Weekly Vulnerabilities Reports > November 13 to 19, 2006
Overview
90 new vulnerabilities reported during this period, including 6 critical vulnerabilities and 52 high severity vulnerabilities. This weekly summary report vulnerabilities in 77 products from 64 vendors including Microsoft, Grisoft, Dynamic Dataworx, Campware ORG, and Superfreaker Studios. Vulnerabilities are notably categorized as "Numeric Errors", "Improper Restriction of Operations within the Bounds of a Memory Buffer", "Improper Input Validation", "Resource Management Errors", and "Permissions, Privileges, and Access Controls".
- 85 reported vulnerabilities are remotely exploitables.
- 23 reported vulnerabilities have public exploit available.
- 1 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 89 reported vulnerabilities are exploitable by an anonymous user.
- Microsoft has the most reported vulnerabilities, with 7 reported vulnerabilities.
- Grisoft has the most reported critical vulnerabilities, with 2 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
6 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2006-11-18 | CVE-2006-5972 | Netgear | Buffer Overflow vulnerability in Netgear Wg111V2 and Wg111V2 Driver Stack-based buffer overflow in WG111v2.SYS in NetGear WG111v2 wireless adapter (USB) allows remote attackers to execute arbitrary code via a long 802.11 beacon request. | 10.0 |
2006-11-18 | CVE-2006-5819 | Verity | Information Disclosure and Request Proxying vulnerability in Verity Ultraseek Verity Ultraseek before 5.7 allows remote attackers to use the server as a proxy for web attacks and host scanning via a direct request to the highlight/index.html script. | 10.0 |
2006-11-16 | CVE-2006-5940 | Grisoft | Numeric Errors vulnerability in Grisoft AVG Antivirus Unspecified vulnerability in Grisoft AVG Anti-Virus before 7.1.407 has unknown impact and remote attack vectors related to "Integer Issues" and parsing of .EXE files. | 10.0 |
2006-11-16 | CVE-2006-5938 | Grisoft | Improper Input Validation vulnerability in Grisoft AVG Antivirus Grisoft AVG Anti-Virus before 7.1.407 has unknown impact and remote attack vectors involving an uninitialized variable and a crafted CAB file. | 10.0 |
2006-11-15 | CVE-2006-5912 | Campware ORG | Remote Security vulnerability in Campware.Org Campsite 2.6.0/2.6.1 Unspecified vulnerability in Campware Campsite before 2.6.2 has unknown impact and attack vectors, related to a "Security fix for you-know-what," possibly related to encrypted passwords. | 10.0 |
2006-11-14 | CVE-2006-4691 | Microsoft | Remote Code Execution vulnerability in Microsoft Windows 2000 and Windows XP Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname. | 10.0 |
52 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2006-11-14 | CVE-2006-5882 | Linksys Broadcom | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products Stack-based buffer overflow in the Broadcom BCMWL5.SYS wireless device driver 3.50.21.10, as used in Cisco Linksys WPC300N Wireless-N Notebook Adapter before 4.100.15.5 and other products, allows remote attackers to execute arbitrary code via an 802.11 response frame containing a long SSID field. | 8.3 |
2006-11-16 | CVE-2006-5939 | Grisoft | Divide BY Zero vulnerability in Grisoft AVG Antivirus Grisoft AVG Anti-Virus before 7.1.407 allows remote attackers to cause a denial of service (crash) via a crafted DOC file that triggers a divide-by-zero error. | 7.8 |
2006-11-17 | CVE-2006-5962 | Hpecs Shopping Cart | SQL-Injection vulnerability in Hpecs Shopping Cart Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp. | 7.5 |
