<?xml version="1.0" encoding="UTF-8"?>
<nvd nvd_xml_version="1.2" pub_date="2008-09-05" xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd"><!--This XML file has been upgraded to support CVSS version 2.  The following new attributes have been added to CVS entries:
* CVSS_version - Indicates the version of the CVSS data
* CVSS_base_score - The CVSSv2 base score
* CVSS_impact_subscore - The CVSSv2 impact sub-score
* CVSS_exploit_subscore - the CVSSv2 exploit sub-score

The following attributes have been mapped to new content in CVS entries:
* CVSS_score - This attribute is the same as the CVSS_base_score and is now deprecated.
* CVSS_vector - Contains the new CVSSv2 vector string--><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2005-08-03" modified="2007-06-26" name="CVE-2006-0001" published="2006-09-12" seq="2006-0001" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/445824/100/0/threaded">20060912 Computer Terrorism (UK) :: Incident Response Centre - Microsoft Publisher Font Parsing Vulnerability</ref><ref adv="1" patch="1" source="" url="http://www.computerterrorism.com/research/ct12-09-2006-2.htm">Security Advisory : CT12-09-2006-2</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS06-054.mspx">MS06-054</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/19951">19951</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3565">ADV-2006-3565</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/21863">21863</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-255A.html">TA06-255A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/406236">VU#406236</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016825">1016825</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/28648">publisher-pub-code-execution(28648)</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446630/100/100/threaded">HPSBST02134</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:590">oval:org.mitre.oval:def:590</ref><ref source="SREASON" url="http://securityreason.com/securityalert/1548">1548</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP1"/><vers num="2003 SP2"/></prod><prod name="Publisher" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-05" name="CVE-2006-0002" published="2006-01-10" seq="2006-0002" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-003.mspx">MS06-003</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/252146">VU#252146</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16197">16197</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0119">ADV-2006-0119</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18368">18368</ref><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421520/100/0/threaded">20060110 Microsoft Outlook Critical Vulnerability</ref><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421518/100/0/threaded">20060110 Microsoft Exchange Critical Vulnerability</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-010A.html">TA06-010A</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015461">1015461</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015460">1015460</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1082">oval:org.mitre.oval:def:1082</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1165">oval:org.mitre.oval:def:1165</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1316">oval:org.mitre.oval:def:1316</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1456">oval:org.mitre.oval:def:1456</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1485">oval:org.mitre.oval:def:1485</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:624">oval:org.mitre.oval:def:624</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/22878">
win-tnef-overflow(22878)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/330">330</ref><ref source="SREASON" url="http://securityreason.com/securityalert/331">331</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="2000 SP3"/><vers num="5.5 SP4"/><vers num="5.5 SP3"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/><vers num="5.0 SP2"/><vers num="5.0 SP1"/><vers num="5.0"/></prod><prod name="Office" vendor="Microsoft"><vers num="XP SP3"/><vers num="2003 SP2"/><vers num="2003 SP1"/><vers num="2000 SP3"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="2003"/><vers num="2002 SP3"/><vers num="2000 SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-13" name="CVE-2006-0003" published="2006-04-11" seq="2006-0003" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.</descript></desc><sols><sol source="nvd">http://www.microsoft.com/technet/security/Bulletin/MS06-014.mspx</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-014.mspx">MS06-014</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html">TA06-101A</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/234812">VU#234812</ref><ref source="BID" url="http://www.securityfocus.com/bid/17462">17462</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1319">ADV-2006-1319</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19583">19583</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015894">1015894</ref><ref source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/01-e.html"></ref><ref source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/index-e.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2452">ADV-2006-2452</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20719">20719</ref><ref source="OSVDB" url="http://www.osvdb.org/24517">24517</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1204">oval:org.mitre.oval:def:1204</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1323">oval:org.mitre.oval:def:1323</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1511">oval:org.mitre.oval:def:1511</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1742">oval:org.mitre.oval:def:1742</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1778">oval:org.mitre.oval:def:1778</ref><ref source="" url="http://www.securityfocus.com/data/vulnerabilities/exploits/0day_ie.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/20797">
20797</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25006">
mdac-rdsdataspace-execute-code(25006)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/29915">
ie-wscriptshell-command-execution(29915)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/475104/100/100/threaded">20070729 Exploit In Internet Explorer</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/475118/100/100/threaded">20070730 RE: Exploit In Internet Explorer</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/475108/100/100/threaded">20070730 Re: Exploit In Internet Explorer</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/475490/100/100/threaded">20070731 Re: Exploit In Internet Explorer</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/2052">2052</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/2164">2164</ref></refs><vuln_soft><prod name="MDAC" vendor="Microsoft"><vers num="2.8"/><vers num="2.7 SP1"/><vers num="2.7"/><vers num="2.5 SP3"/><vers num="2.8 SP2"/><vers num="2.8 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0004" published="2006-02-14" seq="2006-0004" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-010.mspx">MS06-010</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/963628">VU#963628</ref><ref source="BID" url="http://www.securityfocus.com/bid/16634">16634</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0579">ADV-2006-0579</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015632">1015632</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18865">18865</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24490">powerpoint-tiff-information-disclosure(24490)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1555">oval:org.mitre.oval:def:1555</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2006-0005" published="2006-02-14" seq="2006-0005" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-006.mspx">MS06-006</ref><ref source="IDEFENSE" url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=393">20060214 Microsoft Windows Media Player Plugin Buffer Overflow Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/692060">VU#692060</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-045A.html">TA06-045A</ref><ref source="BID" url="http://www.securityfocus.com/bid/16644">16644</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0575">ADV-2006-0575</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015628">1015628</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18852">18852</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24493">win-mediaplayer-plugin-embed-bo(24493)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1559">oval:org.mitre.oval:def:1559</ref></refs><vuln_soft><prod name="Windows 2000 Advanced Server" vendor="Microsoft"><vers num="SP1"/><vers num="SP2"/><vers num="SP3"/><vers num="SP4"/><vers num="unknown"/></prod><prod name="windows-nt" vendor="Microsoft"><vers edition="SP1" num="XP_tablet_PC"/><vers edition="SP2" num="XP_tablet_PC"/><vers edition="unknown" num="XP_tablet_PC"/><vers edition="unknown" num="XP"/><vers edition="sp1" num="XP"/><vers edition="sp2" num="XP"/><vers edition="unknown" num="XP"/><vers edition="sp1" num="XP"/><vers edition="sp2" num="XP"/><vers edition="unknown" num="XP"/><vers edition="unknown" num="XP"/><vers edition="sp1" num="XP"/><vers edition="sp2" num="XP"/><vers edition="unknown" num="XP"/><vers edition="unknown" num="XP"/><vers edition="unknown" num="2000"/><vers edition="sp1" num="2000"/><vers edition="sp2" num="2000"/><vers edition="sp3" num="2000"/><vers edition="sp4" num="2000"/><vers edition="SP4" num="Datacenter Server"/><vers edition="SP3" num="Datacenter Server"/><vers edition="SP2" num="Datacenter Server"/><vers edition="SP1" num="Datacenter Server"/><vers edition="unknown" num="Datacenter Server"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Datacenter Edition"/><vers num="Datacenter Edition 64-bit"/><vers num="Datacenter SP1"/><vers num="Enterprise Edition"/><vers num="Enterprise Edition 64-bit"/><vers num="Enterprise SP1"/><vers num="Standard"/><vers num="Standard 64-bit"/><vers num="Standard SP1"/><vers num="Web Edition"/><vers num="Web Edition SP1"/></prod><prod name="Windows Server 2000" vendor="Microsoft"><vers num="none"/><vers num="SP1"/><vers num="SP2"/><vers num="SP3"/><vers num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-04-01" name="CVE-2006-0006" published="2006-02-14" seq="2006-0006" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-045A.html">TA06-045A</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/291396">VU#291396</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-005.mspx">MS06-005</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424983/100/0/threaded">20060214 [EEYEB-20051017] Windows Media Player BMP Heap Overflow</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425158/100/0/threaded">20060215 Windows Media Player BMP Heap Overflow (MS06-005)</ref><ref adv="1" patch="1" source="" url="http://www.eeye.com/html/research/advisories/AD20060214.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16633">16633</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0574">ADV-2006-0574</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015627">1015627</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18835">18835</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24488">win-media-player-bmp-bo(24488)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1256">oval:org.mitre.oval:def:1256</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1578">oval:org.mitre.oval:def:1578</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1598">oval:org.mitre.oval:def:1598</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1661">oval:org.mitre.oval:def:1661</ref><ref source="SREASON" url="http://securityreason.com/securityalert/423">423</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="Gold"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers edition="FR" num="SP4"/><vers num="SP1"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP2"/><vers edition="Tablet PC" num="SP1"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows Media Player" vendor="Microsoft"><vers num="10"/><vers num="9"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0007" published="2006-07-11" seq="2006-0007" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in GIFIMP32.FLT, as used in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted GIF image that triggers memory corruption when it is parsed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-039.mspx">MS06-039</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/668564">VU#668564</ref><ref source="BID" url="http://www.securityfocus.com/bid/18915">18915</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2757">ADV-2006-2757</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21013">21013</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-192A.html">TA06-192A</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016470">1016470</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/439887/100/0/threaded">20060712 NSFOCUS SA2006-04 : Microsoft Office GIF Filter Buffer Overflow Vulnerability</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:21">oval:org.mitre.oval:def:21</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2006-q3/0005.html">
20060712 NSFOCUS SA2006-04 : Microsoft Office GIF Filter Buffer Overflow Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/27146">
27146</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2003 SP2"/><vers num="2003 SP1"/><vers num="2000 SP3"/><vers num="XP SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-0008" published="2006-02-14" seq="2006-0008" severity="High" type="CVE"><desc><descript source="cve">The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the &quot;shell about dialog box&quot; and clicking the &quot;End-User License Agreement&quot; link, which executes Notepad with the privileges of the program that displays the about box.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-009.mspx">MS06-009</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425141/100/0/threaded">20060215 Security advisory: Windows IME Vulnerability (MS06-009)</ref><ref adv="1" source="" url="http://www.ryanstyle.com/alert/my/5/ms06_009_eng.html"></ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/739844">VU#739844</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16643">16643</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0578">ADV-2006-0578</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015631">1015631</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18859">18859</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24492">win-korean-ime-privilege-elevation(24492)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1595">oval:org.mitre.oval:def:1595</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1650">oval:org.mitre.oval:def:1650</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1664">oval:org.mitre.oval:def:1664</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1688">oval:org.mitre.oval:def:1688</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:727">oval:org.mitre.oval:def:727</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Office" vendor="Microsoft"><vers num="2003 SP2"/><vers num="2003 SP1"/><vers edition="Student_Teacher" num="2003"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Standard 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1" num="Enterprise 64-bit"/><vers edition="SP1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="SP1" num="R2"/><vers edition="64-bit" num="R2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2006-0009" published="2006-03-14" seq="2006-0009" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E in attacks against PowerPoint.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx">MS06-012</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/682820">VU#682820</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015766">1015766</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19138">19138</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html">TA06-073A</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427671/100/0/threaded">20060314 SYMSA-2006-001: Buffer overflow in Microsoft Office 2000, Office XP (2002), and Office 2003 Routing Slip Metadata</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17000">17000</ref><ref source="" url="http://www.symantec.com/enterprise/research/SYMSA-2006-001.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0950">ADV-2006-0950</ref><ref source="OSVDB" url="http://www.osvdb.org/23903">23903</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25009">office-routing-slip-bo(25009)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19238">19238</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/443890/100/0/threaded">20060819 New PowerPoint 0-day and Trojan - FAQ document ready</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0597.html">20060822 Major updates in PowerPoint FAQ document - not a 0-day issue</ref><ref source="" url="http://isc.sans.org/diary.php?storyid=1618"></ref><ref source="" url="http://blogs.securiteam.com/?p=557"></ref><ref source="" url="http://blogs.securiteam.com/?p=559"></ref><ref source="" url="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FMDROPPER%2EBH"></ref><ref source="" url="http://www.darkreading.com/document.asp?doc_id=101970"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016720">1016720</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/444051/100/200/threaded">20060822 Major updates in PowerPoint FAQ document - not a 0-day issue</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049540.html">20060919 New PowerPoint 0-day Trojan in the wild</ref><ref source="" url="http://blogs.securiteam.com/?author=28"></ref><ref source="" url="http://www.symantec.com/security_response/writeup.jsp?docid=2006-091810-5028-99"></ref><ref source="BID" url="http://www.securityfocus.com/bid/20059">20059</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3678">ADV-2006-3678</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/29009">powerpoint-presentation-code-execution(29009)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/446425/100/0/threaded">20060919 Microsoft PowerPoint 0-day Vulnerability FAQ - September written</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/446370/100/0/threaded">20060919 New PowerPoint 0-day Trojan in the wild</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016886">1016886</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1504">oval:org.mitre.oval:def:1504</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1553">oval:org.mitre.oval:def:1553</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1653">oval:org.mitre.oval:def:1653</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:798">oval:org.mitre.oval:def:798</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432004/30/5340/threaded">20060422 PowerPoint Phishing Trojan</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP1"/><vers num="2003 SP2"/><vers edition="Mac" num="v. X"/><vers edition="Mac" num="2004"/></prod><prod name="Works Suite" vendor="Microsoft"><vers num="2006"/><vers num="2005"/><vers num="2004"/><vers num="2003"/><vers num="2002"/><vers num="2001"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-0010" published="2006-01-10" seq="2006-0010" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-002.mspx">MS06-002</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/915930">VU#915930</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16194">16194</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0118">ADV-2006-0118</ref><ref source="OSVDB" url="http://www.osvdb.org/18829">18829</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18365">18365</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-010A.html">TA06-010A</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015459">1015459</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/18391">18391</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18311">18311</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421885/100/0/threaded">20060110 [EEYEB-2000801] - Windows Embedded Open Type (EOT) Font Heap Overflow Vulnerability</ref><ref source="" url="http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=375525"></ref><ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/EEYEB20050801.html">EEYEB20050801</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1126">oval:org.mitre.oval:def:1126</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1185">oval:org.mitre.oval:def:1185</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1462">oval:org.mitre.oval:def:1462</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1491">oval:org.mitre.oval:def:1491</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:698">oval:org.mitre.oval:def:698</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:714">oval:org.mitre.oval:def:714</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23922">
win-embedded-fonts-bo(23922)</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="Gold"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/><vers num="Terminal Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0 alpha"/><vers num="Terminal Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="4.0 SP6a alpha"/><vers num="4.0 SP6a"/><vers num="4.0 SP6 alpha"/><vers num="4.0 SP6"/><vers num="4.0 SP5 alpha"/><vers num="4.0 SP5"/><vers num="4.0 SP4 alpha"/><vers num="4.0 SP4"/><vers num="4.0 SP3 alpha"/><vers num="4.0 SP3"/><vers num="4.0 SP2 alpha"/><vers num="4.0 SP2"/><vers num="4.0 SP1 alpha"/><vers num="4.0 SP1"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="3.5.1 SP5 alpha"/><vers num="3.5.1 SP5"/><vers num="3.5.1 SP4"/><vers num="3.5.1 SP3"/><vers num="3.5.1 SP2"/><vers num="3.5.1 SP1"/><vers num="3.5.1"/><vers num="3.5"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Standard 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1" num="Enterprise 64-bit"/><vers edition="SP1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="SP1" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-0012" published="2006-04-11" seq="2006-0012" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and &quot;crafted files and directories,&quot; aka the &quot;Windows Shell Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-015.mspx">MS06-015</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html">TA06-101A</ref><ref source="BID" url="http://www.securityfocus.com/bid/17464">17464</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1320">ADV-2006-1320</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19606">19606</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/641460">VU#641460</ref><ref source="OSVDB" url="http://www.osvdb.org/24516">24516</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015897">1015897</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25554">win-explorer-com-code-execution(25554)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1191">oval:org.mitre.oval:def:1191</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1448">oval:org.mitre.oval:def:1448</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1679">oval:org.mitre.oval:def:1679</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1743">oval:org.mitre.oval:def:1743</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1764">oval:org.mitre.oval:def:1764</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Standard 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1" num="Enterprise 64-bit"/><vers edition="SP1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="SP1" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-0013" published="2006-02-14" seq="2006-0013" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-008.mspx">MS06-008</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/388900">VU#388900</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16636">16636</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18857">18857</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0577">ADV-2006-0577</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015630">1015630</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24491">msrpc-webclient-message-bo(24491)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1220">oval:org.mitre.oval:def:1220</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1547">oval:org.mitre.oval:def:1547</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1602">oval:org.mitre.oval:def:1602</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:683">oval:org.mitre.oval:def:683</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:716">oval:org.mitre.oval:def:716</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Standard 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1" num="Enterprise 64-bit"/><vers edition="SP1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="SP1" num="R2"/><vers edition="64-bit" num="R2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-09-20" modified="2006-04-13" name="CVE-2006-0014" published="2006-04-11" seq="2006-0014" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing &quot;certain Unicode strings&quot; and modified length values.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430645/100/0/threaded">20060411 ZDI-06-007: Microsoft Windows Address Book (WAB) File Format Parsing Vulnerability</ref><ref adv="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-06-007.html"></ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-016.mspx">MS06-016</ref><ref source="BID" url="http://www.securityfocus.com/bid/17459">17459</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1321">ADV-2006-1321</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19617">19617</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015898">1015898</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1611">oval:org.mitre.oval:def:1611</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1682">oval:org.mitre.oval:def:1682</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1769">oval:org.mitre.oval:def:1769</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1771">oval:org.mitre.oval:def:1771</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1780">oval:org.mitre.oval:def:1780</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1791">oval:org.mitre.oval:def:1791</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:812">oval:org.mitre.oval:def:812</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045003.html">
20060411 ZDI-06-007: Microsoft Windows Address Book (WAB) File Format Parsing Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25535">
outlook-express-wab-bo(25535)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/691">691</ref></refs><vuln_soft><prod name="Outlook Express" vendor="Microsoft"><vers num="6.0 SP1"/><vers num="6.0"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-0015" published="2006-04-11" seq="2006-0015" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS06-017.mspx">MS06-017</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1322">ADV-2006-1322</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19623">19623</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430803/100/0/threaded">20060412 Vulnerability in Microsoft FrontPage Server Extensions Could Allow Cross-Site Scripting</ref><ref adv="1" patch="1" source="" url="http://www.argeniss.com/research/ARGENISS-ADV-040602.txt"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17452">17452</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015895">1015895</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015896">1015896</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1748">oval:org.mitre.oval:def:1748</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25537">
fpse-html-xss(25537)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/704">704</ref></refs><vuln_soft><prod name="SharePoint Team Services" vendor="Microsoft"><vers num=""/></prod><prod name="FrontPage Server Extensions" vendor="Microsoft"><vers num="2002"/></prod></vuln_soft></entry><entry modified="2005-11-30" name="CVE-2006-0018" published="2005-11-29" reject="1" seq="2006-0018" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-3899.  Reason: This candidate is a duplicate of CVE-2005-3899.  Notes: All CVE users should reference CVE-2005-3899 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0019" published="2006-01-20" seq="2006-0019" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422464/100/0/threaded">20060119 [KDE Security Advisory] kjs encodeuri/decodeuri heap overflow</ref><ref adv="1" patch="1" source="" url="http://www.kde.org/info/security/advisory-20060119-1.txt"></ref><ref patch="1" source="" url="ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.3-kdelibs-kjs.diff"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0265">ADV-2006-0265</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18500">18500</ref><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-948">DSA-948</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:019">MDKSA-2006:019</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0184.html">RHSA-2006:0184</ref><ref source="SUSE" url="http://www.securityfocus.com/archive/1/archive/1/422489/100/0/threaded">SUSE-SA:2006:003</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18540">18540</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18561">18561</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200601-11.xml">GLSA-200601-11</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-245-1">USN-245-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18552">18552</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18559">18559</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18570">18570</ref><ref source="BID" url="http://www.securityfocus.com/bid/16325">16325</ref><ref source="OSVDB" url="http://www.osvdb.org/22659">22659</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015512">1015512</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24242">kde-kjs-bo(24242)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18899">18899</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427976/100/0/threaded">FLSA:178606</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.361107">SSA:2006-045-05</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18583">18583</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:019">MDKSA-2006:019</ref><ref source="SREASON" url="http://securityreason.com/securityalert/364">364</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="3.5.0"/><vers num="3.4.2"/><vers num="3.4.1"/><vers num="3.4.0"/><vers num="3.4"/><vers num="3.3.x"/><vers num="3.3.2"/><vers num="3.3.1"/><vers num="3.3.0"/><vers num="3.3"/><vers num="3.2.x"/><vers num="3.2.3"/><vers num="3.2.2"/><vers num="3.2.1"/><vers num="3.2.0 Beta1"/><vers num="3.2.0"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-04-22" name="CVE-2006-0020" published="2006-01-10" seq="2006-0020" severity="High" type="CVE"><desc><descript source="cve">An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka &quot;WMF Image Parsing Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MLIST" url="http://linuxbox.org/pipermail/funsec/2006-January/002828.html">[funsec] 20060110 Another WMF flaw without a Microsoft patch</ref><ref adv="1" source="" url="http://www.microsoft.com/technet/security/advisory/913333.mspx"></ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/312956">VU#312956</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16516">16516</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0469">ADV-2006-0469</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18729">18729</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-004.mspx">MS06-004</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-045A.html">TA06-045A</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18912">18912</ref><ref source="OSVDB" url="http://www.osvdb.org/22976">22976</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1638">oval:org.mitre.oval:def:1638</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP2"/><vers edition="Tablet PC" num="SP1"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="SP1"/><vers num="R2"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-03-24" name="CVE-2006-0021" published="2006-02-14" seq="2006-0021" severity="High" type="CVE"><desc><descript source="cve">Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the &quot;IGMP v3 DoS Vulnerability.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-007.mspx">MS06-007</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html">TA06-018A</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/839284">VU#839284</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16645">16645</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0576">ADV-2006-0576</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18853">18853</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-045A.html">TA06-045A</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015629">1015629</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24489">win-igmpv3-dos(24489)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1310">oval:org.mitre.oval:def:1310</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1425">oval:org.mitre.oval:def:1425</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1647">oval:org.mitre.oval:def:1647</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1662">oval:org.mitre.oval:def:1662</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:678">oval:org.mitre.oval:def:678</ref><ref source="" url="http://www.securiteam.com/exploits/5PP0T0KI0O.html"></ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/1599">1599</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Standard 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="SP1" num="R2"/><vers edition="64-bit" num="R2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-17" name="CVE-2006-0022" published="2006-06-13" seq="2006-0022" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a PowerPoint document with a malformed record, which triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-028.mspx">MS06-028</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/190089">VU#190089</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18382">18382</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2325">ADV-2006-2325</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20633">20633</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-164A.html">TA06-164A</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016287">1016287</ref><ref source="OSVDB" url="http://www.osvdb.org/26435">26435</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26784">powerpoint-record-bo(26784)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1069">oval:org.mitre.oval:def:1069</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1836">oval:org.mitre.oval:def:1836</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1984">oval:org.mitre.oval:def:1984</ref></refs><vuln_soft><prod name="PowerPoint" vendor="Microsoft"><vers edition="Mac" num="2004"/><vers num="2003 SP3"/><vers num="2003 SP2"/><vers num="2003 SP1"/><vers num="2003"/><vers num="2002 SP3"/><vers num="2002 SP2"/><vers num="2002 SP1"/><vers num="2002"/><vers num="2000 SP3"/><vers num="2000 SR1"/><vers num="2000 SP2"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="6.4" CVSS_score="4.3" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-0023" published="2006-02-07" seq="2006-0023" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka &quot;Permissive Windows Services DACLs.&quot;  NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423587/100/0/threaded">20060131 Windows Access Control Demystified</ref><ref source="" url="http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf"></ref><ref adv="1" source="" url="http://www.microsoft.com/technet/security/advisory/914457.mspx"></ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/953860">VU#953860</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0417">ADV-2006-0417</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24463">win-auth-users-insecure-permissions(24463)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015595">1015595</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18756">18756</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-011.mspx">MS06-011</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015765">1015765</ref><ref source="" url="http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=391523&amp;RenditionID="></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19313">19313</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19238">19238</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1671">oval:org.mitre.oval:def:1671</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1696">oval:org.mitre.oval:def:1696</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-0024" published="2006-03-15" seq="2006-0024" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Adobe Flash Player 8.0.22.0 and earlier allow remote attackers to execute arbitrary code via a crafted SWF file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://www.macromedia.com/devnet/security/security_zone/apsb06-03.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17106">17106</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0952">ADV-2006-0952</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19218">19218</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0268.html">RHSA-2006:0268</ref><ref source="OSVDB" url="http://www.osvdb.org/23908">23908</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25005">macromedia-swf-code-execution(25005)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-075A.html">TA06-075A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/945060">VU#945060</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015770">1015770</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19259">19259</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_15_flashplayer.html">SUSE-SA:2006:015</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-20.xml">GLSA-200603-20</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19198">19198</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19328">19328</ref><ref source="" url="http://www.opera.com/docs/changelogs/windows/854/"></ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-020.mspx">MS06-020</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-129A.html">TA06-129A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1744">ADV-2006-1744</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1894">oval:org.mitre.oval:def:1894</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1922">oval:org.mitre.oval:def:1922</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1262">
ADV-2006-1262</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20045">
20045</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307179"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html">APPLE-SA-2007-12-17</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-352A.html">TA07-352A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/4238">ADV-2007-4238</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28136">28136</ref></refs><vuln_soft><prod name="Flash" vendor="Macromedia"><vers num="8.0.22.0" prev="1"/><vers num="7.0.61.0"/><vers num="7.0.60.0"/><vers num="7.0.19.0"/><vers num="7.0 r19"/><vers num="6.0.79.0"/><vers num="6.0.65.0"/><vers num="6.0.47.0"/><vers num="6.0.40.0"/><vers num="6.0.29.0"/><vers num="6.0"/><vers num="5.0 r50"/><vers num="5.0"/><vers num="4.0 r12"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-02-22" modified="2006-06-14" name="CVE-2006-0025" published="2006-06-13" seq="2006-0025" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=406">20060613 Windows Media Player PNG Chunk Decoding Stack-Based Buffer Overflow</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-024.mspx">MS06-024</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18385">18385</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2322">ADV-2006-2322</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20626">20626</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-164A.html">TA06-164A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/608020">VU#608020</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016284">1016284</ref><ref source="OSVDB" url="http://www.osvdb.org/26430">26430</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26788">win-media-player-png-bo(26788)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1230">oval:org.mitre.oval:def:1230</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1729">oval:org.mitre.oval:def:1729</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1805">oval:org.mitre.oval:def:1805</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1807">oval:org.mitre.oval:def:1807</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1820">oval:org.mitre.oval:def:1820</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1974">oval:org.mitre.oval:def:1974</ref></refs><vuln_soft><prod name="Windows Media Player" vendor="Microsoft"><vers num="9"/><vers num="10"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-07-12" name="CVE-2006-0026" published="2006-07-11" seq="2006-0026" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-034.mspx">MS06-034</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/395588">VU#395588</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18858">18858</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2752">ADV-2006-2752</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016466">1016466</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/21006">21006</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/26796">iis-asp-bo(26796)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-192A.html">TA06-192A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:435">oval:org.mitre.oval:def:435</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-07/0316.html">

20060718 ASP.DLL Include File Buffer Overflow</ref><ref source="OSVDB" url="http://www.osvdb.org/27152">
27152</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="6.0"/><vers num="5.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-11" name="CVE-2006-0027" published="2006-05-09" seq="2006-0027" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-019.mspx">MS06-019</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-129A.html">TA06-129A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/303452">VU#303452</ref><ref source="BID" url="http://www.securityfocus.com/bid/17908">17908</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1743">ADV-2006-1743</ref><ref source="OSVDB" url="http://www.osvdb.org/25338">25338</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016048">1016048</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20029">20029</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25556">exchange-calendar-code-execution(25556)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1818">oval:org.mitre.oval:def:1818</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1996">oval:org.mitre.oval:def:1996</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2035">oval:org.mitre.oval:def:2035</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="2003 SP2"/><vers num="2003 SP1"/><vers num="2000 SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0028" published="2006-03-14" seq="2006-0028" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427632/100/0/threaded">20060314 ZDI-06-004: Microsoft Excel File Format Parsing Vulnerability</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx">MS06-012</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/339878">VU#339878</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015766">1015766</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19138">19138</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html">TA06-073A</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25225">excel-parsing-format-file-bo(25225)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0950">ADV-2006-0950</ref><ref source="OSVDB" url="http://www.osvdb.org/23899">23899</ref><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-06-004.html"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19238">19238</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1158">oval:org.mitre.oval:def:1158</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1411">oval:org.mitre.oval:def:1411</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1509">oval:org.mitre.oval:def:1509</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1635">oval:org.mitre.oval:def:1635</ref><ref source="SREASON" url="http://securityreason.com/securityalert/583">583</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP1"/><vers num="2003 SP2"/><vers edition="Mac" num="v. X"/><vers edition="Mac" num="2004"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/><vers edition="Mac OS X" num="X"/><vers edition="Mac OS X" num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0029" published="2006-03-14" seq="2006-0029" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx">MS06-012</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/235774">VU#235774</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015766">1015766</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19138">19138</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html">TA06-073A</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25227">excel-description-bo(25227)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0950">ADV-2006-0950</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19238">19238</ref><ref source="OSVDB" url="http://www.osvdb.org/23900">23900</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1522">oval:org.mitre.oval:def:1522</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1570">oval:org.mitre.oval:def:1570</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1579">oval:org.mitre.oval:def:1579</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1633">oval:org.mitre.oval:def:1633</ref><ref source="SREASON" url="http://securityreason.com/securityalert/585">585</ref><ref source="SREASON" url="http://securityreason.com/securityalert/586">586</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP1"/><vers num="2003 SP2"/><vers edition="Mac" num="v. X"/><vers edition="Mac" num="2004"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/><vers edition="Mac OS X" num="X"/><vers edition="Mac OS X" num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0030" published="2006-03-14" seq="2006-0030" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx">MS06-012</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/123222">VU#123222</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015766">1015766</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19138">19138</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html">TA06-073A</ref><ref source="OSVDB" url="http://www.osvdb.org/23901">23901</ref><ref source="BID" url="http://www.securityfocus.com/bid/16181">16181</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0950">ADV-2006-0950</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25229">excel-graphic-bo(25229)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19238">19238</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1401">oval:org.mitre.oval:def:1401</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1510">oval:org.mitre.oval:def:1510</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1630">oval:org.mitre.oval:def:1630</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1666">oval:org.mitre.oval:def:1666</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP1"/><vers num="2003 SP2"/><vers edition="Mac" num="v. X"/><vers edition="Mac" num="2004"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/><vers edition="Mac OS X" num="X"/><vers edition="Mac OS X" num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0031" published="2006-03-14" seq="2006-0031" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx">MS06-012</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/104302">VU#104302</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015766">1015766</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19138">19138</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html">TA06-073A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17101">17101</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25228">excel-record-bo(25228)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427699/100/0/threaded">20060315 [xfocus-SD-060314]Microsoft Office Excel Buffer Overflow Vulnerability</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/1521.html">20060314 [xfocus-SD-060314]Microsoft Office Excel Buffer Overflow Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0950">ADV-2006-0950</ref><ref source="OSVDB" url="http://www.osvdb.org/23902">23902</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19238">19238</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1327">oval:org.mitre.oval:def:1327</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1525">oval:org.mitre.oval:def:1525</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1750">oval:org.mitre.oval:def:1750</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:763">oval:org.mitre.oval:def:763</ref><ref source="SREASON" url="http://securityreason.com/securityalert/589">589</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP1"/><vers num="2003 SP2"/><vers edition="Mac" num="v. X"/><vers edition="Mac" num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-05" name="CVE-2006-0032" published="2006-09-12" seq="2006-0032" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.</descript></desc><sols><sol source="nvd">Successful exploitation requires that the Indexing service is accessible through IIS.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS06-053.mspx">MS06-053</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/19927">19927</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3564">ADV-2006-3564</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/21861">21861</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-255A.html">TA06-255A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/108884">VU#108884</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016826">1016826</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/28651">ms-indexing-service-xss(28651)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/447511/100/0/threaded">20061001 Microsoft Internet Information Services UTF-7 XSS Vulnerability [MS06-053]</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/447509/100/0/threaded">20061002 IE UXSS (Universal XSS in IE, was Re: Microsoft Internet Information Services UTF-7 XSS Vulnerability [MS06-053])</ref><ref source="" url="http://www.geocities.jp/ptrs_sec/advisory09e.html"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446630/100/100/threaded">HPSBST02134</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:535">oval:org.mitre.oval:def:535</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="SP1 Beta 1" num="Web"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers num="Standard 64-bit"/><vers edition="SP1 Beta 1" num="Standard"/><vers edition="SP1" num="Standard"/><vers num="Standard"/><vers num="Enterprise 64-bit"/><vers edition="SP1 Beta 1" num="Enterprise Edition Itanium"/><vers edition="SP1" num="Enterprise Edition Itanium"/><vers num="Enterprise Edition Itanium"/><vers edition="SP1 Beta 1" num="Enterprise Edition"/><vers edition="SP1" num="Enterprise Edition"/><vers edition="Enterprise" num="SP1"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1 Beta 1" num="Datacenter Edition Itanium"/><vers edition="SP1" num="Datacenter Edition Itanium"/><vers num="Datacenter Edition Itanium"/><vers edition="SP1 Beta 1" num="Datacenter Edition"/><vers edition="SP1" num="Datacenter Edition"/><vers num="Datacenter Edition"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Resource Kit"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0033" published="2006-07-11" seq="2006-0033" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-039.mspx">MS06-039</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18913">18913</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/459388">VU#459388</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2757">ADV-2006-2757</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21013">21013</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-192A.html">TA06-192A</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016470">1016470</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:163">oval:org.mitre.oval:def:163</ref><ref source="" url="http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-22.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/27147">
