Weekly Vulnerabilities Reports > December 11 to 17, 2006

Overview

141 new vulnerabilities reported during this period, including 21 critical vulnerabilities and 49 high severity vulnerabilities. This weekly summary report vulnerabilities in 111 products from 77 vendors including Microsoft, Scriptphp, Xerox, Mxbb, and Drupal. Vulnerabilities are notably categorized as "Resource Management Errors", "Permissions, Privileges, and Access Controls", "Out-of-bounds Write", "NULL Pointer Dereference", and "Information Exposure".

  • 124 reported vulnerabilities are remotely exploitables.
  • 28 reported vulnerabilities have public exploit available.
  • 117 reported vulnerabilities are exploitable by an anonymous user.
  • Microsoft has the most reported vulnerabilities, with 15 reported vulnerabilities.
  • Microsoft has the most reported critical vulnerabilities, with 5 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

21 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2006-12-15 CVE-2006-6584 Italkplus Denial-Of-Service vulnerability in Italkplus 0.80

Multiple buffer overflows in italkplus (Italk+) before 0.92.1 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified vectors.

10.0
2006-12-15 CVE-2006-6568 Mxbb File Include vulnerability in Mxbb KB Mods 2.0.2

Directory traversal vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to include arbitrary files via a ..

10.0
2006-12-15 CVE-2006-6567 Mxbb File Include vulnerability in Mxbb KB Mods 2.0.2

PHP remote file inclusion vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

10.0
2006-12-14 CVE-2006-6222 Symantec Remote vulnerability in Symantec products

Stack-based buffer overflow in the NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 allows remote attackers to execute arbitrary code via a long request with a malformed length prefix.

10.0
2006-12-14 CVE-2006-5822 Symantec Remote vulnerability in Symantec products

Stack-based buffer overflow in the NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 allows remote attackers to execute arbitrary code via a long CONNECT_OPTIONS request, a different issue than CVE-2006-6222.

10.0
2006-12-14 CVE-2006-4902 Symantec Remote vulnerability in Symantec products

The NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 does not properly check for chained commands, which allows remote attackers to execute arbitrary commands by appending malicious commands to valid commands.

10.0
2006-12-14 CVE-2006-6539 Flippet ORG Remote vulnerability in Winamp Web Interface

Multiple buffer overflows in Winamp Web Interface (Wawi) 7.5.13 and earlier (1) allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an (a) long username or a (b) crafted packet to the FindBasicAuth function in security.cpp, related to the /browse URI; and allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a long path string in the (2) Browse, (3) CControl::Download, and (4) CControl::Load functions, related to the file parameter in the /dl URI.

10.0
2006-12-14 CVE-2006-6515 Mantis Remote Security vulnerability in Mantis

Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, which has unknown impact and attack vectors, possibly related to frequency of reminders.

10.0
2006-12-12 CVE-2006-6335 Sophos Buffer Overflow vulnerability in Sophos Anti-Virus 2.3

Multiple buffer overflows in Sophos Anti-Virus scanning engine before 2.40 allow remote attackers to execute arbitrary code via (1) a SIT archive with a long filename that is not null-terminated, which triggers a heap-based overflow in veex.dll due to improper length calculation, and (2) a CPIO archive, with a long filename that is not null-terminated, which triggers a stack-based overflow in veex.dll.

10.0
2006-12-12 CVE-2006-5583 Microsoft Remote Code Execution vulnerability in Microsoft Windows 2003 Server 2000/Sp1/Xpsp2

Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."

10.0
2006-12-12 CVE-2006-6423 Mailenable Remote Buffer Overflow vulnerability in MailEnable IMAP Service Login

Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Professional Edition 1.6 through 1.84, and Enterprise Edition 1.1 through 1.41 allows remote attackers to execute arbitrary code via a pre-authentication command followed by a crafted parameter and a long string, as addressed by the ME-10025 hotfix.

10.0
2006-12-11 CVE-2006-6473 Xerox Remote Security vulnerability in WorkCentre

Multiple unspecified vulnerabilities in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 have unknown impact and attack vectors, related to (1) an Immediate Image Overwrite (IIO) error message at the Local User Interface (LUI) if overwrite fails, (2) an IIO failure when a Held Job is deleted, and (3) an On Demand Image Overwrite failure when the overwrite is greater than 2 Gb.

10.0
2006-12-11 CVE-2006-6472 Xerox Remote Security vulnerability in WorkCentre

The httpd.conf file in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 configures port 443 to be always active, which has unknown impact and remote attack vectors.

10.0
2006-12-11 CVE-2006-6471 Xerox Remote Security vulnerability in WorkCentre

Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 use weak permissions for certain files, which allows unspecified file access.

10.0
2006-12-11 CVE-2006-6470 Xerox Remote Security vulnerability in WorkCentre

The SNMP Agent in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 returns no error for a non-writable object, which has unknown impact and attack vectors.

10.0
2006-12-11 CVE-2006-6460 Short URL
URL Tracker Script
Information Disclosure vulnerability in Url Tracker Script

Yourfreeworld.com Short Url & Url Tracker Script allows remote attackers to obtain sensitive information via an invalid id parameter to login.php, which leaks the path in an error message.

10.0
2006-12-15 CVE-2006-6603 Yahoo Remote Buffer Overflow vulnerability in Yahoo! Messenger YMailAttach ActiveX Control

Buffer overflow in the YMMAPI.YMailAttach ActiveX control (ymmapi.dll) before 2005.1.1.4 in Yahoo! Messenger allows remote attackers to execute arbitrary code via a crafted HTML document.