2006-11-17 | CVE-2006-5961 | Pegasus | Buffer Overflow vulnerability in Pegasus Mercury Mail Transport System 4.0.1B Buffer overflow in Mercury Mail Transport System 4.01b for Windows has unknown impact and attack vectors, as originally reported in a GLEG VulnDisco pack. | 7.5 |
2006-11-17 | CVE-2006-5959 | WEB Inhabit | Unspecified vulnerability in web Inhabit A+ Store E-Commerce SQL injection vulnerability in browse.asp in A+ Store E-Commerce allows remote attackers to execute arbitrary SQL commands via the ParentID parameter. | 7.5 |
2006-11-17 | CVE-2006-5955 | 20 20 Applications | SQL-Injection vulnerability in 20 20 Datashed SQL injection vulnerability in listings.asp in 20/20 DataShed (aka Real Estate Listing System) allows remote attackers to execute arbitrary SQL commands via the itemID parameter. | 7.5 |
2006-11-17 | CVE-2006-5954 | Netvios | SQL-Injection vulnerability in Netvios SQL injection vulnerability in page.asp in NetVIOS 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the NewsID parameter. | 7.5 |
2006-11-17 | CVE-2006-5952 | ASP Smiley | SQL-Injection vulnerability in ASP Smiley ASP Smiley 1.0 SQL injection vulnerability in admin/default.asp in ASP Smiley 1.0 allows remote attackers to execute arbitrary SQL commands via the Username field. | 7.5 |
2006-11-17 | CVE-2006-5951 | Exophpdesk | Remote File Include vulnerability in Exophpdesk 1.2 PHP remote file inclusion vulnerability in pipe.php in Exophpdesk 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file parameter. | 7.5 |
2006-11-17 | CVE-2006-5948 | Ringsworld | Remote File Include vulnerability in Ringsworld PHPpeanuts 1.1 PHP remote file inclusion vulnerability in pntUnit/Inspect.php in phpPeanuts 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the Include parameter. | 7.5 |
2006-11-17 | CVE-2006-5943 | Website Designs FOR Less | Input Validation vulnerability in Inventory Manager Multiple SQL injection vulnerabilities in inventory/display/imager.asp in Website Designs for Less Inventory Manager allow remote attackers to execute arbitrary SQL commands via the (1) pictable, (2) picfield, or (3) where parameter. | 7.5 |
2006-11-16 | CVE-2006-5937 | Grisoft | Integer Overflow OR Wraparound vulnerability in Grisoft AVG Antivirus Multiple integer overflows in Grisoft AVG Anti-Virus before 7.1.407 allow remote attackers to execute arbitrary code via crafted (1) CAB or (2) RAR archives that trigger a heap-based buffer overflow. | 7.5 |
2006-11-16 | CVE-2006-5936 | Sitexpress | SQL Injection vulnerability in SiteXpress E-Commerce System Dept.ASP SQL injection vulnerability in dept.asp in SiteXpress E-Commerce System allows remote attackers to execute arbitrary SQL commands via the id parameter. | 7.5 |
2006-11-16 | CVE-2006-5935 | Shopsystems | SQL Injection vulnerability in Shopsystems 4.0 SQL injection vulnerability in index.php in ShopSystems 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the sessid parameter. | 7.5 |
2006-11-16 | CVE-2006-5934 | Iexpress | SQL Injection vulnerability in Iexpress Estate Agent Manager 1.3 SQL injection vulnerability in admin/default.asp in Estate Agent Manager 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the UserName field. | 7.5 |
2006-11-16 | CVE-2006-5933 | Ultrasite | SQL-Injection vulnerability in Ultrasite 1.0 SQL injection vulnerability in update.asp in UltraSite 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 7.5 |
2006-11-16 | CVE-2006-5932 | Kahua | Authentication Bypass vulnerability in Kahua Shared User Database Kahua before 0.7, when running multiple applications under a single supervisor, grants application access on the basis of username instead of username and database name, which allows remote authenticated users to obtain unauthorized access if different databases assign the same username to different user accounts. | 7.5 |
