CSV
184,638 results for "vulnerability" Page 219
CVE-2006-1047

Unspecified vulnerability in the "Remember Me login functionality" in Joomla! 1.0.7 and earlier has unknown impact and attack vectors.

Mar 7, 2006 8 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2006-1069

Unspecified vulnerability in the session handling for Geeklog 1.4.x before 1.4.0sr2, 1.3.11 before 1.3.11sr5, 1.3.9 before 1.3.9sr5, and possibly earlier versions allows attackers to gain privileges as arbitrary users via unknown vectors.

Mar 7, 2006 12 affected product(s) NVD
10.0
CVSS
1.6%
EPSS
⚡ 40.5
CVE-2006-1032

Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, exoops, and possibly other programs, allows remote attackers to execute arbitrary PHP code via the base64 tag.

Mar 7, 2006 3 affected product(s) NVD
7.5
CVSS
3.6%
EPSS
⚡ 31.1
CVE-2006-1075

Format string vulnerability in the visualization function in Jason Boettcher Liero Xtreme 0.62b and earlier allows remote attackers to execute arbitrary code via format string specifiers in (1) a nickname, (2) a dedicated server name, or (3) a mapname in a level (aka .lxl) file.

Mar 9, 2006 2 affected product(s) NVD
7.5
CVSS
3.8%
EPSS
⚡ 31.1
CVE-2006-1012

SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execute arbitrary SQL commands via the User-Agent field in an HTTP header for a comment.

Mar 6, 2006 1 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2006-1013

PHP remote file include vulnerability in index.php in SMartBlog (aka SMBlog) 1.2 allows remote attackers to include and execute arbitrary PHP files via (1) the pg parameter and (2) a query string without a parameter.

Mar 7, 2006 1 affected product(s) NVD
7.5
CVSS
2.6%
EPSS
⚡ 30.8
CVE-2006-1035

Unspecified vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers to access diagnostics tests via unknown attack vectors.

Mar 7, 2006 13 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2006-1037

SQL injection vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

Mar 7, 2006 13 affected product(s) NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.5
CVE-2006-1081

SQL injection vulnerability in forgotten_password.php in Jonathan Beckett PluggedOut Nexus 0.1 allows remote attackers to execute arbitrary SQL commands via the email parameter.

Mar 9, 2006 1 affected product(s) NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.5
CVE-2006-1020

SQL injection vulnerability in forumlib.php in Johnny_Vegas Vegas Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the postid parameter.

Mar 7, 2006 1 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2006-1024

SQL injection vulnerability in MgrLogin.asp in Addsoft StoreBot 2005 Professional allows remote attackers to execute arbitrary SQL commands via the Pwd parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Mar 7, 2006 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2006-1051

SQL injection vulnerability in Akarru Social BookMarking Engine before 0.4.3.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors, possibly involving the username parameter to akarru.lib/users.php.

Mar 7, 2006 2 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2006-1018

SQL injection vulnerability in poems.php in DCI-Designs Dawaween 1.03 allows remote attackers to execute arbitrary SQL commands via the id parameter in a diwan view action.

Mar 7, 2006 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2006-1076

SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execute arbitrary SQL commands via the st parameter.

Mar 9, 2006 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2006-1015

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

Mar 7, 2006 75 affected product(s) NVD
6.4
CVSS
12.4%
EPSS
⚡ 29.3
CVE-2006-0387

Stack-based buffer overflow in Safari in Mac OS X 10.4.5 and earlier, and 10.3.9 and earlier, allows remote attackers to execute arbitrary code via unspecified vectors involving a web page with crafted JavaScript, a different vulnerability than CVE-2005-4504.

Mar 6, 2006 32 affected product(s) NVD
6.4
CVSS
7.8%
EPSS
⚡ 27.9
CVE-2006-1025

Cross-site scripting (XSS) vulnerability in manage.asp in Addsoft StoreBot 2002 Standard allows remote attackers to inject arbitrary web script or HTML via the ShipMethod parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Mar 7, 2006 1 affected product(s) NVD
6.8
CVSS
1.5%
EPSS
⚡ 27.6
CVE-2006-1073

Directory traversal vulnerability in index.php in Daverave Simplog 1.0.2 and earlier allows remote attackers to include or read arbitrary .txt files via the (1) act and (2) blogid parameters.

Mar 8, 2006 1 affected product(s) NVD
6.4
CVSS
3.1%
EPSS
⚡ 26.5
CVE-2006-1087

Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the option_new[compatibility_mode] parameter, which is not filtered before being stored in config.php. NOTE: this vulnerability can be exploited by remote unauthenticated attackers in conjunction with the option[admin_pass] authentication bypass vulnerability.

Mar 9, 2006 1 affected product(s) NVD
6.5
CVSS
1.7%
EPSS
⚡ 26.5
CVE-2006-1023

Directory traversal vulnerability in HP System Management Homepage (SMH) 2.0.0 through 2.1.4 on Windows allows remote attackers to access certain files via unspecified vectors.

Mar 7, 2006 2 affected product(s) NVD
5.0
CVSS
5.2%
EPSS
⚡ 21.5
← Previous Page 219 of 9232 Next →