9.3
2006-12-14 CVE-2006-6561 Microsoft Unspecified vulnerability in Microsoft products

Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers memory corruption, as demonstrated via the 12122006-djtest.doc file, a different issue than CVE-2006-5994 and CVE-2006-6456.

9.3
2006-12-12 CVE-2006-5581 Microsoft Unspecified vulnerability in Microsoft Internet Explorer

Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via certain DHTML script functions, such as normalize, and "incorrectly created elements" that trigger memory corruption, aka "DHTML Script Function Memory Corruption Vulnerability."

9.3
2006-12-12 CVE-2006-5579 Microsoft Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Internet Explorer 6

Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using JavaScript to cause certain errors simultaneously, which results in the access of previously freed memory, aka "Script Error Handling Memory Corruption Vulnerability."

9.3
2006-12-11 CVE-2006-6456 Microsoft Unspecified vulnerability in Microsoft products

Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than CVE-2006-5994.

9.3

49 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2006-12-15 CVE-2006-6569 Genesistrader Input Validation vulnerability in Genesistrader 1.0

form.php in GenesisTrader 1.0 allows remote attackers to read source code for arbitrary files and obtain sensitive information via the (1) do and (2) chem parameters with a "modfich" floap parameter.

7.8
2006-12-14 CVE-2006-6538 D Link Denial-Of-Service vulnerability in D-Link Dwl-2000Ap+ 2.11

D-LINK DWL-2000AP+ firmware 2.11 allows remote attackers to cause (1) a denial of service (device reset) via a flood of ARP replies on the wired or wireless (radio) link and (2) a denial of service (device crash) via a flood of ARP requests on the wireless link.

7.8
2006-12-12 CVE-2006-5873 L2Tpns
Debian
Denial of Service vulnerability in L2TPNS Heartbeat Handling

Buffer overflow in the cluster_process_heartbeat function in cluster.c in layer 2 tunneling protocol network server (l2tpns) before 2.1.21 allows remote attackers to cause a denial of service via a large heartbeat packet.

7.8
2006-12-11 CVE-2006-6461 Yourfreeworld Remote Security vulnerability in Stylish Text Ads Script

tr1.php in Yourfreeworld Stylish Text Ads Script allows remote attackers to obtain the installation path via an invalid id parameter, which leaks the path in an error message.

7.8
2006-12-11 CVE-2006-6458 Trend Micro Remote Denial Of Service vulnerability in Trend Micro products

The Trend Micro scan engine before 8.320 for Windows and before 8.150 on HP-UX and AIX, as used in Trend Micro PC Cillin - Internet Security 2006, Office Scan 7.3, and Server Protect 5.58, allows remote attackers to cause a denial of service (CPU consumption and system hang) via a malformed RAR archive with an Archive Header section with the head_size and pack_size fields set to zero, which triggers an infinite loop.

7.8
2006-12-15 CVE-2006-6595 Scriptmate SQL-Injection vulnerability in User Manager

Multiple SQL injection vulnerabilities in ScriptMate User Manager 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via "Manage Resources" and possibly other unspecified components.

7.5
2006-12-15 CVE-2006-6594 Scriptmate SQL-Injection vulnerability in Scriptmate User Manager 2.0

SQL injection vulnerability in utilities/usermessages.asp in ScriptMate User Manager 2.0 allows remote attackers to execute arbitrary SQL commands via the mesid parameter.

7.5
2006-12-15 CVE-2006-6593 Phpbb Remote File Include vulnerability in PHPBB Amazonia Component Zufallscodepart.PHP

PHP remote file inclusion vulnerability in zufallscodepart.php in AMAZONIA MOD for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

7.5
2006-12-15 CVE-2006-6592 PHP Remote File Include vulnerability in PHP Bloq 0.5.4

Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] parameter to (1) index.php, (2) admin.php, (3) rss.php, (4) rdf.php, (5) rss2.php, or (6) files/mainfile.php.

7.5
2006-12-15 CVE-2006-6591 Exlor Remote Security vulnerability in Exlor 1.0

PHP remote file inclusion vulnerability in fonctions/template.php in EXlor 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the repphp parameter.

7.5
2006-12-15 CVE-2006-6590 PHP Remote Security vulnerability in AR Memberscript

PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitrary PHP code via a URL in the script_folder parameter.

7.5
2006-12-15 CVE-2006-6588 Apache Remote Security vulnerability in Open For Business Project

The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of content, modify content, or have other unknown impact.

7.5
2006-12-15 CVE-2006-6586 Vblog Remote Security vulnerability in Vblog A0.1Nonfunc

Multiple PHP remote file inclusion vulnerabilities in Vortex Blog (vBlog, aka C12) a0.1_nonfunc allow remote attackers to execute arbitrary PHP code via a URL in the cfgProgDir parameter in (1) secure.php or (2) checklogin.php in admin/auth/.

7.5
2006-12-15 CVE-2006-6583 Scriptmate Information Disclosure vulnerability in User Manager

ScriptMate User Manager 2.1 and earlier allow remote attackers to obtain sensitive information via unspecified vectors related to (1) the Logins box and (2) the Search box.