2006-11-16 | CVE-2006-5930 | Aigaion | Remote File Include vulnerability in Aigaion 1.2.1 Multiple PHP remote file inclusion vulnerabilities in Aigaion Web based bibliography management system 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to (1) _basicfunctions.php, or (2) pageactionauthor.php. | 7.5 |
2006-11-16 | CVE-2006-5929 | Phpjobscheduler | Remote Security vulnerability in PHPjobscheduler 3.0 PHP remote file inclusion vulnerability in firepjs.php in Phpjobscheduler 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter. | 7.5 |
2006-11-16 | CVE-2006-5928 | Phpjobscheduler | Remote File Include vulnerability in PHPjobscheduler 3.0 Multiple PHP remote file inclusion vulnerabilities in Phpjobscheduler 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter to (1) add-modify.php, (2) delete.php, (3) modify.php, and (4) phpjobscheduler.php. | 7.5 |
2006-11-16 | CVE-2006-5927 | ASP Scripter | SQL Injection vulnerability in ASP Scripter Easy Portal and Live Support SQL injection vulnerability in cpLogin.asp in ASP Scripter Easy Portal 1.4 and Live Support 1.3 allows remote attackers to execute arbitrary SQL commands via the Password parameter. | 7.5 |
2006-11-16 | CVE-2006-5926 | Vallheru | SQL Injection vulnerability in Vallheru 1.0.6 Multiple SQL injection vulnerabilities in mail.php in Vallheru before 1.0.7 allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) to parameters. | 7.5 |
2006-11-15 | CVE-2006-5925 | Elinks Links | Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements. | 7.5 |
2006-11-15 | CVE-2006-5923 | Chris MAC | Remote File Include vulnerability in GimeScripts Shopping Catalog PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the custom parameter. | 7.5 |
2006-11-15 | CVE-2006-5919 | Activecampaign | Remote File Include vulnerability in Activecampaign Knowledgebuilder 2.2 PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the visEdit_root parameter, a different vector than CVE-2003-1131. | 7.5 |
2006-11-15 | CVE-2006-5918 | PHP Rapid Kill | Unspecified vulnerability in PHP Rapid Kill PHP Rapid Kill 5.7Pro Unrestricted file upload vulnerability in RapidKill (aka PHP Rapid Kill) 5.7 Pro, and certain other versions, allows remote attackers to upload and execute arbitrary PHP scripts via the "Link to Download" field. | 7.5 |
2006-11-15 | CVE-2006-5914 | Samedia | Input Validation vulnerability in Samedia LandShop LS.PHP SQL injection vulnerability in ls.php in SAMEDIA LandShop allows remote attackers to execute arbitrary SQL commands via the infield parameter. | 7.5 |
2006-11-15 | CVE-2006-5911 | Campware ORG | Remote File Include vulnerability in Campware.Org Campsite 2.6.0/2.6.1 Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) Alias.php, (2) Article.php, (3) ArticleAttachment.php, (4) ArticleComment.php, (5) ArticleData.php, (6) ArticleImage.php, (7) ArticleIndex.php, (8) ArticlePublish.php, (9) ArticleTopic.php, (10) ArticleType.php, (11) ArticleTypeField.php, (12) Attachment.php, (13) Country.php, (14) DatabaseObject.php, (15) Event.php, (16) IPAccess.php, (17) Image.php, (18) Issue.php, (19) IssuePublish.php, (20) Language.php, (21) Log.php, (22) LoginAttempts.php, (23) Publication.php, (24) Section.php, (25) ShortURL.php, (26) Subscription.php, (27) SubscriptionDefaultTime.php, (28) SubscriptionSection.php, (29) SystemPref.php, (30) Template.php, (31) TimeUnit.php, (32) Topic.php, (33) UrlType.php, (34) User.php, and (35) UserType.php in implementation/management/classes/; (36) configuration.php and (37) db_connect.php in implementation/management/; and (38) LocalizerConfig.php and (39) LocalizerLanguage.php in implementation/management/priv/localizer/. | 7.5 |
