject arbitrary web script or HTML via the _path parameter. | 5.8 |
2006-04-02 | CVE-2006-1580 | Websina | Cross-Site Scripting vulnerability in Bugzero Multiple cross-site scripting (XSS) vulnerabilities in Bugzero 4.3.1 and other versions allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in query.jsp and (2) entryId parameter in edit.jsp. | 5.8 |
2006-04-01 | CVE-2006-1574 | Hitachi | Cross-Site Scripting vulnerability in Hitachi Groupmax World Wide Web Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web, World Wide Web Desktop, World Wide Web for Scheduler, and Desktop for Scheduler, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | 5.8 |
2006-03-28 | CVE-2006-1407 | Webhost Automation | Cross-Site Scripting vulnerability in Web Host Automation Ltd. Helm Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp. | 5.8 |
2006-03-28 | CVE-2006-1405 | Sheer Vision Technologies | Cross-Site Scripting vulnerability in SweetSuite.NET Content Management System Search.ASPX Cross-site scripting (XSS) vulnerability in search.aspx in SweetSuite.NET Content Management System (ssCMS) 2.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. | 5.8 |
2006-03-28 | CVE-2006-1404 | Industrial Imagination | Cross-Site Scripting vulnerability in BlankOL Bol.CGI Multiple cross-site scripting (XSS) vulnerabilities in bol.cgi in BlankOL 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) file or (2) function parameter. | 5.8 |
2006-04-01 | CVE-2006-1571 | R2Xdesign | SQL Injection vulnerability in R2Xdesign Qlitenews 20050701 Multiple SQL injection vulnerabilities in loginprocess.php in qliteNews 2005.07.01 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters. | 5.1 |
2006-04-01 | CVE-2006-1569 | Redcms | Input Validation vulnerability in Redcms 0.1 Multiple SQL injection vulnerabilities in RedCMS 0.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters to (a) login.php or (b) register.php; or (3) u parameter to (c) profile.php. | 5.1 |
2006-04-01 | CVE-2006-1568 | Redcms | Input Validation vulnerability in Redcms 0.1 Multiple cross-site scripting (XSS) vulnerabilities in register.php in RedCMS 0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) email, (2) location, or (3) website parameters. | 5.1 |
2006-03-31 | CVE-2006-1561 | Vscripts | SQL Injection vulnerability in Vscripts Vbook 2.0 SQL injection vulnerability in index.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allows remote attackers to execute arbitrary SQL commands via the x parameter. | 5.1 |
2006-03-31 | CVE-2006-1553 | Tachyon | SQL Injection vulnerability in Tachyon Vsns Lemon 3.2.0 SQL injection vulnerability in functions/final_functions.php in VSNS Lemon 3.2.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter. | 5.1 |
2006-03-30 | CVE-2006-1511 | Microsoft | Buffer Overflow vulnerability in Microsoft .NET Framework SDK MSIL Tools Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name. | 5.1 |
2006-03-30 | CVE-2006-1504 | Arab Portal | Cross-Site Scripting vulnerability in Arab Portal Arab Portal 2.0 Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0 (aka Arab Dynamic Portal or ADP) stable allow remote attackers to inject arbitrary web script or HTML via the title parameter in (1) online.php and (2) download.php. | 5.1 |
2006-03-30 | CVE-2006-1503 | Vwar | Code Injection vulnerability in Vwar Virtual WAR PHP remote file inclusion vulnerability in includes/functions_install.php in Virtual War (VWar) 1.5.0 R11 and earlier allows remote attackers to include and execute arbitrary PHP code via a URL in the vwar_root parameter. | 5.1 |
2006-03-30 | CVE-2006-1502 | Mplayer | Integer Overflow vulnerability in MPlayer Multiple integer overflows in MPlayer 1.0pre7try2 allow remote attackers to cause a denial of service and trigger heap-based buffer overflows via (1) a certain ASF file handled by asfheader.c that causes the asf_descrambling function to be passed a negative integer after the conversion from a char to an int or (2) an AVI file with a crafted wLongsPerEntry or nEntriesInUse value in the indx chunk, which is handled in aviheader.c. | 5.1 |