27147</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2003 SP2"/><vers num="2003 SP1"/><vers num="2000 SP3"/><vers num="XP SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2005-10-11" modified="2007-08-13" name="CVE-2006-0034" published="2006-05-09" seq="2006-0034" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllocate function, aka the MSDTC Invalid Memory Access Vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433430/100/0/threaded">20060509 [EEYEB20051011A] - Microsoft Distributed Transaction Coordinator Heap Overflow</ref><ref adv="1" patch="1" source="" url="http://www.eeye.com/html/research/advisories/AD20060509a.html"></ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-018.mspx">MS06-018</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17906">17906</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1742">ADV-2006-1742</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20000">20000</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433677/100/0/threaded">20060511 Microsoft MSDTC NdrAllocate Validation Vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016047">1016047</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0238.html">20060509 [EEYEB20051011A] - Microsoft Distributed Transaction Coordinator Heap Overflow</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0269.html">20060510 Microsoft MSDTC NdrAllocate Validation Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/25335">25335</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1222">oval:org.mitre.oval:def:1222</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1477">oval:org.mitre.oval:def:1477</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1908">oval:org.mitre.oval:def:1908</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25559">msdtc-network-message-dos(25559)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/863">863</ref></refs><vuln_soft><prod name="distributed transaction coordinator" vendor="Microsoft"><vers num=""/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/><vers num="Terminal Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="4.0 SP6a"/><vers num="4.0 SP6"/><vers num="4.0 SP5"/><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="64-bit"/><vers num="64-bit"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Web"/><vers edition="64-bit" num="Standard"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Enterprise"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-05" name="CVE-2006-0035" published="2006-01-11" seq="2006-0035" severity="Medium" type="CVE"><desc><descript source="cve">The netlink_rcv_skb function in af_netlink.c in Linux kernel 2.6.14 and 2.6.15 allows local users to cause a denial of service (infinite loop) via a nlmsg_len field of 0.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ad8e4b75c8a7bed475d72ce09bf5267188621961"></ref><ref patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2006/0004">2006-0004</ref><ref source="BID" url="http://www.securityfocus.com/bid/16414">16414</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18482">18482</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0220">
ADV-2006-0220</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24202">
kernel-afnetlink-dos(24202)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/388">388</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.15-rc7"/><vers num="2.6.15-rc6"/><vers num="2.6.15-rc5"/><vers num="2.6.15-rc4"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.15"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-24" name="CVE-2006-0036" published="2006-01-23" seq="2006-0036" severity="High" type="CVE"><desc><descript source="cve">ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows remote attackers to cause a denial of service (memory corruption or crash) via an inbound PPTP_IN_CALL_REQUEST packet that causes a null pointer to be used in an offset calculation.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=15db34702cfafd24acc60295cf14861e497502ab"></ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0004">2006-0004</ref><ref source="BID" url="http://www.securityfocus.com/bid/16414">16414</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18482">18482</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0220">
ADV-2006-0220</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24203">
kernel-pptpincallrequest-dos(24203)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/388">388</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.14"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-24" name="CVE-2006-0037" published="2006-01-23" seq="2006-0037" severity="Medium" type="CVE"><desc><descript source="cve">ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows local users to cause a denial of service (memory corruption or crash) via a crafted outbound packet that causes an incorrect offset to be calculated from pointer arithmetic when non-linear SKBs (socket buffers) are used.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="" url="http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=03b9feca89366952ae5dfe4ad8107b1ece50b710"></ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0004">2006-0004</ref><ref source="BID" url="http://www.securityfocus.com/bid/16414">16414</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18482">18482</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0220">
ADV-2006-0220</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24204">
kernel-pptpnathelper-dos(24204)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/388">388</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.14"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-04-17" name="CVE-2006-0038" published="2006-03-22" seq="2006-0038" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the do_replace function in netfilter for Linux before 2.6.16-rc3, when using &quot;virtualization solutions&quot; such as OpenVZ, allows local users with CAP_NET_ADMIN rights to cause a buffer overflow in the copy_from_user function.</descript></desc><sols><sol source="nvd">Linux kernel version 2.6.16 has been released to address this issue.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=186295"></ref><ref source="" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ee4bb818ae35f68d1f848eae0a7b150a38eb4168"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17178">17178</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19330">19330</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1046">ADV-2006-1046</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25400">linux-netfilter-doreplace-overflow(25400)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1097">DSA-1097</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20671">20671</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-302-1">USN-302-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20716">20716</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0575.html">RHSA-2006:0575</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21465">21465</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/22417">22417</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.16 -rc1"/><vers num="2.6.15 .4"/><vers num="2.6.15 .3"/><vers num="2.6.15 .2"/><vers num="2.6.15 .1"/><vers num="2.6.15 -rc3"/><vers num="2.6.15 -rc2"/><vers num="2.6.15 -rc1"/><vers num="2.6.15"/><vers num="2.6.14.5"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14 -rc4"/><vers num="2.6.14 -rc3"/><vers num="2.6.14 rc2"/><vers num="2.6.14 rc1"/><vers num="2.6.14"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13 rc7"/><vers num="2.6.13 rc6"/><vers num="2.6.13 rc4"/><vers num="2.6.13 rc1"/><vers num="2.6.13"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12 rc5"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc1"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.6.15.5"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-16" modified="2006-05-22" name="CVE-2006-0039" published="2006-05-19" seq="2006-0039" severity="Low" type="CVE"><desc><descript source="cve">Race condition in the do_add_counters function in netfilter for Linux kernel 2.6.16 allows local users with CAP_NET_ADMIN capabilities to read kernel memory by triggering the race condition in a way that produces a size value that is inconsistent with allocated memory, which leads to a buffer over-read in IPT_ENTRY_ITERATE.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><race/></vuln_types><range><local/></range><refs><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=191698"></ref><ref patch="1" source="" url="http://bugs.gentoo.org/show_bug.cgi?id=133465"></ref><ref patch="1" source="" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2722971cbe831117686039d5c334f2c0f560be13"></ref><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1893">ADV-2006-1893</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20185">20185</ref><ref source="BID" url="http://www.securityfocus.com/bid/18113">18113</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26583">linux-doaddcounters-race-condition(26583)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1097">DSA-1097</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20671">20671</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-311-1">USN-311-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20991">20991</ref><ref source="OSVDB" url="http://www.osvdb.org/25697">25697</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0689.html">RHSA-2006:0689</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22292">22292</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-249.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/22945">22945</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21476">
21476</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.16"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-0040" published="2006-03-09" seq="2006-0040" severity="Medium" type="CVE"><desc><descript source="cve">GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due to unknown problems in gtkhtml.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426452/100/0/threaded">20060301 Evolution Emailer DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/16889">16889</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0801">ADV-2006-0801</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19049">19049</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19094">19094</ref><ref source="BID" url="http://www.securityfocus.com/bid/16899">16899</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25050">
evolution-email-dos(25050)</ref></refs><vuln_soft><prod name="Evolution" vendor="GNOME"><vers num="2.4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-0042" published="2006-02-18" seq="2006-0042" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remote attackers cause a denial of service (CPU consumption) via unknown attack vectors that result in quadratic computational complexity.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://svn.apache.org/viewcvs.cgi/httpd/apreq/tags/v2_07/CHANGES?rev=376998&amp;view=markup"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18846">18846</ref><ref source="" url="http://svn.apache.org/viewcvs.cgi/httpd/apreq/tags/v2_07/CHANGES?rev=376998&amp;view=markup"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16710">16710</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0645">ADV-2006-0645</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1000">DSA-1000</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19139">19139</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-08.xml">GLSA-200604-08</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19658">19658</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24917">
libapreq2-parsing-dos(24917)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/737">737</ref></refs><vuln_soft><prod name="Libapreq2" vendor="Libapreq2"><vers num="2.06 dev"/><vers num="2.05 dev"/><vers num="2.04 dev"/><vers num="2.03 dev"/><vers num="2.02 dev"/><vers num="2.01 dev"/><vers num="1.33"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-01" name="CVE-2006-0043" published="2006-01-30" seq="2006-0043" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the realpath function in nfs-server rpc.mountd, as used in SUSE Linux 9.1 through 10.0, allows local users to execute arbitrary code via unspecified vectors involving mount requests and symlinks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Jan/0007.html">SuSE-SA:2006:005</ref><ref source="BID" url="http://www.securityfocus.com/bid/16388">16388</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0348">ADV-2006-0348</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18614">18614</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18638">18638</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24347">nfs-rpcmountd-realpath-bo(24347)</ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350020"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-975">DSA-975</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18889">18889</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="Professional 10.0"/><vers edition="x86_64" num="Professional 9.3"/><vers num="Professional 9.3"/><vers edition="x86_64" num="Professional 9.2"/><vers num="Professional 9.2"/><vers edition="x86_64" num="Professional 9.1"/><vers num="Professional 9.1"/><vers edition="x86_64" num="Personal 9.3"/><vers num="Personal 9.3"/><vers edition="x86_64" num="Personal 9.2"/><vers num="Personal 9.2"/><vers edition="x86_64" num="Personal 9.1"/><vers num="Personal 9.1"/></prod><prod name="SuSE Novell Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0044" published="2006-01-17" seq="2006-0044" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in context.py in Albatross web application toolkit before 1.33 allows remote attackers to execute arbitrary commands via unspecified vectors involving template files and the &quot;handling of submitted form fields&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.object-craft.com.au/projects/albatross/news.html"></ref><ref source="" url="http://security.debian.org/pool/updates/main/a/albatross/albatross_1.20-2.diff.gz"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-942">DSA-942</ref><ref source="BID" url="http://www.securityfocus.com/bid/16252">16252</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0196">ADV-2006-0196</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18457">18457</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18496">18496</ref><ref source="OSVDB" url="http://www.osvdb.org/22451">22451</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24130">
albatross-context-command-execution(24130)</ref></refs><vuln_soft><prod name="Albatross" vendor="Albatross"><vers num="1.32"/><vers num="1.30"/><vers num="1.20"/><vers num="1.10"/><vers num="1.01"/><vers num="1.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0045" published="2006-01-20" seq="2006-0045" severity="High" type="CVE"><desc><descript source="cve">crawl before 4.0.0 does not securely call programs when saving and loading games, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-949">DSA-949</ref><ref source="BID" url="http://www.securityfocus.com/bid/16337">16337</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0303">ADV-2006-0303</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18545">18545</ref><ref source="OSVDB" url="http://www.osvdb.org/22690">22690</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18573">18573</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24262">crawl-insecure-command-execution(24262)</ref></refs><vuln_soft><prod name="Dungeon Crawl" vendor="Linley Henzell"><vers num="4.0.0 b23"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-14" name="CVE-2006-0046" published="2006-02-13" seq="2006-0046" severity="High" type="CVE"><desc><descript source="cve">squid_redirect script in adzapper before 2006-01-29 allows remote attackers to cause a denial of service (CPU consumption) via a URL with a large number of trailing / (forward slashes), which might produce inefficient regular expressions.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-966">DSA-966</ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350308"></ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi/squid_redirect.diff?bug=350308;msg=5;att=1"></ref><ref source="" url="http://adzapper.sourceforge.net/cvslog.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0491">ADV-2006-0491</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18771">18771</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18777">18777</ref><ref source="BID" url="http://www.securityfocus.com/bid/16558">16558</ref><ref source="OSVDB" url="http://www.osvdb.org/22900">22900</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24640">
adzapper-squid-redirect-dos(24640)</ref></refs><vuln_soft><prod name="adzapper" vendor="Cameron Simpson"><vers num="2006-01-29"/><vers num="2006-01-28"/><vers num="2006-01-25"/><vers num="2006-01-24"/><vers num="2006-01-23"/><vers num="2006-01-15"/><vers num="2006-01-14"/><vers num="2006-01-07"/><vers num="2006-01-05"/><vers num="2006-01-01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-05-20" name="CVE-2006-0047" published="2006-03-07" seq="2006-0047" severity="Medium" type="CVE"><desc><descript source="cve">packets.c in Freeciv 2.0 before 2.0.8 allows remote attackers to cause a denial of service (server crash) via crafted packets with negative compressed size values.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=355211"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0838">ADV-2006-0838</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19120">19120</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426866/100/0/threaded">20060306 Out of memory crash in Freeciv 2.0.7</ref><ref adv="1" patch="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:053">MDKSA-2006:053</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16975">16975</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-11.xml">GLSA-200603-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19253">19253</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-994">DSA-994</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19227">19227</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25166">freeciv-packets-dos(25166)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:053">MDKSA-2006:053</ref></refs><vuln_soft><prod name="Freeciv" vendor="Freeciv"><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-27" name="CVE-2006-0048" published="2006-04-25" seq="2006-0048" severity="Medium" type="CVE"><desc><descript source="cve">Francesco Stablum tcpick 0.2.1 allows remote attackers to cause a denial of service (segmentation fault) via certain fragmented packets, possibly involving invalid headers and an attacker-controlled payload length.  NOTE: this issue might be a buffer overflow or overread.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/mailarchive/forum.php?thread_id=9989610&amp;forum_id=37151"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17665">17665</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1466">ADV-2006-1466</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26090">
tcpick-writec-dos(26090)</ref></refs><vuln_soft><prod name="tcpick" vendor="Francesco Stablum"><vers num="0.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-0049" published="2006-03-13" seq="2006-0049" severity="Medium" type="CVE"><desc><descript source="cve">gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than CVE-2006-0455.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427324/100/0/threaded">20060313 GnuPG does not detect injection of unsigned data</ref><ref adv="1" patch="1" source="MLIST" url="http://lists.gnupg.org/pipermail/gnupg-announce/2006q1/000216.html">[gnupg-announce] 20060309 [Announce] GnuPG does not detect injection of unsigned data</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-993">DSA-993</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-08.xml">GLSA-200603-08</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-264-1">USN-264-1</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17058">17058</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0915">ADV-2006-0915</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/23790">23790</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015749">1015749</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19173">19173</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00021.html">FEDORA-2006-147</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19203">19203</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19244">19244</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0266.html">RHSA-2006:0266</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0014">2006-0014</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19231">19231</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19249">19249</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19287">19287</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:055">MDKSA-2006:055</ref><ref source="SUSE" url="http://lists.suse.de/archive/suse-security-announce/2006-Mar/0003.html">SUSE-SA:2006:014</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19197">19197</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19232">19232</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19234">19234</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.476477">SSA:2006-072-02</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U">20060401-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19532">19532</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/433931/100/0/threaded">FLSA-2006:185355</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25184">
gnupg-nondetached-sig-verification(25184)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:055">MDKSA-2006:055</ref><ref source="SREASON" url="http://securityreason.com/securityalert/450">450</ref><ref source="SREASON" url="http://securityreason.com/securityalert/568">568</ref></refs><vuln_soft><prod name="GNU Privacy Guard" vendor="GNU"><vers num="1.4.2.1"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2 rc1"/><vers num="1.2.2 r1"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3b"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-0050" published="2006-03-23" seq="2006-0050" severity="Low" type="CVE"><desc><descript source="cve">snmptrapfmt in Debian 3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary log file.</descript></desc><loss_types><int/></loss_types><vuln_types><design/><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1013">DSA-1013</ref><ref source="BID" url="http://www.securityfocus.com/bid/17182">17182</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19318">19318</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25442">snmptrapfmt-log-temprary-file(25442)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="3.1 sparc"/><vers num="3.1 s_390"/><vers num="3.1 ppc"/><vers num="3.1 mipsel"/><vers num="3.1 mips"/><vers num="3.1 m68k"/><vers num="3.1 ia-64"/><vers num="3.1 ia-32"/><vers num="3.1 hppa"/><vers num="3.1 arm"/><vers num="3.1 amd64"/><vers num="3.1 alpha"/><vers num="3.1"/><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-21" name="CVE-2006-0051" published="2006-04-05" seq="2006-0051" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in playlistimport.cpp in Kaffeine Player 0.4.2 through 0.7.1 allows user-assisted attackers to execute arbitrary code via long HTTP request headers when Kaffeine is &quot;fetching remote playlists&quot;, which triggers the overflow in the http_peek function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://www.kde.org/info/security/advisory-20060404-1.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17372">17372</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1229">ADV-2006-1229</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19525">19525</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1023">DSA-1023</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430319/100/0/threaded">20060405 [Kaffeine Security Advisory] Heap based buffer overflow in http_peek()</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-04.xml">GLSA-200604-04</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:065">MDKSA-2006:065</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_08_sr.html">SUSE-SR:2006:008</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-268-1">USN-268-1</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015863">1015863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19540">19540</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19542">19542</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19549">19549</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19557">19557</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19571">19571</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25631">kaffeine-http-peek-bo(25631)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:065">MDKSA-2006:065</ref></refs><vuln_soft><prod name="Kaffeine Player" vendor="Kaffeine"><vers num="0.7.1"/><vers num="0.5 rc1"/><vers num="0.4.3b"/><vers num="0.4.3"/><vers num="0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-31" name="CVE-2006-0052" published="2006-03-31" seq="2006-0052" severity="Medium" type="CVE"><desc><descript source="cve">The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python&apos;s library email module 2.5, allows remote attackers to cause a denial of service (mailing list delivery failure) via a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:061">MDKSA-2006:061</ref><ref patch="1" source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=358892"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17311">17311</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015851">1015851</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1027">DSA-1027</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19545">19545</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_08_sr.html">SUSE-SR:2006:008</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-267-1">USN-267-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19522">19522</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19571">19571</ref><ref source="OSVDB" url="http://www.osvdb.org/24367">24367</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0486.html">RHSA-2006:0486</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20624">20624</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc">20060602-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20782">20782</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:061">MDKSA-2006:061</ref></refs><vuln_soft><prod name="Mailman" vendor="GNU"><vers num="2.1.5"/><vers num="2.1.4"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1b1"/><vers num="2.1"/><vers num="2.0.14"/><vers num="2.0.13"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.9"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0 beta5"/><vers num="2.0 beta4"/><vers num="2.0 beta3"/><vers num="2.0.8"/><vers num="2.0"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-04-28" name="CVE-2006-0053" published="2006-04-10" seq="2006-0053" severity="Low" type="CVE"><desc><descript source="cve">Imager (libimager-perl) before 0.50 allows user-assisted attackers to cause a denial of service (segmentation fault) by writing a 2- or 4-channel JPEG image (or a 2-channel TGA image) to a scalar, which triggers a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1028">DSA-1028</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19577">19577</ref><ref source="" url="http://rt.cpan.org/Public/Bug/Display.html?id=18397"></ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359661"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17415">17415</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19575">19575</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1294">ADV-2006-1294</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25717">imager-jpeg-tga-dos(25717)</ref></refs><vuln_soft><prod name="Imager" vendor="Tony Cook"><vers num="0.49"/><vers num="0.48"/><vers num="0.47"/><vers num="0.45_2"/><vers num="0.45"/><vers num="0.44_1"/><vers num="0.43"/><vers num="0.42"/><vers num="0.41"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0054" published="2006-01-11" seq="2006-0054" severity="Medium" type="CVE"><desc><descript source="cve">The ipfw firewall in FreeBSD 6.0-RELEASE allows remote attackers to cause a denial of service (firewall crash) via ICMP IP fragments that match a reset, reject or unreach action, which leads to an access of an uninitialized pointer.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:04.ipfw.asc">FreeBSD-SA-06:04</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16209">16209</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18378">18378</ref><ref source="OSVDB" url="http://www.osvdb.org/22319">22319</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015477">1015477</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24073">ipfw-icmp-fragment-dos(24073)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.0 Release"/><vers num="6.0 Stable"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0055" published="2006-01-11" seq="2006-0055" severity="Low" type="CVE"><desc><descript source="cve">The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:02.ee.asc">FreeBSD-SA-06:02</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16207">16207</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18404">18404</ref><ref source="OSVDB" url="http://www.osvdb.org/22320">22320</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015469">1015469</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24074">ee-ispell-op-symlink(24074)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.0 Stable"/><vers num="6.0 Release"/><vers num="5.4 Releng"/><vers num="5.4 Release"/><vers num="5.4 pre"/><vers num="5.3 Stable"/><vers num="5.3 Releng"/><vers num="5.3 Release"/><vers num="5.3"/><vers num="5.2.1 Release"/><vers num="5.2 Releng"/><vers num="5.2 Release"/><vers num="5.2"/><vers num="5.1 Releng"/><vers num="5.1 Release Alpha"/><vers num="5.1 p5 Release"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.0 Releng"/><vers num="5.0 p14 Release"/><vers num="5.0 alpha"/><vers num="5.0"/><vers num="4.11 Stable"/><vers num="4.11 Releng"/><vers num="4.11 p3 Release"/><vers num="4.10 Releng"/><vers num="4.10 p8 Release"/><vers num="4.10 Release"/><vers num="4.10"/><vers num="4.10 pre"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-26" name="CVE-2006-0056" published="2006-02-13" seq="2006-0056" severity="High" type="CVE"><desc><descript source="cve">Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted passwords, which lead to a double free of a pointer that was created by the pam_get_item function.  NOTE: this issue only occurs in certain configurations in which there are multiple PAM modules, PAM-MySQL is not evaluated first, and there are no requisite modules before PAM-MySQL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/forum/forum.php?forum_id=499394"></ref><ref source="" url="http://jvn.jp/cert/JVNVU%23693909/index.html"></ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/693909">VU#693909</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16564">16564</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0490">ADV-2006-0490</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015603">1015603</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18598">18598</ref><ref source="OSVDB" url="http://www.osvdb.org/22994">22994</ref><ref source="OSVDB" url="http://www.osvdb.org/22995">22995</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200606-18.xml">GLSA-200606-18</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20690">20690</ref></refs><vuln_soft><prod name="PAM-MySQL" vendor="PAM-MySQL"><vers num="0.4.7"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/><vers num="0.7 pre2"/><vers num="0.7 pre1"/><vers num="0.6"/><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0057" published="2006-01-27" seq="2006-0057" severity="High" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to bypass the Kill bit settings for dangerous ActiveX controls via unknown vectors involving crafted HTML, which can expose the browser to attacks that would otherwise be prevented by the Kill bit setting. NOTE: CERT/CC claims that MS05-054 fixes this issue, but it is not described in MS05-054.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/998297">VU#998297</ref><ref adv="1" patch="1" source="" url="http://www.microsoft.com/technet/security/bulletin/ms05-054.mspx"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16409">16409</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24379">ie-activex-killbit-bypass(24379)</ref><ref source="OSVDB" url="http://www.osvdb.org/23657">23657</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01 SP4"/><vers num="6 SP1"/><vers edition="Windows Server 2003 SP1" num="6"/><vers num="5.5 SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-0058" published="2006-03-22" seq="2006-0058" severity="High" type="CVE"><desc><descript source="cve">Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS" url="http://xforce.iss.net/xforce/alerts/id/216">20060322 Sendmail Remote Signal Handling Vulnerability</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0264.html">RHSA-2006:0264</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0265.html">RHSA-2006:0265</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1049">ADV-2006-1049</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1051">ADV-2006-1051</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/428536/100/0/threaded">20060322 sendmail vuln advisories (CVE-2006-0058)</ref><ref source="" url="http://www.sendmail.com/company/advisory/index.shtml"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1015">DSA-1015</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-21.xml">GLSA-200603-21</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:058">MDKSA-2006:058</ref><ref source="OPENPKG" url="http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.007-sendmail.html">OpenPKG-SA-2006.007</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-081A.html">TA06-081A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/834865">VU#834865</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19342">19342</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19363">19363</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19367">19367</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/428656/100/0/threaded">FLSA:186277</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:13.sendmail.asc">FreeBSD-SA-06:13</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_17_sendmail.html">SUSE-SA:2006:017</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428892/100/0/threaded">HPSBUX02108</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata38.html#sendmail">[3.8] 006: SECURITY FIX: March 25, 2006</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102262-1">102262</ref><ref source="BID" url="http://www.securityfocus.com/bid/17192">17192</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1068">ADV-2006-1068</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1072">ADV-2006-1072</ref><ref source="OSVDB" url="http://www.osvdb.org/24037">24037</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015801">1015801</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19368">19368</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19404">19404</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19407">19407</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19349">19349</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19360">19360</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19361">19361</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24584">smtp-timeout-bo(24584)</ref><ref source="" url="http://www.f-secure.com/security/fsc-2006-2.shtml"></ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.asc">NetBSD-SA2006-010</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1139">ADV-2006-1139</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1157">ADV-2006-1157</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19394">19394</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19450">19450</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19466">19466</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY82992&amp;apar=only">IY82992</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY82993&amp;apar=only">IY82993</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY82994&amp;apar=only">IY82994</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.619600">SSA:2006-081-01</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060302-01-P">20060302-01-P</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U">20060401-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19533">19533</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19532">19532</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00018.html">FEDORA-2006-193</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00017.html">FEDORA-2006-194</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/q-151.shtml">Q-151</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19345">19345</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19346">19346</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19356">19356</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19676">19676</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102324-1">102324</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1529">ADV-2006-1529</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19774">19774</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.24/SCOSA-2006.24.txt">SCOSA-2006.24</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20243">20243</ref><ref source="HP" url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635">HPSBTU02116</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2189">ADV-2006-2189</ref><ref source="" url="http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688"></ref><ref source="" url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=2751"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2490">ADV-2006-2490</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20723">20723</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00629555">HPSBUX02108</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1689">oval:org.mitre.oval:def:1689</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:058">MDKSA-2006:058</ref><ref source="SREASON" url="http://securityreason.com/securityalert/612">612</ref><ref source="SREASON" url="http://securityreason.com/securityalert/743">743</ref></refs><vuln_soft><prod name="Sendmail" vendor="Sendmail Consortium"><vers num="8.13.5"/><vers num="8.13.4"/><vers num="8.13.3"/><vers num="8.13.2"/><vers num="8.13.1"/><vers num="8.13.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-19" name="CVE-2006-0059" published="2006-05-19" seq="2006-0059" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the ISO Transport Service over TCP (RFC 1006) implementation of LiveData ICCP Server before 5.00.035 allows remote attackers to cause a denial of service or execute arbitrary code via malformed packets.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
LiveData, ICCP Server, 5.00.035</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="US-CERT" url="http://www.kb.cert.org/vuls/id/JGEI-6MMS9T">VU#190617</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/190617">VU#190617</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1830">ADV-2006-1830</ref><ref source="" url="http://www.digitalbond.com/SCADA_Blog/2006/05/us-cert-livedata-iccp-vulnerability.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/18010">18010</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016113">1016113</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20146">20146</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26490">livedata-iccp-rfc1006-bo(26490)</ref></refs><vuln_soft><prod name="ICCP Server" vendor="LiveData"><vers num="5.00.045"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0063" published="2006-01-05" seq="2006-0063" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when &quot;Allowed HTML tags&quot; is enabled, allows remote attackers to inject arbitrary web script or HTML via a permitted HTML tag with &apos; (single quote) characters and active attributes such as onmouseover, a variant of CVE-2005-4357.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://securityreason.com/achievement_securityalert/30"></ref><ref adv="1" source="" url="http://securityreason.com/securityalert/313"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0051">ADV-2006-0051</ref><ref source="OSVDB" url="http://www.osvdb.org/22672">22672</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.19"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-12" name="CVE-2006-0064" published="2006-01-03" seq="2006-0064" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in the glob[rootDir] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0016">ADV-2006-0016</ref><ref source="" url="http://milw0rm.com/id.php?id=1398"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1398">