2006-11-15 | CVE-2006-5910 | Campware ORG | Remote File Include vulnerability in Campware.Org Campsite 2.6.0/2.6.1 Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 20061110 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) bugreporter/thankyou.php and (2) feedback/thankyou.php in implementation/management/priv/. | 7.5 |
2006-11-15 | CVE-2006-5908 | Lucas Rodriguez SAN Pedro | SQL Injection vulnerability in Lucas Rodriguez SAN Pedro YET Another News System 0.2B Multiple SQL injection vulnerabilities in the login_user function in yans.func.php in Lucas Rodriguez San Pedro Yet Another News System (YANS) 0.2b allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter. | 7.5 |
2006-11-15 | CVE-2006-5907 | Jean Christophe Ramos | SQL Injection vulnerability in Jean-Christophe Ramos BAN and Pls-Bannieres SQL injection vulnerability in modules/bannieres/bannieres.php in Jean-Christophe Ramos SCRIPT BANNIERES (aka ban 0.1 and PLS-Bannieres 1.21) allows remote attackers to execute arbitrary SQL commands via the id parameter. | 7.5 |
2006-11-15 | CVE-2006-5904 | Mwchat PRO | Remote Security vulnerability in Mwchat PRO Mwchat PRO 7.0 Multiple PHP remote file inclusion vulnerabilities in MWChat Pro 7.0 allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[MWCHAT_Libs] parameter to (1) about.php, (2) buddy.php, (3) chat.php, (4) dialog.php, (5) head.php, (6) help.php, (7) index.php, and (8) license.php, different vectors than CVE-2005-1869. | 7.5 |
2006-11-15 | CVE-2006-5903 | Rahul Jonna | Remote Security vulnerability in Gspace Rahul Jonna Gmail File Space (GSpace) allows remote attackers to perform virtual filesystem actions via e-mail messages with certain subject lines, as demonstrated by (1) a GSPACE "2174|1|1|1|gs:/ d$" message, which injects a new file into the filesystem; and (2) a GSPACE "|-135|1|1|0|gs:/ d$" message, which creates a folder. | 7.5 |
2006-11-15 | CVE-2006-5902 | Viksoe | Remote Security vulnerability in Gmail Drive viksoe GMail Drive shell extension allows remote attackers to perform virtual filesystem actions via e-mail messages with certain subject lines, as demonstrated by (1) a GMAILFS: [13;a;1] message with a new filename and a file attachment, which injects a new file into the filesystem; (2) a GMAILFS: [13;a;1] message with an existing filename and a file attachment, which overwrites existing file content; and (3) a GMAILFS: [14;a;1] message, which creates a folder. | 7.5 |
2006-11-14 | CVE-2006-5895 | Encapscms | Remote File Include vulnerability in Encapscms 0.3.6 PHP remote file inclusion vulnerability in core/core.php in EncapsCMS 0.3.6 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter. | 7.5 |
2006-11-14 | CVE-2006-5893 | Iwonder Designs | Remote File Include vulnerability in Iwonder Designs Storystream 0.4.0.0 Multiple PHP remote file inclusion vulnerabilities in iWonder Designs Storystream 0.4.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) mysql.php and (2) mysqli.php in include/classes/pear/DB/. | 7.5 |
2006-11-14 | CVE-2006-5892 | THE NET Guys | SQL Injection vulnerability in Aspired2Poll MoreInfo.ASP SQL injection vulnerability in MoreInfo.asp in The Net Guys ASPired2Poll 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | 7.5 |
2006-11-14 | CVE-2006-5891 | Superfreaker Studios | SQL-Injection vulnerability in Superfreaker Studios Ustore 1.0 SQL injection vulnerability in detail.asp in Superfreaker Studios UStore 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | 7.5 |
2006-11-14 | CVE-2006-5890 | Superfreaker Studios | SQL-Injection vulnerability in Superfreaker Studios Usupport 1.0 SQL injection vulnerability in detail.asp in Superfreaker Studios USupport 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 7.5 |