2006-03-29 | CVE-2006-1480 | Duda | Remote Command Execution vulnerability in WEBalbum Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and execute commands by (1) injecting code into local log files via GET commands, then (2) accessing that log via a .. | 5.1 |
2006-03-28 | CVE-2006-1421 | Arthur Konze Webdesign | SQL Injection vulnerability in Arthur Konze Webdesign Akocomment 2.0 Multiple SQL injection vulnerabilities in akocomment.php in AkoComment 2.0 module for Mambo, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) acname or (2) contentid parameter. | 5.1 |
2006-04-01 | CVE-2006-1572 | O2Php COM | SQL Injection vulnerability in O2PHP Oxygen Post.PHP SQL injection vulnerability in post.php in Oxygen 1.1.3 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a newthread action. | 5.0 |
2006-03-31 | CVE-2006-1552 | Apple | Numeric Errors vulnerability in Apple products Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated using Safari, aka "Deja-Doom". | 5.0 |
2006-03-31 | CVE-2006-0052 | GNU | Denial Of Service vulnerability in GNU Mailman Attachment Scrubber Malformed MIME Message The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a denial of service (mailing list delivery failure) via a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary. | 5.0 |
2006-03-30 | CVE-2006-1537 | Webcalendar | Information Disclosure vulnerability in Webcalendar 1.1.0 Craig Knudsen WebCalendar 1.1.0-CVS allows remote attackers to obtain sensitive information via a direct request to (1) includes/index.php, (2) tests/add_duration_test.php, (3) tests/all_tests.php, (4) groups.php, (5) nonusers.php, (6) includes/settings.php, (7) includes/init.php, (8) includes/settings.php.orig, (9) includes/js/admin.php, (10) includes/js/edit_entry.php, (11) includes/js/edit_layer.php, (12) includes/js/export_import.php, (13) includes/js/popups.php, (14) includes/js/pref.php, or (15) includes/menu/index.php, which reveal the path in various error messages. | 5.0 |
2006-03-30 | CVE-2006-1505 | Basic Analysis AND Security Engine | Authentication Bypass vulnerability in Basic Analysis and Security Engine Base_maintenance.PHP base_maintenance.php in Basic Analysis and Security Engine (BASE) before 1.2.4 (melissa), when running in standalone mode, allows remote attackers to bypass authentication, possibly by setting the standalone parameter to "yes". | 5.0 |
2006-03-30 | CVE-2006-1497 | Vihor | Cross-Site Scripting vulnerability in Vihor Vihordesign 1.0.6 Directory traversal vulnerability in index.php in ViHor Design allows remote attackers to read arbitrary files via the page parameter. | 5.0 |
2006-03-29 | CVE-2006-1492 | Nikolay Avrionov | Input Validation vulnerability in Explorer XP Directory traversal vulnerability in dir.php in Explorer XP allows remote attackers to read arbitrary files via the chemin parameter. | 5.0 |
2006-03-29 | CVE-2006-1488 | Activecampaign | Remote Security vulnerability in Activecampaign Supporttrio 2.50.2 ActiveCampaign SupportTrio 2.5 allows remote attackers to obtain the full path of the server via invalid (1) article or (2) print parameters in a kb action to index.php, or (3) an invalid category parameter to modules/KB/pdf.php, which leaks the path in an error message. | 5.0 |
2006-03-29 | CVE-2006-1483 | Desiderata Software | Unspecified vulnerability in Desiderata Software Blazix web Server Blazix Web Server before 1.2.6, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . | 5.0 |
2006-03-28 | CVE-2006-1432 | Fusionzone | Information Disclosure vulnerability in Fusionzone Couponzone 4.2 fusionZONE couponZONE 4.2 allows remote attackers to obtain the full path of the web server, and other sensitive information, via invalid values, as demonstrated using manipulations associated with SQL. | 5.0 |
2006-03-28 | CVE-2006-1423 | Ubbcentral | SQL Injection vulnerability in Ubbcentral Ubb.Threads SQL injection vulnerability in showflat.php in UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2, and earlier, allows remote attackers to execute arbitrary SQL commands via the Number parameter. | 5.0 |