7.5
2006-12-15 CVE-2006-6581 Vernet Loic Improper Input Validation vulnerability in Vernet Loic PHP Debug 1.1.0

PHP remote file inclusion vulnerability in tests/debug_test.php in Vernet Loic PHP_Debug 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the debugClassLocation parameter.

7.5
2006-12-15 CVE-2006-6578 Microsoft Unspecified vulnerability in Microsoft Internet Information Services 5.1

Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EXE files such as .COM files, which allows attackers to execute arbitrary commands via arguments to any .COM file that executes those arguments, as demonstrated using win.com when it is in a web directory with certain permissions.

7.5
2006-12-15 CVE-2006-6576 Goldenftpserver Out-Of-Bounds Write vulnerability in Goldenftpserver Golden FTP Server 1.92

Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long PASS command.

7.5
2006-12-15 CVE-2006-6575 Brian Drawert Remote Security vulnerability in Yaplap 0.6/0.6.1

PHP remote file inclusion vulnerability in ldap.php in Brian Drawert Yet Another PHP LDAP Admin Project (yaplap) 0.6 and 0.6.1 allows remote attackers to execute arbitrary PHP code via a URL in the LOGIN_style parameter.

7.5
2006-12-15 CVE-2006-6570 Genesistrader Input Validation vulnerability in Genesistrader 1.0

Unrestricted file upload vulnerability in upload.php in GenesisTrader 1.0 allows remote authenticated users to upload arbitrary files via unspecified vectors, possibly involving form.php and the ajoutfich "foap" action.

7.5
2006-12-15 CVE-2006-6566 Mxbb Remote Security vulnerability in Mxbb 0.91C

PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module for mxBB 0.91c allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

7.5
2006-12-14 CVE-2006-6304 Linux Resource Management Errors vulnerability in Linux Kernel 2.6.19

The do_coredump function in fs/exec.c in the Linux kernel 2.6.19 sets the flag variable to O_EXCL but does not use it, which allows context-dependent attackers to modify arbitrary files via a rewrite attack during a core dump.

7.5
2006-12-14 CVE-2006-6560 Mxbb Remote Security vulnerability in Mxbb Modsdb 1.0.0

PHP remote file inclusion vulnerability in includes/common.php in the mx_modsdb 1.0.0 module for MxBB (aka MX-System) Portal allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

7.5
2006-12-14 CVE-2006-6559 Lotfian SQL-Injection vulnerability in Lotfian Request for Travel 1.0

SQL injection vulnerability in ProductDetails.asp in Lotfian Request For Travel 1.0 allows remote attackers to execute arbitrary SQL commands via the PID parameter.

7.5
2006-12-14 CVE-2006-6556 Eyeos Unspecified vulnerability in Eyeos 0.9.2

The eyeHome function in apps/eyeHome.eyeapp/aplic.php in EyeOS before 0.9.3-3 allows remote attackers to upload and execute arbitrary code via dangerous file extensions that are not all lowercase, which bypasses a cleansing operation.

7.5
2006-12-14 CVE-2006-6555 Easyfill SQL-Injection vulnerability in Easyfill 0.5

Multiple SQL injection vulnerabilities in EasyFill before 0.5.1 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

7.5
2006-12-14 CVE-2006-6553 Mxbb Remote File Include vulnerability in Mxbb Newssuite 1.03

PHP remote file inclusion vulnerability in includes/newssuite_constants.php in the NewsSuite 1.03 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter.

7.5
2006-12-14 CVE-2006-6552 PHP Remote Security vulnerability in PHP Blog CMS 4.1.3

PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DIR_ADMIN parameter.

7.5
2006-12-14 CVE-2006-6551 Tucows Remote Security vulnerability in Tucows Client Code Suite 1.2.1015

PHP remote file inclusion vulnerability in libs/tucows/api/cartridges/crt_TUCOWS_domains/lib/domainutils.inc.php in Tucows Client Code Suite (CCS) 1.2.1015 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _ENV[TCA_HOME] parameter.

7.5
2006-12-14 CVE-2006-6546 Cutenews AJ Fork Remote File Include vulnerability in Cutenews Aj-Fork Cutenews Aj-Fork Beta

PHP remote file inclusion vulnerability in inc/shows.inc.php in cutenews aj-fork (CN:AJ) 167f and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter.

7.5
2006-12-14 CVE-2006-6545 PHP Remote Security vulnerability in PHP Errordocs 1.0.0

PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_errordocs) allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

7.5
2006-12-14 CVE-2006-6543 Appintellect SQL-Injection vulnerability in Appintellect Spotlight CRM 1.0

Multiple SQL injection vulnerabilities in login.asp in AppIntellect SpotLight CRM 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) login (UserName) and possibly (2) password parameter.

7.5
2006-12-14 CVE-2006-6542 Fantastic News SQL-Injection vulnerability in Fantastic News

SQL injection vulnerability in news.php in Fantastic News 2.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

7.5
2006-12-14 CVE-2006-6537 IBM Security Bypass vulnerability in Websphere Host On-Demand

IBM WebSphere Host On-Demand 6.0, 7.0, 8.0, 9.0, and possibly 10, allows remote attackers to bypass authentication via a modified pnl parameter, related to hod/HODAdmin.html and hod/frameset.html.

7.5
2006-12-14 CVE-2006-6533 Oscommerce Input Validation vulnerability in Oscommerce 3.0A3

Directory traversal vulnerability in admin/templates_boxes_layout.php in osCommerce 3.0a3 allows remote attackers to include and execute arbitrary PHP files via a ..