2006-11-14 | CVE-2006-5888 | Superfreaker Studios | SQL-Injection vulnerability in Superfreaker Studios Upublisher 1.0 SQL injection vulnerability in viewarticle.asp in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | 7.5 |
2006-11-14 | CVE-2006-5887 | Dynamic Dataworx | SQL Injection vulnerability in Dynamic Dataworx Nuschool 1.0 SQL injection vulnerability in CampusNewsDetails.asp in Dynamic Dataworx NuSchool 1.0 allows remote attackers to execute arbitrary SQL commands via the NewsID parameter. | 7.5 |
2006-11-14 | CVE-2006-5886 | Dynamic Dataworx | SQL Injection vulnerability in Dynamic Dataworx Nurealestate 1.0 SQL injection vulnerability in propertysdetails.asp in Dynamic Dataworx NuRealestate (NuRems) 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the PropID parameter. | 7.5 |
2006-11-14 | CVE-2006-5885 | Dynamic Dataworx | SQL Injection vulnerability in Dynamic Dataworx Nustore 1.0 SQL injection vulnerability in Products.asp in NuStore 1.0 allows remote attackers to execute arbitrary SQL commands via the SubCatagoryID parameter. | 7.5 |
2006-11-14 | CVE-2006-4688 | Microsoft | Remote Code Execution vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability." | 7.5 |
2006-11-14 | CVE-2006-5884 | Microsoft | Unspecified vulnerability in Microsoft IE and Internet Explorer Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Explorer 5.01 through 6 have unknown impact and remote attack vectors, possibly related to (1) Danim.dll and (2) Lmrt.dll, a different set of vulnerabilities than CVE-2006-4446 and CVE-2006-4777. | 7.5 |
2006-11-14 | CVE-2006-3445 | Microsoft | Numeric Errors vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP Integer overflow in the ReadWideString function in agentdpv.dll in Microsoft Agent on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a large length value in an .ACF file, which results in a heap-based buffer overflow. | 7.5 |
2006-11-14 | CVE-2006-5881 | Dynamic Dataworx | SQL Injection vulnerability in Dynamic Dataworx Nucommunity 1.0 SQL injection vulnerability in cl_CatListing.asp in Dynamic Dataworx NuCommunity 1.0 allows remote attackers to execute arbitrary SQL commands via the cl_cat_ID parameter. | 7.5 |
2006-11-14 | CVE-2006-5880 | Isystems | SQL Injection vulnerability in Isystems Munch PRO 1.0 SQL injection vulnerability on the subMenu page in switch.asp in Munch Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter. | 7.5 |
2006-11-14 | CVE-2006-5879 | Aspportal | SQL Injection vulnerability in Aspportal 3.0.0/3.1.0/3.1.1 SQL injection vulnerability in default1.asp in ASPPortal 4.0.0 beta and earlier allows remote attackers to execute arbitrary SQL commands via the Poll_ID parameter, a different vector than CVE-2006-1353. | 7.5 |
2006-11-14 | CVE-2006-5878 | Edgewall Software | Cross-Site Request Forgery vulnerability in Trac Cross-site request forgery (CSRF) vulnerability in Edgewall Trac 0.10 and earlier allows remote attackers to perform unauthorized actions as other users via unknown vectors. | 7.5 |
2006-11-14 | CVE-2006-4251 | Powerdns | Remote Denial of Service and Buffer Overflow vulnerability in PowerDNS Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to execute arbitrary code via a malformed TCP DNS query that prevents Recursor from properly calculating the TCP DNS query length. | 7.5 |
2006-11-18 | CVE-2006-4413 | Apple | Remote Desktop Insecure Default Package Permission vulnerability in Apple Remote Desktop 2.0/2.1/3.0 Apple Remote Desktop before 3.1 uses insecure permissions for certain built-in packages, which allows local users on an Apple Remote Desktop administration system to modify the packages and gain root privileges on client systems that use the packages. | 7.2 |