2006-03-28 | CVE-2006-1422 | Jjwwebdesign | SQL Injection vulnerability in Jjwwebdesign PHPbookingcalendar 1.0C SQL injection vulnerability in details_view.php in PHP Booking Calendar 1.0c and earlier allows remote attackers to execute arbitrary SQL commands via the event_id parameter. | 5.0 |
2006-03-28 | CVE-2006-1420 | Arabless | SQL Injection vulnerability in Arabless Saphplesson 2.0 SQL injection vulnerability in print.php in SaphpLesson 2.0 allows remote attackers to execute arbitrary SQL commands via the lessid parameter. | 5.0 |
2006-03-28 | CVE-2006-1419 | Nuked Klan | SQL Injection vulnerability in Nuked-Klan SQL injection vulnerability in the Calendar module in nuked-klan 1.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter to index.php. | 5.0 |
2006-03-28 | CVE-2006-1412 | TFT Gallery | Information Disclosure vulnerability in TFT Gallery TFT Gallery 0.10 TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin password file and obtain password hashes via a direct request to admin/passwd. | 5.0 |
2006-03-28 | CVE-2006-1409 | Vavoom | Denial of Service vulnerability in Vavoom Buffer overflow in Vavoom 1.19.1 and earlier allows remote attackers to cause a denial of service (application crash) via an invalid comprLength value in a compressed packet. | 5.0 |
2006-03-28 | CVE-2006-1408 | Vavoom | Denial of Service vulnerability in Vavoom Vavoom 1.19.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via (1) a packet with no data or (2) a large packet, which prevents Vavoom from discarding the packet from the socket. | 5.0 |
2006-03-30 | CVE-2006-1538 | Enova | Local Security vulnerability in X-Wall Asic The Enova X-Wall ASIC encrypts with a key obtained via Microwire from a serial EEPROM that stores the key in cleartext, which allows local users with physical access to obtain the key by reading and duplicating an EEPROM that is located on a hardware token, or by sniffing the Microwire bus. | 4.9 |
2006-03-30 | CVE-2006-1509 | HP | Local Denial of Service vulnerability in HP Hp-Ux 11.00/11.11/11.23 /sbin/passwd in HP-UX B.11.00, B.11.11, and B.11.23 before 20060326 "does not recover gracefully from some error conditions," which allows local users to cause a denial of service. | 4.9 |
2006-03-31 | CVE-2006-1566 | Debian | Packages Insecure RUNPATH vulnerability in Debian Linux 3.1 Untrusted search path vulnerability in libtunepimp-perl 0.4.2-1 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the tunepimp.so module, which might allow local users to gain privileges by installing malicious libraries in that directory. | 4.6 |
2006-03-31 | CVE-2006-1565 | Debian | Packages Insecure RUNPATH vulnerability in Debian Linux 3.1 Untrusted search path vulnerability in libgpib-perl 3.2.06-2 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the LinuxGpib.so module, which might allow local users to gain privileges by installing malicious libraries in that directory. | 4.6 |
2006-03-31 | CVE-2006-1564 | Debian | Packages Insecure RUNPATH vulnerability in Debian Linux 3.1 Untrusted search path vulnerability in libapache2-svn 1.3.0-4 for Subversion in Debian GNU/Linux includes RPATH values under the /tmp/svn directory for the (1) mod_authz_svn.so and (2) mod_dav_svn.so modules, which might allow local users to gain privileges by installing malicious libraries in that directory. | 4.6 |
2006-04-01 | CVE-2006-1570 | Esqlanelapse | Cross-Site Scripting vulnerability in Esqlanelapse 2.0/2.2 Cross-site scripting (XSS) vulnerability in Esqlanelapse 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | 4.3 |
2006-04-01 | CVE-2006-1567 | Sitesearch | Cross-Site Scripting vulnerability in SiteSearch Indexer Searchresults.ASP Cross-site scripting (XSS) vulnerability in searchresults.asp in SiteSearch Indexer 3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchField parameter. | 4.3 |
2006-03-30 | CVE-2006-1548 | Apache | Remote vulnerability in Apache Struts Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message. | 4.3 |
2006-03-30 | CVE-2006-1544 | Vscripts | Cross-Site Scripting vulnerability in Vscripts Vnews 1.2 Multiple cross-site scripting (XSS) vulnerabilities in news.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) autorkomentarza and (2) tresckomentarza parameters. | 4.3 |