7.5
2006-12-14 CVE-2006-6530 Drupal SQL-Injection vulnerability in Help Tip Module

SQL injection vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

7.5
2006-12-14 CVE-2006-6529 Drupal Information Disclosure vulnerability in Drupal Chatroom Module 4.7

The Chatroom Module before 4.7.x.-1.0 for Drupal displays private messages in a chatroom's last messages overview, which allows remote attackers to obtain sensitive information by reading the overview.

7.5
2006-12-14 CVE-2006-6528 Drupal Remote Security vulnerability in Chatroom Module

The Chatroom Module before 4.7.x.-1.0 for Drupal broadcasts Chatroom visitors' session IDs to all participants, which allows remote attackers to hijack sessions and gain privileges.

7.5
2006-12-14 CVE-2006-6527 Gizzar Remote Security vulnerability in gizzar

PHP remote file inclusion vulnerability in guest.php in Gizzar 03162002 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the basePath parameter.

7.5
2006-12-14 CVE-2006-6526 Gizzar Remote File Include vulnerability in Gizzar

PHP remote file inclusion vulnerability in index.php in Gizzar 03162002 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the basePath parameter.

7.5
2006-12-14 CVE-2006-6525 Ezhrs SQL-Injection vulnerability in HR Assist

SQL injection vulnerability in vdateUsr.asp in EzHRS HR Assist 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the password parameter.

7.5
2006-12-14 CVE-2006-6524 Ezhrs SQL-Injection vulnerability in HR Assist

SQL injection vulnerability in vdateUsr.asp in EzHRS HR Assist 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the Uname (UserName) parameter.

7.5
2006-12-14 CVE-2006-6521 Scriptphp Input Validation vulnerability in Scriptphp Messageriescripthp 2.0

SQL injection vulnerability in lire-avis.php in Messageriescripthp 2.0 allows remote attackers to execute arbitrary SQL commands via the aa parameter.

7.5
2006-12-14 CVE-2006-6519 Scriptphp Input Validation vulnerability in Scriptphp Pronews 1.5

SQL injection vulnerability in lire-avis.php in ProNews 1.5 allows remote attackers to execute arbitrary SQL commands via the aa parameter.

7.5
2006-12-14 CVE-2006-6516 Kdpics Input Validation vulnerability in KDPics

Multiple PHP remote file inclusion vulnerabilities in KDPics 1.16 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) page parameter to (a) index.php3, or the (2) lib_path parameter to (b) authenticate.inc.php3 or (c) lib/exifer/exif.php.

7.5
2006-12-13 CVE-2006-5584 Microsoft Remote Installation Service Remote Code Execution vulnerability in Microsoft Windows 2000

The Remote Installation Service (RIS) in Microsoft Windows 2000 SP4 uses a TFTP server that allows anonymous access, which allows remote attackers to upload and overwrite arbitrary files to gain privileges on systems that use RIS.

7.5
2006-12-12 CVE-2006-6486 Easypage SQL-Injection vulnerability in EasyPage

SQL injection vulnerability in EasyPage allows remote attackers to execute arbitrary SQL commands via unspecified vectors in sptrees/default.aspx, possibly involving the docId parameter.

7.5
2006-12-12 CVE-2006-6478 Scriptphp Input Validation vulnerability in Scriptphp Annoncescripthp 2.0

Multiple SQL injection vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) email.php, the (2) no parameter in (b) voirannonce.php, the (3) idmembre parameter in (c) admin/admin_membre/fiche_membre.php, and the (4) idannonce parameter in (d) admin/admin_annonce/okvalannonce.php and (e) admin/admin_annonce/changeannonce.php.

7.5
2006-12-11 CVE-2006-6462 Cm68 News Code Injection vulnerability in Cm68 News Cm68 News 12.02.06

PHP remote file inclusion vulnerability in engine/oldnews.inc.php in CM68 News 12.02.06 allows remote attackers to execute arbitrary PHP code via a URL in the addpath parameter.

7.5
2006-12-13 CVE-2006-5585 Microsoft Permissions, Privileges, and Access Controls vulnerability in Microsoft Windows 2003 Server and Windows XP

The Client-Server Run-time Subsystem in Microsoft Windows XP SP2 and Server 2003 allows local users to gain privileges via a crafted file manifest within an application, aka "File Manifest Corruption Vulnerability."

7.2

63 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2006-12-15 CVE-2006-6596 Hilgraeve Remote Command Execution vulnerability in Hilgraeve Hyperaccess 8.4

HyperAccess 8.4 allows user-assisted remote attackers to execute arbitrary vbscript and commands via a session (HAW) file, which can be automatically opened using Internet Explorer.

6.8
2006-12-15 CVE-2006-6589 Apache HTML Injection vulnerability in Apache Ofbiz and Opentaps

Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows remote attackers to inject arbitrary web script or HTML via the SEARCH_STRING parameter, a different issue than CVE-2006-6587.

6.8
2006-12-15 CVE-2006-6587 Apache HTML Injection vulnerability in OFBiz

Cross-site scripting (XSS) vulnerability in the forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) allows remote attackers to inject arbitrary web script or HTML by posting a message.

6.8
2006-12-15 CVE-2006-6582 Scriptmate Cross-Site Scripting vulnerability in User Manager

Multiple cross-site scripting (XSS) vulnerabilities in ScriptMate User Manager 2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) members_username (user) and (2) members_password (password) fields in a login action in members/default.asp, and (3) the Search box.