28 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2006-11-17 | CVE-2006-5960 | WEB Inhabit | Unspecified vulnerability in web Inhabit A+ Store E-Commerce Multiple cross-site scripting (XSS) vulnerabilities in account_login.asp in A+ Store E-Commerce allow remote attackers to inject arbitrary web script or HTML via the (1) username (txtUserName) and (2) password (txtPassword) parameters. | 6.8 |
2006-11-17 | CVE-2006-5958 | Infinicart | Cross-Site Scripting vulnerability in infinicart Multiple cross-site scripting (XSS) vulnerabilities in INFINICART allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password fields in (a) login.asp, (3) search field in (b) search.asp, and (4) email field in (c) sendpassword.asp. | 6.8 |
2006-11-17 | CVE-2006-5942 | Website Designs FOR Less | Input Validation vulnerability in Inventory Manager Cross-site scripting (XSS) vulnerability in inventory/display/display_results.asp in Website Designs For Less Inventory Manager allows remote attackers to inject arbitrary web script or HTML via the category parameter. | 6.8 |
2006-11-15 | CVE-2006-5915 | Samedia | Input Validation vulnerability in Samedia LandShop LS.PHP Multiple cross-site scripting (XSS) vulnerabilities in ls.php in SAMEDIA LandShop allow remote attackers to inject arbitrary web script or HTML via the (1) start, (2) CAT_ID, (3) keyword, (4) search_area, (5) search_type, (6) infield, or (7) search_order parameter. | 6.8 |
2006-11-15 | CVE-2006-5900 | Zend | Cross-Site Scripting vulnerability in Zend Framework Preview 0.2.0 Cross-site scripting (XSS) vulnerability in the incubator/tests/Zend/Http/_files/testRedirections.php sample code in Zend Framework Preview 0.2.0 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters. | 6.8 |
2006-11-14 | CVE-2006-5894 | Rama CMS | Local File Include vulnerability in Rama CMS Lang Parameter Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. | 6.8 |
2006-11-17 | CVE-2006-5966 | Panda | Resource Management Errors vulnerability in Panda Activescan 5.0/5.53.00 Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to (1) reboot the system using the Reinicializar method in the ActiveScan.1 ActiveX control, or (2) determine arbitrary file existence and size via the ObtenerTamano method in the PAVPZ.SOS.1 ActiveX control. | 6.4 |
2006-11-15 | CVE-2006-5913 | Microsoft | Remote Security vulnerability in Microsoft IE 7.0 Microsoft Internet Explorer 7 allows remote attackers to (1) cause a security certificate from a secure web site to appear invalid via a link to res://ieframe.dll/sslnavcancel.htm with the target site in the anchor identifier, which displays the site's URL in the address bar but causes Internet Explorer to report that the certificate is invalid, or (2) trigger a "The webpage no longer exists" report via a link to res://ieframe.dll/http_410.htm, a variant of CVE-2006-5805. | 6.4 |
2006-11-15 | CVE-2006-5905 | WEB Directory PRO | Remote Security vulnerability in Web Directory Pro Web Directory Pro allows remote attackers to (1) backup the database and obtain the backup via a direct request to admin/backup_db.php or (2) modify configuration via a direct request to admin/options.php. | 6.4 |
2006-11-15 | CVE-2006-5924 | Efficientip | Cross-Site Scripting vulnerability in Efficientip Ipmanager 2.3 Cross-site scripting (XSS) vulnerability in index.php in Efficient IP iPmanager (IPm) 2.3 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter. | 5.8 |
2006-11-15 | CVE-2006-5921 | Wheatblog | HTML Injection vulnerability in WheatBlog Multiple cross-site scripting (XSS) vulnerabilities in add_comment.php in Wheatblog (wB) allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) WWW, and (3) Comment fields. | 5.8 |