1398</ref></refs><vuln_soft><prod name="CubeCart" vendor="Devellion"><vers num="3.0.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0065" published="2006-01-03" seq="2006-0065" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in (1) functions.php, (2) functions_update.php, and (3) functions_display.php in VEGO Web Forum 1.26 and earlier allows remote attackers to execute arbitrary SQL commands via the theme_id parameter in index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420661/100/0/threaded">20060101 [eVuln] VEGO Web Forum SQL Injection Vulnerability</ref><ref adv="1" source="" url="http://evuln.com/vulns/1/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0003">ADV-2006-0003</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18273">18273</ref><ref source="BID" url="http://www.securityfocus.com/bid/16107">16107</ref><ref source="OSVDB" url="http://www.osvdb.org/22140">22140</ref><ref source="SREASON" url="http://securityreason.com/securityalert/315">315</ref></refs><vuln_soft><prod name="VEGO Web Forum" vendor="VEGO"><vers num="1.26" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0066" published="2006-01-03" seq="2006-0066" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in PHPjournaler 1.0 allows remote attackers to execute arbitrary SQL commands via the readold parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420666/100/0/threaded">20060101 [eVuln] PHPjournaler SQL Injection Vulnerability</ref><ref adv="1" source="" url="http://evuln.com/vulns/9/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0006">ADV-2006-0006</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18265">18265</ref><ref source="BID" url="http://www.securityfocus.com/bid/16111">16111</ref><ref source="OSVDB" url="http://www.osvdb.org/22149">22149</ref></refs><vuln_soft><prod name="PHPjournaler" vendor="PHPjournaler"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0067" published="2006-01-03" seq="2006-0067" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.php in VEGO Links Builder 2.00 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/2/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0004">ADV-2006-0004</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18272">18272</ref><ref source="OSVDB" url="http://www.osvdb.org/22139">22139</ref><ref source="BID" url="http://www.securityfocus.com/bid/16108">16108</ref></refs><vuln_soft><prod name="VEGO Links Builder" vendor="VEGO"><vers num="2.00" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0068" published="2006-01-03" seq="2006-0068" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Primo Cart 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) q parameter to search.php and (2) email parameter to user.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://pridels.blogspot.com/2006/01/primo-cart-sql-inj.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0008">ADV-2006-0008</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18264">18264</ref><ref source="BID" url="http://www.securityfocus.com/bid/16125">16125</ref><ref source="OSVDB" url="http://www.osvdb.org/22146">22146</ref><ref source="OSVDB" url="http://www.osvdb.org/22147">22147</ref><ref source="" url="http://pridels0.blogspot.com/2006/01/primo-cart-sql-inj.html"></ref></refs><vuln_soft><prod name="Primo Cart" vendor="Primo Place"><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0069" published="2006-01-03" seq="2006-0069" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in addentry.php in Chipmunk Guestbook 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the homepage parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420667/100/0/threaded">20060101 [eVuln] Chipmunk Guestbook XSS Vulnerability</ref><ref adv="1" source="" url="http://evuln.com/vulns/4/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16112">16112</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18270">18270</ref><ref source="BID" url="http://www.securityfocus.com/bid/19087">19087</ref></refs><vuln_soft><prod name="Chipmunk Guestbook" vendor="Chipmunk PHP Scripts"><vers num="1.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0070" published="2006-01-03" seq="2006-0070" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of the alert() function.  NOTE: a followup by the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when &quot;Filtered HTML&quot; is enabled, and since &quot;Full HTML&quot; would not filter HTML by design, perhaps this should not be included in CVE.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/420671/100/0/threaded">20060102 Drupal all versiyon xss cehennem.org</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420683/100/0/threaded">20060103 Re: Drupal all versiyon xss cehennem.org</ref></refs><vuln_soft><prod name="Drupal" vendor="Drupal"><vers num="4.5.6"/><vers num="4.6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="9.2" CVSS_score="6.6" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0071" published="2006-01-03" seq="2006-0071" severity="Medium" type="CVE"><desc><descript source="cve">The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files as gid 0.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200601-01.xml">GLSA-200601-01</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16120">16120</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18284">18284</ref><ref source="OSVDB" url="http://www.osvdb.org/22211">22211</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="app-crypt_pinentry" vendor="Gentoo"><vers num="0.7.2 r1"/><vers num="0.7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-12" name="CVE-2006-0072" published="2006-01-03" seq="2006-0072" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in termsh on SCO OpenServer 5.0.7 allows remote attackers to execute arbitrary code via a long -o command line argument.  NOTE: this is probably a different vulnerability than CVE-2005-0351 since it involves a distinct attack vector.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/420677">20060102 SCO Openserver 5.0.x exploit</ref><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/Openserver_bof.c"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16122">16122</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0.7"/><vers num="5.0.6a"/><vers num="5.0.6"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0073" published="2006-01-03" seq="2006-0073" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in DiscusWare Discus Freeware 3.10.5 and Professional 3.10.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a URL, which is not properly sanitized from the resulting error message.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16119">16119</ref><ref source="OSVDB" url="http://www.osvdb.org/22153">22153</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18283">18283</ref></refs><vuln_soft><prod name="Discus Freeware" vendor="DiscusWare"><vers num="3.10.5"/></prod><prod name="Discus Professional" vendor="DiscusWare"><vers num="3.10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0074" published="2006-01-03" seq="2006-0074" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420690/100/0/threaded">20060101 [eVuln] PHPenpals SQL Injection Vulnerabilit</ref><ref source="" url="http://evuln.com/vulns/5/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16109">16109</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0005">ADV-2006-0005</ref><ref source="OSVDB" url="http://www.osvdb.org/22150">22150</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18269">18269</ref></refs><vuln_soft><prod name="PHPenpals" vendor="Jevontech"><vers num="310704"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0075" published="2006-01-03" seq="2006-0075" severity="High" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (mail variable) in a new message, which is written to a PHP file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420698/100/0/threaded">20060101 [eVuln] phpBook PHP Code Execution (phpbook)</ref><ref patch="1" source="" url="http://evuln.com/vulns/6/summary.html"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/16106">16106</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0002">ADV-2006-0002</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18268">18268</ref></refs><vuln_soft><prod name="phpBook" vendor="GNU"><vers num="1.3.2" prev="1"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-21" name="CVE-2006-0076" published="2006-01-03" seq="2006-0076" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420676/100/0/threaded">20060101 [eVuln] oaBoard PHP Code Execution (oaboard)</ref><ref source="" url="http://evuln.com/vulns/3/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16105">16105</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435371/100/0/threaded">20060530 OaBoard 1.0 Remote File inclusion</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435859/100/0/threaded">20060531 Re: OaBoard 1.0 Remote File inclusion</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016211">1016211</ref></refs><vuln_soft><prod name="OaBoard" vendor="OaBoard"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-05" name="CVE-2006-0077" published="2006-01-03" seq="2006-0077" severity="Low" type="CVE"><desc><descript source="cve">Off-by-one error in the getfattr function in File::ExtAttr before 0.03 allows attackers to trigger a buffer overflow via unspecified attack vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=382199&amp;group_id=153116"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16118">16118</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0013">ADV-2006-0013</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18253">18253</ref><ref source="OSVDB" url="http://www.osvdb.org/22160">22160</ref></refs><vuln_soft><prod name="File::ExtAttr" vendor="Richard Dawe"><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0078" published="2006-01-04" seq="2006-0078" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in B-net Software 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) shout variables to (a) shout.php, or the (3) title and (4) message variables to (b) guestbook.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420673/100/0/threaded">20060102 [eVuln] B-net Software Multiple XSS Vulnerabilities</ref><ref adv="1" source="" url="http://evuln.com/vulns/10/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16114">16114</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18271">18271</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0018">ADV-2006-0018</ref><ref source="OSVDB" url="http://www.osvdb.org/22190">22190</ref><ref source="OSVDB" url="http://www.osvdb.org/22191">22191</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/444320/100/0/threaded">20060825 Re: [eVuln] B-net Software Multiple XSS Vulnerabilities</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=442067&amp;group_id=117067"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/316">316</ref></refs><vuln_soft><prod name="B-Net Software" vendor="Haddad Said"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0079" published="2006-01-04" seq="2006-0079" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in auth.php in ScozNet ScozBook BETA 1.1 allows remote attackers to execute arbitrary SQL commands via the username field (adminname variable).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420675/100/0/threaded">20060102 [eVuln] ScozBook &apos;adminname&apos; Authentication Bypass </ref><ref source="" url="http://evuln.com/vulns/11/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16115">16115</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0027">ADV-2006-0027</ref><ref source="OSVDB" url="http://www.osvdb.org/22221">22221</ref><ref source="SREASON" url="http://securityreason.com/securityalert/318">318</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8476">8476</ref></refs><vuln_soft><prod name="ScozBook" vendor="ScozNet"><vers num="1.1 BETA"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-20" name="CVE-2006-0080" published="2006-01-04" seq="2006-0080" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the title of an event, which is not properly filtered by (1) calendar.php and (2) reminder.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420663/100/0/threaded">20060101 [KAPDA::#19] - Html Injection in vBulletin 3.5.2</ref><ref adv="1" source="" url="http://kapda.ir/advisory-177.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16116">16116</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0033">ADV-2006-0033</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18299">18299</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421310/100/0/threaded">20060108 Html_Injection in vBulletin 3.5.2</ref><ref source="OSVDB" url="http://www.osvdb.org/22210">22210</ref><ref source="OSVDB" url="http://www.osvdb.org/22220">22220</ref></refs><vuln_soft><prod name="vBulletin" vendor="Jelsoft"><vers num="3.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-12" name="CVE-2006-0081" published="2006-01-04" seq="2006-0081" severity="High" type="CVE"><desc><descript source="cve">ialmnt5.sys in the ialmrnt5 display driver in Intel Graphics Accelerator Driver 6.14.10.4308 allows attackers to cause a denial of service (crash or screen resolution change) via a long text field, as demonstrated using a long window title.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16127">16127</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18286">18286</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0003.html">20060102 Buffer Overflow vulnerability in Windows Display Manager [Suspected]</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0029.html">20060103 Re: Buffer Overflow vulnerability in Windows Display Manager [Suspected]</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0017">ADV-2006-0017</ref><ref source="OSVDB" url="http://www.osvdb.org/22196">22196</ref></refs><vuln_soft><prod name="Graphics Accelerator Driver" vendor="Intel"><vers num="6.14.10.4308"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0082" published="2006-01-04" seq="2006-0082" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876"></ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-246-1">USN-246-1</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18607">18607</ref><ref adv="1" patch="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:024">MDKSA-2006:024</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12717">12717</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18261">18261</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200602-06.xml">GLSA-200602-06</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0178.html">RHSA-2006:0178</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18851">18851</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18871">18871</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015623">1015623</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200602-13.xml">GLSA-200602-13.xml</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19030">19030</ref><ref patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc">20060301-01-U</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19183">19183</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_06_sr.html">SUSE-SR:2006:006</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19408">19408</ref><ref patch="1" source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.341682">SSA:2006-045-03</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1213">DSA-1213</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22998">22998</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/452718/100/100/threaded">20061127 rPSA-2006-0218-1 ImageMagick</ref><ref source="" url="https://issues.rpath.com/browse/RPL-389"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23090">23090</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:024">MDKSA-2006:024</ref><ref source="SREASON" url="http://securityreason.com/securityalert/500">500</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1">231321</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0412">ADV-2008-0412</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28800">28800</ref></refs><vuln_soft><prod name="ImageMagick" vendor="ImageMagick"><vers num="6.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-10" name="CVE-2006-0083" published="2006-01-09" seq="2006-0083" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the logging code of SMS Server Tools (smstools) 1.14.8 and earlier allows local users to execute arbitrary code via unspecified attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-930">DSA-930</ref><ref source="BID" url="http://www.securityfocus.com/bid/16188">16188</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18343">18343</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18357">18357</ref><ref source="OSVDB" url="http://www.osvdb.org/22287">22287</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24034">smstools-logging-format-string(24034)</ref></refs><vuln_soft><prod name="SMS Server Tools" vendor="Stefan Frings"><vers edition="1.14.8" num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-05" name="CVE-2006-0084" published="2006-01-05" seq="2006-0084" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in index.php in raSMP 2.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the $_SERVER[HTTP_USER_AGENT] variable (User-Agent header).</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/13/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16138">16138</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0030">ADV-2006-0030</ref><ref source="OSVDB" url="http://www.osvdb.org/22198">22198</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18292">18292</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015432">1015432</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-January/000486.html">[VIM] 20060116 vendor ack/fix: 22198: raSMP index.php User-Agent Field XSS (fwd)</ref></refs><vuln_soft><prod name="raSMP" vendor="raSMP"><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-06" name="CVE-2006-0085" published="2006-01-05" seq="2006-0085" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Nkads 1.0 alfa 3 allows remote attackers to execute arbitrary SQL commands via the (1) usuario_nkads_admin or (2) password_nkads_admin parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.soulblack.com.ar/repo/papers/advisory/nkads_advisory.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0040">ADV-2006-0040</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18302">18302</ref><ref source="OSVDB" url="http://www.osvdb.org/22206">22206</ref></refs><vuln_soft><prod name="Nkads" vendor="Nkads"><vers num="1.0alfa3"/><vers num="1.0alfa2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-06" name="CVE-2006-0086" published="2006-01-05" seq="2006-0086" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in index.php in Next Generation Image Gallery 0.0.1 Lite Edition allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0037">ADV-2006-0037</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18309">18309</ref><ref source="" url="http://osvdb.org/ref/22/22202-nextgen.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22202">22202</ref></refs><vuln_soft><prod name="Next Generation Image Gallery" vendor="Next Generation Image Gallery"><vers num="0.0.1 Lite"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-06" name="CVE-2006-0087" published="2006-01-05" seq="2006-0087" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in (1) pages.php and (2) detail.php in Lizard Cart CMS 1.04 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420772/100/0/threaded">20060104 [eVuln] Lizard Cart CMS SQL Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16140">16140</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0029">ADV-2006-0029</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18297">18297</ref><ref source="OSVDB" url="http://www.osvdb.org/22199">22199</ref><ref source="OSVDB" url="http://www.osvdb.org/22200">22200</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015435">1015435</ref><ref source="" url="http://www.evuln.com/vulns/12/summary.html"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/314">314</ref></refs><vuln_soft><prod name="Lizard Cart CMS" vendor="Lizard Cart"><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-06" name="CVE-2006-0088" published="2006-01-05" seq="2006-0088" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in intouch.lib.php in inTouch 0.5.1 Alpha allows remote attackers to execute arbitrary SQL commands via the user parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420672/100/0/threaded">20060101 [eVuln] inTouch Authentication Bypass</ref><ref adv="1" source="" url="http://evuln.com/vulns/8/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16110">16110</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0026">ADV-2006-0026</ref><ref source="OSVDB" url="http://www.osvdb.org/22382">22382</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23954">intouch-intouch-sql-injection(23954)</ref></refs><vuln_soft><prod name="inTouch" vendor="inTouch"><vers num="0.5.1 Alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-06" name="CVE-2006-0089" published="2006-01-05" seq="2006-0089" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in ESRI ArcPad 7.0.0.156 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .amp file with a COORDSYS tag with a long string attribute.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://users.pandora.be/bratax/advisories/b007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16136">16136</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0032">ADV-2006-0032</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18294">18294</ref><ref source="OSVDB" url="http://www.osvdb.org/22208">22208</ref></refs><vuln_soft><prod name="ArcPad" vendor="ESRI"><vers num="7.0.0.156" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-06" name="CVE-2006-0090" published="2006-01-05" seq="2006-0090" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in IDV Directory Viewer before 2005.1 allows remote attackers to view arbitrary directory contents via a .. (dot dot) in the dir parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=382593&amp;group_id=152499"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0031">ADV-2006-0031</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18298">18298</ref><ref source="BID" url="http://www.securityfocus.com/bid/16137">16137</ref></refs><vuln_soft><prod name="IDV Directory Viewer" vendor="IDV Directory Viewer"><vers num="2005.1 b1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-06" name="CVE-2006-0091" published="2006-01-05" seq="2006-0091" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in webmail in Open-Xchange 0.8.1-6 and earlier, with &quot;Inline HTML&quot; enabled, allows remote attackers to inject arbitrary web script or HTML via e-mail attachments, which are rendered inline.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113629092325679&amp;w=2">20060103 Open Xchange XSS</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0034">ADV-2006-0034</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18285">18285</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015431">1015431</ref></refs><vuln_soft><prod name="Open-Xchange" vendor="Open-Xchange"><vers num="0.8.1.6" prev="1"/></prod></vuln_soft></entry><entry modified="2006-04-19" name="CVE-2006-0092" published="2006-01-05" reject="1" seq="2006-0092" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0992, CVE-2006-0158.  Reason: this candidate was intended for one issue, but a typo caused it to be associated with a Novell/Groupwise issue.  In addition, this issue was a duplicate of a SiteSuite issue that was also assigned CVE-2006-0158.  Notes: All CVE users should consult CVE-2006-0992 and CVE-2006-0158 to determine which ID is appropriate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><refs><ref source="SREASON" url="http://securityreason.com/securityalert/709">709</ref></refs></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-12" name="CVE-2006-0093" published="2006-01-05" seq="2006-0093" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in @Card ME PHP allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0039">ADV-2006-0039</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18306">18306</ref><ref source="OSVDB" url="http://www.osvdb.org/22203">22203</ref><ref source="" url="http://osvdb.org/ref/22/22203-ecardmax.txt"></ref></refs><vuln_soft><prod name="@Card ME PHP" vendor="eCardMAX.com"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-12" name="CVE-2006-0094" published="2006-01-05" seq="2006-0094" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_stat parameter, a different vulnerability than CVE-2006-0076. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0028">ADV-2006-0028</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17373">17373</ref></refs><vuln_soft><prod name="oaBoard" vendor="oaBoard"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0095" published="2006-01-06" seq="2006-0095" severity="Low" type="CVE"><desc><descript source="cve">dm-crypt in Linux kernel 2.6.15 and earlier does not clear a structure before it is freed, which leads to a memory disclosure that could allow local users to obtain sensitive information about a cryptographic key.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113640535312572&amp;w=2">[linux-kernel] 20060104 [Patch 2.6] dm-crypt: zero key before freeing it</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113641114812886&amp;w=2">[linux-kernel] 20060104 [Patch 2.6] dm-crypt: Zero key material before free to avoid information leak</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0235">ADV-2006-0235</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18487">18487</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-244-1">USN-244-1</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0004">2006-0004</ref><ref source="BID" url="http://www.securityfocus.com/bid/16301">16301</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:040">MDKSA-2006:040</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0132.html">RHSA-2006:0132</ref><ref source="OSVDB" url="http://www.osvdb.org/22418">22418</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015740">1015740</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19160">19160</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24189">kernel-dmcrypt-information-disclosure(24189)</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427981/100/0/threaded">FLSA:157459-4</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1017">DSA-1017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19374">19374</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00037.html">FEDORA-2006-102</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18527">18527</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18774">18774</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:040">MDKSA-2006:040</ref><ref source="SREASON" url="http://securityreason.com/securityalert/388">388</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.15"/><vers num="2.6.15-rc7"/><vers num="2.6.15-rc6"/><vers num="2.6.15-rc5"/><vers num="2.6.15-rc4"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.13"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11.10"/><vers num="2.6.11.9"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11"/><vers num="2.6.10"/><vers num="2.6.9"/><vers num="2.6.8"/><vers num="2.6.8.1"/><vers num="2.6.7"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1"/><vers num="2.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0096" published="2006-01-06" seq="2006-0096" severity="High" type="CVE"><desc><descript source="cve">wan/sdla.c in Linux kernel 2.6.x before 2.6.11 and 2.4.x before 2.4.29 does not require the CAP_SYS_RAWIO privilege for an SDLA firmware upgrade, with unknown impact and local attack vectors.  NOTE: further investigation suggests that this issue requires root privileges to exploit, since it is protected by CAP_NET_ADMIN; thus it might not be a vulnerability, although capabilities provide finer distinctions between privilege levels.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://www.kernel.org/git/?p=linux/kernel/git/tglx/history.git;a=commitdiff;h=0f1d4813a4a65296e1131f320a60741732bc068f"></ref><ref source="" url="http://linux.bkbits.net:8080/linux-2.4/cset@1.1448.91.23?nav=index.html%7Csrc/%7Csrc/drivers%7Csrc/drivers/net%7Csrc/drivers/net/wan%7Crelated/drivers/net/wan/sdla.c"></ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-244-1">USN-244-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/16304">16304</ref><ref source="MANDRIVA" url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044">MDKSA-2006:044</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18977">18977</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1017">DSA-1017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19374">19374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18527">18527</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.15"/><vers num="2.6.15-rc7"/><vers num="2.6.15-rc6"/><vers num="2.6.15-rc5"/><vers num="2.6.15-rc4"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.13"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11.10"/><vers num="2.6.11.9"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8"/><vers num="2.6.8.1"/><vers num="2.6.7"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1"/><vers num="2.6.0"/><vers num="2.4.28"/><vers num="2.4.27-pre5"/><vers num="2.4.27-pre4"/><vers num="2.4.27-pre3"/><vers num="2.4.27-pre2"/><vers num="2.4.27-pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24-ow1"/><vers num="2.4.24"/><vers num="2.4.23-pre9"/><vers num="2.4.23-ow2"/><vers num="2.4.23"/><vers num="2.4.22"/><vers num="2.4.21-pre7"/><vers num="2.4.21-pre4"/><vers num="2.4.21-pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.19-pre6"/><vers num="2.4.19-pre5"/><vers num="2.4.19-pre4"/><vers num="2.4.19-pre3"/><vers num="2.4.19-pre2"/><vers num="2.4.19-pre1"/><vers num="2.4.19"/><vers num="2.4.18 pre-8"/><vers num="2.4.18 pre-7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3"/><vers num="2.4.2"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-10" name="CVE-2006-0097" published="2006-01-06" seq="2006-0097" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long named pipe variable in the host argument to the mysql_connect function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041013.html">20060105 Windows PHP 4.x &apos;0-day&apos; buffer overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/16145">16145</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0046">ADV-2006-0046</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18275">18275</ref><ref source="OSVDB" url="http://www.osvdb.org/22232">22232</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420986/100/0/threaded">20060105 Windows PHP 4.x </ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0274.html">20060108 RE: Windows PHP 4.x </ref><ref source="" url="http://www.php.net/ChangeLog-4.php#4.4.3"></ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.4.0.2"/><vers num="4.4.0.1"/><vers num="4.4.0.0"/><vers num="4.3.10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0098" published="2006-01-06" seq="2006-0098" severity="Medium" type="CVE"><desc><descript source="cve">The dupfdopen function in sys/kern/kern_descrip.c in OpenBSD 3.7 and 3.8 allows local users to re-open arbitrary files by using setuid programs to access file descriptors using /dev/fd/.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref patch="1" source="OPENBSD" url="http://www.openbsd.org/errata37.html#fd">[3.7] 20060105 008: SECURITY FIX: January 5, 2006</ref><ref patch="1" source="" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/008_fd.patch"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16144">16144</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18296">18296</ref><ref source="OSVDB" url="http://www.osvdb.org/22231">22231</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015437">1015437</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.8"/><vers num="3.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0099" published="2006-01-06" seq="2006-0099" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/templates/categories/ PHP scripts in Valdersoft Shopping Cart 3.0 allows remote attackers to execute arbitrary code via a URL in the catalogDocumentRoot parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/id.php?id=1401"></ref><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/cijfer-vscxpl.pl"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16126">16126</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1401">

1401</ref></refs><vuln_soft><prod name="Valdersoft Shopping Cart" vendor="Valdersoft"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0100" published="2006-01-06" seq="2006-0100" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in NicoFTP 3.0.1.19 and earlier might allow local users to execute arbitrary code via a long string in the &quot;Name of site&quot; field of an FTP account.  NOTE: because this program executes with the privileges of the invoking user, and because remote programs do not normally have the ability to create or modify FTP accounts in this program, there may not be a typical attack vector for the issue that crosses privilege boundaries.  Therefore this may not be a vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420670/100/0/threaded">20060102 NicoFTP Stack Overflow</ref><ref source="SREASON" url="http://securityreason.com/securityalert/317">317</ref></refs><vuln_soft><prod name="NicoFTP" vendor="NicoSW"><vers num="3.0.1.19" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-01-06" modified="2006-05-11" name="CVE-2006-0101" published="2006-01-06" seq="2006-0101" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in sBLOG 0.7.1 Beta 20051202 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p and (2) keyword parameters in (a) index.php and (b) search.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0041">ADV-2006-0041</ref><ref source="" url="http://osvdb.org/ref/22/22373-sblog.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22373">22373</ref><ref source="OSVDB" url="http://www.osvdb.org/22374">22374</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23979">sblog-multiple-scripts-xss(23979)</ref></refs><vuln_soft><prod name="sBLOG" vendor="sBLOG"><vers num="0.7.1 Build2005-12-02 Beta" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-11" name="CVE-2006-0102" published="2006-01-06" seq="2006-0102" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in TinyPHPForum (TPF) 3.6 and earlier allows remote attackers to inject arbitrary web script via a javascript: scheme in an &quot;[a]&quot; bbcode tag, possibly the txt parameter to action.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</ref><ref adv="1" source="" url="http://evuln.com/vulns/14/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0054">ADV-2006-0054</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18293">18293</ref><ref source="OSVDB" url="http://www.osvdb.org/22256">22256</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015436">1015436</ref><ref source="SREASON" url="http://securityreason.com/securityalert/320">320</ref></refs><vuln_soft><prod name="TinyPHPForum" vendor="Ralph Capper"><vers num="3.6"/><vers num="3.5"/><vers num="3.499"/><vers num="3.49"/><vers num="3.48"/><vers num="3.47"/><vers num="3.46"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-11" name="CVE-2006-0103" published="2006-01-06" seq="2006-0103" severity="Medium" type="CVE"><desc><descript source="cve">TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</ref><ref source="" url="http://evuln.com/vulns/14/exploit.html"></ref><ref adv="1" source="" url="http://evuln.com/vulns/14/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0054">ADV-2006-0054</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18293">18293</ref><ref source="OSVDB" url="http://www.osvdb.org/22257">22257</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015436">1015436</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431133/100/0/threaded">20060417 Tiny PHP forum - vulns</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24016">
tinyphpforum-users-information-disclosure(24016)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/320">320</ref></refs><vuln_soft><prod name="TinyPHPForum" vendor="Ralph Capper"><vers num="3.6"/><vers num="3.5"/><vers num="3.499"/><vers num="3.49"/><vers num="3.48"/><vers num="3.47"/><vers num="3.46"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0104" published="2006-01-06" seq="2006-0104" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in TinyPHPForum 3.6 and earlier allows remote attackers to create a new user account, create a new topic, or view the profile of a user account, as demonstrated via a .. (dot dot) in the uname parameter to profile.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</ref><ref source="" url="http://evuln.com/vulns/14/exploit.html"></ref><ref adv="1" source="" url="http://evuln.com/vulns/14/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0054">ADV-2006-0054</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18293">18293</ref><ref source="BID" url="http://www.securityfocus.com/bid/16163">16163</ref><ref source="OSVDB" url="http://www.osvdb.org/22258">22258</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015436">1015436</ref><ref source="SREASON" url="http://securityreason.com/securityalert/320">320</ref></refs><vuln_soft><prod name="TinyPHPForum" vendor="Ralph Capper"><vers num="3.6"/><vers num="3.5"/><vers num="3.499"/><vers num="3.49"/><vers num="3.48"/><vers num="3.47"/><vers num="3.46"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0105" published="2006-01-10" seq="2006-0105" severity="Medium" type="CVE"><desc><descript source="cve">PostgreSQL 8.0.x before 8.0.6 and 8.1.x before 8.1.2, when running on Windows, allows remote attackers to cause a denial of service (postmaster exit and no new connections) via a large number of simultaneous connection requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://archives.postgresql.org/pgsql-announce/2006-01/msg00001.php">[pgsql-announce] 20060109 CRITICAL RELEASE: Minor Releases to Fix DoS Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421592/100/0/threaded">20060111 PostgreSQL security releases 8.0.6 and 8.1.2</ref><ref source="" url="http://www.postgresql.org/about/news.456"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16201">16201</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0114">ADV-2006-0114</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015482">1015482</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18419">18419</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24049">
postgresql-connection-request-dos(24049)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/327">327</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="8.0.5"/><vers num="8.0.4"/><vers num="8.0.3"/><vers num="8.0.2"/><vers num="8.0.1"/><vers num="8.0"/><vers num="8.1.1"/><vers num="8.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0106" published="2006-01-06" seq="2006-0106" severity="High" type="CVE"><desc><descript source="cve">gdi/driver.c and gdi/printdrv.c in Wine 20050930, and other versions, implement the SETABORTPROC GDI Escape function call for Windows Metafile (WMF) files, which allows attackers to execute arbitrary code, the same vulnerability as CVE-2005-4560 but in a different codebase.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2006-January/002806.html">[Dailydave] 20060105 WMF goes away :&lt;</ref><ref patch="1" source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=346197"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0098">ADV-2006-0098</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18323">18323</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200601-09.xml">GLSA-200601-09</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18451">18451</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422128/100/0/threaded">20060117 ERRATA: [ GLSA 200601-09 ] Wine: Windows Metafile SETABORTPROC vulnerability</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:014">MDKSA-2006:014</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_02_sr.html">SUSE-SR:2006:002</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18549">18549</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-954">DSA-954</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18578">18578</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23846">
win-wmf-execute-code(23846)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:014">MDKSA-2006:014</ref></refs><vuln_soft><prod name="Wine" vendor="Wine"><vers num="2005-09-30"/><vers num="0.9.5"/><vers num="0.9.4"/><vers num="0.9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0107" published="2006-01-06" seq="2006-0107" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the viewID parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0108.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16159">16159</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18324">18324</ref><ref source="OSVDB" url="http://www.osvdb.org/22252">22252</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24014">
timecancms-sql-injection(24014)</ref></refs><vuln_soft><prod name="Timecan CMS" vendor="Idea Development ID Oy"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0108" published="2006-01-06" seq="2006-0108" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in mcl_login.asp in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the email parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0107.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0078">ADV-2006-0078</ref><ref source="OSVDB" url="http://www.osvdb.org/22253">22253</ref><ref source="OSVDB" url="http://www.osvdb.org/22252">22252</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24014">
timecancms-sql-injection(24014)</ref></refs><vuln_soft><prod name="Timecan CMS" vendor="Idea Development ID Oy"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-01-06" modified="2006-05-11" name="CVE-2006-0109" published="2006-01-06" seq="2006-0109" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in category.php in Modular Merchant Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16160">16160</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0076">ADV-2006-0076</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18320">18320</ref><ref source="OSVDB" url="http://www.osvdb.org/22243">22243</ref><ref source="" url="http://osvdb.org/ref/22/22243-modular.txt"></ref><ref source="" url="http://www.modularmerchant.com/forums/viewtopic.php?t=46"></ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-February/000548.html">[VIM] 20060214 vendor ack/fix 22243: Modular Merchant Marketplace Shopping Cart category.php cat Variable XSS (fwd)</ref></refs><vuln_soft><prod name="Shopping Cart" vendor="Modular Merchant"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-01-06" modified="2006-05-11" name="CVE-2006-0110" published="2006-01-06" seq="2006-0110" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to inject arbitrary web script via the email parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421056/100/0/threaded">20060106 [eVuln] Proyecto Domus &apos;email&apos; XSS Vulnerability</ref><ref source="" url="http://evuln.com/vulns/16/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16154">16154</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0073">ADV-2006-0073</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18327">18327</ref><ref source="OSVDB" url="http://www.osvdb.org/22263">22263</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24020">
domus-escribir-xss(24020)</ref></refs><vuln_soft><prod name="Foro Domus" vendor="Javier Suarez Sanz"><vers num="2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-01-06" modified="2006-05-11" name="CVE-2006-0111" published="2006-01-06" seq="2006-0111" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in index.php in Boxcar Media Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) parent or (2) pg parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0080">ADV-2006-0080</ref><ref source="" url="http://osvdb.org/ref/22/22360-boxcar.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22360">22360</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24019">boxcar-index-xss(24019)</ref></refs><vuln_soft><prod name="Shopping Cart" vendor="Boxcar Media"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0112" published="2006-01-06" seq="2006-0112" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Enhanced Simple PHP Gallery 1.7 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://osvdb.org/ref/22/22201-espg.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0036">ADV-2006-0036</ref><ref source="OSVDB" url="http://www.osvdb.org/22201">22201</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18310">18310</ref></refs><vuln_soft><prod name="Enhanced Simple PHP Gallery" vendor="Enhanced Simple PHP Gallery"><vers num="1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0113" published="2006-01-06" seq="2006-0113" severity="Medium" type="CVE"><desc><descript source="cve">Enhanced Simple PHP Gallery 1.7 allows remote attackers to obtain the full path of the application via a direct request to sp_helper_functions.php, which leaks the pathname in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="" url="http://osvdb.org/ref/22/22201-espg.txt"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18310">18310</ref><ref source="OSVDB" url="http://www.osvdb.org/22417">22417</ref></refs><vuln_soft><prod name="Enhanced Simple PHP Gallery" vendor="Enhanced Simple PHP Gallery"><vers num="1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-01-09" modified="2006-05-10" name="CVE-2006-0114" published="2006-01-09" seq="2006-0114" severity="Medium" type="CVE"><desc><descript source="cve">The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses to conduct spam attacks by modifying the contact_id parameter to index2.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://forum.joomla.org/index.php/topic,29031.0.html"></ref><ref source="" url="http://forge.joomla.org/sf/go/artf2950"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16185">16185</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0097">ADV-2006-0097</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18361">18361</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24042">
joomla-vcard-information-disclosure(24042)</ref></refs><vuln_soft><prod name="Joomla" vendor="Joomla"><vers num="1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-11" name="CVE-2006-0115" published="2006-01-09" seq="2006-0115" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL commands via the (1) Press_Release_ID parameter in press/details.asp, (2) Service_ID parameter in services/details.asp, and (3) Product_ID parameter in products/details.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16155">16155</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0079">ADV-2006-0079</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18325">18325</ref><ref source="OSVDB" url="http://www.osvdb.org/22248">22248</ref><ref source="OSVDB" url="http://www.osvdb.org/22249">22249</ref><ref source="OSVDB" url="http://www.osvdb.org/22250">22250</ref><ref source="" url="http://osvdb.org/ref/22/22248-oneplug.txt"></ref></refs><vuln_soft><prod name="OnePlug CMS" vendor="OnePlug Solutions"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-11" name="CVE-2006-0116" published="2006-01-09" seq="2006-0116" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability search.inetstore in iNETstore Ebusiness Software 2.0 allows remote attackers to inject arbitrary web script or HTML via the searchterm parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16156">16156</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0075">ADV-2006-0075</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18322">18322</ref><ref source="OSVDB" url="http://www.osvdb.org/22251">22251</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423137/100/0/threaded">20060126 Re: [OSVDB Mods] iNETstore E Commerce Solution - Cross Site Scripting</ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-January/000515.html">[VIM] 20060127 vendor confirms versions: iNETstore E Commerce Solution - Cross Site Scripting (fwd)</ref><ref source="" url="http://osvdb.org/ref/22/22251-inetstore.txt"></ref></refs><vuln_soft><prod name="iNETstore Online" vendor="iNETstore"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0117" published="2006-01-09" seq="2006-0117" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in IBM Lotus Notes and Domino Server before 6.5.5 allows attackers to cause a denial of service (router crash or hang) via unspecified vectors involving &quot;CD to MIME Conversion&quot;.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16158">16158</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18328">18328</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24205">
lotus-cdtomime-dos(24205)</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5"/></prod><prod name="Lotus Domino" vendor="IBM"><vers num="6.5.4 FP 2"/><vers num="6.5.4 FP 1"/><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5.0"/></prod><prod name="Lotus Domino Enterprise Server" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0118" published="2006-01-09" seq="2006-0118" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, allows attackers to cause a denial of service (deep recursion leading to stack overflow and crash) via long formulas.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16158">16158</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18328">18328</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24206">
lotus-long-formula-bo(24206)</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5"/></prod><prod name="Lotus Domino" vendor="IBM"><vers num="6.5.4 FP 2"/><vers num="6.5.4 FP 1"/><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5.0"/></prod><prod name="Lotus Domino Enterprise Server" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-06-30" name="CVE-2006-0119" published="2006-01-09" seq="2006-0119" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to &quot;potential security issues&quot; as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4) GPKS5YQGPT in Security, or (5) HSAO6BNL6Y in the Web Server. NOTE: vector 3 is related to an issue in NROUTER in IBM Lotus Notes and Domino Server before 6.5.4 FP1, 6.5.5, and 7.0, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted vCal meeting request sent via SMTP (aka SPR# KSPR699NBP).</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/f97fe7cfd9a8113b8525709200001db4?OpenDocument&amp;Highlight=0,GPKS6C9J67"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/d1150fc9c5dec8b18525709200001da6?OpenDocument&amp;Highlight=0,GPKS6C9J67"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/94a77eb898843aca8525709200001de1?OpenDocument&amp;Highlight=0,JGAN6B6TZ3"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/de2ab57a5b9547848525701b00420c2c?OpenDocument&amp;Highlight=0,KSPR699NBP"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/e4deb1cbb011c747852570e4001ba9bb?OpenDocument&amp;Highlight=0,GPKS5YQGPT"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/9a1650d1a771f3078525702a00420def?OpenDocument&amp;Highlight=0,HSAO6BNL6Y"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16158">16158</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18328">18328</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/438461/100/0/threaded">20060626 SYMSA-2006-006: Lotus Domino SMTP Based Denial of Service</ref><ref source="BID" url="http://www.securityfocus.com/bid/18020">18020</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2564">ADV-2006-2564</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016390">1016390</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20855">20855</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27413">domino-smtp-nrouter-dos(27413)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24207">