6.8
2006-12-15 CVE-2006-6577 Neocrome SQL Injection vulnerability in Seditio/Land Down Under Polls.PHP

SQL injection vulnerability in polls.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

6.8
2006-12-15 CVE-2006-6571 Genesistrader Input Validation vulnerability in Genesistrader 1.0

Multiple cross-site scripting (XSS) vulnerabilities in form.php in GenesisTrader 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cuve, (2) chem, (3) do, and possibly other parameters.

6.8
2006-12-14 CVE-2006-6557 Skulls Remote Security vulnerability in Skulls 0.2.5

Multiple unspecified vulnerabilities in Skulls! before 0.2.6 have unknown impact and attack vectors, as addressed by "Many security fixes."

6.8
2006-12-14 CVE-2006-6544 Cm68 News Cross-Site Scripting vulnerability in Cm68 News

Cross-site scripting (XSS) vulnerability in CM68 News allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

6.8
2006-12-14 CVE-2006-6540 Bluetrait SQL-Injection vulnerability in Bluetrait

SQL injection vulnerability in bt-trackback.php in Bluetrait before 1.2.0, when trackback is enabled, allows remote attackers to execute arbitrary SQL commands via unspecified parameters.

6.8
2006-12-14 CVE-2006-6536 Cilem Cross-Site Scripting vulnerability in Cilem Haber Freeedition

Cross-site scripting (XSS) vulnerability in hata.asp in Cilem Haber Free Edition allows remote attackers to inject arbitrary web script or HTML via the hata parameter.

6.8
2006-12-14 CVE-2006-6532 VT Forum Cross-Site Scripting vulnerability in Vt-Forum Lite

Multiple cross-site scripting (XSS) vulnerabilities in Vt-Forum Lite 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) StrMsg or (2) Topic_ID parameter to (a) vf_info.asp, (b) vf_newtopic.asp, (c) vf_settings.asp, and (d) vf_replytopic.asp, different vectors than CVE-2006-6447.

6.8
2006-12-14 CVE-2006-6531 Drupal Cross-Site Scripting vulnerability in Help Tip Module

Cross-site scripting (XSS) vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to inject arbitrary web script or HTML, and possibly obtain administrative access, via node titles.

6.8
2006-12-14 CVE-2006-6523 Cpanel Cross-Site Scripting vulnerability in Cpanel 11

Cross-site scripting (XSS) vulnerability in mail/manage.html in BoxTrapper in cPanel 11 allows remote attackers to inject arbitrary web script or HTML via the account parameter.

6.8
2006-12-14 CVE-2006-6522 Wikitimescale Cross-Site Scripting vulnerability in Twozero

Multiple cross-site scripting (XSS) vulnerabilities in WikiTimeScale TwoZero before 2.31 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in the (1) forum module and (2) event descriptions.

6.8
2006-12-14 CVE-2006-6520 Scriptphp Input Validation vulnerability in Scriptphp Messageriescripthp 2.0

Multiple cross-site scripting (XSS) vulnerabilities in Messageriescripthp 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo parameter to (a) existepseudo.php, the (2) email parameter to (b) existeemail.php, or the (3) pageName or (4) cssform parameter to (c) Contact/contact.php.

6.8
2006-12-14 CVE-2006-6518 Scriptphp Input Validation vulnerability in Scriptphp Pronews 1.5

Multiple cross-site scripting (XSS) vulnerabilities in ProNews 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo, (2) email, (3) date, (4) sujet, (5) message, (6) site, and (7) lien parameters to (a) admin/change.php, and the (8) aa parameter to (b) lire-avis.php.

6.8
2006-12-14 CVE-2006-6517 Kdpics Input Validation vulnerability in KDPics

Multiple cross-site scripting (XSS) vulnerabilities in KDPics 1.16 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) categories parameter to (a) index.php3 or (b) galeries.inc.php3.

6.8
2006-12-14 CVE-2006-6511 Dadaimc Remote Security vulnerability in dadaimc

dadaIMC .99.3 uses an insufficiently restrictive FilesMatch directive in the installed .htaccess file, which allows remote attackers to execute arbitrary PHP code by uploading files whose names contain (1) feature, (2) editor, (3) newswire, (4) otherpress, (5) admin, (6) pbook, (7) media, or (8) mod, which are processed as PHP file types (application/x-httpd-php).

6.8
2006-12-13 CVE-2006-4702 Microsoft Remote ASF File Buffer Overflow vulnerability in Microsoft products

Buffer overflow in the Windows Media Format Runtime in Microsoft Windows Media Player (WMP) 6.4 and Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.

6.8
2006-12-13 CVE-2006-2386 Microsoft Remote Code Execution vulnerability in Microsoft Outlook Express Windows Address Book Contact Record

Unspecified vulnerability in Microsoft Outlook Express 6 and earlier allows remote attackers to execute arbitrary code via a crafted contact record in a Windows Address Book (WAB) file.

6.8
2006-12-12 CVE-2006-6485 Shopsite Cross-Site Scripting vulnerability in Shopsite 8.1

Multiple cross-site scripting (XSS) vulnerabilities in ShopSite 8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the prevlocation parameter in shopper/sc/registration.cgi and other unspecified vectors.