2006-11-17 | CVE-2006-5967 | Panda | Remote vulnerability in Panda ActiveScan ActiveX Controls Race condition in Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to cause memory corruption and execute arbitrary code via unknown vectors related to multiple invocations of the Analizar method in the ActiveScan.1 ActiveX control, which is not thread safe. | 5.1 |
2006-11-16 | CVE-2006-5931 | Aigaion | Remote Security vulnerability in Aigaion 1.2.1 Multiple PHP remote file inclusion vulnerabilities in Aigaion Web based bibliography management system 1.2.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to certain PHP scripts in (1) lib/actions/, (2) lib/displays/, (3) lib/editforms/, (4) lib/functions/, (5) scheme/, and (6) the root directory. | 5.1 |
2006-11-14 | CVE-2006-4687 | Microsoft | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft IE and Internet Explorer Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via crafted layout combinations involving DIV tags and HTML CSS float properties that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability." | 5.1 |
2006-11-18 | CVE-2006-5971 | Verity | Directory Traversal vulnerability in Ultraseek Absolute path traversal vulnerability in admin/logfile.txt in Verity Ultraseek before 5.6.2 allows remote attackers to read arbitrary files via the name variable. | 5.0 |
2006-11-18 | CVE-2006-5970 | Verity | Information Disclosure vulnerability in Ultraseek Verity Ultraseek before 5.7 allows remote attackers to obtain sensitive information via direct requests with (1) a null ("%00") terminated url parameter to help/urlstatusgo.html; or missing parameters to (2) help/header.html, (3) help/footer.html, (4) spell.html, (5) coreforma.html, (6) daterange.html, (7) hits.html, (8) hitsnavbottom.html, (9) indexform.html, (10) indexforma.html, (11) languages.html, (12) nohits.html, (13) onehit1.html, (14) onehit2.html, (15) query.html, (16) queryform0.html, (17) queryform0a.html, (18) queryform1.html, (19) queryform1a.html, (20) queryform2.html, (21) queryform2a.html, (22) quicklinks.html, (23) relatedtopics.html, (24) signin.html, (25) subtopics.html, (26) thesaurus.html, (27) topics.html, (28) hitspagebar.html, (29) highlight/highlight.html, (30) highlight/highlight_one.html, and (31) highlight/topnav.html, which leaks the installation path in the resulting error message. | 5.0 |
2006-11-17 | CVE-2006-5950 | Altools | Unspecified vulnerability in Altools Alftp FTP Server 4.1Beta1 Unspecified vulnerability in ALTools ALFTP FTP Server 4.1 beta 1, and possibly earlier, allows remote authenticated users to obtain the installation path via unknown vectors related to the REN command, probably due to response messages. | 5.0 |
2006-11-17 | CVE-2006-5949 | Altools | Unspecified vulnerability in Altools Alftp FTP Server 4.1Beta1 Directory traversal vulnerability in ALTools ALFTP FTP Server 4.1 beta 1, and possibly earlier, allows remote attackers to create arbitrary directories via directory traversal sequences in a MKD request. | 5.0 |
2006-11-17 | CVE-2006-5947 | Conxint | Directory Traversal vulnerability in Conxint FTP Server 2.2.0603 Multiple directory traversal vulnerabilities in Conxint FTP Server 2.2.0603, and possibly earlier, allow remote attackers to read arbitrary files and list arbitrary directories via directory traversal sequences in (1) DIR (LIST or NLST) and (2) GET (RETR) commands. | 5.0 |
2006-11-15 | CVE-2006-5922 | Wheatblog | Information Disclosure vulnerability in Wheatblog index.php in Wheatblog (wB) allows remote attackers to obtain sensitive information via certain values of the postPtr[] and next parameters, which reveals the path in an error message. | 5.0 |