lotus-multiple-unspecified(24207)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24211">
lotus-web-unspecified-xss(24211)</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5"/></prod><prod name="Lotus Domino" vendor="IBM"><vers num="6.5.4 FP 2"/><vers num="6.5.4 FP 1"/><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5.0"/></prod><prod name="Lotus Domino Enterprise Server" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0120" published="2006-01-09" seq="2006-0120" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an &quot;Out Of Office&quot; agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap images (MYAA6FH5HW), (4) the &quot;Delete Attachment&quot; action (YPHG6844LD), (5) parsing certificates from a remote Certificate Table (AELE6DZFJW), and (6) creating a SSL key ring with the Domino Administration client (NSUA4FQPTN).</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/258394eaa824f2c08525708a004209d3?OpenDocument"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/040482aeb1416bb7852570e4001badd6?OpenDocument"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/2bb4f466a9e986ae852570e4001babbb?OpenDocument"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/4118a1f266afb26c852570e4001baf5e?OpenDocument"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/5f166a44ee743b2c852570e4001baf31?OpenDocument"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ad0dd14aa109f96b852570e4001bb08c?OpenDocument"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ced5f873baea4e8b852570e4001baa6d?OpenDocument"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16158">16158</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18328">18328</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24214">
lotus-bmp-dos(24214)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24216">
lotus-certificate-parsing-dos(24216)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24213">
lotus-compact-dos(24213)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24215">
lotus-delete-attachment-dos(24215)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24212">
lotus-outofoffice-dos(24212)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24217">
lotus-ssl-keyring-dos(24217)</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5"/></prod><prod name="Lotus Domino" vendor="IBM"><vers num="6.5.4 FP 2"/><vers num="6.5.4 FP 1"/><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5.0"/></prod><prod name="Lotus Domino Enterprise Server" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0121" published="2006-01-09" seq="2006-0121" severity="High" type="CVE"><desc><descript source="cve">Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (memory consumption and crash) via unknown vectors related to (1) unspecified vectors during the SSL handshake (SPR# MKIN67MQVW), (2) the stash file during the SSL handshake (SPR# MKIN693QUT), and possibly other vectors. NOTE: due to insufficient information in the original vendor advisory, it is not clear whether there is an attacker role in other memory leaks that are specified in the advisory.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/20f66e356a76c90f8525702a00420e08?OpenDocument&amp;Highlight=0,MKIN67MQVW"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/2221243535d88a2b8525701b00420cd6?OpenDocument&amp;Highlight=0,MKIN693QUT"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16158">16158</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18328">18328</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24223">
lotus-ssl-handshake-dos(24223)</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5"/></prod><prod name="Lotus Domino" vendor="IBM"><vers num="6.5.4 FP 2"/><vers num="6.5.4 FP 1"/><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5.0"/></prod><prod name="Lotus Domino Enterprise Server" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-11" name="CVE-2006-0122" published="2006-01-09" seq="2006-0122" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Public/Index.asp in Aquifer CMS allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter.</descript></desc><sols><sol source="nvd">Vendor provided solution:

&quot;Liquid Development has identified this vulnerability in all shipping versions of AquiferCMS and coded a software fix. The fix will be included in all releases of AquiferCMS built on or after January 24, 2006. Customers should contact Liquid Development to obtain the fix for this vulnerability.  For more information visit www.aquifercms.com.&quot; 
</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16162">16162</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0074">ADV-2006-0074</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18326">18326</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22247">22247</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-January/000509.html">[VIM] 20060124 vendor ack/fix: Aquifer CMS Index.asp Keyword Variable XSS (fwd)</ref><ref source="" url="http://osvdb.org/ref/22/22247-aquifer.txt"></ref></refs><vuln_soft><prod name="Aquifer CMS" vendor="Aquifer CMS"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-01-05" modified="2006-05-11" name="CVE-2006-0123" published="2006-01-09" seq="2006-0123" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in ADN Forum 1.0b allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter in index.php and (2) pagid parameter in verpag.php, and possibly other vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420990/100/0/threaded">20060105 [eVuln] ADNForum Multiple Vulnerabilities</ref><ref adv="1" source="" url="http://evuln.com/vulns/15/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16157">16157</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0077">ADV-2006-0077</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015445">1015445</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18300">18300</ref><ref source="OSVDB" url="http://www.osvdb.org/22240">22240</ref><ref source="OSVDB" url="http://www.osvdb.org/22241">22241</ref></refs><vuln_soft><prod name="ADN Forum" vendor="ADN Forum"><vers num="1.0b"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0124" published="2006-01-09" seq="2006-0124" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in crear.php in ADN Forum 1.0b allows remote attackers to inject arbirary web script or HTML via the titulo parameter, which is used by the &quot;Topic name&quot; field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420990/100/0/threaded">20060105 [eVuln] ADNForum Multiple Vulnerabilities</ref><ref adv="1" source="" url="http://evuln.com/vulns/15/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16157">16157</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0077">ADV-2006-0077</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18300">18300</ref><ref source="OSVDB" url="http://www.osvdb.org/22242">22242</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015445">1015445</ref></refs><vuln_soft><prod name="ADN Forum" vendor="ADN Forum"><vers num="1.0b"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0125" published="2006-01-09" seq="2006-0125" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in appserv/main.php in AppServ 2.4.5 allows remote attackers to include arbitrary files via the appserv_root parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  There is not enough detail from these third party sources to know whether this is directory traversal, remote file include, or another issue.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0053">ADV-2006-0053</ref><ref source="OSVDB" url="http://www.osvdb.org/22228">22228</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18163">18163</ref><ref source="BID" url="http://www.securityfocus.com/bid/16166">16166</ref></refs><vuln_soft><prod name="AppServ" vendor="AppServ Open Project"><vers num="2.4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0126" published="2006-01-09" seq="2006-0126" severity="Medium" type="CVE"><desc><descript source="cve">rxvt-unicode before 6.3, on certain platforms that use openpty and non-Unix pty devices such as Linux and most BSD platforms, does not maintain the intended permissions of tty devices, which allows local users to gain read and write access to the devices.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://dist.schmorp.de/rxvt-unicode/Changes"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0052">ADV-2006-0052</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22223">22223</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18301">18301</ref></refs><vuln_soft><prod name="rxvt-unicode" vendor="rxvt-unicode"><vers num="6.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0127" published="2006-01-09" seq="2006-0127" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote authenticated users to rename the folders of other users via a .. (dot dot) in the RENAME command.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040969.html">20060104 Rockliffe Directory Transversal Vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041039.html">20060105 Re: Rockliffe Directory Transversal Vulnerability</ref><ref adv="1" patch="1" source="" url="http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt"></ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22229">22229</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18318">18318</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0055">ADV-2006-0055</ref></refs><vuln_soft><prod name="MailSite" vendor="Rockliffe"><vers num="6.1.22.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0128" published="2006-01-09" seq="2006-0128" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote attackers to have an unknown impact via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040969.html">20060104 Rockliffe Directory Transversal Vulnerability</ref><ref adv="1" patch="1" source="" url="http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39991">rockliffe-imap-unspecified-bo(39991)</ref></refs><vuln_soft><prod name="MailSite" vendor="Rockliffe"><vers num="6.1.22.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0129" published="2006-01-09" seq="2006-0129" severity="Medium" type="CVE"><desc><descript source="cve">Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier generates different responses depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames via user requests to TCP port 106.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040970.html">20060104 Rockliffe Mailsite User Enumeration Flaw</ref><ref adv="1" source="" url="http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18318">18318</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0055">ADV-2006-0055</ref><ref source="OSVDB" url="http://www.osvdb.org/22230">22230</ref></refs><vuln_soft><prod name="MailSite" vendor="Rockliffe"><vers num="7.0.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0130" published="2006-01-09" seq="2006-0130" severity="High" type="CVE"><desc><descript source="cve">Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier allows remote attackers to attempt authentication with an unlimited number of user account names and passwords without denying connections, limiting the rate of connections, or locking out an account.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040970.html">20060104 Rockliffe Mailsite User Enumeration Flaw</ref><ref adv="1" source="" url="http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt"></ref></refs><vuln_soft><prod name="MailSite" vendor="Rockliffe"><vers num="7.0.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0131" published="2006-01-09" seq="2006-0131" severity="Medium" type="CVE"><desc><descript source="cve">boastMachine 3.1 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php and (2) side_menu.php, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420969/100/0/threaded">20060105 [ECHO_ADV_25$2006] Full path disclosure on boastMachine v3.1</ref><ref source="" url="http://echo.or.id/adv/adv26-K-159-2006.txt"></ref></refs><vuln_soft><prod name="BoastMachine" vendor="BoastMachine"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0132" published="2006-01-09" seq="2006-0132" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in webftp.php in SysCP WebFTP 1.2.6 and possibly earlier allows remote attackers to include and execute arbitrary local PHP scripts, and possibly read other types of files, via a .. (dot dot) and a trailing null in the webftp_language parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420973/100/0/threaded">20060104 SysCP WebFTP local file inclusion vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16175">16175</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0090">ADV-2006-0090</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18355">18355</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24018">
webftp-language-file-include(24018)</ref></refs><vuln_soft><prod name="WebFTP" vendor="WebFTP"><vers num="1.2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0133" published="2006-01-09" seq="2006-0133" severity="Low" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and read partial contents of certain files via a .. (dot dot) in the argument to (1) getCommand.new (aka getCommand) and (2) getShell, a different vulnerability than CVE-2005-4273.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420589/100/0/threaded">20060101 [xfocus-SD-060101]AIX getCommand&amp;getShell two vulnerabilities</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015429">1015429</ref><ref source="BID" url="http://www.securityfocus.com/bid/16102">16102</ref><ref source="BID" url="http://www.securityfocus.com/bid/16103">16103</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3 ML03"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0134" published="2006-01-09" seq="2006-0134" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in register.php in TheWebForum (twf) 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the www parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421039/100/0/threaded">20060106 [eVuln] TheWebForum Script Insertion and Authentication Bypass</ref><ref source="" url="http://evuln.com/vulns/17/exploit.html"></ref><ref source="" url="http://evuln.com/vulns/17/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16161">16161</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0093">ADV-2006-0093</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015450">1015450</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18392">18392</ref><ref source="OSVDB" url="http://www.osvdb.org/22295">22295</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24007">
thewebforum-register-xss(24007)</ref></refs><vuln_soft><prod name="TheWebForum" vendor="TheWebForum"><vers num="1.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0135" published="2006-01-09" seq="2006-0135" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421039/100/0/threaded">20060106 [eVuln] TheWebForum Script Insertion and Authentication Bypass</ref><ref source="" url="http://evuln.com/vulns/17/exploit.html"></ref><ref source="" url="http://evuln.com/vulns/17/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16161">16161</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0093">ADV-2006-0093</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015450">1015450</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18392">18392</ref><ref source="OSVDB" url="http://www.osvdb.org/22294">22294</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24027">thewebforum-login-sql-injection(24027)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/321">321</ref></refs><vuln_soft><prod name="TheWebForum" vendor="TheWebForum"><vers num="1.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0136" published="2006-01-09" seq="2006-0136" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the guestbook module in modules.php in Phanatic Softwares Chimera Web Portal System 0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) comment_poster, (2) comment_poster_email, (3) comment_poster_homepage, and (4) comment_text parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420669/100/0/threaded">20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities</ref><ref source="" url="http://evuln.com/vulns/7/exploit.html"></ref><ref source="" url="http://evuln.com/vulns/7/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0025">ADV-2006-0025</ref><ref source="BID" url="http://www.securityfocus.com/bid/16113">16113</ref></refs><vuln_soft><prod name="Chimera Web Portal" vendor="Phanatic Softwares"><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0137" published="2006-01-09" seq="2006-0137" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in linkcategory.php in Phanatic Softwares Chimera Web Portal System 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420669/100/0/threaded">20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities</ref><ref source="" url="http://evuln.com/vulns/7/exploit.html"></ref><ref source="" url="http://evuln.com/vulns/7/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0025">ADV-2006-0025</ref><ref source="BID" url="http://www.securityfocus.com/bid/16113">16113</ref><ref source="OSVDB" url="http://www.osvdb.org/22420">22420</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23963">chimera-linkcategory-sql-injection(23963)</ref></refs><vuln_soft><prod name="Chimera Web Portal" vendor="Phanatic Softwares"><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0138" published="2006-01-09" seq="2006-0138" severity="Medium" type="CVE"><desc><descript source="cve">aMSN (aka Alvaro&apos;s Messenger) allows remote attackers to cause a denial of service (client hang and termination of client&apos;s instant-messaging session) by repeatedly sending crafted data to the default file-transfer port (TCP 6891).</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.securiteam.com/exploits/5JP090KHFQ.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/22186">22186</ref></refs><vuln_soft><prod name="aMSN" vendor="aMSN"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0139" published="2006-01-09" seq="2006-0139" severity="Medium" type="CVE"><desc><descript source="cve">The send-private-message functionality (send-private-message.asp) in PD9 Software MegaBBS 2.1 allows remote attackers to read private messages of other users via a modified replyid parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.hamid.ir/security/megabbs.txt"></ref><ref adv="1" patch="1" source="" url="http://www.pd9soft.com/megabbs/forums/thread-view.asp?tid=4924"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16168">16168</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0095">ADV-2006-0095</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18342">18342</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015452">1015452</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24050">
megabbs-sendprivatemessage-disclosure(24050)</ref></refs><vuln_soft><prod name="MegaBBS" vendor="PD9 Software"><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0140" published="2006-01-09" seq="2006-0140" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in post.php in NavBoard V16 Stable(2.6.0) and V17beta2 allows remote attackers to inject arbitrary web script or HTML via the (1) b, (2) textlarge, and (3) url bbcode tags.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421149/100/0/threaded">20060107 [eVuln] NavBoard BBcode XSS Vulnerability</ref><ref adv="1" source="" url="http://evuln.com/vulns/19/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16165">16165</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0092">ADV-2006-0092</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18345">18345</ref><ref source="OSVDB" url="http://www.osvdb.org/22277">22277</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24021">
navboard-post-xss(24021)</ref></refs><vuln_soft><prod name="Navboard" vendor="Navboard"><vers num="V17 Beta2"/><vers num="V16 Stable2.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-01-09" modified="2006-05-10" name="CVE-2006-0141" published="2006-01-09" seq="2006-0141" severity="Medium" type="CVE"><desc><descript source="cve">Qualcomm Eudora Internet Mail Server (EIMS) before 3.2.8 allows remote attackers to cause a denial of service (crash) via (1) malformed NTLM authentication requests, or a malformed (2) Incoming Mail X or (3) Temporary Mail file.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.eudora.co.nz/updates.html"></ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0099">ADV-2006-0099</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18356">18356</ref><ref source="BID" url="http://www.securityfocus.com/bid/16179">16179</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24033">
eims-corrupted-mail-dos(24033)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24032">
eims-ntlm-auth-dos(24032)</ref></refs><vuln_soft><prod name="Internet Mail Server" vendor="Eudora"><vers num="3.2.8"/><vers num="3.2.7"/><vers num="3.2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0142" published="2006-01-09" seq="2006-0142" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in andromeda.php in Andromeda 1.9.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the s parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0096">ADV-2006-0096</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18359">18359</ref><ref source="BID" url="http://www.securityfocus.com/bid/16183">16183</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24031">
andromeda-script-xss(24031)</ref></refs><vuln_soft><prod name="Andromeda" vendor="Andromeda Software"><vers num="1.9.3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-10" name="CVE-2006-0143" published="2006-01-09" seq="2006-0143" severity="High" type="CVE"><desc><descript source="cve">Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421257/100/0/threaded">20060107 Microsoft Windows GRE WMF Format Multiple Memory Overrun Vulnerabilities</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421258/100/0/threaded">20060109 [UPDATE]Microsoft Windows GRE WMF Format Multiple Unauthorized Memory Access Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16167">16167</ref><ref source="" url="http://blogs.technet.com/msrc/archive/2006/01/09/417198.aspx"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0115">ADV-2006-0115</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015453">1015453</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24044">
win-gre-wmf-dos(24044)</ref><ref source="" url="http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html"></ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Standard 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1" num="Enterprise 64-bit"/><vers edition="SP1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="SP1" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-04-04" name="CVE-2006-0144" published="2006-01-09" seq="2006-0144" severity="High" type="CVE"><desc><descript source="cve">The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16174">16174</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421469/100/0/threaded">20060109 New PEAR / Apache2Triad Exploit</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18390">18390</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0148">ADV-2006-0148</ref><ref source="" url="http://apache2triad.net/forums/viewtopic.php?p=14670"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24076">gopear-proxy-redirection(24076)</ref></refs><vuln_soft><prod name="PEAR" vendor="PHP"><vers num="0.2.2"/></prod><prod name="Apache2Triad" vendor="Apache2Triad"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-09" name="CVE-2006-0145" published="2006-01-09" seq="2006-0145" severity="Medium" type="CVE"><desc><descript source="cve">The kernfs_xread function in kernfs in NetBSD 1.6 through 2.1, and OpenBSD 3.8, does not properly validate file offsets against negative 32-bit values that occur as a result of truncation, which allows local users to read arbitrary kernel memory and gain privileges via the lseek system call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><local/></range><refs><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-001.txt.asc">NetBSD-SA2006-001</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16173">16173</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18388">18388</ref><ref source="OSVDB" url="http://www.osvdb.org/22293">22293</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423827/100/0/threaded">20060202 [SLAB] NetBSD / OpenBSD kernfs_xread patch evasion</ref><ref adv="1" source="" url="http://www.securitylab.net/research/2006/02/advisory_netbsd_openbsd_kernfs.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18712">18712</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24035">
netbsd-kernfs-memory-disclosure(24035)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/405">405</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="2.1"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6 Beta"/><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0146" published="2006-01-09" seq="2006-0146" severity="High" type="CVE"><desc><descript source="cve">The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2005-64/advisory/"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16187">16187</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0101">ADV-2006-0101</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0102">ADV-2006-0102</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0103">ADV-2006-0103</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0104">ADV-2006-0104</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0105">ADV-2006-0105</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/17418">17418</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18254">18254</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18267">18267</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18260">18260</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18276">18276</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18233">18233</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22290">22290</ref><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423784/100/0/threaded">20060202 Bug for libs in php link directory 2.0</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0447">ADV-2006-0447</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18720">18720</ref><ref patch="1" source="" url="http://www.xaraya.com/index.php/news/569"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0370">ADV-2006-0370</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1029">DSA-1029</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1030">DSA-1030</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1031">DSA-1031</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19555">19555</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19590">19590</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19591">19591</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430448/100/0/threaded">20060409 PhpOpenChat 3.0.x ADODB Server.php </ref><ref source="" url="http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html"></ref><ref source="" url="http://www.maxdev.com/Article550.phtml"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1304">ADV-2006-1304</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1305">ADV-2006-1305</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19563">19563</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19600">19600</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml">GLSA-200604-07</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1419">ADV-2006-1419</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19699">19699</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19691">19691</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24051">adodb-server-command-execution(24051)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466171/100/0/threaded">20070418 MediaBeez Sql query Execution .. Wear isn&apos;t ?? :)</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24954">24954</ref><ref source="SREASON" url="http://securityreason.com/securityalert/713">713</ref></refs><vuln_soft><prod name="Mantis" vendor="Mantis"><vers num="1.0.0 rc4"/><vers num="0.19.4"/></prod><prod name="ADOdb" vendor="John Lim"><vers num="4.68"/><vers num="4.66"/></prod><prod name="Moodle" vendor="Moodle"><vers num="1.5.3"/></prod><prod name="Cacti" vendor="The Cacti Group"><vers num="0.8.6g"/></prod><prod name="MediaBeez" vendor="MediaBeez"><vers num=""/></prod><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.761"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-08" name="CVE-2006-0147" published="2006-01-09" seq="2006-0147" severity="High" type="CVE"><desc><descript source="cve">Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2005-64/advisory/"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0101">ADV-2006-0101</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0102">ADV-2006-0102</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0103">ADV-2006-0103</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0104">ADV-2006-0104</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/17418">17418</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18254">18254</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18267">18267</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18260">18260</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18276">18276</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18233">18233</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1029">DSA-1029</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1030">DSA-1030</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1031">DSA-1031</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19555">19555</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19590">19590</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19591">19591</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430448/100/0/threaded">20060409 PhpOpenChat 3.0.x ADODB Server.php </ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430743/100/0/threaded">20060412 Simplog &lt;=0.9.2 multiple vulnerabilities</ref><ref source="" url="http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html"></ref><ref source="" url="http://milw0rm.com/exploits/1663"></ref><ref source="" url="http://retrogod.altervista.org/simplog_092_incl_xpl.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1305">ADV-2006-1305</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1332">ADV-2006-1332</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19600">19600</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19628">19628</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml">GLSA-200604-07</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22291">22291</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19691">
19691</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24052">
adodb-tmssql-command-execution(24052)</ref></refs><vuln_soft><prod name="Mantis" vendor="Mantis"><vers num="1.0.0 rc4"/><vers num="0.19.4"/></prod><prod name="ADOdb" vendor="John Lim"><vers num="4.68"/><vers num="4.66"/></prod><prod name="Moodle" vendor="Moodle"><vers num="1.5.3"/></prod><prod name="Cacti" vendor="The Cacti Group"><vers num="0.8.6g"/></prod><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.761"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0148" published="2006-01-09" seq="2006-0148" severity="Medium" type="CVE"><desc><descript source="cve">NetSarang Xlpd 2.1 allows remote attackers to cause a denial of service (crash) via a large number of connections from the same IP address.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.ipomonis.com/advisories/xlpd.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16164">16164</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015444">1015444</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24041">
xlpd-connection-dos(24041)</ref></refs><vuln_soft><prod name="Xlpd" vendor="NetSarang"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0149" published="2006-01-09" seq="2006-0149" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in SimpBook 1.0, with html_enable on (the default), allows remote attackers to inject arbitrary web script or HTML via the message field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041127.html">20060106 SimpBook &apos;message&apos; Remote Cross-Site Scripting Vulnerability</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1015451">1015451</ref></refs><vuln_soft><prod name="SimpBook" vendor="SimpBook"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-12-22" modified="2006-05-10" name="CVE-2006-0150" published="2006-01-09" seq="2006-0150" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421286/100/0/threaded">20060109 Digital Armaments Security Advisory 01.09.2006: Apache auth_ldap module Multiple Format Strings Vulnerability</ref><ref adv="1" source="" url="http://www.digitalarmaments.com/2006090173928420.html"></ref><ref source="" url="http://www.rudedog.org/auth_ldap/Changes.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16177">16177</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0179.html">RHSA-2006:0179</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0117">ADV-2006-0117</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18382">18382</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18405">18405</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015456">1015456</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-952">DSA-952</ref><ref adv="1" patch="1" source="MANDRIVA" url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:017">MDKSA-2006:017</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18412">18412</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18568">18568</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24030">
apache-authldap-format-string(24030)</ref></refs><vuln_soft><prod name="auth_ldap" vendor="Dave Carrigan"><vers num="1.6.0"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.0"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3.0"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0151" published="2006-01-09" seq="2006-0151" severity="High" type="CVE"><desc><descript source="cve">sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/><env/></vuln_types><range><local/></range><refs><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-235-2">USN-235-2</ref><ref source="BID" url="http://www.securityfocus.com/bid/16184">16184</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18358">18358</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18363">18363</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-946">DSA-946</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_02_sr.html">SUSE-SR:2006:002</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18549">18549</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18906">18906</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0010">2006-0010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18558">18558</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.421822">SSA:2006-045-08</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19016">19016</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:159">MDKSA-2006:159</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21692">21692</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:159">MDKSA-2006:159</ref></refs><vuln_soft><prod name="Sudo" vendor="Todd Miller"><vers num="1.6.8 p9"/><vers num="1.6.8 p8"/><vers num="1.6.8 p7"/><vers num="1.6.8 p5"/><vers num="1.6.8 p2"/><vers num="1.6.8 p12"/><vers num="1.6.8 p1"/><vers num="1.6.8"/><vers num="1.6.7 p5"/><vers num="1.6.7"/><vers num="1.6.6"/><vers num="1.6.5 p2"/><vers num="1.6.5 p1"/><vers num="1.6.5"/><vers num="1.6.4 p2"/><vers num="1.6.4 p1"/><vers num="1.6.4"/><vers num="1.6.3 p7"/><vers num="1.6.3 p6"/><vers num="1.6.3 p5"/><vers num="1.6.3 p4"/><vers num="1.6.3 p3"/><vers num="1.6.3 p2"/><vers num="1.6.3 p1"/><vers num="1.6.3"/><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6"/><vers num="1.5.9"/><vers num="1.5.8"/><vers num="1.5.7"/><vers num="1.5.6"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="powerpc" num="5.10"/><vers edition="i386" num="5.10"/><vers edition="amd64" num="5.10"/><vers edition="powerpc" num="5.04"/><vers edition="i386" num="5.04"/><vers edition="amd64" num="5.04"/><vers edition="ia64 ppc" num="4.1"/><vers edition="ia64 ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0152" published="2006-01-10" seq="2006-0152" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) in search_result.php in phpChamber 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the needle parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16180">16180</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0094">ADV-2006-0094</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18360">18360</ref><ref source="OSVDB" url="http://www.osvdb.org/22282">22282</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24029">phpchamber-searchresult-xss(24029)</ref></refs><vuln_soft><prod name="phpChamber" vendor="phpChamber"><vers num="1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0153" published="2006-01-10" seq="2006-0153" severity="High" type="CVE"><desc><descript source="cve">427BB 2.2 and 2.2.1 verifies authentication credentials based on the username, authenticated, and usertype cookies, which allows remote attackers to bypass authentication by using a valid username and usertype and setting the authenticated cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</ref><ref adv="1" source="" url="http://evuln.com/vulns/18/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16178">16178</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0091">ADV-2006-0091</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18354">18354</ref><ref source="OSVDB" url="http://www.osvdb.org/22274">22274</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24038">427bb-scripts-security-bypass(24038)</ref></refs><vuln_soft><prod name="fourtwosevenbb" vendor="427BB"><vers num="2.2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0154" published="2006-01-10" seq="2006-0154" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in showthread.php in 427BB 2.2 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the ForumID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</ref><ref adv="1" source="" url="http://evuln.com/vulns/18/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16169">16169</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0091">ADV-2006-0091</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18354">18354</ref><ref source="OSVDB" url="http://www.osvdb.org/22275">22275</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24039">427bb-showthread-sql-injection(24039)</ref></refs><vuln_soft><prod name="fourtwosevenbb" vendor="427BB"><vers num="2.2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0155" published="2006-01-10" seq="2006-0155" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in posts.php in 427BB 2.2 and 2.2.1 allows remote attackers to inject arbitrary Javascript via a new message with a url bbcode tag containing a javascript URI.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</ref><ref source="" url="http://evuln.com/vulns/18/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0091">ADV-2006-0091</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18354">18354</ref><ref source="OSVDB" url="http://www.osvdb.org/22276">22276</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24040">427bb-posts-xss(24040)</ref></refs><vuln_soft><prod name="fourtwosevenbb" vendor="427BB"><vers num="2.2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0156" published="2006-01-10" seq="2006-0156" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Foxrum 4.0.4f allows remote attackers to inject arbitrary Javascript via the javascript URI in bbcode url tags in (1) addpost1.php and (2) addtopic1.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421277/100/0/threaded">20060109 [eVuln] Foxrum BBCode XSS Vulnerabilty</ref><ref adv="1" source="" url="http://evuln.com/vulns/20"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16172">16172</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0121">ADV-2006-0121</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18386">18386</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24043">
foxrum-bbcode-xss(24043)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/325">325</ref></refs><vuln_soft><prod name="foxrum" vendor="foxrum"><vers num="4.0.4f"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0157" published="2006-01-10" seq="2006-0157" severity="Medium" type="CVE"><desc><descript source="cve">settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specifies identical values for the passwd and admin_password parameters, then declares the new password string in the new_passwd and confirm_passwd parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/MagicNewsPlus-pw-change.pl"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16182">16182</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18601">18601</ref></refs><vuln_soft><prod name="Magic News Plus" vendor="Reamday Enterprises"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-0158" published="2006-01-10" seq="2006-0158" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in CyberDoc SiteSuite CMS allows remote attackers to execute arbitrary SQL commands via the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://osvdb.org/ref/22/22205-sitesuite.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0038">ADV-2006-0038</ref><ref source="OSVDB" url="http://www.osvdb.org/22205">22205</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18305">18305</ref></refs><vuln_soft><prod name="SiteSuite CMS" vendor="CyberDoc"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0159" published="2006-01-10" seq="2006-0159" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to execute arbitrary SQL commands via the email parameter.  NOTE: the provenance of this information is unknown, although it may be based on post-disclosure analysis of CVE-2006-0110; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0073">ADV-2006-0073</ref><ref source="OSVDB" url="http://www.osvdb.org/22264">22264</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18327">18327</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24017">
domus-escribir-sql-injection(24017)</ref></refs><vuln_soft><prod name="Foro Domus" vendor="Javier Suarez Sanz"><vers num="2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-05" name="CVE-2006-0160" published="2006-01-10" seq="2006-0160" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in add_post.php3 in Venom Board 1.22 allows remote attackers to execute arbitrary SQL commands via the (1) parent, (2) root, and (3) topic_id parameters to post.php3.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113683807903915&amp;w=2">20060109 [eVuln] Venom Board SQL Injection Vulnerability</ref><ref adv="1" source="" url="http://evuln.com/vulns/21/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16176">16176</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113683807903915&amp;w=2">20060109 [eVuln] Venom Board SQL Injection Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0122">ADV-2006-0122</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18383">18383</ref><ref source="OSVDB" url="http://www.osvdb.org/22297">22297</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24046">venomboard-addpost-sql-injection(24046)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/326">326</ref></refs><vuln_soft><prod name="Venom Board" vendor="Venom Board"><vers num="1.22"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0161" published="2006-01-10" seq="2006-0161" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors.  NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101933-1">101933</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0113">ADV-2006-0113</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18371">18371</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015455">1015455</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19087">19087</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1534">oval:org.mitre.oval:def:1534</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="8.0"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0162" published="2006-01-10" seq="2006-0162" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before 0.88 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted UPX files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.clamav.net/doc/0.88/ChangeLog"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16191">16191</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0116">ADV-2006-0116</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18379">18379</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015457">1015457</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200601-07.xml">GLSA-200601-07</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18453">18453</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/385908">VU#385908</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041325.html">20060112 ZDI-06-001: Clam AntiVirus UPX Unpacking Code Execution Vulnerability</ref><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-06-001.html"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-947">DSA-947</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:016">MDKSA-2006:016</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0002/">2006-0002</ref><ref source="OSVDB" url="http://www.osvdb.org/22318">22318</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18478">18478</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18548">18548</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18463">18463</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24047">
