CSV
184,340 results for "vulnerability" Page 206
CVE-2006-0435

Unspecified vulnerability in Oracle PL/SQL (PLSQL), as used in Database Server DS 9.2.0.7 and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0.0, E-Business Suite and Applications 11.5.10, and Collaboration Suite 10.1.1, 10.1.2.0, 10.1.2.1, and 9.0.4.2, allows attackers to bypass the PLSQLExclusion list and access excluded packages and procedures, aka Vuln# PLSQL01.

Jan 26, 2006 40 affected product(s) NVD
7.5
CVSS
6.8%
EPSS
⚡ 32.1
CVE-2006-0418

Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a crafted username.

Jan 25, 2006 2 affected product(s) NVD
7.5
CVSS
3.7%
EPSS
⚡ 31.1
CVE-2006-0428

Unspecified vulnerability in BEA WebLogic Portal 8.1 SP3 through SP5, when using Web Services Remote Portlets (WSRP), allows remote attackers to access restricted web resources via crafted URLs.

Jan 25, 2006 3 affected product(s) NVD
7.5
CVSS
2.9%
EPSS
⚡ 30.9
CVE-2006-0478

CRE Loaded 6.15 allows remote attackers to perform privileged actions, including uploading and creating arbitrary files, via a direct request to files.php. NOTE: the vendor states "The initial announcement of this risk was made on our website... and it included a patch which will close the vulnerability on all known 6.0x and 6.1x releases. We strongly encourage users of CRE Loaded 6.x, osCMax, and other users of osCommerce who have installed HTMLArea based WYSIWYG editors and Admin Access with Levels to modify thier installations at the earliest possible moment."

Jan 31, 2006 1 affected product(s) NVD
7.5
CVSS
3.1%
EPSS
⚡ 30.9
CVE-2006-0417

SQL injection vulnerability in login.php in miniBloggie 1.0 and earlier, when gpc_magic_quotes is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameters.

Jan 25, 2006 1 affected product(s) NVD
7.5
CVSS
2.0%
EPSS
⚡ 30.6
CVE-2006-0462

SQL injection vulnerability in comentarios.php in AndoNET Blog 2004.09.02 allows remote attackers to execute arbitrary SQL commands via the entrada parameter.

Jan 27, 2006 1 affected product(s) NVD
7.5
CVSS
2.1%
EPSS
⚡ 30.6
CVE-2006-0402

SQL injection vulnerability in Zoph before 0.5pre1 allows remote attackers to execute arbitrary SQL commands.

Jan 25, 2006 2 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.4
CVE-2006-0412

SQL injection vulnerability in CyberShop allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action.

Jan 25, 2006 1 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.4
CVE-2006-0436

Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown attack vectors.

Jan 26, 2006 3 affected product(s) NVD
7.2
CVSS
0.5%
EPSS
⚡ 28.9
CVE-2006-0444

SQL injection vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.1 allows remote attackers to execute arbitrary SQL commands via the (1) par parameter in the post function on the forum page and possibly the (2) poll_id parameter on the poll page. NOTE: the poll_id vector can also allow resultant cross-site scripting (XSS) from an unquoted error message for invalid SQL syntax.

Jan 26, 2006 1 affected product(s) NVD
6.8
CVSS
3.0%
EPSS
⚡ 28.1
CVE-2006-0446

Unspecified vulnerability in WeBWorK 2.1.3 and 2.2-pre1 allows remote privileged attackers to execute arbitrary commands as the web server via unknown attack vectors.

Jan 27, 2006 2 affected product(s) NVD
6.5
CVSS
3.2%
EPSS
⚡ 26.9
CVE-2006-0367

Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote authenticated users with read-only administrative privileges to obtain full administrative privileges via a "crafted URL on the CCMAdmin web page."

Jan 22, 2006 18 affected product(s) NVD
6.5
CVSS
2.2%
EPSS
⚡ 26.7
CVE-2006-0371

Directory traversal vulnerability in index.php in Noah Medling RCBlog 1.03 allows remote attackers to read arbitrary .txt files, possibly including one that stores the administrator's account name and password, via a .. (dot dot) in the post parameter.

Jan 22, 2006 1 affected product(s) NVD
5.0
CVSS
2.9%
EPSS
⚡ 20.9
CVE-2006-0410

SQL injection vulnerability in ADOdb before 4.71, when using PostgreSQL, allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors involving binary strings.

Jan 25, 2006 3 affected product(s) NVD
5.0
CVSS
2.9%
EPSS
⚡ 20.9
CVE-2006-0467

Unspecified vulnerability in Pioneers (formerly gnocatan) before 0.9.49 allows remote attackers to cause a denial of service (application crash) via long chat messages.

Jan 31, 2006 1 affected product(s) NVD
5.0
CVSS
2.8%
EPSS
⚡ 20.8
CVE-2006-0434

Directory traversal vulnerability in action.php in phpXplorer allows remote attackers to read arbitrary files via ".." (dot dot) sequences and null bytes in the sAction parameter, a different vulnerability than CVE-2006-0244. NOTE: if the functionality of phpXplorer supports the upload of PHP files, then this issue would not cross privilege boundaries and would not be a vulnerability.

Jan 26, 2006 1 affected product(s) NVD
5.0
CVSS
1.8%
EPSS
⚡ 20.5
CVE-2006-0449

Early termination vulnerability in the IMAP service in E-Post Mail 4.05 and SPA-PRO Mail 4.05 allows remote attackers to cause a denial of service (infinite loop) by sending an APPEND command and disconnecting before the expected amount of data is sent.

Jan 27, 2006 2 affected product(s) NVD
5.0
CVSS
1.8%
EPSS
⚡ 20.5
CVE-2006-0440

Text Rider 2.4 allows attackers to bypass authentication and upload files without providing a valid password by obtaining the MD5 hash of the password (possibly via another vulnerability that reads it from a data file), then including the hash in a cookie.

Jan 26, 2006 1 affected product(s) NVD
5.0
CVSS
1.4%
EPSS
⚡ 20.4
CVE-2006-0407

Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter. NOTE: the original disclosure specified the name parameter, but a correction was later provided. NOTE: followup posts have both disputed and confirmed the original claim.

Jan 25, 2006 16 affected product(s) NVD
4.3
CVSS
2.6%
EPSS
⚡ 18
CVE-2006-0473

Cross-site scripting (XSS) vulnerability in the bbcode function in weblog.php in my little homepage my little weblog, as last modified in April 2004, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags.

Jan 31, 2006 1 affected product(s) NVD
4.3
CVSS
2.6%
EPSS
⚡ 18
← Previous Page 206 of 9217 Next →