2006-03-30 | CVE-2006-1535 | Phoetux NET | Cross-Site Scripting vulnerability in Phxcontacts 0.93/0.93.1 Cross-site scripting (XSS) vulnerability in login.php in Phoetux.net PhxContacts 0.93.1 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the m parameter. | 4.3 |
2006-03-30 | CVE-2006-1532 | Deltascripts | Cross-Site Scripting vulnerability in Deltascripts PHP Classifieds 6.18/6.20 Cross-site scripting (XSS) vulnerability in search.php in PHP Classifieds 6.18, 6.20, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchword parameter. | 4.3 |
2006-03-30 | CVE-2006-1508 | MH Software | Cross-Site Scripting vulnerability in MH Software Connect Daily 3.2.8 Multiple cross-site scripting (XSS) vulnerabilities in MH Software Connect Daily Web Calendar Software 3.2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) calendar_id, (2) style_sheet, and (3) start parameters in (a) ViewDay.html; the (4) txtSearch and (5) opgSearch parameters in (b) ViewSearch.html; the (6) calendar_id and (7) approved parameters in (c) ViewYear.html; the (8) item_type_id parameter in (d) ViewCal.html; and the (9) week parameter in (e) ViewWeek.html. | 4.3 |
2006-03-30 | CVE-2006-1498 | Mediawiki | HTML Injection vulnerability in MediaWiki Encoded Page Link Cross-site scripting (XSS) vulnerability in MediaWiki before 1.5.8 and 1.4.15 allows remote attackers to inject arbitrary web script or HTML via crafted encoded links. | 4.3 |
2006-03-30 | CVE-2006-1496 | Vihor | Cross-Site Scripting vulnerability in VihorDesign Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1) a remote URL in the page parameter, which is processed by an fopen call, or (2) HTML or script in the page parameter, which is returned to the client in an error message for the failed fopen call. | 4.3 |
2006-03-29 | CVE-2006-1493 | Nikolay Avrionov | Input Validation vulnerability in Explorer XP Cross-site scripting (XSS) vulnerability in dir.php in Explorer XP allows remote attackers to inject arbitrary web script or HTML via the chemin parameter. | 4.3 |
2006-03-29 | CVE-2006-1487 | Activecampaign | Cross-Site Scripting vulnerability in Activecampaign Supporttrio 2.50.2 Cross-site scripting (XSS) vulnerability in ActiveCampaign SupportTrio 2.50.2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the KnowledgeBase search module. | 4.3 |
2006-03-29 | CVE-2006-1486 | Fusionzone | Cross-Site Scripting vulnerability in RealestateZONE Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in realestateZONE 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) bamin, (2) bemin, (3) pmin, and (4) state parameters. | 4.3 |
2006-03-29 | CVE-2006-1482 | Conftool | Cross-Site Scripting vulnerability in Conftool 1.1 Cross-site scripting (XSS) vulnerability in index.php in ConfTool 1.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | 4.3 |
2006-03-29 | CVE-2006-1479 | Serge REY | Input Validation vulnerability in Serge REY Gtd-PHP 0.5 Multiple cross-site scripting (XSS) vulnerabilities in Serge Rey gtd-php (aka Getting Things Done) 0.5 allow remote attackers to inject arbitrary web script or HTML via the Description field in (1) newProject.php, (2) newList.php, and (3) newWaitingOn.php; the Title field in (4) newProject.php, (5) newList.php, (6) newWaitingOn.php, (7) newChecklist.php, (8) newContext.php, and (9) newGoal.php; the (10) Category Name field in newCategory.php; the (11) listTitle field in listReport.php; the (12) projectName field in projectReport.php; and the (13) checklistTitle field in checklistReport.php. | 4.3 |
2006-03-29 | CVE-2006-1474 | Raindance | Cross-Site Scripting vulnerability in Web Conferencing Pro Cross-site scripting (XSS) vulnerability in the "failed" functionality in Raindance Web Conferencing Pro allows remote attackers to inject arbitrary web script or HTML via the browser parameter. | 4.3 |
2006-03-28 | CVE-2006-1431 | Fusionzone | Cross-Site Scripting vulnerability in Fusionzone Couponzone 4.2 Cross-site scripting (XSS) vulnerability in local.cfm in fusionZONE couponZONE 4.2 allows remote attackers to inject arbitrary web script or HTML via URL-encoded (1) srchfor and (2) srchby parameters. | 4.3 |