6.8
2006-12-12 CVE-2006-6479 Scriptphp Input Validation vulnerability in Scriptphp Annoncescripthp 2.0

Multiple cross-site scripting (XSS) vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the email parameter in (1) erreurinscription.php, (2) Templates/admin.dwt.php, (3) Templates/commun.dwt.php, (4) membre.dwt.php, and (5) admin/admin_config/Aide.php.

6.8
2006-12-11 CVE-2006-6466 Wikyblog Cross-Site Scripting vulnerability in WikyBlog

Multiple cross-site scripting (XSS) vulnerabilities in WBmap.php in WikyBlog 1.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) key, (2) d, (3) l, or (4) v parameter.

6.8
2006-12-11 CVE-2006-6459 Phpbb HTML Injection vulnerability in PHPbb Toplist 1.3.7

Cross-site scripting (XSS) vulnerability in toplist.php in PhpBB Toplist 1.3.7 allows remote attackers to inject arbitrary HTML or web script via the (1) Name and (2) Information fields when adding a new site (toplistnew action).

6.8
2006-12-15 CVE-2006-6563 Proftpd Project Local Buffer Overflow vulnerability in Proftpd Project Proftpd 1.3.0/1.3.0A

Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1.3.1rc1 allows local users to execute arbitrary code via a large reqarglen length value.

6.6
2006-12-13 CVE-2006-6496 Broadcom Unspecified vulnerability in Broadcom Etrust Antivirus and Internet Security Suite

The (1) VetMONNT.sys and (2) VetFDDNT.sys drivers in CA Anti-Virus 2007 8.1, Anti-Virus for Vista Beta 8.2, and CA Internet Security Suite 2007 v3.0 do not properly handle NULL buffers, which allows local users with administrative access to cause a denial of service (system crash) via certain IOCTLs.

6.6
2006-12-13 CVE-2006-6495 SUN Local vulnerability in Sun Solaris LD.SO

Stack-based buffer overflow in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via large precision padding values in a format string specifier in the format parameter of the doprf function.

6.6
2006-12-13 CVE-2006-6494 SUN Local vulnerability in Sun Solaris LD.SO

Directory traversal vulnerability in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via a ..

6.6
2006-12-15 CVE-2006-6604 Torrentflux Directory Traversal vulnerability in Torrentflux 2.2

Directory traversal vulnerability in downloaddetails.php in TorrentFlux 2.2 allows remote authenticated users to read arbitrary files via ..

6.5
2006-12-15 CVE-2006-6598 Torrentflux Directory Traversal vulnerability in Torrentflux and Torrentflux-B4Rt

Directory traversal vulnerability in viewnfo.php in (1) TorrentFlux before 2.2 and (2) torrentflux-b4rt before 2.1-b4rt-972 allows remote authenticated users to read arbitrary files via ..

6.5
2006-12-15 CVE-2006-6572 Citrix Multiple vulnerability in Citrix Access Gateway Advanced Access Control

Unspecified vulnerability in Citrix Advanced Access Control (AAC) Option 4.0, and Access Gateway 4.2 with Advanced Access Control 4.2, before 20061114, when the Browser-Only access feature is enabled, allows remote authenticated users to bypass access policies via a certain login method, a different issue than CVE-2006-4846.

6.5
2006-12-15 CVE-2006-6585 Mozilla Remote Security vulnerability in Mozilla Firefox 2.0/3.0

The Extensions manager in Mozilla Firefox 2.0 does not properly populate the list of local extensions, which allows attackers to construct an extension that hides itself by finding its name in the list and then calling RemoveElement, as demonstrated by the FFsniFF extension.

6.4
2006-12-15 CVE-2006-6580 Scriptphp Authentication Bypass vulnerability in Scriptphp Pronews 1.5

admin/change.php in ProNews 1.5 does not check whether a user is permitted to change news items, which allows remote attackers to add or delete information within an item, and possibly have other impacts.

6.4
2006-12-15 CVE-2006-6600 Torrentflux Cross-Site Scripting vulnerability in TorrentFlux

Cross-site scripting (XSS) vulnerability in dir.php in TorrentFlux 2.2, when allows remote attackers to inject arbitrary web script or HTML via double URL-encoded strings in the dir parameter, a related issue to CVE-2006-5609.

6.0
2006-12-15 CVE-2006-6599 Torrentflux Remote Command Execution vulnerability in Torrentflux 2.2

maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters (";" semicolon) in the announce parameter.

6.0
2006-12-15 CVE-2006-6573 Citrix Information Disclosure vulnerability in Citrix Access Gateway

Unspecified vulnerability in Citrix Access Gateway 4.5 Advanced Edition, and 4.2 with Advanced Access Control (AAC) 4.2, when deployed on the Access Gateway appliance 4.2 through 4.2.2 allows remote authenticated users to "gain access to data" and obtain sensitive information via unspecified vectors.

6.0
2006-12-14 CVE-2006-6508 Phpbb Group Cross-Site Request Forgery vulnerability in PHPbb Group PHPbb 2.0.21

Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.21 allows remote authenticated users to send unauthorized messages as an arbitrary user via unspecified vectors.

6.0
2006-12-11 CVE-2006-6469 Xerox Remote Security vulnerability in WorkCentre

Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not block the postgres port (5432/tcp), which has unknown impact and remote attack vectors, probably related to unauthorized connections to a PostgreSQL daemon.