clamav-libclamav-upx-bo(24047)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:016">MDKSA-2006:016</ref><ref source="SREASON" url="http://securityreason.com/securityalert/342">342</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.87.1"/><vers num=""/><vers num="0.87"/><vers num="0.86.2"/><vers num="0.86.1"/><vers num="0.86"/><vers num="0.85.1"/><vers num="0.85"/><vers num="0.84 rc2"/><vers num="0.84 rc1"/><vers num="0.84"/><vers num="0.83"/><vers num="0.82"/><vers num="0.81"/><vers num="0.80 rc4"/><vers num="0.80 rc3"/><vers num="0.80 rc2"/><vers num="0.80 rc1"/><vers num="0.80"/><vers num="0.75.1"/><vers num="0.70"/><vers num="0.68.1"/><vers num="0.68"/><vers num="0.67"/><vers num="0.65"/><vers num="0.60"/><vers num="0.54"/><vers num="0.53"/><vers num="0.52"/><vers num="0.51"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-23" name="CVE-2006-0163" published="2006-01-11" seq="2006-0163" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the search module (modules/Search/index.php) of PHPNuke EV 7.7 -R1 allows remote attackers to execute arbitrary SQL commands via the query parameter, which is used by the search field.  NOTE: This is a different vulnerability than CVE-2005-3792.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://lostmon.blogspot.com/2006/01/phpnuke-ev-77-search-module-query.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16186">16186</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0120">ADV-2006-0120</ref><ref source="OSVDB" url="http://www.osvdb.org/22316">22316</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18394">18394</ref></refs><vuln_soft><prod name="PHP-Nuke EV" vendor="Francisco Burzi"><vers num="7.7 r1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0164" published="2006-01-11" seq="2006-0164" severity="High" type="CVE"><desc><descript source="cve">phgstats.inc.php in phgstats before 0.5.1, if register_globals is enabled, allows remote attackers to include arbitrary files and execute arbitrary PHP code by modifying the PHGDIR variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=384232"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0123">ADV-2006-0123</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18346">18346</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24062">phgstats-php-file-include(24062)</ref><ref source="OSVDB" url="http://www.osvdb.org/22302">22302</ref><ref source="BID" url="http://www.securityfocus.com/bid/17469">17469</ref></refs><vuln_soft><prod name="phgstats" vendor="woah-projekt"><vers num="0.5"/><vers num="0.4.2"/><vers num="0.4.1"/><vers num="0.4"/><vers num="0.3.1"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0165" published="2006-01-11" seq="2006-0165" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the DataForm Entries functionality in Plain Black WebGUI before 6.8.4 (gamma) allows remote attackers to inject arbitrary Javascript via the (1) url and (2) name field of the default email form.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=384153&amp;group_id=51417"></ref><ref source="" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1395371&amp;group_id=51417&amp;atid=463213"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0126">ADV-2006-0126</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18372">18372</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24053">webgui-forms-xss(24053)</ref></refs><vuln_soft><prod name="WebGUI" vendor="Plain Black"><vers num="6.8.3 Gamma"/><vers num="6.8.2 Beta"/><vers num="6.8.1 Beta"/><vers num="6.7.8 gamma"/><vers num="6.7.7 Gamma"/><vers num="6.7.6 Gamma"/><vers num="6.7.5 Gamma"/><vers num="6.7.4 Gamma"/><vers num="6.7.3 Gamma"/><vers num="6.7.2 Beta"/><vers num="6.7.1 Beta"/><vers num="6.7.0 Beta"/><vers num="6.6.5"/><vers num="6.6.4 Gamma"/><vers num="6.6.3 Gamma"/><vers num="6.6.2 Gamma"/><vers num="6.6.1 Beta"/><vers num="6.6.0 Beta"/><vers num="6.5.6 Gamma"/><vers num="6.5.5 Gamma"/><vers num="6.5.4 Gamma"/><vers num="6.5.3 Beta"/><vers num="6.5.2 Beta"/><vers num="6.5.1 Beta"/><vers num="6.5.0 Beta"/><vers num="6.4.0 Beta"/><vers num="6.3.0 Beta"/><vers num="6.2.10 Gamma"/><vers num="6.2.11 Gamma"/><vers num="5.5.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-28" name="CVE-2006-0166" published="2006-01-11" seq="2006-0166" severity="High" type="CVE"><desc><descript source="cve">Symantec Norton SystemWorks and SystemWorks Premier 2005 and 2006 stores temporary copies of files in the Norton Protected Recycle Bin NProtect directory, which is hidden from the FindFirst and FindNext Windows APIs and allows remote attackers to hide arbitrary files from virus scanners and other products.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://securityresponse.symantec.com/avcenter/security/Content/2006.01.10.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0143">ADV-2006-0143</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015462">1015462</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18402">18402</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24061">systemworks-nprotect-hidden(24061)</ref></refs><vuln_soft><prod name="Norton System Works" vendor="Symantec"><vers num="2005"/><vers num="2006"/><vers num="2005 Premier"/><vers num="2006 Premier"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-21" name="CVE-2006-0167" published="2006-01-11" seq="2006-0167" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in MyPhPim 01.05 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter in calendar.php3 and the (2) password field on the login page.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/22/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0147">ADV-2006-0147</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18399">18399</ref><ref source="BID" url="http://www.securityfocus.com/bid/16210">16210</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24066">myphpim-calendar-sql-injection(24066)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24075">myphpim-login-sql-injection(24075)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421863/100/0/threaded">20060111 [eVuln] MyPhPim Multiple SQL Injection and XSS Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/22324">22324</ref><ref source="OSVDB" url="http://www.osvdb.org/22325">22325</ref></refs><vuln_soft><prod name="MyPhPim" vendor="MyPhPim"><vers num="01.05"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-21" name="CVE-2006-0168" published="2006-01-11" seq="2006-0168" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in MyPhPim 01.05 allows remote attackers to inject arbitrary web script or HTML via the description field on the &quot;Create New todo&quot; page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/22/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0147">ADV-2006-0147</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18399">18399</ref><ref source="BID" url="http://www.securityfocus.com/bid/16210">16210</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24071">myphpim-todo-xss(24071)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421863/100/0/threaded">20060111 [eVuln] MyPhPim Multiple SQL Injection and XSS Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/22326">22326</ref></refs><vuln_soft><prod name="MyPhPim" vendor="MyPhPim"><vers num="01.05"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-05" name="CVE-2006-0169" published="2006-01-11" seq="2006-0169" severity="High" type="CVE"><desc><descript source="cve">addresses.php3 in MyPhPim 01.05 does not restrict uploaded files, which allows remote attackers to execute arbitrary PHP code via the pdbfile variable, then directly accessing those files from the uploads directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/23/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16208">16208</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0147">ADV-2006-0147</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18399">18399</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421626/100/0/threaded">20060111 [eVuln] MyPhPim Arbitrary File Upload</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24070">myphpim-addresses-file-upload(24070)</ref></refs><vuln_soft><prod name="MyPhPim" vendor="MyPhPim"><vers num="01.05"/></prod></vuln_soft></entry><entry modified="2006-01-19" name="CVE-2006-0170" published="2006-01-11" reject="1" seq="2006-0170" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0035.  Reason: This candidate is a duplicate of CVE-2006-0035.  Notes: All CVE users should reference CVE-2006-0035 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-19" name="CVE-2006-0171" published="2006-01-11" seq="2006-0171" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in index.php in OrjinWeb E-commerce allows remote attackers to execute arbitrary code via a URL in the page parameter.  NOTE: it is not clear, but OrjinWeb might be an application service, in which case it should not be included in CVE.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421312/100/0/threaded">20060106 Orjinweb E-commerce</ref><ref source="BID" url="http://www.securityfocus.com/bid/16199">16199</ref><ref source="OSVDB" url="http://www.osvdb.org/22387">22387</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24097">orjinweb-url-file-include(24097)</ref></refs><vuln_soft><prod name="OrjinWeb E-commerce" vendor="Orjinweb"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0172" published="2006-01-11" seq="2006-0172" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the file manager utility in Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML in an uploaded page, which is published without a check for hostile scripting.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421392/100/0/threaded">20060110 Multiple Vulnerabilities in Hummingbird Collaboration</ref><ref adv="1" source="" url="http://www.securenetwork.it/advisories/sn-2006-01.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16195">16195</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0145">ADV-2006-0145</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18411">18411</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24067">
hummingbird-enterprise-xss(24067)</ref></refs><vuln_soft><prod name="Hummingbird Enterprise Collaboration" vendor="Hummingbird"><vers num="5.21" prev="1"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0173" published="2006-01-11" seq="2006-0173" severity="Medium" type="CVE"><desc><descript source="cve">Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpected content.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421392/100/0/threaded">20060110 Multiple Vulnerabilities in Hummingbird Collaboration</ref><ref adv="1" source="" url="http://www.securenetwork.it/advisories/sn-2006-01.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16195">16195</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0145">ADV-2006-0145</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18411">18411</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24068">
hummingbird-enterprise-file-download(24068)</ref></refs><vuln_soft><prod name="Hummingbird Enterprise Collaboration" vendor="Hummingbird"><vers num="5.21" prev="1"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0174" published="2006-01-11" seq="2006-0174" severity="Medium" type="CVE"><desc><descript source="cve">Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the information in an error message or a cookie.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421392/100/0/threaded">20060110 Multiple Vulnerabilities in Hummingbird Collaboration</ref><ref source="" url="http://www.securenetwork.it/advisories/sn-2006-01.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16195">16195</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0145">ADV-2006-0145</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18411">18411</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24069">
hummingbird-enterprise-information-disclosure(24069)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/328">328</ref></refs><vuln_soft><prod name="Hummingbird Collaboration" vendor="Hummingbird"><vers num="5.21" prev="1"/><vers num="5.2"/></prod><prod name="Hummingbird Enterprise Collaboration" vendor="Hummingbird"><vers num="5.21" prev="1"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0175" published="2006-01-11" seq="2006-0175" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arbitrary web script or HTML via the search parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0299.html">20060109 Advisory:XSS vulnerability on WebWiz Forums &lt;= 6.34 (search_form.asp)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16196">16196</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421615/100/0/threaded">20060111 Advisory:XSS vulnerability on WebWiz Forums &lt;= 6.34 (search_form.asp)</ref><ref source="OSVDB" url="http://www.osvdb.org/22398">22398</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24048">webwizforums-searchform-xss(24048)</ref></refs><vuln_soft><prod name="Web Wiz Forums" vendor="BDC Enterprises"><vers num="6.34"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0176" published="2006-01-11" seq="2006-0176" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in certain functions in src/fileio.c and src/unix/fileio.c in xmame before 11 January 2006 may allow local users to gain privileges via a long (1) -lang, (2) -ctrlr, (3) -pb, or (4) -rec argument on many operating systems, and via a long (5) -jdev argument on Ubuntu Linux.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0353.html">20060110 mysec.org Security Advisory : Xmame buffer overflow, with a possibility of privilege escalation.</ref><ref source="BID" url="http://www.securityfocus.com/bid/16203">16203</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421849/100/0/threaded">20060110 mysec.org Security Advisory : Xmame buffer overflow, with a possibility of privilege escalation</ref><ref source="" url="http://x.mame.net/changes-unix.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24102">
xmame-multiple-parameters-bo(24102)</ref></refs><vuln_soft><prod name="Xmame" vendor="Xmame"><vers num="0.102"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-16" name="CVE-2006-0177" published="2006-01-11" seq="2006-0177" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Cray UNICOS 9.0.2.2 might allow local users to gain privileges by (1) invoking /usr/bin/script with a long command line argument or (2) setting the -c option of /etc/nu to the name of a file containing a long line.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0343.html">20060110 SUID root overflows in UNICOS and partial shellcode</ref><ref source="BID" url="http://www.securityfocus.com/bid/16205">16205</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24276">
unicos-command-line-bo(24276)</ref></refs><vuln_soft><prod name="UNICOS" vendor="Cray"><vers num="9.0.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-16" name="CVE-2006-0178" published="2006-01-11" seq="2006-0178" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in /bin/ftp in UNICOS 9.0.2.2 allows local users to have an unknown impact via format string specifiers in the quote command.  NOTE: because the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0343.html">20060110 SUID root overflows in UNICOS and partial shellcode</ref><ref source="BID" url="http://www.securityfocus.com/bid/16205">16205</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24277">
unicos-ftp-format-string(24277)</ref></refs><vuln_soft><prod name="UNICOS" vendor="Cray"><vers num="9.0.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0179" published="2006-01-11" seq="2006-0179" severity="Medium" type="CVE"><desc><descript source="cve">The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary ports, as demonstrated to port 80.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/cisco_ip7940_dos.pl"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16200">16200</ref><ref source="" url="http://www.milw0rm.com/id.php?id=1411"></ref><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-response-20060113-ip-phones.shtml">20060113 Response to Cisco IP Phone 7940 DoS Exploit posted on milw0rm.com</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0202">ADV-2006-0202</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015488">1015488</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18479">18479</ref><ref source="OSVDB" url="http://www.osvdb.org/22469">22469</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24117">cisco-ipphone-synflood-dos(24117)</ref></refs><vuln_soft><prod name="IP Phone" vendor="Cisco"><vers num="7940"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0180" published="2006-01-12" seq="2006-0180" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the Title field on the &quot;Adding New Event&quot; page, and possibly other vectors, involving iframe tags.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/22322">22322</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24077">calogic-newevent-xss(24077)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422163/100/0/threaded">20060116 [eVuln] CaLogic Calendars Multiple XSS Vulnerabilities</ref><ref adv="1" source="" url="http://evuln.com/vulns/24/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16206">16206</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0149">ADV-2006-0149</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18417">18417</ref></refs><vuln_soft><prod name="CaLogic Calendars" vendor="CaLogic"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0181" published="2006-01-12" seq="2006-0181" severity="High" type="CVE"><desc><descript source="cve">Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.1.3 has an undocumented administrative account with a default password, which allows local users to gain privileges via the expert command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20060111-mars.shtml">20060111 Default Administrative Password in Cisco Security Monitoring, Analysis and Response System (CS-MARS)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16211">16211</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0154">ADV-2006-0154</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015471">1015471</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18424">18424</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24065">cisco-csmars-default-password(24065)</ref><ref source="OSVDB" url="http://www.osvdb.org/22346">22346</ref><ref source="SREASON" url="http://securityreason.com/securityalert/335">335</ref></refs><vuln_soft><prod name="CS-MARS" vendor="Cisco"><vers num="4.1.2"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0182" published="2006-01-12" seq="2006-0182" severity="High" type="CVE"><desc><descript source="cve">login.php in ACal Calendar Project 2.2.5 allows remote attackers to bypass authentication by setting the ACalAuthenticate cookie variable to &quot;inside&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/25/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0152">ADV-2006-0152</ref><ref source="OSVDB" url="http://www.osvdb.org/22344">22344</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18432">18432</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24104">acal-login-auth-bypass(24104)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421744/100/0/threaded">20060112 [eVuln] ACal Authentication Bypass &amp; PHP Code Insertion</ref><ref source="SREASON" url="http://securityreason.com/securityalert/343">343</ref></refs><vuln_soft><prod name="Calendar Project" vendor="ACal"><vers num="2.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0183" published="2006-01-12" seq="2006-0183" severity="Medium" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in edit.php in ACal Calendar Project 2.2.5 allows authenticated users to execute arbitrary PHP code via (1) the edit=header value, which modifies header.php, or (2) the edit=footer value, which modifies footer.php.  NOTE: this issue might be resultant from the poor authentication as identified by CVE-2006-0182.  Since the design of the product allows the administrator to edit the code, perhaps this issue should not be included in CVE, except as a consequence of CVE-2006-0182.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/25/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0152">ADV-2006-0152</ref><ref source="OSVDB" url="http://www.osvdb.org/22345">22345</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18432">18432</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24107">acal-header-footer-code-execute(24107)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421744/100/0/threaded">20060112 [eVuln] ACal Authentication Bypass &amp; PHP Code Insertion</ref><ref source="SREASON" url="http://securityreason.com/securityalert/343">343</ref></refs><vuln_soft><prod name="Calendar Project" vendor="ACal"><vers num="2.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0184" published="2006-01-12" seq="2006-0184" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in AspTopSites allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to goto.asp or (2) password parameter to includeloginuser.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.exploitlabs.com/files/advisories/EXPL-A-2006-001-asptopsites.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0146">ADV-2006-0146</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18408">18408</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24072">asptopsites-goto-sql-injection(24072)</ref><ref source="OSVDB" url="http://www.osvdb.org/22330">22330</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0351.html">20060110 AspTopSites SQL injection</ref></refs><vuln_soft><prod name="AspTopSites" vendor="MaineNet Enterprises"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0185" published="2006-01-12" seq="2006-0185" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/421322">20060107 Php-Nuke Pool and News Module IMG Tag Cross Site</ref><ref source="BID" url="http://www.securityfocus.com/bid/16192">16192</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0125">ADV-2006-0125</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18374">18374</ref></refs><vuln_soft><prod name="PHP-Nuke News Module" vendor="PHP-Nuke"><vers num=""/></prod><prod name="PHP-Nuke Pool Module" vendor="PHP-Nuke"><vers num=""/></prod></vuln_soft></entry><entry modified="2006-01-17" name="CVE-2006-0186" published="2006-01-12" reject="1" seq="2006-0186" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-4500.  Reason: This candidate is a duplicate of CVE-2005-4500.  Notes: All CVE users should reference CVE-2005-4500 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><refs/></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0187" published="2006-01-12" seq="2006-0187" severity="Medium" type="CVE"><desc><descript source="cve">By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0151">ADV-2006-0151</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18409">18409</ref><ref source="BID" url="http://www.securityfocus.com/bid/16225">16225</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421943/100/0/threaded">20060113 Visual Studio Remote Code Execution</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24116">
visualstudio-usercontrol-code-execution(24116)</ref></refs><vuln_soft><prod name="Visual Studio" vendor="Microsoft"><vers num="2005"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-24" name="CVE-2006-0188" published="2006-02-23" seq="2006-0188" severity="Medium" type="CVE"><desc><descript source="cve">webmail.php in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary web pages into the right frame via a URL in the right_frame parameter.  NOTE: this has been called a cross-site scripting (XSS) issue, but it is different than what is normally identified as XSS.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.squirrelmail.org/security/issue/2006-02-01"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16756">16756</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0689">ADV-2006-0689</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015662">1015662</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18985">18985</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24847">squirrelmail-webmail-xss(24847)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-988">DSA-988</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00004.html">FEDORA-2006-133</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:049">MDKSA-2006:049</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_05_sr.html">SUSE-SR:2006:005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19131">19131</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19130">19130</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19176">19176</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-09.xml">GLSA-200603-09</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19205">19205</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0283.html">RHSA-2006:0283</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19960">19960</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:049">MDKSA-2006:049</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.4.6 rc1"/><vers num="1.4.5"/><vers num="1.4.4 RC1"/><vers num="1.4.4"/><vers num="1.4.3 RC1"/><vers num="1.4.3 r3"/><vers num="1.4.3a"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4 RC1"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0189" published="2006-01-13" seq="2006-0189" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in eStara Softphone 3.0.1.14 through 3.0.1.46 allows remote attackers to execute arbitrary code via a long attribute (aka &quot;a&quot;) field in the SDP data of a SIP packet on UDP port 5060.</descript></desc><sols><sol source="nvd">This is the vendor provided solution:

&quot;eStara has released Softphone version 3.0.1.47 to resolve the buffer overflow demonstrated in parsing SDP with long &quot;a=&quot; lines.  Licensed customers can download a new version via the email sent to them with purchase, customers testing may go back to http://www.estara.com/softphone/ to obtain a new free trial.   Version information can be gathered by going to Help-&gt;About.  eStara highly recommends all customers upgrade to avoid this issue.  If there&apos;s further questions please email us: softphone@estara.com.
 
eStara would like to thank ZwelL for bringing the issue to our attention.&quot;</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421596/100/0/threaded">20060111 eStara Softphone SIP stack Buffer Overflow Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16213">16213</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0167">ADV-2006-0167</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015481">1015481</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18410">18410</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24090">estara-sip-sdp-bo(24090)</ref><ref source="OSVDB" url="http://www.osvdb.org/22348">22348</ref></refs><vuln_soft><prod name="Softphone" vendor="eStara"><vers num="3.0.1.14"/><vers num="3.0.1.46"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0190" published="2006-01-13" seq="2006-0190" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors, possibly involving functions from the mm driver.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102066-1">102066</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0165">ADV-2006-0165</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18421">18421</ref><ref source="BID" url="http://www.securityfocus.com/bid/16224">16224</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015478">1015478</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24084">solaris-unspecified-root-access(24084)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19087">19087</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:702">oval:org.mitre.oval:def:702</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="9.0"/><vers edition="SPARC" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0191" published="2006-01-13" seq="2006-0191" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Sun Solaris 10 allows local users to cause a denial of service (null dereference) via unspecified vectors involving the use of the find command on the &quot;/proc&quot; filesystem. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2005-3250.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102108-1">102108</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0166">ADV-2006-0166</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18420">18420</ref><ref source="BID" url="http://www.securityfocus.com/bid/16222">16222</ref><ref source="OSVDB" url="http://www.osvdb.org/22347">22347</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015479">1015479</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24085">solaris-find-proc-dos(24085)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19087">19087</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1608">oval:org.mitre.oval:def:1608</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-03" name="CVE-2006-0192" published="2006-01-13" seq="2006-0192" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Login_Validate.asp in ASPSurvey 1.10 allows remote attackers to execute arbitrary SQL commands via the Password parameter to login.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0164">ADV-2006-0164</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18422">18422</ref><ref source="OSVDB" url="http://www.osvdb.org/22342">22342</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24087">aspsurvey-loginvalidate-sql-injection(24087)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423949/100/0/threaded">20060204 sql injection in ASP Survey</ref><ref source="BID" url="http://www.securityfocus.com/bid/16496">16496</ref><ref source="SREASON" url="http://securityreason.com/securityalert/414">414</ref></refs><vuln_soft><prod name="ASPSurvey" vendor="Philip Loftin"><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0193" published="2006-01-13" seq="2006-0193" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch 8 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter in a login action.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421704/100/0/threaded">20060112 H-Sphere Security Vulnerability</ref><ref source="" url="http://www.psoft.net/HSdocumentation/versions/?v=all&amp;p=r"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0172">ADV-2006-0172</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18447">18447</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24096">hsphere-login-xss(24096)</ref><ref source="OSVDB" url="http://www.osvdb.org/22372">22372</ref><ref source="" url="http://www.psoft.net/HSdocumentation/versions/index.php?v=243p9&amp;p=r"></ref></refs><vuln_soft><prod name="H-Sphere" vendor="Positive Software"><vers num="2.4.3 Patch 8"/><vers num="2.4.3 Patch 7"/><vers num="2.4.3 Patch 6"/><vers num="2.4.3 Patch 5"/><vers num="2.4.3 Patch 4"/><vers num="2.4.3 Patch 3"/><vers num="2.4.3 Patch 2"/><vers num="2.4.3 Patch 1"/><vers num="2.4.3"/><vers num="2.4.3 RC2"/><vers num="2.4.2 Patch 5"/><vers num="2.4.3 RC1"/><vers num="2.4.2 Patch 4"/><vers num="2.4.3 Beta 2"/><vers num="2.4.3 Beta 1"/><vers num="2.4.2 Patch 3"/><vers num="2.4.2 Patch 2"/><vers num="2.4.2 Patch 1"/><vers num="2.4.2"/><vers num="2.4.2 RC2"/><vers num="2.4.1 Patch 7"/><vers num="2.4.2 RC1"/><vers num="2.4.2 Beta 3"/><vers num="2.4.1 Patch 6"/><vers num="2.4.1 Patch 5"/><vers num="2.4.2 Beta 2"/><vers num="2.4.1 Patch 4"/><vers num="2.4.1 Patch 3"/><vers num="2.4.1 Patch 2"/><vers num="2.4.2 Beta 1"/><vers num="2.4.1 Patch 1"/><vers num="2.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0194" published="2006-01-13" seq="2006-0194" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in default.asp in FogBugz 4.029, and other versions before 4.0.33, allows remote attackers to inject arbitrary web script or HTML via the dest parameter in the pgLogon page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421729/100/0/threaded">20060112 FogBugz Cross Site Scripting Vulnerability</ref><ref source="" url="http://www.fogcreek.com/FogBugz/KB/releaseNotes/WhatsNewInFogBugz4.0.33.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16216">16216</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0174">ADV-2006-0174</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18443">18443</ref><ref source="OSVDB" url="http://www.osvdb.org/22370">22370</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24103">fogbugz-login-xss(24103)</ref></refs><vuln_soft><prod name="FogBugz" vendor="Fog Creek Software"><vers num="4.029" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-24" name="CVE-2006-0195" published="2006-02-23" seq="2006-0195" severity="Medium" type="CVE"><desc><descript source="cve">Interpretation conflict in the MagicHTML filter in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via style sheet specifiers with invalid (1) &quot;/*&quot; and &quot;*/&quot; comments, or (2) a newline in a &quot;url&quot; specifier, which is processed by certain web browsers including Internet Explorer.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.squirrelmail.org/security/issue/2006-02-10"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16756">16756</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0689">ADV-2006-0689</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015662">1015662</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18985">18985</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24848">squirrelmail-magichtml-xss(24848)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-988">DSA-988</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00004.html">FEDORA-2006-133</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:049">MDKSA-2006:049</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_05_sr.html">SUSE-SR:2006:005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19131">19131</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19130">19130</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19176">19176</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-09.xml">GLSA-200603-09</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19205">19205</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0283.html">RHSA-2006:0283</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19960">19960</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:049">MDKSA-2006:049</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.4.6 rc1"/><vers num="1.4.5"/><vers num="1.4.4 RC1"/><vers num="1.4.4"/><vers num="1.4.3 RC1"/><vers num="1.4.3 r3"/><vers num="1.4.3a"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4 RC1"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0196" published="2006-01-13" seq="2006-0196" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Serial line sniffer (aka slsnif) 0.4.4 allows local users to gain privileges via a long value of the HOME environment variable, possibly because of a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421583/100/0/threaded">20060111 Serial Line Sniffer 0.4.4 Buffer Overflow</ref><ref source="" url="http://shellcoders.com/sintigan/slsnif-ploit.pl"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24082">slsnif-home-bo(24082)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0212">ADV-2006-0212</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18497">18497</ref></refs><vuln_soft><prod name="Serial Line Sniffer" vendor="Serial Line Sniffer"><vers num="0.4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0197" published="2006-01-13" seq="2006-0197" severity="Medium" type="CVE"><desc><descript source="cve">The XClientMessageEvent struct used in certain components of X.Org 6.8.2 and earlier, possibly including (1) the X server and (2) Xlib, uses a &quot;long&quot; specifier for elements of the l array, which results in inconsistent sizes in the struct on 32-bit versus 64-bit platforms, and might allow attackers to cause a denial of service (application crash) and possibly conduct other attacks.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421256/100/0/threaded">20060108 xorg server 6.8.2 and below on 64bit arch</ref></refs><vuln_soft><prod name="X.Org" vendor="X.Org"><vers num="6.8.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0198" published="2006-01-13" seq="2006-0198" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in a certain module, possibly poll or Pool, for XOOPS allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element in a comment.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421325/100/0/threaded">20060107 Xoops Pool Module IMG Tag Cross Site Scripting</ref><ref adv="1" source="" url="http://www.xoops.org/modules/newbb/viewtopic.php?topic_id=45637&amp;forum=2&amp;post_id=200481"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16189">16189</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24091">
xoops-pool-imagetag-xss(24091)</ref></refs><vuln_soft><prod name="Xoops Pool Module" vendor="Xoops"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0199" published="2006-01-13" seq="2006-0199" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0173">ADV-2006-0173</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18439">18439</ref><ref source="OSVDB" url="http://www.osvdb.org/22384">22384</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24098">mininuke-news-sql-injection(24098)</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421727/100/0/threaded">20060113 Advisory: MiniNuke CMS System &lt;= 1.8.2 (news.asp) SQL Injectionvulnerability</ref><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0439.html">20060112 Advisory: MiniNuke CMS System &lt;= 1.8.2 (news.asp) SQL Injection vulnerability</ref><ref source="" url="http://www.nukedx.com/?viewdoc=7"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/340">340</ref></refs><vuln_soft><prod name="CMS System" vendor="Mini-Nuke"><vers num="1.8.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0200" published="2006-01-13" seq="2006-0200" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421705/100/0/threaded">20060112 Advisory 02/2006: PHP ext/mysqli Format String Vulnerability</ref><ref adv="1" source="" url="http://www.hardened-php.net/advisory_022006.113.html"></ref><ref patch="1" source="" url="http://www.php.net/release_5_1_2.php"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16219">16219</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0177">ADV-2006-0177</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18431">18431</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24095">php-extmysqli-format-string(24095)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015485">1015485</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0369">ADV-2006-0369</ref><ref source="SREASON" url="http://securityreason.com/securityalert/337">337</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.1.1"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0201" published="2006-01-13" seq="2006-0201" severity="Medium" type="CVE"><desc><descript source="cve">Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50, and possibly earlier versions, allows remote attackers to enter false payment entries into the log file via HTTP POST requests to ipn_success.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/421739">20060112 Multiple PHP Toolkit for PayPal Vulnerabilities</ref><ref adv="1" source="" url="http://www.uinc.ru/articles/vuln/ptpaypal050.shtml"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16218">16218</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0183">ADV-2006-0183</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18444">18444</ref><ref source="OSVDB" url="http://www.osvdb.org/22378">22378</ref></refs><vuln_soft><prod name="PHP Toolkit" vendor="PayPal"><vers num="0.50" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0202" published="2006-01-13" seq="2006-0202" severity="Low" type="CVE"><desc><descript source="cve">Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50 and possibly earlier has (1) world-readable permissions for ipn/logs/ipn_success.txt, which allows local users to view sensitive information (payment data), and (2) world-writable permissions for ipn/logs, which allows local users to delete or replace payment data.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/421739">20060112 Multiple PHP Toolkit for PayPal Vulnerabilities</ref><ref adv="1" source="" url="http://www.uinc.ru/articles/vuln/ptpaypal050.shtml"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16218">16218</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0183">ADV-2006-0183</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18444">18444</ref><ref source="OSVDB" url="http://www.osvdb.org/22379">22379</ref></refs><vuln_soft><prod name="PHP Toolkit" vendor="PayPal"><vers num="0.50" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0203" published="2006-01-13" seq="2006-0203" severity="Medium" type="CVE"><desc><descript source="cve">membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other members via a lostpassnew action with a modified x parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0173">ADV-2006-0173</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18439">18439</ref><ref source="OSVDB" url="http://www.osvdb.org/22385">22385</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24101">mininuke-membership-change-password(24101)</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421748/100/0/threaded">20060113 Advisory: MiniNuke CMS System &lt;= 1.8.2 (membership.asp) remoteuser password change exploit</ref><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0439.html">20060112 Advisory: MiniNuke CMS System &lt;= 1.8.2 (news.asp) SQL Injection vulnerability</ref><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0483.html">20060129 [xpl#2] MiniNuke 1.8.2 - change member&apos;s passwrod &lt; Perl &gt;</ref><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0437.html">20060112 Advisory: MiniNuke CMS System &lt;= 1.8.2 (membership.asp) remote user password change exploit</ref><ref source="SREASON" url="http://securityreason.com/securityalert/344">344</ref></refs><vuln_soft><prod name="CMS System" vendor="Mini-Nuke"><vers num="1.8.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-22" name="CVE-2006-0204" published="2006-01-13" seq="2006-0204" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Wordcircle 2.17 allow remote attackers to inject arbitrary web script or HTML via (1) the &quot;Course name&quot; field in index.php when the frm parameter has the value &quot;mine&quot; and (2) possibly certain other fields in unspecified scripts.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421746/100/0/threaded">20060112 [eVuln] Wordcircle Multiple SQL Injection &amp; XSS Vulnerabilities</ref><ref adv="1" source="" url="http://evuln.com/vulns/28/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0185">ADV-2006-0185</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18440">18440</ref><ref source="BID" url="http://www.securityfocus.com/bid/16227">16227</ref><ref source="OSVDB" url="http://www.osvdb.org/22359">22359</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24106">wordcircle-index-xss(24106)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/345">345</ref></refs><vuln_soft><prod name="Wordcircle" vendor="Wordcircle"><vers num="2.17"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-23" name="CVE-2006-0205" published="2006-01-13" seq="2006-0205" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Wordcircle 2.17 allow remote attackers to (1) execute arbitrary SQL commands and bypass authentication via the password field in the login action to index.php (involving v_login.php and s_user.php) and (2) have other unknown impact via certain other fields in unspecified scripts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421745/100/0/threaded">20060112 [eVuln] Wordcircle Authentication Bypass</ref><ref source="" url="http://evuln.com/vulns/27/summary.html"></ref><ref source="" url="http://evuln.com/vulns/28/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16227">16227</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0185">ADV-2006-0185</ref><ref source="OSVDB" url="http://www.osvdb.org/22358">22358</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18440">18440</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24108">wordcircle-login-security-bypass(24108)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24105">wordcircle-sql-injection(24105)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421746/100/0/threaded">20060112 [eVuln] Wordcircle Multiple SQL Injection &amp; XSS Vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/345">345</ref><ref source="SREASON" url="http://securityreason.com/securityalert/346">346</ref></refs><vuln_soft><prod name="Wordcircle" vendor="Wordcircle"><vers num="2.17"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0206" published="2006-01-13" seq="2006-0206" severity="High" type="CVE"><desc><descript source="cve">Eval injection vulnerability in Light Weight Calendar (LWC) 1.0 (20040909) and earlier allows remote attackers to execute arbitrary PHP code via the date parameter in cal.php, which is included by index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/29/summary.html"></ref><ref source="" url="http://evuln.com/vulns/29/exploit.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16229">16229</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18450">18450</ref><ref source="OSVDB" url="http://www.osvdb.org/22376">22376</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24110">lwc-cal-execute-code(24110)</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-March/000612.html">[VIM] 20060318 Source VERIFY - Light Weight Calendar issue is eval injection</ref></refs><vuln_soft><prod name="Light Weight Calendar" vendor="Light Weight Calendar"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0207" published="2006-01-13" seq="2006-0207" severity="Medium" type="CVE"><desc><descript source="cve">Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php.net/release_5_1_2.php"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0177">ADV-2006-0177</ref><ref adv="1" source="" url="http://www.hardened-php.net/advisory_012006.112.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16220">16220</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18431">18431</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24094">php-session-response-splitting(24094)</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015484">1015484</ref><ref adv="1" patch="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:028">MDKSA-2006:028</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18697">18697</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0369">ADV-2006-0369</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-261-1">USN-261-1</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19179">19179</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-22.xml">GLSA-200603-22</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19355">19355</ref><ref source="SUSE" url="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html">SUSE-SR:2006:004</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19012">19012</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1331">DSA-1331</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:028">MDKSA-2006:028</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25945">25945</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.0.5"/><vers num="5.0.0.4"/><vers num="5.0.0.3"/><vers num="5.0.0.2"/><vers num="5.0.0.1"/><vers num="5.0.0 candidate 3"/><vers num="5.0.0 candidate 2"/><vers num="5.0.0 candidate 1"/><vers num="5.0.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-03" name="CVE-2006-0208" published="2006-01-13" seq="2006-0208" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHP 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.php.net/release_5_1_2.php"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0177">ADV-2006-0177</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18431">18431</ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=178028"></ref><ref adv="1" patch="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:028">MDKSA-2006:028</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18697">18697</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0369">ADV-2006-0369</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16803">16803</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-261-1">USN-261-1</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19179">19179</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-22.xml">GLSA-200603-22</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19355">19355</ref><ref source="SUSE" url="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html">SUSE-SR:2006:004</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19012">19012</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0276.html">RHSA-2006:0276</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19832">19832</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0501.html">RHSA-2006:0501</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20222">20222</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2685">ADV-2006-2685</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20951">20951</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21252">21252</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21564">21564</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0549.html">RHSA-2006:0549</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:028">MDKSA-2006:028</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.1.1"/><vers num="5.1.0"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0.0"/><vers num="5.0.0 RC3"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC1"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta1"/><vers num="4.4.2"/><vers num="4.4.1"/><vers num="4.3.11"/><vers num="4.3.10"/><vers num="4.3.9"/><vers num="4.3.8"/><vers num="4.3.7"/><vers num="4.3.6"/><vers num="4.3.5"/><vers num="4.3.4"/><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.3"/><vers num="4.2.2"/><vers num="4.2.1"/><vers num="4.2.0"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1.0"/><vers num="4.0.6"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1"/><vers num="4.0.0"/><vers num="4.0 RC2"/><vers num="4.0 RC1"/><vers num="4.0 Beta 4 Patch Level 1"/><vers num="4.0 Beta 4"/><vers num="4.0 Beta 3"/><vers num="4.0 Beta 2"/><vers num="4.0 Beta 1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-16" name="CVE-2006-0209" published="2006-01-13" seq="2006-0209" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in general_functions.php in TankLogger 2.4 allows remote attackers to execute arbitrary SQL commands via the (1) livestock_id parameter to showInfo.php and (2) tank_id parameter, possibly to livestock.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/26/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0153">ADV-2006-0153</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421743/100/0/threaded">20060112 [eVuln] TankLogger SQL Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16228">16228</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18441">18441</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24080">tanklogger-generalfunctions-sql-injection(24080)</ref><ref source="OSVDB" url="http://www.osvdb.org/22368">22368</ref><ref source="OSVDB" url="http://www.osvdb.org/22369">22369</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-January/000480.html">[VIM] 20060113 Verified TankLogger SQl inject by source inspection</ref><ref source="SREASON" url="http://securityreason.com/securityalert/341">341</ref></refs><vuln_soft><prod name="TankLogger" vendor="TankLogger"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-16" name="CVE-2006-0210" published="2006-01-13" seq="2006-0210" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter when using the Login page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.interspire.com/forum/showthread.php?p=29606"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16214">16214</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421740/100/0/threaded">20060112 Interspire TrackPoint NX XSS Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0175">ADV-2006-0175</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18445">18445</ref><ref source="OSVDB" url="http://www.osvdb.org/22377">22377</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24112">trackpointnx-login-xss(24112)</ref></refs><vuln_soft><prod name="TrackPoint NX" vendor="Interspire"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-16" name="CVE-2006-0211" published="2006-01-13" seq="2006-0211" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421791/100/0/threaded">20060112 Helm XSS Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16234">16234</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0203">ADV-2006-0203</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18492">18492</ref><ref source="OSVDB" url="http://www.osvdb.org/22454">22454</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24139">helm-forgotpassword-xss(24139)</ref><ref source="" url="http://www.webhostautomation.com/webhost-301"></ref></refs><vuln_soft><prod name="Helm Hosting Control Panel" vendor="Helm Hosting"><vers num="3.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0212" published="2006-01-13" seq="2006-0212" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and earlier allows remote attackers to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by ..\\ sequences in the RFILE argument of ussp-push.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113712413907526&amp;w=2">20060113 DMA[2006-0112a] - &apos;Toshiba Bluetooth Stack Directory Transversal&apos;</ref><ref adv="1" source="" url="http://www.digitalmunition.com/DMA%5B2006-0112a%5D.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0184">ADV-2006-0184</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18437">18437</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113712413907526&amp;w=2">20060113 DMA[2006-0112a] - &apos;Toshiba Bluetooth Stack Directory Transversal&apos;</ref><ref source="BID" url="http://www.securityfocus.com/bid/16236">16236</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421993/100/0/threaded">20060113 DMA[2006-0112a] - &apos;Toshiba Bluetooth Stack Directory Transversal&apos;</ref><ref source="OSVDB" url="http://www.osvdb.org/22380">22380</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015486">1015486</ref><ref source="" url="http://aps.toshiba-tro.de/bluetooth/pages/driverinfo.php?txt=sp2"></ref></refs><vuln_soft><prod name="Bluetooth Stack" vendor="Toshiba"><vers num="4.00.23T" prev="1"/><vers num="4.00.11"/><vers num="4.00.01T"/><vers num="3.20.04"/><vers num="3.20.02"/><vers num="3.20.01"/><vers num="3.20.00"/><vers num="3.10.00"/><vers num="3.01.03"/><vers num="3.00.32"/><vers num="3.00.31a"/><vers num="3.00.12"/><vers num="3.00.11"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0213" published="2006-01-13" seq="2006-0213" severity="Medium" type="CVE"><desc><descript source="cve">Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier, when authenticating users via secure SMTP, stores authentication credentials in plaintext in the postfix.log file, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://kolab.org/security/kolab-vendor-notice-08.txt"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0186">ADV-2006-0186</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18438">18438</ref><ref source="OSVDB" url="http://www.osvdb.org/22381">22381</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24123">