2006-03-28 | CVE-2006-1430 | Controlzx | Cross-Site Scripting vulnerability in CONTROLzx HMS Multiple cross-site scripting (XSS) vulnerabilities in CONTROLzx HMS (formerly DRZES) 3.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dedicatedPlanID parameter to dedicated_order.php, (2) sharedPlanID parameter to shared_order.php, (3) plan_id parameter to customers/server_management.php, and (4) email field to customers/forgotpass.php. | 4.3 |
2006-03-28 | CVE-2006-1429 | Fusionzone | Cross-Site Scripting vulnerability in ClassifiedZONE Accountlogon.CFM Cross-site scripting (XSS) vulnerability in accountlogon.cfm in classifiedZONE 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the rtn parameter. | 4.3 |
2006-03-28 | CVE-2006-1428 | Coinsoft Technologies | Cross-Site Scripting vulnerability in phpCOIN Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the fs parameter to (1) mod.php or (2) mod_print.php. | 4.3 |
2006-03-28 | CVE-2006-1427 | WEB APP ORG | Cross-Site Scripting vulnerability in Web-App.Org and Web-App.Net Multiple cross-site scripting (XSS) vulnerabilities in WebAPP 0.9.9.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) id, (3) num, (4) board, (5) cat, (6) real, (7) viewcat, (8) img, or (9) curcatname parameter in cgi-bin/index.cgi, or (10) vsSD parameter in /mods/calendar/index.cgi. | 4.3 |
2006-03-28 | CVE-2006-1425 | Phpmyfamily | Cross-Site Scripting vulnerability in PHPmyfamily 1.4.1 Cross-site scripting (XSS) vulnerability in track.php in phpmyfamily 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter. | 4.3 |
2006-03-28 | CVE-2006-1417 | Caloris Planitia Technologies | Cross-Site Scripting vulnerability in Caloris Planitia Technologies web Quiz PRO 1.0 Multiple cross-site scripting (XSS) vulnerabilities in Caloris Planitia Online Quiz System (aka Web Quiz pro), possibly 1.0, allow remote attackers to inject arbitrary web script or HTML via the (1) exam parameter in prequiz.asp or (2) msg parameter in student.asp. | 4.3 |
2006-03-28 | CVE-2006-1416 | Xigla | Cross-Site Scripting vulnerability in Absolute FAQ Manager Cross-site scripting (XSS) vulnerability in afmsearch.aspx in Absolute FAQ Manager .NET 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the question parameter. | 4.3 |
2006-03-28 | CVE-2006-1415 | Dotnetbb | Cross-Site Scripting vulnerability in dotNetBB Forums dotNetBB Cross-site scripting (XSS) vulnerability in iforget.aspx in dotNetBB 2.42EC SP 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the em parameter. | 4.3 |
2006-03-28 | CVE-2006-1414 | Toast Forums | Cross-Site Scripting vulnerability in Toast Forums Toast Forums 1.6 Multiple cross-site scripting (XSS) vulnerabilities in toast.asp in Toast Forums 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) author, (2) subject, (3) message, or (4) dayprune parameter. | 4.3 |
2006-03-28 | CVE-2006-1413 | Htmljunction | Cross-Site Scripting vulnerability in EZHomePagePro Multiple cross-site scripting (XSS) vulnerabilities in EZHomepagePro 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) adid or (2) aname parameter in (a) common/email.asp, (b) users/users_search.asp, or (c) users/users_profiles.asp; (3) page parameter in (d) users/users_calendar.asp; (4) usid parameter in (e) users/users_mgallery.asp; or (5) m parameter in (f) users/users_search.asp. | 4.3 |
2006-03-28 | CVE-2006-1411 | Xigla | Cross-Site Scripting vulnerability in Absolute Image Gallery XE Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the shownew parameter in gallery.asp and (2) unspecified search module parameters. | 4.3 |
2006-03-28 | CVE-2006-1410 | Xigla | HTML Injection vulnerability in Xigla Absolute Live Support XE 2.0 Multiple cross-site scripting (XSS) vulnerabilities in XIGLA Absolute Live Support XE 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Screen name or (2) Session Topic field. | 4.3 |
2006-03-28 | CVE-2006-1406 | Uniforum | Cross-Site Scripting vulnerability in uniForum Multiple cross-site scripting (XSS) vulnerabilities in wbadmlog.aspx in uniForum 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtuser or (2) txtpassword parameters. | 4.3 |