5.8
2006-12-11 CVE-2006-6468 Xerox Remote Security vulnerability in WorkCentre

Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not check the Fully Qualified Domain Name (FQDN) during a "Validate Repository SSL Certificate" scan, which has unknown impact and attack vectors, possibly related to spoofed certificates.

5.8
2006-12-11 CVE-2006-6467 Xerox Remote Security vulnerability in WorkCentre

Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not properly restrict access to SMB file resources, which allows remote attackers to gain unspecified file or directory access via vectors related to (1) visibility of the SMB "Homes" share and (2) SMB file system browsing.

5.8
2006-12-13 CVE-2006-6493 Openldap Remote Security vulnerability in OpenLDAP

Buffer overflow in the krbv4_ldap_auth function in servers/slapd/kerberos.c in OpenLDAP 2.4.3 and earlier, when OpenLDAP is compiled with the --enable-kbind (Kerberos KBIND) option, allows remote attackers to execute arbitrary code via an LDAP bind request using the LDAP_AUTH_KRBV41 authentication method and long credential data.

5.1
2006-12-15 CVE-2006-6574 Mantis Information Disclosure vulnerability in Mantis Custom Fields

Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain sensitive information by reading the Change column, as demonstrated by the Change column of a custom field.

5.0
2006-12-14 CVE-2006-6558 Crob Remote Heap Buffer Overflow vulnerability in Crob FTP Server 3.6.1B.263

Crob FTP Server 3.6.1 b.263 allows remote attackers to cause a denial of service via a long series of "?A" sequences in the (1) LIST and possibly (2) NLST command.

5.0
2006-12-14 CVE-2006-6554 Kerio Denial-Of-Service vulnerability in Kerio Mailserver

Unspecified vulnerability in Kerio MailServer before 6.3.1 allows remote attackers to cause a denial of service (segmentation fault and service stop) via certain long LDAP queries, as demonstrated by vd_kms6.pm.

5.0
2006-12-12 CVE-2006-6484 Mailenable Remote Denial of Service vulnerability in MailEnable IMAP Service

The IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.34, Professional Edition 1.6 through 1.83, and Enterprise Edition 1.1 through 1.40 allows remote attackers to cause a denial of service (crash) via unspecified vectors that trigger a null pointer dereference, as addressed by the ME-10023 hotfix, and a different issue than CVE-2006-6423.

5.0
2006-12-12 CVE-2006-6482 Adobe Input Validation vulnerability in Adobe Coldfusion 7.0

Adobe ColdFusion MX7 allows remote attackers to obtain sensitive information via a URL request (1) for a non-existent (a) JWS, (b) CFM, (c) CFML, or (d) CFC file, which displays the installation path in the resulting error message; or (2) to /CFIDE/administrator/login.cfm without a host, which can reveal the server's internal IP address in an HREF tag.

5.0
2006-12-12 CVE-2006-6481 Clam Anti Virus Denial Of Service vulnerability in Clam Anti-Virus Clamav 0.88.6

Clam AntiVirus (ClamAV) 0.88.6 allows remote attackers to cause a denial of service (stack overflow and application crash) by wrapping many layers of multipart/mixed content around a document, a different vulnerability than CVE-2006-5874 and CVE-2006-6406.

5.0
2006-12-12 CVE-2006-6480 Scriptphp Input Validation vulnerability in Scriptphp Annoncescripthp 2.0

admin/admin_membre/fiche_membre.php in AnnonceScriptHP 2.0 allows remote attackers to obtain sensitive information via the idmembre parameter, which discloses the passwords for arbitrary users.

5.0
2006-12-11 CVE-2006-6457 Tiki Information Exposure vulnerability in Tiki Tikiwiki Cms/Groupware 1.9.2/1.9.5

tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message.

5.0
2006-12-14 CVE-2006-6474 Mcafee Remote Code Execution vulnerability in McAfee VirusScan For Linux Insecure DT_RPATH

Untrusted search path vulnerability in McAfee VirusScan for Linux 4510e and earlier includes the current working directory in the DT_RPATH environment variable, which allows local users to load arbitrary ELF DSO libraries and execute arbitrary code by installing malicious libraries in that directory.

4.6
2006-12-14 CVE-2006-5649 Ubuntu Multiple vulnerability in Linux Kernel

Unspecified vulnerability in the "alignment check exception handling" in Ubuntu 5.10, 6.06 LTS, and 6.10 for the PowerPC (PPC) allows local users to cause a denial of service (kernel panic) via unspecified vectors.

4.6
2006-12-14 CVE-2006-5648 Ubuntu Local Denial of Service vulnerability in Ubuntu Linux 6.10

Ubuntu Linux 6.10 for the PowerPC (PPC) allows local users to cause a denial of service (resource consumption) by using the (1) sys_get_robust_list and (2) sys_set_robust_list functions to create processes that cannot be killed.

4.6
2006-12-15 CVE-2006-6579 Microsoft Unspecified vulnerability in Microsoft products

Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WINDIR%\pchealth\ERRORREP\QHEADLES, which allows local users to write and read files in this folder, as demonstrated by an ASP shell that has write access by IWAM_machine and read access by IUSR_Machine.

4.4
2006-12-15 CVE-2006-6602 Microsoft Denial of Service vulnerability in Microsoft Windows Explorer and Windows XP

explorer.exe in Windows Explorer 6.00.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a crafted WMV file.

4.3
2006-12-15 CVE-2006-6601 Windows
Microsoft
Resource Management Errors vulnerability in multiple products

Windows Media Player 10.00.00.4036 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a .MID (MIDI) file with a malformed header chunk without any track chunks, possibly involving (1) number of tracks of (2) time division fields that are set to 0.