kolab-smtp-logging(24123)</ref></refs><vuln_soft><prod name="Kolab Groupware Server" vendor="Kolab"><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2005-12-15 pre2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-16" name="CVE-2006-0214" published="2006-01-15" seq="2006-0214" severity="High" type="CVE"><desc><descript source="cve">Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupload.php, as demonstrated using phpinfo and include function calls.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://pridels.blogspot.com/2006/01/ezdatabase-20-and-below.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/18043">18043</ref><ref source="BID" url="http://www.securityfocus.com/bid/16237">16237</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24136">
ezdatabase-visitorupload-file-include(24136)</ref><ref source="" url="http://pridels0.blogspot.com/2006/01/ezdatabase-20-and-below.html"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/351">351</ref></refs><vuln_soft><prod name="ezDatabase" vendor="IndexCOR"><vers num="2.0"/><vers num="2.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0215" published="2006-01-16" seq="2006-0215" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in admin.php in QualityEBiz Quality PPC (QPPC) 1.0 build 1644 allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.  NOTE: this issue might be resultant from CVE-2006-0216.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://osvdb.org/ref/22/22352-qualityppc.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22352">22352</ref></refs><vuln_soft><prod name="Quality PPC" vendor="QualityEBiz"><vers num="1.0 build 1644"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0216" published="2006-01-16" seq="2006-0216" severity="Medium" type="CVE"><desc><descript source="cve">admin.php in QualityEBiz Quality PPC (QPPC) 1.0 build 1644 allows remote attackers to obtain sensitive information, possibly the installation path of the application, via unspecified &quot;meta characters&quot; to the cpage parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://osvdb.org/ref/22/22352-qualityppc.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22353">22353</ref><ref source="" url="http://osvdb.org/ref/22/22353-qualityppc.txt"></ref></refs><vuln_soft><prod name="Quality PPC" vendor="QualityEBiz"><vers num="1.0 build 1644"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0217" published="2006-01-16" seq="2006-0217" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 3.67 allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in item.pl and (2) category parameter in itemlist.pl, which reflects the XSS in an error message. NOTE: the affected version might be wrong since the current version as of 20060116 is 3.6.1.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16239">16239</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0187">ADV-2006-0187</ref><ref source="OSVDB" url="http://www.osvdb.org/22443">22443</ref><ref source="OSVDB" url="http://www.osvdb.org/22444">22444</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18477">18477</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0517.html">20060115 Ultimate Auction &lt;=3.67</ref><ref source="BID" url="http://www.securityfocus.com/bid/16254">16254</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24138">
ultimate-auction-item-xss(24138)</ref></refs><vuln_soft><prod name="Ultimate Auction" vendor="Ultimate Auction"><vers num="3.67"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2006-0218" published="2006-01-16" seq="2006-0218" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0.2 have unspecified impact and attack vectors, related to (1) admin/moderate.php, (2) admin/themes.php, (3) inc/functions.php, (4) inc/functions_upload.php, (5) printthread.php, and (6) usercp.php, and probably related to SQL injection.  NOTE: it is likely that this issue subsumes CVE-2005-4602 and CVE-2005-4603.  However, since the vendor advisory is vague and additional files are mentioned, is is likely that this contains at least one distinct vulnerability from CVE-2005-4602 and CVE-2005-4603.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://community.mybboard.net/showthread.php?tid=5852"></ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0 Preview Release 2"/><vers num="1.0 &quot;Final&quot;"/><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0219" published="2006-01-16" seq="2006-0219" severity="High" type="CVE"><desc><descript source="cve">The original distribution of MyBulletinBoard (MyBB) to update from older versions to 1.0.2 omits or includes older versions of certain critical files, which allows attackers to conduct (1) SQL injection attacks via an attachment name that is not properly handled by inc/functions_upload.php (CVE-2005-4602), and possibly (2) other attacks related to threadmode in usercp.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://community.mybboard.net/showthread.php?tid=5853&amp;pid=35088#pid35088"></ref><ref source="" url="http://community.mybboard.net/showthread.php?tid=5853&amp;pid=35151#pid35151"></ref><ref patch="1" source="" url="http://community.mybboard.net/showthread.php?tid=5960"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16230">16230</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24115">
mybb-usercp-script-sql-injection(24115)</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0 Preview Release 2"/><vers num="1.0 &quot;Final&quot;"/><vers num="1.01"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-0220" published="2006-01-16" seq="2006-0220" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3 through 6.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the day parameter in calendar.php and (2) the input form in search.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  It is possible that this issue is resultant from an SQL injection problem in CVE-2005-4227.3 and CVE-2005-4227.13.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16232">16232</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421914/100/0/threaded">20060113 DCP Portal Cross-Site Scripting Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24153">
dcpportal-calendar-search-xss(24153)</ref></refs><vuln_soft><prod name="DCP-Portal" vendor="Codeworx Technologies"><vers num="6.1.1"/><vers num="6.1"/><vers num="6.0"/><vers num="5.3.2"/><vers num="5.3.1"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0221" published="2006-01-16" seq="2006-0221" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.asp in the Admin Panel in Dragon Design Services Network (DDSN) cm3 content manager (CM3CMS) allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16231">16231</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421941/100/0/threaded">20060113 DDSN CMS Admin Panel SQL Injection Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/22696">22696</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24266">cm3-login-sql-injection(24266)</ref></refs><vuln_soft><prod name="CM3CMS" vendor="DDSN"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0222" published="2006-01-16" seq="2006-0222" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in fullview.php in AlstraSoft Template Seller Pro allows remote attackers to inject arbitrary web script or HTML via the tempid parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16233">16233</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421916/100/0/threaded">20060113 AlstraSoft Template Seller Pro Cross-Site Scripting Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/22746">22746</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24235">template-seller-fullview-xss(24235)</ref></refs><vuln_soft><prod name="Template Seller" vendor="AlstraSoft"><vers edition="Pro" num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-0223" published="2006-01-16" seq="2006-0223" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Shanghai TopCMM 123 Flash Chat Server Software 5.1 allows attackers to create or overwrite arbitrary files on the server via &quot;..&quot; (dot dot) sequences in the username field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.123flashchat.com/flash-chat-server-v512.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16235">16235</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0198">ADV-2006-0198</ref><ref source="OSVDB" url="http://www.osvdb.org/22440">22440</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18455">18455</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24137">
123flashchat-user-directory-traversal(24137)</ref></refs><vuln_soft><prod name="123 Flash Chat Server" vendor="TopCMM Computing"><vers num="5.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-31" name="CVE-2006-0224" published="2006-01-24" seq="2006-0224" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Library of Assorted Spiffy Things (LibAST) 0.6.1 and earlier, as used in Eterm and possibly other software, allows local users to execute arbitrary code as the utmp user via a long -X command line argument (alternative configuration file name).</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="" url="http://freshmeat.net/projects/libast/?branch_id=17907&amp;release_id=217840"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16350">16350</ref><ref source="" url="http://freshmeat.net/projects/libast/?branch_id=17907&amp;release_id=217840"></ref><ref adv="1" patch="1" source="" url="http://www.rosiello.org/en/read_bugs.php?id=25"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0314">ADV-2006-0314</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423207/100/0/threaded">20060123 [ Rosiello Security ] Eterm-LibAST Advisory</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423366/100/0/threaded">20060123 LibAST 0.7 Release Fixes Security Vulnerability</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423088/100/0/threaded">20060125 Rosiello Security - Eterm-LibAST Advisory</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200601-14.xml">GLSA-200601-14</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18586">18586</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18632">18632</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:029">MDKSA-2006:029</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-976">DSA-976</ref><ref source="OSVDB" url="http://www.osvdb.org/22735">22735</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18916">18916</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24303">eterm-libast-filename-bo(24303)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:029">MDKSA-2006:029</ref><ref source="SREASON" url="http://securityreason.com/securityalert/373">373</ref></refs><vuln_soft><prod name="LibAST" vendor="LibAST"><vers num="0.6.1"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-0225" published="2006-01-25" seq="2006-0225" severity="Medium" type="CVE"><desc><descript source="cve">scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174026"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16369">16369</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0306">ADV-2006-0306</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18579">18579</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18595">18595</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0004">2006-0004</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015540">1015540</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24305">openssh-scp-command-execution(24305)</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:034">MDKSA-2006:034</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18650">18650</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18736">18736</ref><ref source="OPENBSD" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/005_ssh.patch">20060212 [3.8] 005: SECURITY FIX: February 12, 2006</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_08_openssh.html">SuSE-SA:2006:008</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18798">18798</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18850">18850</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/425397/100/0/threaded">FLSA-2006:168935</ref><ref source="OPENPKG" url="http://www.openpkg.org/security/OpenPKG-SA-2006.003-openssh.html">OpenPKG-SA-2006.003</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.425802">SSA:2006-045-06</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18910">18910</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200602-11.xml">GLSA-200602-11</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-255-1">USN-255-1</ref><ref source="OSVDB" url="http://www.osvdb.org/22692">22692</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18964">18964</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18969">18969</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18970">18970</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0044.html">RHSA-2006:0044</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19159">19159</ref><ref source="" url="http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688"></ref><ref source="" url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=2751"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2490">ADV-2006-2490</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20723">20723</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0298.html">RHSA-2006:0298</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21129">21129</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc">20060703-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21262">21262</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-158.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21492">21492</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-174.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21724">21724</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0698.html">RHSA-2006:0698</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22196">22196</ref><ref source="HP" url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00815112">HPSBUX02178</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4869">ADV-2006-4869</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23241">23241</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-262.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23340">23340</ref><ref source="" url="http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html"></ref><ref source="" url="http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23680">23680</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="" url="http://blogs.sun.com/security/entry/sun_alert_102961_security_vulnerability"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-246.htm"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:034">MDKSA-2006:034</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102961-1">102961</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2120">ADV-2007-2120</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1138">oval:org.mitre.oval:def:1138</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25607">25607</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25936">25936</ref><ref source="SREASON" url="http://securityreason.com/securityalert/462">462</ref></refs><vuln_soft><prod name="OpenSSH" vendor="OpenBSD"><vers num="4.2 p1"/><vers num="4.1 p1"/><vers num="4.0 p1"/><vers num="3.0 p1"/><vers num="3.0"/><vers num="3.0.1 p1"/><vers num="3.0.1"/><vers num="3.0.2 p1"/><vers num="3.0.2"/><vers num="3.1 p1"/><vers num="3.1"/><vers num="3.2"/><vers num="3.2.2 p1"/><vers num="3.2.3 p1"/><vers num="3.3 p1"/><vers num="3.3"/><vers num="3.4 p1"/><vers num="3.4"/><vers num="3.5"/><vers num="3.5 p1"/><vers num="3.6"/><vers num="3.6.1 p1"/><vers num="3.6.1 p2"/><vers num="3.6.1"/><vers num="3.7"/><vers num="3.7.1 p2"/><vers num="3.7.1"/><vers num="3.8"/><vers num="3.8.1 p1"/><vers num="3.8.1"/><vers num="3.9"/><vers num="3.9.1 p1"/><vers num="3.9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0226" published="2006-01-18" seq="2006-0226" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in IEEE 802.11 network subsystem (ieee80211_ioctl.c) in FreeBSD before 6.0-STABLE, while scanning for wireless networks, allows remote attackers to execute arbitrary code by broadcasting crafted (1) beacon or (2) probe response frames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.signedness.org/advisories/sps-0x1.txt"></ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:05.80211.asc">FreeBSD-SA-06:05</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16296">16296</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18353">18353</ref><ref source="OSVDB" url="http://www.osvdb.org/22537">22537</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015518">1015518</ref><ref source="" url="http://kernelwars.blogspot.com/2007/01/alive.html"></ref><ref source="" url="http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Eriksson"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24192">
bsd-ieee80211-bo(24192)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.0 Stable"/><vers num="6.0 Release"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="4.9" CVSS_score="2.6" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0227" published="2006-01-17" seq="2006-0227" severity="Low" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to delete arbitrary files or disable the LP print service via unknown attack vectors.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102033-1">102033</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0200">ADV-2006-0200</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015492">1015492</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18498">18498</ref><ref source="OSVDB" url="http://www.osvdb.org/22441">22441</ref><ref source="OSVDB" url="http://www.osvdb.org/22442">22442</ref><ref source="BID" url="http://www.securityfocus.com/bid/16245">16245</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19087">19087</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:662">oval:org.mitre.oval:def:662</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24127">
solaris-lpsched-dos(24127)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="9.1"/><vers edition="SPARC" num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="x86" num="10.0"/><vers edition="SPARC" num="10.0"/><vers edition="SPARC" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0228" published="2006-01-17" seq="2006-0228" severity="High" type="CVE"><desc><descript source="cve">The RBAC functionality in grsecurity before 2.1.8 does not properly handle when the admin role creates a service and then exits the shell without unauthenticating, which causes the service to be restarted with the admin role still active.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://www.grsecurity.org/news.php#grsec218"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16261">16261</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0199">ADV-2006-0199</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18458">18458</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24156">
grsecurity-rbac-admin-privileges(24156)</ref></refs><vuln_soft><prod name="grsecurity Kernel Patch" vendor="grsecurity"><vers num="2.1.7"/><vers num="2.1.6"/><vers num="2.1.5"/><vers num="2.1.4"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1.0"/><vers num="2.0.2"/><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0229" published="2006-01-17" seq="2006-0229" severity="Low" type="CVE"><desc><descript source="cve">Unquoted Windows search path vulnerability in Wehntrust might allow local users to gain privileges via a malicious &quot;program.exe&quot; file in the C: folder, which is run when Wehntrust creates the autostart key.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422020/100/0/threaded">20060116 WehnTrust - When you have to trust Wehntrust</ref><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/422046/100/0/threaded">20060116 Re: [Full-disclosure] WehnTrust - When you have to trust Wehntrust</ref><ref source="BID" url="http://www.securityfocus.com/bid/16268">16268</ref><ref source="" url="http://www.wehnus.com/downloads.pl"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24315">
wehntrust-service-start-file-execution(24315)</ref></refs><vuln_soft><prod name="WehnTrust" vendor="Wehnus"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-0230" published="2006-04-24" seq="2006-0230" severity="High" type="CVE"><desc><descript source="cve">Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses a client-side check to verify a password, which allows remote attackers to gain administrator privileges via a modified client that sends certain XML requests.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0010.html">20060421 Rapid7 Advisory R7-0021: Symantec Scan Engine Authentication Fundamental Design Error</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431734/100/0/threaded">20060421 [Symantec Security Advisor] Symantec Scan Engine Multiple Vulnerabilities</ref><ref source="" url="http://www.symantec.com/avcenter/security/Content/2006.04.21.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17637">17637</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1464">ADV-2006-1464</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19734">19734</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/118388">VU#118388</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431724/100/0/threaded">20060421 Rapid7 Advisory R7-0021: Symantec Scan Engine Authentication Fundamental Design Error</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25972">
sse-unauth-admin-access(25972)</ref></refs><vuln_soft><prod name="Scan Engine" vendor="Symantec"><vers num="5.0.0.24"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-0231" published="2006-04-24" seq="2006-0231" severity="Medium" type="CVE"><desc><descript source="cve">Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses the same private DSA key for each installation, which allows remote attackers to conduct man-in-the-middle attacks and decrypt communications.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0011.html">20060421 Rapid7 Advisory R7-0022: Symantec Scan Engine Known Immutable DSA Private Key</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431725/100/0/threaded">20060421 Rapid7 Advisory R7-0022: Symantec Scan Engine Known Immutable DSA Private Key</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431734/100/0/threaded">20060421 [Symantec Security Advisor] Symantec Scan Engine Multiple Vulnerabilities</ref><ref source="" url="http://www.symantec.com/avcenter/security/Content/2006.04.21.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17637">17637</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1464">ADV-2006-1464</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015974">1015974</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19734">19734</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25973">
sse-insecure-private-key(25973)</ref></refs><vuln_soft><prod name="Scan Engine" vendor="Symantec"><vers num="5.0.0.24"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-0232" published="2006-04-24" seq="2006-0232" severity="Medium" type="CVE"><desc><descript source="cve">Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with insufficient access control, which allows remote attackers to obtain the information via direct requests.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0012.html">20060421 Rapid7 Advisory R7-0023: Symantec Scan Engine File Disclosure Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431728/100/0/threaded">20060421 Rapid7 Advisory R7-0023: Symantec Scan Engine File Disclosure Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431734/100/0/threaded">20060421 [Symantec Security Advisor] Symantec Scan Engine Multiple Vulnerabilities</ref><ref source="" url="http://www.symantec.com/avcenter/security/Content/2006.04.21.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17637">17637</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1464">ADV-2006-1464</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015974">1015974</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19734">19734</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25974">
sse-unauth-file-access(25974)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/758">758</ref><ref source="SREASON" url="http://securityreason.com/securityalert/759">759</ref></refs><vuln_soft><prod name="Scan Engine" vendor="Symantec"><vers num="5.0.0.24"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0233" published="2006-01-17" seq="2006-0233" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in functions.php in microBlog 2.0 RC-10 allows remote attackers to inject arbitrary web script and HTML via a javascript: URI in a [url] BBcode tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422145/100/0/threaded">20060117 [eVuln] microBlog BBCode XSS Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16272">16272</ref><ref source="" url="http://evuln.com/vulns/36/summary.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015496">1015496</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24140">microblog-functions-xss(24140)</ref></refs><vuln_soft><prod name="microBlog" vendor="microBlog"><vers num="2.0 rc10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0234" published="2006-01-17" seq="2006-0234" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in microBlog 2.0 RC-10 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422141/100/0/threaded">20060117 [eVuln] microBlog SQL Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16270">16270</ref><ref source="" url="http://evuln.com/vulns/35/summary.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0239">ADV-2006-0239</ref><ref source="OSVDB" url="http://www.osvdb.org/22512">22512</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015496">1015496</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18442">18442</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24132">
microblog-index-sql-injection(24132)</ref></refs><vuln_soft><prod name="microBlog" vendor="microBlog"><vers num="2.0 rc10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0235" published="2006-01-17" seq="2006-0235" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in WhiteAlbum 2.5 allows remote attackers to execute arbitrary SQL commands via the dir parameter to pictures.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422105/100/0/threaded">20060116 White Album Sql &amp;#304;njection biyosecurity.be</ref><ref source="BID" url="http://www.securityfocus.com/bid/16247">16247</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18460">18460</ref><ref source="" url="http://www.biyosecurity.be/bugs/whitealbum.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0241">ADV-2006-0241</ref><ref source="OSVDB" url="http://www.osvdb.org/22520">22520</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24271">
whitealbum-pictures-sql-injection(24271)</ref></refs><vuln_soft><prod name="White Album" vendor="White Angle"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0236" published="2006-01-17" seq="2006-0236" severity="Medium" type="CVE"><desc><descript source="cve">GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an attachment with a filename containing a large number of spaces ending with a dangerous extension that is not displayed by Thunderbird, along with an inconsistent Content-Type header, which could be used to trick a user into downloading dangerous content by dragging or saving the attachment.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422148/100/0/threaded">20060117 Secunia Research: Mozilla Thunderbird Attachment SpoofingVulnerability</ref><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2005-22/advisory"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=300246"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16271">16271</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0230">ADV-2006-0230</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15907">15907</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:021">MDKSA-2006:021</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24164">
thunderbird-attachment-ext-spoofing(24164)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:021">MDKSA-2006:021</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0237" published="2006-01-17" seq="2006-0237" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in GTP iCommerce allows remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) subcat parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16255">16255</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0214">ADV-2006-0214</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18470">18470</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24150">
gtpicommerce-index-xss(24150)</ref></refs><vuln_soft><prod name="iCommerce" vendor="GTP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0238" published="2006-01-17" seq="2006-0238" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in wp-stats.php in GaMerZ WP-Stats 2.0 allows remote attackers to execute arbitrary SQL commands via the author parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.lesterchan.net/blogs/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16241">16241</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0192">ADV-2006-0192</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18471">18471</ref><ref source="" url="http://osvdb.org/ref/22/22450-wpstats.txt"></ref><ref source="" url="http://www.lesterchan.net/blogs/archives/2006/01/18/wp-stats-sql-injection-vulnerability"></ref><ref source="OSVDB" url="http://www.osvdb.org/22450">22450</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24163">
wpstats-script-sql-injection(24163)</ref></refs><vuln_soft><prod name="WP-Stats" vendor="GaMerZ"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0239" published="2006-01-17" seq="2006-0239" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Simple Blog 2.1 allow remote attackers to inject arbitrary web script or HTML via (1) a comment to comments.asp and (2) possibly certain other fields in unspecified scripts.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422102/100/0/threaded">20060114 [HSC Security Group] Multiple SQL injection/XSS in SimpleBlog 2.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/16243">16243</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0194">ADV-2006-0194</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18488">18488</ref><ref source="" url="http://www.hackerscenter.com/archive/view.asp?id=21926"></ref><ref source="OSVDB" url="http://www.osvdb.org/22448">22448</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24154">
simpleblog-comment-xss(24154)</ref></refs><vuln_soft><prod name="Simple Blog" vendor="8pixel.net"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0240" published="2006-01-17" seq="2006-0240" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote attackers to execute arbitrary SQL commands via the month parameter in an archives view operation and possibly certain other parameters in unspecified scripts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/422102/100/0/threaded">20060114 [HSC Security Group] Multiple SQL injection/XSS in SimpleBlog 2.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/16243">16243</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0194">ADV-2006-0194</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18488">18488</ref><ref source="" url="http://www.hackerscenter.com/archive/view.asp?id=21926"></ref><ref source="OSVDB" url="http://www.osvdb.org/22447">22447</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24155">simpleblog-month-sql-injection(24155)</ref></refs><vuln_soft><prod name="Simple Blog" vendor="8pixel.net"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0241" published="2006-01-17" seq="2006-0241" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in WBNews 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the Name field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422133/100/0/threaded">20060117 XSS in WBNews &lt; = v1.1.0</ref><ref source="BID" url="http://www.securityfocus.com/bid/16277">16277</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0237">ADV-2006-0237</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18499">18499</ref></refs><vuln_soft><prod name="WBNews" vendor="WebMobo"><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0242" published="2006-01-17" seq="2006-0242" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in index.php in PHP Fusebox 4.0.6 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422124/100/0/threaded">20060117 IndonesiaHack Advisory HTML injection in PHP Fusebox</ref><ref source="BID" url="http://www.securityfocus.com/bid/16274">16274</ref><ref source="SREASON" url="http://securityreason.com/securityalert/355">355</ref></refs><vuln_soft><prod name="PHP Fusebox" vendor="PHP Fusebox"><vers num="4.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0243" published="2006-01-17" seq="2006-0243" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in SMBCMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the text parameter, which is used by the &quot;Search Site&quot; field.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16281">16281</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0229">ADV-2006-0229</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18454">18454</ref><ref source="OSVDB" url="http://www.osvdb.org/22494">22494</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24187">
smbcms-sitesearch-xss(24187)</ref></refs><vuln_soft><prod name="SMBCMS" vendor="SMBCMS"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0244" published="2006-01-17" seq="2006-0244" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED ** Directory traversal vulnerability in workspaces.php in phpXplorer 0.9.33 allows remote attackers to include arbitrary files via a .. (dot dot) and trailing null byte (%00) in the sShare parameter.  NOTE: a followup post claims that this is not a vulnerability since the functionality of phpXplorer supports the upload of PHP files, which would not cross privilege boundaries since the PHP functionality would support read access outside the web root.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421997/100/0/threaded">20060116 Directory traversal in phpXplorer</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422158/100/0/threaded">20060116 Re: Directory traversal in phpXplorer</ref><ref adv="1" source="" url="http://www.arrelnet.com/advisories/adv20060116.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16263">16263</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0232">ADV-2006-0232</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18518">18518</ref><ref source="SREASON" url="http://securityreason.com/securityalert/353">353</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39982">phpxplorer-sshare-directory-traversal(39982)</ref></refs><vuln_soft><prod name="phpXplorer" vendor="phpXplorer"><vers num="0.9.33"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-30" name="CVE-2006-0245" published="2006-01-17" seq="2006-0245" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.7-pl1 allow remote attackers to inject arbitrary web script or HTML via the (3) redir, (4) productId, (5) docId, (6) act, and (7) catId parameters in index.php; and the (8) username field in a login action in index.php.  NOTE: the cart.php/redir and index.php/searchStr vectors are already covered by CVE-2005-3152.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://bugs.cubecart.com/?do=details&amp;id=459"></ref><ref adv="1" source="" url="http://lostmon.blogspot.com/2006/01/cubecart-307-pl1-indexphp-multiple.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16259">16259</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0227">ADV-2006-0227</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18519">18519</ref><ref source="OSVDB" url="http://www.osvdb.org/22471">22471</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24177">
cubecart-index-script-xss(24177)</ref></refs><vuln_soft><prod name="CubeCart" vendor="Devellion"><vers num="3.0.7-pl1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0246" published="2006-01-17" seq="2006-0246" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in down.pl in Widexl Download Tracker 1.06 allows remote attackers to inject arbitrary web script or HTML via the ID parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16265">16265</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0213">ADV-2006-0213</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18472">18472</ref><ref source="" url="http://osvdb.org/ref/22/22462-widexl.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22462">22462</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24161">
downloadtracker-down-xss(24161)</ref></refs><vuln_soft><prod name="Download Tracker" vendor="Widexl"><vers num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0247" published="2006-01-17" seq="2006-0247" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in anyboard.cgi in Netbula Anyboard 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the tK parameter in a find command.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16264">16264</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0188">ADV-2006-0188</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18469">18469</ref><ref source="" url="http://osvdb.org/ref/22/22461-anyboard.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22461">22461</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24167">
netbula-anyboard-script-xss(24167)</ref></refs><vuln_soft><prod name="Anyboard" vendor="Netbula"><vers num="9.9.5.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0248" published="2006-01-17" seq="2006-0248" severity="Medium" type="CVE"><desc><descript source="cve">Virata-EmWeb web server 6_1_0, as used in (1) Intracom JetSpeed 500 and 520 and (2) Allied Data Technologies CopperJet 811 RouterPlus, allows remote attackers to access privileged information, such as user lists and configuration settings, via direct HTTP requests.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://blog.globalnetworks.gr/?p=4"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0218">ADV-2006-0218</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18483">18483</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24304">
virata-emweb-unauth-access(24304)</ref></refs><vuln_soft><prod name="JetSpeed" vendor="Intracom"><vers num="500"/><vers num="520"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0249" published="2006-01-17" seq="2006-0249" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in viewcat.php in BitDamaged geoBlog MOD_1.0 allows remote attackers to execute arbitrary SQL commands, then steal credentials and upload files, via the cat parameter ($tmpCategory variable).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/33/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16249">16249</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0191">ADV-2006-0191</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18504">18504</ref><ref source="OSVDB" url="http://www.osvdb.org/22463">22463</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015493">1015493</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24146">
geoBlog-viewcat-sql-injection(24146)</ref></refs><vuln_soft><prod name="geoBlog" vendor="BitDamaged"><vers num="MOD_1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0250" published="2006-01-17" seq="2006-0250" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the snmp_input function in snmptrapd in CMU SNMP utilities (cmu-snmp) allows remote attackers to execute arbitrary code by sending crafted SNMP messages to UDP port 162.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422086/100/0/threaded">20060116 Digital Armaments Security Advisory 01.16.2006: CMU SNMP utilities snmptrad Format String Vulnerability</ref><ref source="" url="http://www.digitalarmaments.com/2006040164883273.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16267">16267</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0234">ADV-2006-0234</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18525">18525</ref><ref source="OSVDB" url="http://www.osvdb.org/22493">22493</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24178">
cmusnmp-snmpinput-format-string(24178)</ref></refs><vuln_soft><prod name="snmptrapd" vendor="Carnegie Mellon University"><vers num="3.7"/><vers num="3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0251" published="2006-01-17" seq="2006-0251" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in fom.cgi in Faq-O-Matic 2.711 allows remote attackers to inject arbitrary web script or HTML via the (1) _duration, (2) file, and (3) cmd parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16251">16251</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0189">ADV-2006-0189</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18468">18468</ref><ref source="" url="http://osvdb.org/ref/22/22439-faqomatic.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22439">22439</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24165">
faqomatic-fom-xss(24165)</ref></refs><vuln_soft><prod name="FAQ-O-Matic" vendor="FAQ-O-Matic"><vers num="2.711" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0252" published="2006-01-17" seq="2006-0252" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Benders Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by the (1) year, (2) month, and (3) day parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422052/100/0/threaded">20060115 [eVuln] Benders Calendar SQL Injection</ref><ref adv="1" source="" url="http://evuln.com/vulns/30/summary.html"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/16242">16242</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0190">ADV-2006-0190</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1015491">1015491</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18462">18462</ref><ref source="OSVDB" url="http://www.osvdb.org/22449">22449</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24120">
benderscalendar-sql-injection(24120)</ref></refs><vuln_soft><prod name="Benders Calendar" vendor="Benders Calendar"><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0253" published="2006-01-17" seq="2006-0253" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the Bluetooth OBEX Object Push service in &quot;Blue Neighbors.EXE&quot; in AmbiCom Blue Neighbors 2.50 Build 2500 and earlier allows remote attackers to execute arbitrary code via a long file name, as demonstrated via a long RFILE argument to ussp-push.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.digitalmunition.com/DMA%5B2006-0115a%5D.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0219">ADV-2006-0219</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18466">18466</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422481/100/0/threaded">20060120 DMA[2006-0115a] - %27AmbiCom Bluetooth Object Push Overflow%27</ref><ref source="BID" url="http://www.securityfocus.com/bid/16258">
16258</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24179">
ambicom-bluetooth-objectpush-bo(24179)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/366">366</ref></refs><vuln_soft><prod name="Blue Neighbors" vendor="AmbiCom"><vers num="2.50 Build 2500"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0254" published="2006-01-17" seq="2006-0254" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421996/100/0/threaded">20060115 Apache Geronimo 1.0 - CSS and persistent HTML-Injectionvulnerabilities</ref><ref adv="1" source="" url="http://issues.apache.org/jira/browse/GERONIMO-1474"></ref><ref adv="1" source="" url="http://www.oliverkarow.de/research/geronimo_css.txt"></ref><ref source="" url="https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12310181&amp;styleName=Html&amp;projectId=10220&amp;Create=Create"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16260">16260</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0217">ADV-2006-0217</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18485">18485</ref><ref source="" url="https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12310181&amp;styleName=Html&amp;projectId=10220&amp;Create=Create"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24159">
