CSV
184,638 results for "vulnerability" Page 220
CVE-2006-1047

Unspecified vulnerability in the "Remember Me login functionality" in Joomla! 1.0.7 and earlier has unknown impact and attack vectors.

Mar 7, 2006 8 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2006-1123

SQL injection vulnerability in D2KBlog 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the memName parameter in a cookie.

Mar 9, 2006 4 affected product(s) NVD
10.0
CVSS
2.0%
EPSS
⚡ 40.6
CVE-2006-1069

Unspecified vulnerability in the session handling for Geeklog 1.4.x before 1.4.0sr2, 1.3.11 before 1.3.11sr5, 1.3.9 before 1.3.9sr5, and possibly earlier versions allows attackers to gain privileges as arbitrary users via unknown vectors.

Mar 7, 2006 12 affected product(s) NVD
10.0
CVSS
1.6%
EPSS
⚡ 40.5
CVE-2006-1032

Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, exoops, and possibly other programs, allows remote attackers to execute arbitrary PHP code via the base64 tag.

Mar 7, 2006 3 affected product(s) NVD
7.5
CVSS
3.6%
EPSS
⚡ 31.1
CVE-2006-1075

Format string vulnerability in the visualization function in Jason Boettcher Liero Xtreme 0.62b and earlier allows remote attackers to execute arbitrary code via format string specifiers in (1) a nickname, (2) a dedicated server name, or (3) a mapname in a level (aka .lxl) file.

Mar 9, 2006 2 affected product(s) NVD
7.5
CVSS
3.8%
EPSS
⚡ 31.1
CVE-2006-1035

Unspecified vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers to access diagnostics tests via unknown attack vectors.

Mar 7, 2006 13 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2006-1094

SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) database.php.

Mar 9, 2006 14 affected product(s) NVD
7.5
CVSS
2.4%
EPSS
⚡ 30.7
CVE-2006-1099

PHP remote file include vulnerability in logIT 1.3 and 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Mar 9, 2006 2 affected product(s) NVD
7.5
CVSS
2.3%
EPSS
⚡ 30.7
CVE-2006-1037

SQL injection vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

Mar 7, 2006 13 affected product(s) NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.5
CVE-2006-1081

SQL injection vulnerability in forgotten_password.php in Jonathan Beckett PluggedOut Nexus 0.1 allows remote attackers to execute arbitrary SQL commands via the email parameter.

Mar 9, 2006 1 affected product(s) NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.5
CVE-2006-1051

SQL injection vulnerability in Akarru Social BookMarking Engine before 0.4.3.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors, possibly involving the username parameter to akarru.lib/users.php.

Mar 7, 2006 2 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2006-1108

SQL injection vulnerability in news.php in NMDeluxe before 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

Mar 9, 2006 1 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2006-1109

SQL injection vulnerability in index.asp in Total Ecommerce 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it is not clear whether this report is associated with a specific product. If not, then it should not be included in CVE.

Mar 9, 2006 1 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2006-1076

SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execute arbitrary SQL commands via the st parameter.

Mar 9, 2006 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2006-1095

Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie.

Mar 9, 2006 1 affected product(s) NVD
7.2
CVSS
0.9%
EPSS
⚡ 29.1
CVE-2006-1121

Cross-site scripting (XSS) vulnerability in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the query string to index.php.

Mar 9, 2006 1 affected product(s) NVD
6.8
CVSS
2.1%
EPSS
⚡ 27.8
CVE-2006-1122

Cross-site scripting (XSS) vulnerability in Default.asp in D2KBlog 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

Mar 9, 2006 4 affected product(s) NVD
6.8
CVSS
1.6%
EPSS
⚡ 27.7
CVE-2006-1128

Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote attackers to access and delete files by specifying the session in a cookie, which is used in constructing file paths before the session value is sanitized.

Mar 9, 2006 11 affected product(s) NVD
6.4
CVSS
3.9%
EPSS
⚡ 26.8
CVE-2006-1073

Directory traversal vulnerability in index.php in Daverave Simplog 1.0.2 and earlier allows remote attackers to include or read arbitrary .txt files via the (1) act and (2) blogid parameters.

Mar 8, 2006 1 affected product(s) NVD
6.4
CVSS
3.1%
EPSS
⚡ 26.5
CVE-2006-1087

Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the option_new[compatibility_mode] parameter, which is not filtered before being stored in config.php. NOTE: this vulnerability can be exploited by remote unauthenticated attackers in conjunction with the option[admin_pass] authentication bypass vulnerability.

Mar 9, 2006 1 affected product(s) NVD
6.5
CVSS
1.7%
EPSS
⚡ 26.5
← Previous Page 220 of 9232 Next →