4.3
2006-12-15 CVE-2006-6105 Gnome Local Format String vulnerability in GNOME Display Manager GDMChooser

Format string vulnerability in the host chooser window (gdmchooser) in GNOME Foundation Display Manager (gdm) allows local users to execute arbitrary code via format string specifiers in a hostname, which are used in an error dialog.

4.3
2006-12-14 CVE-2006-6547 Mlipod Remote Denial-of-Service vulnerability in Winamp iPod Plugin Audio Book File Handling

Buffer overflow in the readAA function in read_aa.cpp in Winamp iPod Plugin (ml_ipod) 2.00 p19 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long tag in an audible.com audiobook (aa) file.

4.3
2006-12-14 CVE-2006-6534 Oscommerce Input Validation vulnerability in Oscommerce 3.0A3

Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 3.0a3 allow remote attackers to inject arbitrary web script or HTML via the (1) set parameter to admin/modules.php, the (2) selected_box parameter to definitiva/admin/customers.php, the (3) lID parameter to admin/languages_definitions.php, or the (4) pID parameter to admin/products.php.

4.3
2006-12-12 CVE-2006-5577 Microsoft Information Disclosure vulnerability in Microsoft Internet Explorer Object Tag TIF Folder

Microsoft Internet Explorer 6 and earlier allows remote attackers to obtain sensitive information via unspecified uses of the OBJECT HTML tag, which discloses the absolute path of the corresponding TIF folder, aka "TIF Folder Information Disclosure Vulnerability," and a different issue than CVE-2006-5578.

4.3
2006-12-14 CVE-2006-6509 Sitekiosk Unspecified vulnerability in Sitekiosk

Cross-site scripting (XSS) vulnerability in the skinning feature in SiteKiosk before 6.5.150 allows local users to bypass security protections and inject arbitrary web script or HTML via an ABOUT: URI, which is displayed in the title bar of the browser.

4.1
2006-12-11 CVE-2006-5871 Linux Multiple vulnerability in Linux Kernel 2.4.33/2.6.8

smbfs in Linux kernel 2.6.8 and other versions, and 2.4.x before 2.4.34, when UNIX extensions are enabled, ignores certain mount options, which could cause clients to use server-specified uid, gid and mode settings.

4.1
2006-12-15 CVE-2006-6565 Filezilla Project Null Pointer Dereference vulnerability in Filezilla-Project Filezilla Server 0.9.21/0.9.6

FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST commands, which results in a NULL pointer dereference, a different set of vectors than CVE-2006-6564.

4.0
2006-12-15 CVE-2006-6564 Filezilla Denial-Of-Service vulnerability in FileZilla

FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a malformed argument to the STOR command, which results in a NULL pointer dereference.

4.0

8 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2006-12-14 CVE-2006-6548 Cpanel Cross-Site Scripting vulnerability in Cpanel Webhost Manager 3.1.0

Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the domain parameter to (1) scripts2/changeemail, (2) scripts2/limitbw, or (3) scripts/rearrangeacct.

3.5
2006-12-14 CVE-2006-6514 Flippet ORG Remote vulnerability in Winamp Web Interface

Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target directory, as demonstrated by accessing C:\folder2 when the root directory is C:\folder.

3.5
2006-12-14 CVE-2006-6513 Flippet ORG Remote vulnerability in Winamp Web Interface 7.5.11/7.5.9

The CControl::Download function (/dl URI) in Winamp Web Interface (Wawi) 7.5.13 and earlier allows remote authenticated users to download arbitrary file types under the root via a trailing "." (dot) in a filename in the file parameter, related to erroneous behavior of the IsWinampFile function.

3.5
2006-12-14 CVE-2006-6512 Flippet ORG Directory Traversal vulnerability in Winamp Web Interface

Directory traversal vulnerability in the Browse function (/browse URI) in Winamp Web Interface (Wawi) 7.5.13 and earlier allows remote authenticated users to list arbitrary directories via URL encoded backslashes ("%2F") in the path parameter.

3.5
2006-12-12 CVE-2006-6483 Adobe Cross-Site Scripting vulnerability in ColdFusion MX

Adobe ColdFusion MX 7.x before 7.0.2 does not properly filter HTML tags when protecting against cross-site scripting (XSS) attacks, which allows remote attackers to inject arbitrary web script or HTML via a NULL byte (%00) in certain HTML tags, as demonstrated using "%00script" in a tag.

2.6
2006-12-12 CVE-2006-5578 Microsoft Information Disclosure vulnerability in Microsoft Internet Explorer Drag and Drop TIF Folder

Microsoft Internet Explorer 6 and earlier allows remote attackers to read Temporary Internet Files (TIF) and obtain sensitive information via unspecified vectors involving certain drag and drop operations, aka "TIF Folder Information Disclosure Vulnerability," and a different issue than CVE-2006-5577.

2.6
2006-12-14 CVE-2006-6510 Sitekiosk Unspecified vulnerability in Sitekiosk

An unspecified ActiveX control in SiteKiosk before 6.5.150 is installed "safe for scripting", which allows local users to bypass security protections and read arbitrary files via certain functions.

1.7
2006-12-14 CVE-2006-6107 D BUS Local Denial of Service vulnerability in D-Bus Signals.C

Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).

1.7