2006-03-28 | CVE-2006-1401 | PHP Lite | Cross-Site Scripting vulnerability in PHP Lite Calendar Express 2.2 Multiple cross-site scripting (XSS) vulnerabilities in search.php in Calendar Express 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) allwords or (2) oneword parameter. | 4.3 |
2006-03-28 | CVE-2006-1400 | Metisware | Cross-Site Scripting vulnerability in Metisware Instructor PersonalTaskEdit.ASP Cross-site scripting (XSS) vulnerability in MyTasks/PersonalTaskEdit.asp in Metisware Instructor 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the Task parameter. | 4.3 |
2006-03-28 | CVE-2006-1399 | PHP Lite | Cross-Site Scripting vulnerability in PHP Lite Meeting Reserve 1.0Beta Cross-site scripting (XSS) vulnerability in searchresult.php in Meeting Reserve 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the search_term parameter. | 4.3 |
2006-03-28 | CVE-2006-1398 | Sixal | HTML Injection vulnerability in Sixal G-Book 1.0 Cross-site scripting (XSS) vulnerability in guestbook.php in G-Book 1.0 allows remote attackers to inject arbitrary web script or HTML via the g_message parameter. | 4.3 |
2006-03-28 | CVE-2006-1397 | Phpadsnew Phppgads | Input Validation vulnerability in PHPAdsNew and PHPPGAds Multiple cross-site scripting (XSS) vulnerabilities in (a) phpAdsNew and (b) phpPgAds before 2.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) certain parameters to the banner delivery module, which is not properly handled in the administrator interface, or (2) certain parameters to the login form. | 4.3 |
2006-03-30 | CVE-2006-1510 | Microsoft | Buffer Overflow vulnerability in Microsoft .NET Framework SDK MSIL Tools Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file with a large static method. | 4.0 |
6 Low Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2006-03-31 | CVE-2006-1554 | Tachyon | HTML Injection vulnerability in Tachyon Vsns Lemon 3.2.0 Cross-site scripting (XSS) vulnerability in VSNS Lemon 3.2.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter while adding a comment. | 2.6 |
2006-03-29 | CVE-2006-1476 | Microsoft | Remote Security vulnerability in Windows XP Tablet PC Edition Windows Firewall in Microsoft Windows XP SP2 produces incorrect application block alerts when the application filename is ".exe" (with no characters before the "."), which might allow local user-assisted users to trick a user into unblocking a Trojan horse program, as demonstrated by a malicious ".exe" program in a folder named "Internet Explorer," which triggers a question about whether to unblock the "Internet Explorer" program. | 2.6 |
2006-03-28 | CVE-2006-1418 | Caloris Planitia Technologies | Cross-Site Scripting vulnerability in Caloris Planitia Technologies School Management System Cross-site scripting (XSS) vulnerability in default.asp in Caloris Planitia E-School Management System 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | 2.6 |
2006-03-29 | CVE-2006-1475 | Microsoft | Local Security vulnerability in Windows XP Tablet PC Edition Windows Firewall in Microsoft Windows XP SP2 does not produce application alerts when an application is executed using the NTFS Alternate Data Streams (ADS) filename:stream syntax, which might allow local users to launch a Trojan horse attack in which the victim does not obtain the alert that Windows Firewall would have produced for a non-ADS file. | 2.1 |
2006-03-30 | CVE-2006-1059 | Samba | Local Information Disclosure vulnerability in Samba Machine Trust Account The winbindd daemon in Samba 3.0.21 to 3.0.21c writes the machine trust account password in cleartext in log files, which allows local users to obtain the password and spoof the server in the domain. | 1.2 |
2006-03-27 | CVE-2006-1066 | Linux | Local Denial Of Service vulnerability in Linux Kernel Get_Compat_Timespec and PTrace Linux kernel 2.6.16-rc2 and earlier, when running on x86_64 systems with preemption enabled, allows local users to cause a denial of service (oops) via multiple ptrace tasks that perform single steps, which can cause corruption of the DEBUG_STACK stack during the do_debug function call. | 1.2 |