2006-11-15 | CVE-2006-5909 | Paul Tarjan | Permissions, Privileges, and Access Controls vulnerability in Paul Tarjan Stanford Conference and Research Forum Beta generaloptions.php in Paul Tarjan Stanford Conference And Research Forum (SCARF) before 20070227 does not require the admin privilege, which allows remote attackers to reconfigure the application or its user accounts. | 5.0 |
2006-11-15 | CVE-2006-5901 | Hawking Technology | Denial-Of-Service vulnerability in Wr254-Ca Wireless Router Hawking Technology wireless router WR254-CA uses a hardcoded IP address among the set of DNS server IP addresses, which could allow remote attackers to cause a denial of service or hijack the router by attacking or spoofing the server at the hardcoded address. | 5.0 |
2006-11-15 | CVE-2006-5898 | Phpheaven | Directory Traversal vulnerability in phpMyChat Directory traversal vulnerability in localization/languages.lib.php3 in PhpMyChat 0.14.5 and earlier allows remote attackers to read arbitrary files via a .. | 5.0 |
2006-11-15 | CVE-2006-5897 | Phpheaven | Path Traversal vulnerability in PHPheaven PHPmychat Plus Multiple directory traversal vulnerabilities in PhpMyChat Plus 1.9 and earlier allow remote attackers to read arbitrary files via a .. | 5.0 |
2006-11-14 | CVE-2006-4689 | Microsoft | Denial-Of-Service vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka "NetWare Driver Denial of Service Vulnerability." | 5.0 |
2006-11-14 | CVE-2006-4252 | Powerdns | Remote Denial of Service and Buffer Overflow vulnerability in PowerDNS PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application crash) via a CNAME record with a zero TTL, which triggers an infinite loop. | 5.0 |
2006-11-17 | CVE-2006-5968 | ALT N | Local Security vulnerability in Mdaemon MDaemon 9.0.5, 9.0.6, 9.51, and 9.53, and possibly other versions, installs the MDaemon application folder with insecure permissions (Users create files/directories), which allows local users to execute arbitrary code by creating malicious RASAPI32.DLL or MPRAPI.DLL libraries in the MDaemon\APP folder, which is an untrusted search path element due to insecure permissions. | 4.6 |
2006-11-14 | CVE-2006-5198 | Winzip | Remote Code Execution vulnerability in Winzip 10.0 The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers to execute arbitrary code via unspecified "unsafe methods." | 4.0 |
4 Low Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2006-11-14 | CVE-2006-5883 | Cpanel | Cross-Site Scripting vulnerability in Cpanel 10 Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote authenticated users to inject arbitrary web script or HTML via the (1) dir parameter in (a) seldir.html, and the (2) user and (3) dir parameters in (b) newuser.html. | 3.5 |
2006-11-17 | CVE-2006-5793 | Greg Roelofs | Improper Input Validation vulnerability in Greg Roelofs Libpng The sPLT chunk handling code (png_set_sPLT function in pngset.c) in libpng 1.0.6 through 1.2.12 uses a sizeof operator on the wrong data type, which allows context-dependent attackers to cause a denial of service (crash) via malformed sPLT chunks that trigger an out-of-bounds read. | 2.6 |
2006-11-17 | CVE-2006-5956 | Xlinesoft | Local Information Disclosure vulnerability in Xlinesoft PHPrunner 3.1 XLineSoft PHPRunner 3.1 stores the (1) database server name, (2) database names, (3) usernames, and (4) passwords in plaintext in %WINDIR%\PHPRunner.ini, which allows local users to obtain sensitive information by reading the file. | 2.1 |
2006-11-14 | CVE-2006-5461 | Avahi | Unspecified vulnerability in Avahi Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows local users to spoof network changes to Avahi. | 2.1 |