geronimo-webaccesslog-viewer-xss(24159)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24158">geronimo-jspexamples-xss(24158)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2008-0630.html">RHSA-2008:0630</ref><ref source="SECUNIA" url="http://secunia.com/advisories/31493">31493</ref></refs><vuln_soft><prod name="Geronimo" vendor="Apache Software Foundation"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0255" published="2006-01-17" seq="2006-0255" severity="High" type="CVE"><desc><descript source="cve">Unquoted Windows search path vulnerability in Check Point VPN-1 SecureClient might allow local users to gain privileges via a malicious &quot;program.exe&quot; file in the C: folder, which is run when SecureClient attempts to launch the Sr_GUI.exe program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://secdev.zoller.lu/research/checkpoint.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16290">16290</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0258">ADV-2006-0258</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422263/100/0/threaded">20060117 [ TZO-012006 ] Checkpoint VPN-1 SecureClient insecure usage of CreateProcess()</ref></refs><vuln_soft><prod name="VPN-1" vendor="Checkpoint"><vers num="4.1 SP6"/><vers num="4.1 SP5a"/><vers num="4.1 SP5"/><vers num="4.1 SP4"/><vers num="4.1 SP3"/><vers num="4.1 SP2"/><vers num="4.1 SP1"/><vers num="4.1"/><vers num="FP1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2006-0256" published="2006-01-18" seq="2006-0256" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Advanced Queuing component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.6, 10.1.0.3 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB01.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.6"/><vers num="9.0.1.5"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.3"/></prod><prod name="Oracle8i Database Server" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2006-0257" published="2006-01-18" seq="2006-0257" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Change Data Capture component of Oracle Database server 9.2.0.7, 10.1.0.5, and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB02.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the CDC_ALLOCATE_LOCK function of the DBMS_CDC_UTILITY package.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="OSVDB" url="http://www.osvdb.org/22540">22540</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.7"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.5"/><vers num="10.2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2006-0258" published="2006-01-18" seq="2006-0258" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Connection Manager component of Oracle Database server 8.1.7.4 and 9.0.1.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB03.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers edition="FIPS" num="9.0.1.5"/></prod><prod name="Oracle8i Database Server" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" discovered="2006-01-17" modified="2008-03-03" name="CVE-2006-0259" published="2006-01-18" seq="2006-0259" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB04 and (2) DB06 in the (a) Data Pump component; (3) DB10 in the (b) Net Listener component; and (4) DB16 in the (c) Oracle Text component.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB06 is SQL injection in the GENERATE_JOB_NAME, GET_WORKERSTATUSLIST1010, GET_PARAMVALUES1010, GET_DUMPFILESET1010, GET_JOBSTATUS1010, ATTACH, and ESTABLISH_REMOTE_CONTEXT functions in DBMS_DATAPUMP.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="OSVDB" url="http://www.osvdb.org/22544">22544</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2006-0260" published="2006-01-18" seq="2006-0260" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 9.2.0.7 and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB05 in the (a) Data Pump component; (2) DB15 in the (b) Oracle Text component; (3) DB22 in the (c) Streams Apply component; (4) DB23 and (5) DB24 in the (d) Streams Capture component; and (6) DB26 in the (e) Streams Subcomponent.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB05 involves SQL injection in the (f) LONG2VARCHAR, LONG2VCMAX, LONG2VCNT, and LONG2CLOB functions in the DBMS_METADATA_UTIL package; (g) MAKE_FILTER, FETCH_VIEWS_ERROR, FETCH_FILTERS, FETCH_VIEWS, SET_FILTER_COMMON, DO_FILTER_SCRIPT, SET_TABLE_FILTERS, and MAKE_FILTER_TEXT functions in the DBMS_METADATA_INT package; and (h) GET_PREPOST_TABLE_ACT function in the DBMS_METADATA package.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="OSVDB" url="http://www.osvdb.org/22543">22543</ref><ref source="OSVDB" url="http://www.osvdb.org/22643">22643</ref><ref source="OSVDB" url="http://www.osvdb.org/22637">22637</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.7"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0261" published="2006-01-18" seq="2006-0261" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB07 in the Dictionary component and (2) DB14 in the Oracle Label Security component.  NOTE: Oracle has not disputed reliable researcher claims that DB07 involves plaintext storage of the TDE wallet password in a trace file by event 10053.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422255/30/7430/threaded">20060117 Oracle Database 10g Rel. 2 - Event 10053 logs TDE wallet password in cleartext</ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_tde_wallet_password.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24168">oracle-masterkey-plaintext(24168)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.7"/><vers edition="FIPS" num="9.0.1.5"/><vers num="9.0.1.5"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.5"/></prod><prod name="Oracle8i Database Server" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2006-0262" published="2006-01-18" seq="2006-0262" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Net Foundation Layer component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB08.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="Standard 8.1.7.4"/><vers num="Enterprise 8.1.7.4"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.6"/><vers num="Enterprise 9.0.1.5 FIPS"/><vers num="Enterprise 9.0.1.5"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.1.0.4"/><vers num="Personal 10.1.0.4"/><vers num="Enterprise 10.1.0.4"/></prod><prod name="Oracle8" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2006-0263" published="2006-01-18" seq="2006-0263" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB09 in the (a) Net Listener component; and (2) DB12 and (3) DB13 in the Network Communications (RPC) component.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html">TA06-018A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/870172">VU#870172</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="OSVDB" url="http://www.osvdb.org/22547">22547</ref><ref source="OSVDB" url="http://www.osvdb.org/22550">22550</ref><ref source="OSVDB" url="http://www.osvdb.org/22551">22551</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.7"/><vers edition="FIPS" num="9.0.1.5"/><vers num="9.0.1.5"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.2.0.1"/><vers num="10.1.0.5"/></prod><prod name="Oracle8i Database Server" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry modified="2006-02-08" name="CVE-2006-0264" published="2006-01-18" reject="1" seq="2006-0264" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0259.  Reason: This candidate is subsumed by CVE-2006-0259.  An error during initial CVE analysis used the wrong set of affected versions for &quot;DB10&quot;. Notes: All CVE users should reference CVE-2006-0259 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">
oracle-january2006-update(24321)</ref></refs></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2006-0265" published="2006-01-18" seq="2006-0265" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB17 in the Oracle Text component and (2) DB18 in the Program Interface Network component.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB17 involves SQL injection in the (a) VALIDATE_STATEMENT and BUILD_DML functions in CTXSYS.DRILOAD; (b) CLEAN_DML function in CTXSYS.DRIDML; (c) GET_ROWID function in CTXSYS.CTX_DOC; (d) BROWSE_WORDS function in CTXSYS.CTX_QUERY; and (e) ODCIINDEXTRUNCATE, ODCIINDEXDROP, and ODCIINDEXDELETE functions in CATINDEXMETHODS.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref adv="1" source="" url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/22555">22555</ref><ref source="OSVDB" url="http://www.osvdb.org/22639">22639</ref><ref source="OSVDB" url="http://www.osvdb.org/22640">22640</ref><ref source="OSVDB" url="http://www.osvdb.org/22641">22641</ref><ref source="OSVDB" url="http://www.osvdb.org/22642">22642</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.7"/><vers num="9.0.1.5"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.2.0.1"/><vers num="10.1.0.5"/></prod><prod name="Oracle8i Database Server" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-05-15" name="CVE-2006-0266" published="2006-01-18" seq="2006-0266" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Query Optimizer component of Oracle Database server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB19.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.7"/><vers num="9.0.1.5"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-05-15" name="CVE-2006-0267" published="2006-01-18" seq="2006-0267" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Query Optimizer component of Oracle Database server 9.2.0.6 and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB20.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.6"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-05-15" name="CVE-2006-0268" published="2006-01-18" seq="2006-0268" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Security component of Oracle Database server 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB21.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.6"/><vers edition="FIPS" num="9.0.1.5"/><vers num="9.0.1.5"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-04-11" name="CVE-2006-0269" published="2006-01-18" seq="2006-0269" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Streams Capture component of Oracle Database server 10.1.0.5 and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB25.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the SET_DIRECTORY_ROOT function in the DBMS_CDC_PUBLISH package.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/22563">22563</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.2.0.1"/><vers num="Standard 10.1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0270" published="2006-01-18" seq="2006-0270" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB27.  NOTE: Oracle has not disputed a reliable researcher report that TDA stores the master key without encryption, which allows local users to obtain the key via the SGA.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_tde_unencrypted_sga.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422262/30/7400/threaded">20060117 Oracle Database 10g Rel. 2- Transparent Data Encryption plaintext masterkey in SGA</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24186">oracle-sga-masterkey-plaintext(24186)</ref></refs><vuln_soft><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0271" published="2006-01-18" seq="2006-0271" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Upgrade &amp; Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB28.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the DBMS_REGISTRY package in certain parameters to the (1) IS_COMPONENT, (2) GET_COMP_OPTION, (3) DISABLE_DDL_TRIGGERS, (4) SCRIPT_EXISTS, (5) COMP_PATH, (6) GATHER_STATS, (7) NOTHING_SCRIPT, and (8) VALIDATE_COMPONENTS functions.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/22566">22566</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="Standard 8.1.7.4"/><vers num="Enterprise 8.1.7.4"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.7"/><vers num="Enterprise 9.0.1.5"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.1.0.4"/><vers num="Personal 10.1.0.4"/><vers num="Enterprise 10.1.0.4"/></prod><prod name="Oracle8" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0272" published="2006-01-18" seq="2006-0272" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the XML Database component of Oracle Database server 9.2.0.7 and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB29.  NOTE: based on mutual credits by the relevant sources, it is highly likely that this issue is a buffer overflow in the (a) DBMS_XMLSCHEMA and (b) DBMS_XMLSCHEMA_INT packages, as exploitable via long arguments to (1) XDB.DBMS_XMLSCHEMA.GENERATESCHEMA or (2) XDB.DBMS_XMLSCHEMA.GENERATESCHEMAS.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="" url="http://www.argeniss.com/research/ARGENISS-ADV-010601.txt"></ref><ref source="" url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html">TA06-018A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/891644">VU#891644</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0893.html">20060126 [Argeniss] Oracle Database Buffer overflows vulnerabilities in public procedures of XDB.DBMS_XMLSCHEMA{_INT}</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24376">oracle-xdbdbmx-xmlschema-bo(24376)</ref></refs><vuln_soft><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.7"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.1.0.4"/><vers num="Personal 10.1.0.4"/><vers num="Enterprise 10.1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0273" published="2006-01-18" seq="2006-0273" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Portal component of Oracle Application Server 9.0.4.2 and 10.1.2.0 has unspecified impact and attack vectors, as identified by Oracle Vuln# AS01.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.2.0"/><vers num="9.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0274" published="2006-01-18" seq="2006-0274" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 and 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP03.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="9.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0275" published="2006-01-18" seq="2006-0275" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP04.  NOTE: Oracle has not disputed reliable researcher claims that this issue is related to directory traversal that allows reading of portions of arbitrary XML files via the customize parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422261/30/7430/threaded">20060117 Oracle Reports - Read parts of files via customize(fixed after 875 days)</ref></refs><vuln_soft><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0276" published="2006-01-18" seq="2006-0276" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) OCS01, 2) OCS02, 3) OCS03, 4) OCS04, 5) OCS05, 6) OCS06, 7) OCS07, (8) OCS08, and (9) OCS09 in the (a) Email Server component; 10) OCS10 (and (11) OCS11 in the (b) Oracle Collaboration Suite Wireless &amp; Voice (component; 12) OCS12 and (13) OCS13 in the (c) Oracle Content (Management SDK component; 14) OCS14 and (15) OCS15 in the (d) Oracle (Content Services component.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="Release 2 9.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0277" published="2006-01-18" seq="2006-0277" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS01 in the (a) Application Install component; (2) APPS07 in the (b) Oracle Applications Framework component; (3) APPS08, (4) APPS09, (5) APPS10, and (6) APPS11 in the (c) Oracle Applications Technology Stack component; (7) APPS12 in the (d) Oracle Human Resources component; (8) APPS15 and (9) APPS16 in the (e) Oracle Marketing component; (10) APPS17 in the (f) Marketing Encyclopedia System component; (11) APPS18 in the (g) Oracle Trade Management component; and (12) APPS19 in the (h) Oracle Web Applications Desktop Integration component.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.10"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0278" published="2006-01-18" seq="2006-0278" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.9 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS02 in the (a) CRM Technical Foundation component; (2) APPS03 in the (b) iProcurement component; and (3) APPS04, (4) APPS05, and (5) APPS06 in the Oracle Application Object Library component.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0279" published="2006-01-18" seq="2006-0279" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 4.3 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS13 and (2) APPS14 in the Oracle iLearning component.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="E-Business Suite" vendor="Oracle"><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0280" published="2006-01-18" seq="2006-0280" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle PeopleSoft Enterprise Portal 8.4 Bundle 15, 8.8 Bundle 10, and 8.9 Bundle 2 has unspecified impact and attack vectors, as identified by Oracle Vuln# PSE01.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="PeopleSoft Enterprise Portal" vendor="Oracle"><vers num="8.9 Bundle 2"/><vers num="8.8 Bundle 10"/><vers num="8.4 Bundle 15"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0281" published="2006-01-18" seq="2006-0281" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle JD Edwards HTML Server 8.95.F1 SP23_L1 has unspecified impact and attack vectors, as identified by Oracle Vuln# JDE01.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="JD Edwards EnterpriseOne" vendor="Oracle"><vers num="8.95 _F1"/><vers num="SP23_L1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0282" published="2006-01-18" seq="2006-0282" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC01 in the Protocol Support component.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="Release 2 9.0.4.2"/></prod><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="10.1.0.5"/><vers num="9.2.0.7"/><vers edition="FIPS" num="9.0.1.5"/><vers num="9.0.1.5"/></prod><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="1.0.2.2 r1"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="Release 2 10.1.2.0.2"/><vers num="9.0.4.2"/></prod><prod name="Oracle8i Database Server" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0283" published="2006-01-18" seq="2006-0283" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Database Server 10.1.0.4.2, Application Server 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC02 in the Reorganize Objects &amp; Convert Tablespace component.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.4.2"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.2.0.2"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="Release 2 9.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0284" published="2006-01-18" seq="2006-0284" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.2 and 10.1.2.0.2, and E-Business Suite and Applications 11.5.10, have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) FORM01 and (2) FORM02 in the Oracle Forms component.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle Application Server" vendor="Oracle"><vers num="Release 2 10.1.2.0.2"/></prod><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.10"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0285" published="2006-01-18" seq="2006-0285" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Java Net component of Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.4, and Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, has unspecified impact and attack vectors, as identified by Oracle Vuln# JN01.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.7"/><vers edition="FIPS" num="9.0.1.5"/><vers num="9.0.1.5"/><vers num="8.1.7.4"/></prod><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="1.0.2.2"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="9.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0286" published="2006-01-18" seq="2006-0286" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, and Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS01.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.7"/><vers edition="FIPS" num="9.0.1.5"/><vers num="9.0.1.5"/></prod><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="1.0.2.2"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.5"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="9.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-05" name="CVE-2006-0287" published="2006-01-18" seq="2006-0287" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS02.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.5"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.2.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-05" name="CVE-2006-0288" published="2006-01-18" seq="2006-0288" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in the Oracle Reports Developer component of Oracle Application Server 9.0.4.1 and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) REP01 and (2) REP02.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.10"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0289" published="2006-01-18" seq="2006-0289" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Application Server 6.0.8.26(PS17) and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) REP05 and (2) REP06 in the Oracle Reports Developer component. NOTE: Oracle has not disputed reliable researcher claims that REP05 is the same as CVE-2005-2378 and REP06 is the same as CVE-2005-2371, both of which involve directory traversal.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422257/30/7430/threaded">20060117 Oracle Reports - Overwrite any application server file via desname (fixed after 889 days)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422256/30/7430/threaded">20060117 Oracle Reports - Read parts of files via desname (fixed after 874 days)</ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_reports_overwrite_any_file.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_reports_read_any_file.html"></ref></refs><vuln_soft><prod name="Oracle Application Server" vendor="Oracle"><vers num="6.0.8.26 PS17"/></prod><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.10"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-05" name="CVE-2006-0290" published="2006-01-18" seq="2006-0290" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Database Server 9.2.0.7, Application Server 9.0.4.2 and 10.1.2.1, Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i), and E-Business Suite and Applications 11.5.10 has unspecified impact and attack vectors, as identified by Oracle Vuln# WF01 in the Oracle Workflow Cartridge component.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.7"/></prod><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.10"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.2.1"/><vers num="9.0.4.2"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="Release 2 9.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-05" name="CVE-2006-0291" published="2006-01-18" seq="2006-0291" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database Server 10.2.0.1, Application Server 9.0.4.2 and 10.1.2.1, Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i), and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) WF02 and (2) WF03 in the Oracle Workflow Cartridge component.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.10"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.2.0.1"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.2.1.0"/><vers num="9.0.4.2"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="Release 2 9.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0292" published="2006-02-02" seq="2006-0292" severity="High" type="CVE"><desc><descript source="cve">The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before 1.5.1 does not properly dereference objects, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via unknown attack vectors related to garbage collection.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.mozilla.org/security/announce/mfsa2006-01.html"></ref><ref patch="1" source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=316885"></ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0199.html">RHSA-2006:0199</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0200.html">RHSA-2006:0200</ref><ref source="BID" url="http://www.securityfocus.com/bid/16476">16476</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0413">ADV-2006-0413</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18700">18700</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18703">18703</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18704">18704</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00005.html">FEDORA-2006-075</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00006.html">FEDORA-2006-076</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015570">1015570</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18708">18708</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18709">18709</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18705">18705</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18706">18706</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24430">mozilla-javascript-memory-corruption(24430)</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:036">MDKSA-2006:036</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/425978/100/0/threaded">FLSA-2006:180036-2</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/425975/100/0/threaded">FLSA:180036-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U">20060201-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19230">19230</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">GLSA-200605-09</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:037">MDKSA-2006:037</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3391">ADV-2006-3391</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-01.html"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:670">oval:org.mitre.oval:def:670</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19780">
19780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">
20051</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:036">MDKSA-2006:036</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:037">MDKSA-2006:037</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4.1"/><vers num="1.4"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.0.7"/><vers edition="Linux" num="1.0.6"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0293" published="2006-02-02" seq="2006-0293" severity="High" type="CVE"><desc><descript source="cve">The function allocation code (js_NewFunction in jsfun.c) in Firefox 1.5 allows attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via user-defined methods that trigger garbage collection in a way that operates on freed objects.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.mozilla.org/security/announce/mfsa2006-01.html"></ref><ref patch="1" source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=322045"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16476">16476</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0413">ADV-2006-0413</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18700">18700</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18704">18704</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015570">1015570</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24430">mozilla-javascript-memory-corruption(24430)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3391">ADV-2006-3391</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-01.html"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1494">oval:org.mitre.oval:def:1494</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42654">firefox-function-allocation-code-execution(42654)</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0294" published="2006-02-02" seq="2006-0294" severity="High" type="CVE"><desc><descript source="cve">Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element&apos;s style from position:relative to position:static, which causes Gecko to operate on freed memory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.mozilla.org/security/announce/mfsa2006-02.html"></ref><ref patch="1" source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=317934"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16476">16476</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0413">ADV-2006-0413</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18700">18700</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18704">18704</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015570">1015570</ref><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-02.html"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1514">oval:org.mitre.oval:def:1514</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24431">
mozilla-element-change-memory-corruption(24431)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Alpha" num="1.0"/><vers edition="Beta" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.0.7"/><vers edition="Linux" num="1.0.6"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-02" name="CVE-2006-0295" published="2006-02-02" seq="2006-0295" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://www.mozilla.org/security/announce/mfsa2006-04.html"></ref><ref patch="1" source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=319296"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16476">16476</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0413">ADV-2006-0413</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18700">18700</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18704">18704</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/759273">VU#759273</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015570">1015570</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24433">mozilla-queryinterface-memory-corruption(24433)</ref><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-04.html"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1562">oval:org.mitre.oval:def:1562</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-038A.html">TA06-038A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Alpha" num="1.0"/><vers edition="Beta" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0296" published="2006-02-02" seq="2006-0296" severity="Medium" type="CVE"><desc><descript source="cve">The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user&apos;s localstore.rdf file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.mozilla.org/security/announce/mfsa2006-05.html"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=319847"></ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0199.html">RHSA-2006:0199</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0200.html">RHSA-2006:0200</ref><ref source="BID" url="http://www.securityfocus.com/bid/16476">16476</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0413">ADV-2006-0413</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18700">18700</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18703">18703</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18704">18704</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00005.html">FEDORA-2006-075</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3391">ADV-2006-3391</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-05.html"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1493">oval:org.mitre.oval:def:1493</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19780">
19780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">
20051</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:036">MDKSA-2006:036</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:037">MDKSA-2006:037</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-038A.html">TA06-038A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00006.html">FEDORA-2006-076</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/592425">VU#592425</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015570">1015570</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18708">18708</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18709">18709</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18705">18705</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18706">18706</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24434">mozilla-xuldocument-command-execution(24434)</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:036">MDKSA-2006:036</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/425978/100/0/threaded">FLSA-2006:180036-2</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/425975/100/0/threaded">FLSA:180036-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U">20060201-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19230">19230</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">GLSA-200605-09</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:037">MDKSA-2006:037</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref></refs><vuln_soft><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Alpha" num="1.0"/><vers edition="Beta" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.0.7"/><vers edition="Linux" num="1.0.6"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0297" published="2006-02-02" seq="2006-0297" severity="Medium" type="CVE"><desc><descript source="cve">Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://www.mozilla.org/security/announce/mfsa2006-06.html"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=319872"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=322215"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16476">16476</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0413">ADV-2006-0413</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18700">18700</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18704">18704</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015570">1015570</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24435">mozilla-component-integer-overflow(24435)</ref><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-06.html"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1339">oval:org.mitre.oval:def:1339</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Alpha" num="1.0"/><vers edition="Beta" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5"/><vers edition="Beta 1" num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-07-30" name="CVE-2006-0298" published="2006-02-02" seq="2006-0298" severity="Medium" type="CVE"><desc><descript source="cve">The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://www.mozilla.org/security/announce/mfsa2006-07.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16476">16476</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0413">ADV-2006-0413</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18700">18700</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18704">18704</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015570">1015570</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24436">mozilla-xml-parser-dos(24436)</ref><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-07.html"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:677">oval:org.mitre.oval:def:677</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref></refs><vuln_soft><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Alpha" num="1.0"/><vers edition="Beta" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5"/><vers edition="Beta 1" num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0299" published="2006-02-02" seq="2006-0299" severity="Medium" type="CVE"><desc><descript source="cve">The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal &quot;AnyName&quot; object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.mozilla.org/security/announce/mfsa2006-08.html"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=322312"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16476">16476</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0413">ADV-2006-0413</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18700">18700</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18704">18704</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015570">1015570</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24437">mozilla-e4x-security-bypass(24437)</ref><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-08.html"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1625">oval:org.mitre.oval:def:1625</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Alpha" num="1.0"/><vers edition="Beta" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5"/><vers edition="Beta 1" num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0300" published="2006-02-23" seq="2006-0300" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="MLIST" url="http://lists.gnu.org/archive/html/bug-tar/2006-02/msg00051.html">[Bug-tar] 20060220 tar 1.15.90 released</ref><ref adv="1" patch="1" source="MANDRIVA" url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:046">MDKSA-2006:046</ref><ref adv="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-257-1">USN-257-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/16764">16764</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0684">ADV-2006-0684</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/23371">23371</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18976">18976</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18973">18973</ref><ref adv="1" source="TRUSTIX" url="http://www.trustix.org/errata/2006/0010">2006-0010</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18999">18999</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24855">gnu-tar-pax-headers-bo(24855)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-987">DSA-987</ref><ref source="OPENPKG" url="http://www.openpkg.org/security/OpenPKG-SA-2006.006-tar.html">OpenPKG-SA-2006.006</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0232.html">RHSA-2006:0232</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_05_sr.html">SUSE-SR:2006:005</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015705">1015705</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19093">19093</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19130">19130</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19152">19152</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-06.xml">GLSA-200603-06</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19236">19236</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/430299/100/0/threaded">FLSA:183571-2</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19016">19016</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20042">
20042</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">
APPLE-SA-2007-04-19</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">
ADV-2007-1470</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">
24966</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="SREASON" url="http://securityreason.com/securityalert/480">480</ref><ref source="SREASON" url="http://securityreason.com/securityalert/543">543</ref></refs><vuln_soft><prod name="tar" vendor="GNU"><vers num="1.15.90"/><vers num="1.15.1"/><vers num="1.15"/><vers num="1.14.1"/><vers num="1.14"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-07" name="CVE-2006-0301" published="2006-01-30" seq="2006-0301" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted splash images that produce certain values that exceed the width or height of the associated bitmap.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18838">18838</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18860">18860</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18862">18862</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18864">18864</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18882">18882</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18908">18908</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18913">18913</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200602-12.xml">GLSA-200602-12</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18983">18983</ref><ref adv="1" patch="1" source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427990/100/0/threaded">FLSA:175404</ref><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.15/SCOSA-2006.15.txt">SCOSA-2006.15</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19377">19377</ref><ref patch="1" source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.474747">SSA:2006-045-04</ref><ref patch="1" source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.472683">SSA:2006-045-09</ref><ref adv="1" patch="1" source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00039.html">FEDORA-2006-103</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18839">18839</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:030">MDKSA-2006:030</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:031">MDKSA-2006:031</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:032">MDKSA-2006:032</ref><ref source="SREASON" url="http://securityreason.com/securityalert/470">470</ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179046"></ref><ref source="" url="https://bugzilla.novell.com/show_bug.cgi?id=141242"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0389">ADV-2006-0389</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:030">MDKSA-2006:030</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:031">MDKSA-2006:031</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:032">MDKSA-2006:032</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18677">18677</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/423899/100/0/threaded">20060202 [KDE Security Advisory] kpdf/xpdf heap based buffer overflow</ref><ref adv="1" patch="1" source="" url="http://www.kde.org/info/security/advisory-20060202-1.txt"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0422">ADV-2006-0422</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015576">1015576</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18707">18707</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24391">xpdf-splash-bo(24391)</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-971">DSA-971</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-974">DSA-974</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-972">DSA-972</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200602-04.xml">GLSA-200602-04</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200602-05.xml">GLSA-200602-05</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0201.html">RHSA-2006:0201</ref><ref adv="1" patch="1" source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0206.html">RHSA-2006:0206</ref><ref patch="1" source="UBUNTU" url="http://www.ubuntu.com/usn/usn-249-1">USN-249-1</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18834">18834</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18875">18875</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18274">18274</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18825">18825</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18826">18826</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18837">18837</ref></refs><vuln_soft><prod name="Xpdf" vendor="Xpdf"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0302" published="2006-01-18" seq="2006-0302" severity="Medium" type="CVE"><desc><descript source="cve">ZyXel P2000W VoIP 802.11b Wireless Phone running firmware WV.00.02 allows remote attackers to obtain sensitive information, such as MAC address and software version, by directly accessing UDP port 9090.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041438.html">20060116 ZyXel P2000W (Version 2) VoIP wireless phone undocumented port UDP/9090</ref><ref source="BID" url="http://www.securityfocus.com/bid/16285">16285</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18511">18511</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24145">
zyxel-p2000w-default-port(24145)</ref><ref source="OSVDB" url="http://www.osvdb.org/22516">22516</ref></refs><vuln_soft><prod name="P2000W Version 2 VOIP WIFI Phone" vendor="ZyXel"><vers num="WV.00.02"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-01" name="CVE-2006-0303" published="2006-01-18" seq="2006-0303" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in the (1) publishing component, (2) Contact Component, (3) TinyMCE Compressor, and (4) other components in Joomla! 1.0.5 and earlier have unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://www.joomla.org/content/view/738/66/"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18513">18513</ref></refs><vuln_soft><prod name="Joomla" vendor="Joomla"><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-31" name="CVE-2006-0304" published="2006-01-18" seq="2006-0304" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Dual DHCP DNS Server 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via the DHCP options field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://aluigi.altervista.org/adv/dualsbof-adv.txt"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18486">18486</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0245">ADV-2006-0245</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015495">1015495</ref><ref source="BID" url="http://www.securityfocus.com/bid/16298">16298</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24191">
dualdhcpdns-options-field-bo(24191)</ref></refs><vuln_soft><prod name="Dual DHCP DNS Server" vendor="Achal Dhir"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-31" name="CVE-2006-0305" published="2006-01-18" seq="2006-0305" severity="High" type="CVE"><desc><descript source="cve">Clipcomm CPW-100E VoIP 802.11b Wireless Handset Phone running firmware 1.1.12 (051129) and CP-100E VoIP 802.11b Wireless Phone running firmware 1.1.60 allows remote attackers to gain unauthorized access via the debug service on TCP port 60023.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041439.html">20060116 Clipcomm CP-100E VoIP wireless desktop phone open debug service TCP/60023</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041436.html">20060116 Clipcomm CPW-100E VoIP wireless handset phone open debug service TCP/60023</ref><ref source="BID" url="http://www.securityfocus.com/bid/16289">16289</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18505">18505</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24144">
clipcomm-cp100e-default-port(24144)</ref></refs><vuln_soft><prod name="CP-100E VOIP WIFI Phone" vendor="Clipcomm"><vers num="1.1.60"/></prod><prod name="CPW-100E VOIP WIFI Phone" vendor="Clipcomm"><vers num="1.1.12"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-0306" published="2006-01-18" seq="2006-0306" severity="Medium" type="CVE"><desc><descript source="cve">The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops &amp; Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business Protection Suite r2 allows remote attackers to cause a denial of service (CPU consumption or application hang) via a large network packet, which causes a WSAEMESGSIZE error code that is not handled, leading to a thread exit.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.designfolks.com.au/karma/DMPrimer/"></ref><ref adv="1" source="" url="http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp"></ref><ref adv="1" source="" url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16276">16276</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0236">ADV-2006-0236</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18531">18531</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422381/100/0/threaded">20060118 CAID 33756 - DM Deployment Common Component Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/22529">22529</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015504">1015504</ref></refs><vuln_soft><prod name="Unicenter Remote Control" vendor="Computer Associates"><vers num="German GA 6.0 (Build 6.0.74)"/><vers num="German 6.0 SP1 (Build 6.0.77)"/><vers num="French GA 6.0 (Build 6.0.74)"/><vers num="French 6.0 SP1 (Build 6.0.77)"/><vers num="English QO48974 6.0 (Build 6.0.74)"/><vers num="English GA 6.0 (6.0.56.3)"/><vers num="English 6.0 SP1 (Build 6.0.77)"/><vers num="6.0 SP1"/><vers num="6.0"/><vers num="5.2"/></prod><prod name="Server Protection Suite" vendor="Computer Associates"><vers num="r2"/></prod><prod name="Business Protection Suite" vendor="Computer Associates"><vers num="r2"/></prod><prod name="Desktop Protection Suite" vendor="Computer Associates"><vers num="r2"/></prod><prod name="BrightStor Mobile Backup" vendor="Computer Associates"><vers num="r4.0"/></prod><prod name="BrightStor ARCserve Backup Laptops_Desktops" vendor="Computer Associates"><vers num="r11.0"/><vers num="r11.1"/><vers num="r11.1 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-0307" published="2006-01-18" seq="2006-0307" severity="Medium" type="CVE"><desc><descript source="cve">The DM Primer in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops &amp; Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business Protection Suite r2 allows remote attackers to cause a denial of service (CPU consumption and log file consumption) via unspecified &quot;unrecognized network messages&quot; that are not properly handled.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp"></ref><ref adv="1" source="" url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16276">16276</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0236">ADV-2006-0236</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18531">18531</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422381/100/0/threaded">20060118 CAID 33756 - DM Deployment Common Component Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/22529">22529</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015504">1015504</ref></refs><vuln_soft><prod name="Unicenter Remote Control" vendor="Computer Associates"><vers num="German GA 6.0 (Build 6.0.74)"/><vers num="German 6.0 SP1 (Build 6.0.77)"/><vers num="French GA 6.0 (Build 6.0.74)"/><vers num="French 6.0 SP1 (Build 6.0.77)"/><vers num="English QO48974 6.0 (Build 6.0.74)"/><vers num="English GA 6.0 (6.0.56.3)"/><vers num="English 6.0 SP1 (Build 6.0.77)"/><vers num="6.0 SP1"/><vers num="6.0"/><vers num="5.2"/></prod><prod name="Server Protection Suite" vendor="Computer Associates"><vers num="r2"/></prod><prod name="Business Protection Suite" vendor="Computer Associates"><vers num="r2"/></prod><prod name="Desktop Protection Suite" vendor="Computer Associates"><vers num="r2"/></prod><prod name="BrightStor Mobile Backup" vendor="Computer Associates"><vers num="r4.0"/></prod><prod name="BrightStor ARCserve Backup Laptops_Desktops" vendor="Computer Associates"><vers num="r11.0"/><vers num="r11.1"/><vers num="r11.1 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0308" published="2006-01-18" seq="2006-0308" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the filnavn parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16282">16282</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3524">3524</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33092">htmltonuke-htmltonuke-file-include(33092)</ref></refs><vuln_soft><prod name="HTMLtoNuke" vendor="HTMLtoNuke"><vers num="2.0_Alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-20" name="CVE-2006-0309" published="2006-01-18" seq="2006-0309" severity="Medium" type="CVE"><desc><descript source="cve">Linksys BEFVP41 VPN Router 2.0 with firmware 1.01.04 allows remote attackers on the local network, to cause a denial of service via IP packets with a null IP option length.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421929/100/0/threaded">20060113 Linksys VPN Router (BEFVP41) DoS Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422064/100/0/threaded">20060116 Re: Linksys VPN Router (BEFVP41) DoS</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0238">ADV-2006-0238</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015490">1015490</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18461">18461</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422266/100/0/threaded">20060117 Re: Linksys VPN Router (BEFVP41) DoS Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16307">16307</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24125">
linksys-null-length-dos(24125)</ref></refs><vuln_soft><prod name="BEFVP41" vendor="Linksys"><vers num="2.0 firmware 1.01.04"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-20" name="CVE-2006-0310" published="2006-01-18" seq="2006-0310" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/37/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16286">16286</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0240">ADV-2006-0240</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16889">16889</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0322.html">20060117 [eVuln] aoblogger Multiple Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/22526">22526</ref><ref source="" url="http://mikeheltonisawesome.com/viewcomments.php?idd=46"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24141">
aoblogger-url-xss(24141)</ref></refs><vuln_soft><prod name="aoblogger" vendor="Mike Helton"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-20" name="CVE-2006-0311" published="2006-01-18" seq="2006-0311" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/37/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16286">16286</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0240">ADV-2006-0240</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16889">16889</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0322.html">20060117 [eVuln] aoblogger Multiple Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/22527">22527</ref><ref source="" url="http://mikeheltonisawesome.com/viewcomments.php?idd=46"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24142">
aoblogger-login-sql-injection(24142)</ref></refs><vuln_soft><prod name="aoblogger" vendor="Mike Helton"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-20" name="CVE-2006-0312" published="2006-01-18" seq="2006-0312" severity="Medium" type="CVE"><desc><descript source="cve">create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/37/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16286">16286</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0240">ADV-2006-0240</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16889">16889</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0322.html">20060117 [eVuln] aoblogger Multiple Vulnerabilities</ref><ref source="" url="http://mikeheltonisawesome.com/viewcomments.php?idd=46"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24143">
aoblogger-create-security-bypass(24143)</ref></refs><vuln_soft><prod name="aoblogger" vendor="Mike Helton"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-20" name="CVE-2006-0313" published="2006-01-18" seq="2006-0313" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in PDFdirectory before 1.0 allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors involving (1) util.php, (2) userpref.php, (3) user.php, (4) uploadfrm.php, (5) title.php, (6) team.php, (7) stats.php, (8) page.php, (9) org.php, (10) member.php, (11) index.php, (12) group.php, or (13) anniv.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=382411&amp;group_id=122682"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16273">16273</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0231">ADV-2006-0231</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22403">22403</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22404">22404</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22405">22405</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22406">22406</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22407">22407</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22408">22408</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22409">22409</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22410">22410</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22411">22411</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22412">22412</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22413">22413</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22414">22414</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22415">22415</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18459">18459</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=382411&amp;group_id=122682"></ref></refs><vuln_soft><prod name="PDFdirectory" vendor="PDFdirectory"><vers num="0.2.11"/><vers num="0.2.10"/><vers num="0.2.9"/><vers num="0.2.8"/><vers num="0.2.7"/><vers num="0.2.6"/><vers num="0.2.5"/><vers num="0.2.4"/><vers num="0.2.3"/><vers num="0.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-20" name="CVE-2006-0314" published="2006-01-18" seq="2006-0314" severity="High" type="CVE"><desc><descript source="cve">PDFdirectory before 1.0 stores sensitive data in plaintext, which allows remote attackers to obtain arbitrary users&apos; passwords by direct queries to the database, possibly via one of the SQL injection vulnerabilities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=382411&amp;group_id=122682"></ref><ref source="OSVDB" url="http://www.osvdb.org/22402">22402</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=382411&amp;group_id=122682"></ref></refs><vuln_soft><prod name="PDFdirectory" vendor="PDFdirectory"><vers num="0.2.11"/><vers num="0.2.10"/><vers num="0.2.9"/><vers num="0.2.8"/><vers num="0.2.7"/><vers num="0.2.6"/><vers num="0.2.5"/><vers num="0.2.4"/><vers num="0.2.3"/><vers num="0.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-20" name="CVE-2006-0315" published="2006-01-18" seq="2006-0315" severity="Medium" type="CVE"><desc><descript source="cve">index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) and path disclosure.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422071/100/0/threaded">20060115 EZDatabase Directory Transversal, XSS and Path Disclosure Vulnerability</ref><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0515.html">20060115 EZDatabase Directory Transversal, XSS and Path Disclosure Vulnerability</ref><ref source="" url="http://zur.homelinux.com/Advisories/ezdatabase_dir_trans.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16257">16257</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18043">18043</ref><ref source="OSVDB" url="http://www.osvdb.org/22684">22684</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24135">
ezdatabase-index-p-path-disclosure(24135)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24134">
ezdatabase-index-p-xss(24134)</ref></refs><vuln_soft><prod name="EZDatabase" vendor="IndexCOR"><vers num="2.1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-26" name="CVE-2006-0316" published="2006-01-18" seq="2006-0316" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in YGPPicFinder.DLL in AOL You&apos;ve Got Pictures (YGP) Picture Finder Tool ActiveX Control, as used in AOL 8.0, 8.0 Plus, and 9.0 Classic, allows remote attackers to execute arbitrary code via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://news.com.com/2061-10789_3-6027865.html?part=rss&amp;tag=6027865&amp;subj=news"></ref><ref adv="1" source="" url="http://www.kb.cert.org/vuls/id/MIMG-6KRSQP"></ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/715730">VU#715730</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16262">16262</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0221">ADV-2006-0221</ref><ref source="OSVDB" url="http://www.osvdb.org/22486">22486</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18521">18521</ref><ref source="" url="http://news.com.com/2061-10789_3-6027865.html?part=rss&amp;tag=6027865&amp;subj=news"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015494">1015494</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24160">aol-youvegotpictures-activex-bo(24160)</ref></refs><vuln_soft><prod name="AOL Client Software" vendor="AOL"><vers num="8.0"/><vers edition="Plus" num="8.0"/><vers edition="Classic" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-20" name="CVE-2006-0317" published="2006-01-18" seq="2006-0317" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in rkrt_stats.php in RedKernel Referrer Tracker 1.1.0-3 allows remote attackers to inject arbitrary web script or HTML via a query string value as a GET, which is stored in the $QUERY_STRING variable.  NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16266">16266</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0197">ADV-2006-0197</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18473">18473</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24151">
referertracker-rkrtstats-xss(24151)</ref></refs><vuln_soft><prod name="Referrer Tracker" vendor="RedKernel"><vers num="1.1.0_3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-0318" published="2006-01-18" seq="2006-0318" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disbled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422137/100/0/threaded">20060117 [eVuln] BlogPHP Authentication Bypass</ref><ref adv="1" source="" url="http://evuln.com/vulns/34/summary"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16269">16269</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0204">ADV-2006-0204</ref><ref source="OSVDB" url="http://www.osvdb.org/22495">22495</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18467">18467</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24131">
blogphp-index-bypass-security(24131)</ref></refs><vuln_soft><prod name="BlogPHP" vendor="Insane Visions"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-20" name="CVE-2006-0319" published="2006-01-18" seq="2006-0319" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the FTP server (port 22003/tcp) in Farmers WIFE 4.4 SP1 allows remote attackers to create arbitrary files via &quot;..&quot; (dot dot) sequences in a (1) PUT, (2) SIZE, and possibly other commands.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113717162320654&amp;w=2">20060113 Farmers wife 4.4 sp1 remote SYSTEM access</ref><ref source="" url="http://www.lort.dk/DSR-farmerswife44sp1.pl"></ref><ref source="OSVDB" url="http://www.osvdb.org/22496">22496</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18508">18508</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113717162320654&amp;w=2">20060113 Farmers wife 4.4 sp1 remote SYSTEM access</ref><ref source="BID" url="http://www.securityfocus.com/bid/16321">16321</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24190">
farmerswife-ftp-directory-traversal(24190)</ref></refs><vuln_soft><prod name="Farmers WIFE" vendor="Farmers WIFE"><vers num="4.4 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-20" name="CVE-2006-0320" published="2006-01-18" seq="2006-0320" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in admin/processlogin.php in Bit 5 Blog 8.01 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422068/100/0/threaded">20060115 [eVuln] Bit 5 Blog SQL Injection &amp; Authentication Bypass Vulnerability</ref><ref adv="1" source="" url="http://evuln.com/vulns/31/summary"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16244">16244</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0195">ADV-2006-0195</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18464">18464</ref><ref source="OSVDB" url="http://www.osvdb.org/22445">22445</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24124">
bit5blog-processlogin-sql-injection(24124)</ref></refs><vuln_soft><prod name="Bit 5 Blog" vendor="Bit 5 Blog"><vers num="8.01" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-24" name="CVE-2006-0321" published="2006-01-23" seq="2006-0321" severity="Medium" type="CVE"><desc><descript source="cve">fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages that cause a free of an invalid pointer when fetchmail bounces the message to the originator or local postmaster.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://fetchmail.berlios.de/fetchmail-SA-2006-01.txt"></ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=348747"></ref><ref source="" url="http://developer.berlios.de/project/shownotes.php?release_id=8784"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0300">ADV-2006-0300</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18571">18571</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422936/100/0/threaded">20060122 fetchmail security announcement fetchmail-SA-2006-01 (CVE-2006-0321)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16365">16365</ref><ref source="OSVDB" url="http://www.osvdb.org/22691">22691</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015527">1015527</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24265">fetchmail-message-bounce-dos(24265)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18895">18895</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.443499">SSA:2006-045-01</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html">APPLE-SA-2006-08-01</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21253">21253</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3101">ADV-2006-3101</ref><ref source="BID" url="http://www.securityfocus.com/bid/19289">19289</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html">
TA06-214A</ref></refs><vuln_soft><prod name="Fetchmail" vendor="Eric Raymond"><vers num="6.3"/><vers num="6.3.1"/><vers num="6.3.2 rc1"/><vers num="6.3.2 rc2"/><vers num="6.3.2 rc3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-20" name="CVE-2006-0322" published="2006-01-19" seq="2006-0322" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability the edit comment formatting functionality in MediaWiki 1.5.x before 1.5.6 and 1.4.x before 1.4.14 allows attackers to cause a denial of service (infinite loop) via &quot;certain malformed links.&quot;</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=386609"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0392">ADV-2006-0392</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18711">18711</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24478">mediawiki-comment-format-dos(24478)</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Feb/0001.html">SUSE-SR:2006:003</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18717">18717</ref></refs><vuln_soft><prod name="MediaWiki" vendor="MediaWiki"><vers num="1.5.5"/><vers num="1.5.4"/><vers num="1.5.3"/><vers num="1.5.2"/><vers num="1.5.1"/><vers num="1.5.0"/><vers num="1.5 rc4"/><vers num="1.5 rc3"/><vers num="1.5 rc2"/><vers num="1.5 Beta4"/><vers num="1.5 Beta3"/><vers num="1.5 Beta2"/><vers num="1.5 Beta1"/><vers num="1.5 alpha2"/><vers num="1.5 alpha1"/><vers num="1.4.14"/><vers num="1.4.13"/><vers num="1.4.12"/><vers num="1.4.11"/><vers num="1.4.10"/><vers num="1.4.9"/><vers num="1.4.8"/><vers num="1.4.7"/><vers num="1.4.6"/><vers num="1.4.5"/><vers num="1.4.4"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4 beta6"/><vers num="1.4 beta5"/><vers num="1.4 beta4"/><vers num="1.4 beta3"/><vers num="1.4 beta2"/><vers num="1.4 beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" discovered="2005-10-07" modified="2008-04-22" name="CVE-2006-0323" published="2006-03-23" seq="2006-0323" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in swfformat.dll in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, Rhapsody 3, and Helix Player allows remote attackers to execute arbitrary code via a crafted SWF (Flash) file with (1) a a size value that is less than the actual size, or (2) other unspecified manipulations.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.service.real.com/realplayer/security/03162006_player/en/"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015806">1015806</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_18_realplayer.html">SUSE-SA:2006:018</ref><ref source="BID" url="http://www.securityfocus.com/bid/17202">17202</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1057">ADV-2006-1057</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19358">19358</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-24.xml">GLSA-200603-24</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/231028">VU#231028</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19365">19365</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19390">19390</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25408">realnetworks-swf-bo(25408)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430621/100/0/threaded">20060411 Realplayer .SWF Multiple Remote Memory Corruption Vulnerabilities</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0257.html">RHSA-2006:0257</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19362">19362</ref><ref source="SREASON" url="http://securityreason.com/securityalert/690">690</ref></refs><vuln_soft><prod name="Rhapsody" vendor="RealNetworks"><vers num="3"/></prod><prod name="RealPlayer" vendor="RealNetworks"><vers edition="Gold" num="10.0"/><vers num="10.0.6"/><vers num="10.5"/></prod><prod name="Helix Player" vendor="RealNetworks"><vers num=""/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-20" name="CVE-2006-0324" published="2006-01-19" seq="2006-0324" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter to login.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422364/100/0/threaded">20060119 [eVuln] WebspotBlogging Authentication Bypass Vulnerability</ref><ref adv="1" source="" url="http://evuln.com/vulns/41/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16319">16319</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0268">ADV-2006-0268</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18560">18560</ref><ref source="OSVDB" url="http://www.osvdb.org/22670">22670</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015522">1015522</ref><ref source="" url="https://sourceforge.net/forum/forum.php?forum_id=532233"></ref><ref source="" url="https://sourceforge.net/project/shownotes.php?release_id=387180&amp;group_id=156586"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24222">webspotblogging-login-sql-injection(24222)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/356">356</ref></refs><vuln_soft><prod name="WebspotBlogging" vendor="Webspot"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-0325" published="2006-01-20" seq="2006-0325" severity="High" type="CVE"><desc><descript source="cve">Etomite Content Management System 0.6, and possibly earlier versions, when downloaded from the web site in January 2006 after January 10, contains a back door in manager/includes/todo.inc.php, which allows remote attackers to execute arbitrary commands via the &quot;cij&quot; parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.lucaercoli.it/advs/etomite.txt"></ref><ref source="" url="http://www.etomite.org/forums/index.php?showtopic=4185"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0283">ADV-2006-0283</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18556">18556</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423523/100/0/threaded">20060130 Etomite followup information</ref><ref source="" url="http://www.etomite.org/forums/index.php?showtopic=4291"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16336">16336</ref><ref source="OSVDB" url="http://www.osvdb.org/22693">22693</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24254">etomite-default-backdoor(24254)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423497/100/0/threaded">20060127 Etomite CMS </ref></refs><vuln_soft><prod name="Etomite Content Management System" vendor="Etomite"><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0327" published="2006-01-20" seq="2006-0327" severity="Medium" type="CVE"><desc><descript source="cve">TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which causes them to incorrectly define a variable and reveal the path in an error message when a require function call fails.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422360/100/0/threaded">20060119 IRM 015: File system path disclosure on TYPO3 Web Content Manager</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422390/100/0/threaded">20060119 Re: IRM 015: File system path disclosure on TYPO3 Web Content Manage</ref><ref adv="1" source="" url="http://www.irmplc.com/advisory015.htm"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18546">18546</ref><ref source="" url="http://bugs.typo3.org/view.php?id=2248"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0269">ADV-2006-0269</ref><ref source="OSVDB" url="http://www.osvdb.org/22665">22665</ref><ref source="OSVDB" url="http://www.osvdb.org/22666">22666</ref><ref source="OSVDB" url="http://www.osvdb.org/22667">22667</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24244">typo3-multiple-path-disclosure(24244)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/361">361</ref></refs><vuln_soft><prod name="TYPO3" vendor="TYPO3"><vers num="3.8.1"/><vers num="3.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0328" published="2006-01-20" seq="2006-0328" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422405/100/0/threaded">20060119 Critical security advisory #006 tftpd32 Format string</ref><ref adv="1" source="" url="http://www.critical.lt/?vulnerabilities/200"></ref><ref source="" url="http://www.critical.lt/research/tftpd32_281_dos.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0263">ADV-2006-0263</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18539">18539</ref><ref source="BID" url="http://www.securityfocus.com/bid/16333">16333</ref><ref source="OSVDB" url="http://www.osvdb.org/22661">22661</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24250">
tftpd32-request-format-string(24250)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/362">362</ref></refs><vuln_soft><prod name="Tftpd32" vendor="Philippe Jounin"><vers num="2.81"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0329" published="2006-01-20" seq="2006-0329" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in HITSENSER Data Mart Server BS, BS-S, BS-M, BS-L, and EX allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS05-026_e/index-e.html"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18553">18553</ref><ref source="BID" url="http://www.securityfocus.com/bid/16326">16326</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0266">ADV-2006-0266</ref><ref source="OSVDB" url="http://www.osvdb.org/22669">22669</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015519">1015519</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24240">hitachi-hitsenser-sql-injection(24240)</ref></refs><vuln_soft><prod name="HITSENSER Data Mart Server" vendor="Hitachi"><vers num="BS"/><vers num="BS_S"/><vers num="BS_M"/><vers num="BS_L"/><vers num="EX"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-0330" published="2006-01-20" seq="2006-0330" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname).</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://gallery.menalto.com/page/gallery_1_5_2_release"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18557">18557</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200601-13.xml">GLSA-200601-13</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16334">16334</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0282">ADV-2006-0282</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22660">22660</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18627">18627</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24247">gallery-unknown-xss(24247)</ref><ref source="DEBIAN" url="http://www.us.debian.org/security/2006/dsa-1148">DSA-1148</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21502">21502</ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=325285"></ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="1.5.2 rc2"/><vers num="1.5.1 rc2"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4.4 pl5"/><vers num="1.4.4 pl4"/><vers num="1.4.4 pl3"/><vers num="1.4.4 pl2"/><vers num="1.4.3 pl2"/><vers num="1.4.3 pl1"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4 pl2"/><vers num="1.4 pl1"/><vers num="1.4"/><vers num="1.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0331" published="2006-01-20" seq="2006-0331" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422414/100/0/threaded">20060119 Change passwd 3.1 (SquirrelMail plugin )</ref><ref source="" url="http://www.squirrelmail.org/plugin_view.php?id=117"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24258">
changepassword-changepasswd-bo(24258)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/363">363</ref></refs><vuln_soft><prod name="change_passwd" vendor="Thiago Melo de Paula"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-0332" published="2006-01-20" seq="2006-0332" severity="Medium" type="CVE"><desc><descript source="cve">Pantomime in Ecartis 1.0.0 snapshot 20050909 stores e-mail attachments in a publicly accessible directory, which may allow remote attackers to upload arbitrary files.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=listar-dev&amp;m=113732552708625&amp;w=2">[listar-dev] 20060115 [EDev] Re: Potential vulnerability -- who to contact?</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=listar-dev&amp;m=113770802408358&amp;w=2">[listar-dev] 20060119 [EDev] Re: Potential vulnerability -- who to contact?</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16317">16317</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0260">ADV-2006-0260</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18524">18524</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24220">
ecartis-pantomime-bypass-security(24220)</ref></refs><vuln_soft><prod name="Ecartis" vendor="Ecartis"><vers num="1.0.0 snapshot 2005-09-09"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-0333" published="2006-01-20" seq="2006-0333" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) month or (2) year parameter to index.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422386/100/0/threaded">20060118 -2- [XSS] in ar-blog v 5.2</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435205/100/0/threaded">20060527 Multiple Xss exploits in ar-blog v 5.2</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24246">
arblog-index-xss(24246)</ref></refs><vuln_soft><prod name="Ar-blog" vendor="Ar-blog"><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-0334" published="2006-01-20" seq="2006-0334" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in My Amazon Store Manager 1.0 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter.  NOTE: some sources claim that the affected parameter is &quot;q&quot;, but the only public archive of the original researcher notification shows an XSS manipulation in &quot;Keywords&quot;.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16312">16312</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0252">ADV-2006-0252</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18535">18535</ref><ref source="" url="http://osvdb.org/ref/22/22626-my_amazon.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22626">22626</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24230">masm-search-xss(24230)</ref></refs><vuln_soft><prod name="My Amazon Store Manager" vendor="Freekrai.net"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0335" published="2006-01-20" seq="2006-0335" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service via multiple unspecified vectors involving (1) long strings received from Active Directory and (2) the filtering of HTML.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.kerio.com/kwf_history.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16314">16314</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0247">ADV-2006-0247</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22631">22631</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18542">18542</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24232">kerio-winroute-html-dos(24232)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24233">kerio-winroute-activedirectory-dos(24233)</ref></refs><vuln_soft><prod name="WinRoute Firewall" vendor="Kerio"><vers num="6.1.4"/><vers num="6.1.3 Patch1"/><vers num="6.1.3"/><vers num="6.1.2"/><vers num="6.1.1"/><vers num="6.1.0"/><vers num="6.0.11"/><vers num="6.0.10"/><vers num="6.0.9"/><vers num="6.0.8"/><vers num="6.0.7"/><vers num="6.0.6"/><vers num="6.0.5"/><vers num="6.0.4"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0.0"/><vers num="5.10"/><vers num="5.1.10"/><vers num="5.1.9"/><vers num="5.1.8"/><vers num="5.1.7"/><vers num="5.1.6"/><vers num="5.1.5"/><vers num="5.1.4"/><vers num="5.1.3"/><vers num="5.1.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.9"/><vers num="5.0.8"/><vers num="5.0.7"/><vers num="5.0.6"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0336" published="2006-01-20" seq="2006-0336" severity="Medium" type="CVE"><desc><descript source="cve">Kerio WinRoute Firewall before 6.1.4 Patch 2 allows attackers to cause a denial of service (CPU consumption and hang) via unknown vectors involving &quot;browsing the web&quot;.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://www.kerio.com/kwf_history.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16385">16385</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0324">ADV-2006-0324</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18589">18589</ref><ref source="OSVDB" url="http://www.osvdb.org/22631">22631</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24317">
kerio-winroute-browsing-dos(24317)</ref></refs><vuln_soft><prod name="WinRoute Firewall" vendor="Kerio"><vers num="6.1.4 Patch 1"/><vers num="6.1.4"/><vers num="6.1.3 Patch1"/><vers num="6.1.3"/><vers num="6.1.2"/><vers num="6.1.1"/><vers num="6.1.0"/><vers num="6.0.11"/><vers num="6.0.10"/><vers num="6.0.9"/><vers num="6.0.8"/><vers num="6.0.7"/><vers num="6.0.6"/><vers num="6.0.5"/><vers num="6.0.4"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0.0"/><vers num="5.10"/><vers num="5.1.10"/><vers num="5.1.9"/><vers num="5.1.8"/><vers num="5.1.7"/><vers num="5.1.6"/><vers num="5.1.5"/><vers num="5.1.4"/><vers num="5.1.3"/><vers num="5.1.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.9"/><vers num="5.0.8"/><vers num="5.0.7"/><vers num="5.0.6"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0337" published="2006-01-20" seq="2006-0337" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote attackers to execute arbitrary code via crafted ZIP archives.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.f-secure.com/security/fsc-2006-1.shtml"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16309">16309</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0257">ADV-2006-0257</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18529">18529</ref><ref source="OSVDB" url="http://www.osvdb.org/22632">22632</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015507">1015507</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015508">1015508</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015509">1015509</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015510">1015510</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/q-103.shtml">Q-103</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24198">
fsecure-zip-bo(24198)</ref></refs><vuln_soft><prod name="Internet Gatekeeper" vendor="F-secure"><vers edition="Linux" num="2.14"/><vers edition="Linux" num="2.6"/><vers edition="Linux" num="2.06"/><vers num="6.42"/><vers num="6.41"/><vers num="6.32"/><vers num="6.31"/><vers num="6.4"/><vers num="6.3"/></prod><prod name="Solutions based on F-secure Personal Express" vendor="F-secure"><vers num="6.20"/></prod><prod name="F-Secure Anti-Virus" vendor="F-secure"><vers edition="Linux Server Security" num="5.11"/><vers edition="Linux Server Security" num="5.01"/><vers edition="Linux Server Security" num="5.0"/><vers edition="Linux Client Security" num="5.11"/><vers edition="Linux Client Security" num="5.01"/><vers edition="Linux Client Security" num="5.0"/><vers edition="Workstations" num="5.44"/><vers edition="Workstations" num="5.43"/><vers edition="Workstations" num="5.42"/><vers edition="Workstations" num="5.41"/><vers edition="Workstations" num="5.40"/><vers edition="Windows Servers" num="5.52"/><vers edition="Windows Servers" num="5.5"/><vers edition="Windows Servers" num="5.42"/><vers edition="Windows Servers" num="5.41"/><vers edition="Samba Servers" num="4.62"/><vers edition="MS Exchange" num="6.40"/><vers edition="MS Exchange" num="6.31"/><vers edition="MS Exchange" num="6.30 sr1"/><vers edition="MS Exchange" num="6.21"/><vers edition="MS Exchange" num="6.30"/><vers edition="MS Exchange" num="6.2"/><vers edition="MS Exchange" num="6.01"/><vers edition="MIMESweeper" num="5.61"/><vers edition="MIMESweeper" num="5.51"/><vers edition="MIMESweeper" num="5.5"/><vers edition="MIMESweeper" num="5.42"/><vers edition="MIMESweeper" num="5.41"/><vers edition="Linux Workstations" num="4.52"/><vers edition="Linux Workstations" num="4.51"/><vers edition="Linux Servers" num="4.64"/><vers edition="Linux Servers" num="4.61"/><vers edition="Linux Servers" num="4.52"/><vers edition="Linux Servers" num="4.51"/><vers edition="Linux Gateways" num="4.64"/><vers edition="Linux Gateways" num="4.61"/><vers edition="Linux Gateways" num="4.52"/><vers edition="Linux Gateways" num="4.51"/><vers edition="Linux Gateways" num="2.16"/><vers edition="Firewalls" num="6.2"/><vers edition="Citrix Servers" num="5.52"/><vers edition="Citrix Servers" num="5.5"/><vers edition="Client Security" num="6.01"/><vers edition="Client Security" num="5.55"/><vers edition="Client Security" num="5.54"/><vers edition="Client Security" num="5.52"/><vers edition="Client Security" num="5.5"/><vers num="2006"/><vers num="2005"/><vers num="2004"/></prod><prod name="F-secure Internet Security" vendor="F-secure"><vers num="2006"/><vers num="2005"/><vers num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-16" name="CVE-2006-0338" published="2006-01-20" seq="2006-0338" severity="Medium" type="CVE"><desc><descript source="cve">Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allow remote attackers to hide arbitrary files and data via malformed (1) RAR and (2) ZIP archives, which are not properly scanned.</descript></desc><loss_types><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.f-secure.com/security/fsc-2006-1.shtml"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16309">16309</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0257">ADV-2006-0257</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18529">18529</ref><ref source="OSVDB" url="http://www.osvdb.org/22633">22633</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015507">1015507</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015508">1015508</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015509">1015509</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015510">1015510</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/q-103.shtml">Q-103</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24199">
fsecure-rar-zip-scan-bypass(24199)</ref></refs><vuln_soft><prod name="Internet Gatekeeper" vendor="F-Secure"><vers num="6.42"/><vers num="6.41"/><vers num="6.32"/><vers edition="Linux" num="2.14"/><vers edition="Linux" num="2.06"/></prod><prod name="F-Secure Personal Express" vendor="F-Secure"><vers num="5.0"/><vers num="4.7"/><vers num="4.6"/><vers num="4.5"/></prod><prod name="F-Secure Anti-Virus" vendor="F-secure"><vers edition="Windows Servers" num="5.52"/><vers edition="Windows Servers" num="5.5"/><vers edition="Windows Servers" num="5.42"/><vers edition="Firewalls" num="6.2"/><vers edition="Linux Workstations" num="4.52"/><vers edition="Workstations" num="5.44"/><vers edition="Workstations" num="5.43"/><vers edition="Workstations" num="5.42"/><vers edition="Workstations" num="5.41"/><vers edition="Citrix Servers" num="5.52"/><vers edition="MIMESweeper" num="5.52"/><vers edition="MIMESweeper" num="5.5"/><vers edition="MIMESweeper" num="5.42"/><vers edition="MIMESweeper" num="5.41"/><vers edition="Client Security" num="6.01"/><vers edition="Client Security" num="5.55"/><vers edition="Client Security" num="5.52"/><vers edition="Client Security" num="5.5"/><vers edition="MS Exchange" num="6.40"/><vers edition="MS Exchange" num="6.31"/><vers edition="MS Exchange" num="6.30 sr1"/><vers edition="MS Exchange" num="6.30"/><vers edition="MS Exchange" num="6.21"/><vers edition="MS Exchange" num="6.2"/><vers edition="MS Exchange" num="6.01"/><vers num="2005"/><vers num="2004"/><vers num="2003"/><vers edition="Linux Servers" num="4.64"/><vers edition="Linux Servers" num="4.61"/><vers edition="Linux Servers" num="4.52"/><vers edition="Linux Servers" num="4.51"/><vers edition="Linux Gateways" num="4.64"/><vers edition="Linux Gateways" num="4.61"/><vers edition="Linux Gateways" num="4.52"/><vers edition="Linux Gateways" num="4.51"/><vers edition="Samba Servers" num="4.62"/><vers edition="Samba Servers" num="4.60"/><vers edition="Linux Client Security" num="5.11"/><vers edition="Linux Client Security" num="5.0"/><vers edition="Linux Server Security" num="5.11"/><vers edition="Linux Server Security" num="5.0"/></prod><prod name="F-Secure Internet Security" vendor="F-Secure"><vers num="2004"/><vers num="2005"/><vers num="2006"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0339" published="2006-01-20" seq="2006-0339" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in BitComet Client 0.60 allows remote attackers to execute arbitrary code, when the publisher&apos;s name link is clicked, via a long publisher URI in a torrent file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422361/100/0/threaded">20060118 Fortinet Advisory: BitComet URI Buffer Overflow Vulnerability</ref><ref adv="1" source="" url="http://www.fortinet.com/FortiGuardCenter/FSA-2006-07.html"></ref><ref source="" url="http://www.bitcomet.com/doc/changelog.htm"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16311">16311</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0251">ADV-2006-0251</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18522">18522</ref><ref source="OSVDB" url="http://www.osvdb.org/22625">22625</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24229">bitcomet-torrent-publisher-bo(24229)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0442.html">20060122 BitComet URI Proof of Concept</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0669.html">20060118 Fortinet Advisory: BitComet URI Buffer Overflow Vulnerability</ref><ref source="SREASON" url="http://securityreason.com/securityalert/357">357</ref></refs><vuln_soft><prod name="BitComet" vendor="BitComet"><vers num="0.60"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-08-20" name="CVE-2006-0340" published="2006-01-20" seq="2006-0340" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote attackers on the local network to cause a denial of service (device hang and network traffic loss) via a crafted UDP packet to port 9900.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20060118-sgbp.shtml">20060118 IOS Stack Group Bidding Protocol Crafted Packet DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/16303">16303</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0248">ADV-2006-0248</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015501">1015501</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18490">18490</ref><ref source="OSVDB" url="http://www.osvdb.org/22624">22624</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24182">cisco-ios-sgbp-dos(24182)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/358">358</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.4 XB"/><vers num="12.4 XA"/><vers num="12.4 T"/><vers num="12.4 MR"/><vers num="12.4"/><vers num="12.3 YX"/><vers num="12.3 YU"/><vers num="12.3 YT"/><vers num="12.3 YQ"/><vers num="12.3 YM"/><vers num="12.3 YK"/><vers num="12.3 YJ"/><vers num="12.3 YG"/><vers num="12.3 YF"/><vers num="12.3 XW"/><vers num="12.3 XU"/><vers num="12.3 XQ"/><vers num="12.3 XM"/><vers num="12.3 XJ"/><vers num="12.3 XI"/><vers num="12.3 XH"/><vers num="12.3 XF"/><vers num="12.3 XD"/><vers num="12.3 XB"/><vers num="12.3 T"/><vers num="12.3 BW"/><vers num="12.3 BC"/><vers num="12.3 B"/><vers num="12.3"/><vers num="12.2 ZN"/><vers num="12.2 ZJ"/><vers num="12.2 ZE"/><vers num="12.2 ZD"/><vers num="12.2 ZB"/><vers num="12.2 ZA"/><vers num="12.2 YZ"/><vers num="12.2 YY"/><vers num="12.2 YX"/><vers num="12.2 YW"/><vers num="12.2 YT"/><vers num="12.2 YN"/><vers num="12.2 YE"/><vers num="12.2 YD"/><vers num="12.2 XV"/><vers num="12.2 XT"/><vers num="12.2 XS"/><vers num="12.2 XL"/><vers num="12.2 XK"/><vers num="12.2 XG"/><vers num="12.2 XF"/><vers num="12.2 XC"/><vers num="12.2 XB"/><vers num="12.2 XA"/><vers num="12.2 T"/><vers num="12.2 SZ"/><vers num="12.2 SY"/><vers num="12.2 SU"/><vers num="12.2 S"/><vers num="12.2 MC"/><vers num="12.2 DX"/><vers num="12.2 DD"/><vers num="12.2 CX"/><vers num="12.2 BY"/><vers num="12.2 BW"/><vers num="12.2 BC"/><vers num="12.2 B"/><vers num="12.2"/><vers num="12.1 YD"/><vers num="12.1 YB"/><vers num="12.1 YA"/><vers num="12.1 XZ"/><vers num="12.1 XY"/><vers num="12.1 XX"/><vers num="12.1 XW"/><vers num="12.1 XU"/><vers num="12.1 XS"/><vers num="12.1 XQ"/><vers num="12.1 XM"/><vers num="12.1 XL"/><vers num="12.1 XI"/><vers num="12.1 XH"/><vers num="12.1 XD"/><vers num="12.1 XA"/><vers num="12.1 T"/><vers num="12.1 GB"/><vers num="12.1 GA"/><vers num="12.1 EZ"/><vers num="12.1 EX"/><vers num="12.1 EC"/><vers num="12.1 E"/><vers num="12.1 AA"/><vers num="12.1"/><vers num="12.0 XR"/><vers num="12.0 XN"/><vers num="12.0 XL"/><vers num="12.0 XK"/><vers num="12.0 XJ"/><vers num="12.0 XI"/><vers num="12.0 XH"/><vers num="12.0 XG"/><vers num="12.0 XE"/><vers num="12.0 XD"/><vers num="12.0 XC"/><vers num="12.0 XA"/><vers num="12.0 T"/><vers num="12.0 SC"/><vers num="12.0 S"/><vers num="12.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-23" name="CVE-2006-0341" published="2006-01-06" seq="2006-0341" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in WCONSOLE.DLL in Rockliffe MailSite 5.x and 6.1.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113777628702043&amp;w=2">20060120 RockLiffe MailSite wconsole.dll Denial of Service/Script Injection Vulnerability</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0284">ADV-2006-0284</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18551">18551</ref><ref source="BID" url="http://www.securityfocus.com/bid/16330">16330</ref><ref source="OSVDB" url="http://www.osvdb.org/22677">22677</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24256">mailsite-wconsole-xss(24256)</ref></refs><vuln_soft><prod name="MailSite" vendor="Rockliffe"><vers num="6.1.22" prev="1"/><vers num="7.0.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-0342" published="2006-01-20" seq="2006-0342" severity="High" type="CVE"><desc><descript source="cve">RockLiffe MailSite HTTP Mail management agent (httpma) 7.0.3.1 allows remote attackers to cause a denial of service (CPU consumption and crash) via a malformed query string containing special characters such as &quot;|&quot;.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113777628702043&amp;w=2">20060120 RockLiffe MailSite wconsole.dll Denial of Service/Script Injection Vulnerability</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0284">ADV-2006-0284</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18551">18551</ref><ref source="BID" url="http://www.securityfocus.com/bid/16331">16331</ref><ref source="OSVDB" url="http://www.osvdb.org/22678">22678</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24255">mailsite-wconsole-dos(24255)</ref></refs><vuln_soft><prod name="MailSite" vendor="Rockliffe"><vers num="7.0.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0343" published="2006-01-20" seq="2006-0343" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Port Discovery Standard and Advanced features in Hitachi JP1/NetInsight II allows attackers to stop the Port Discovery service via unknown vectors involving &quot;invalid format data&quot;.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS05-027_e/index-e.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0267">ADV-2006-0267</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18538">18538</ref><ref source="BID" url="http://www.securityfocus.com/bid/16327">16327</ref><ref source="OSVDB" url="http://www.osvdb.org/22676">22676</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015520">1015520</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24243">hitachi-jp1netinsight-port-dos(24243)</ref></refs><vuln_soft><prod name="JPI Netsight II Port Discovery Standard" vendor="Hitachi"><vers num="R_15237_9164 07_11"/><vers num="R_15237_9164 07_10"/><vers num="R_15237_9164 07_09"/><vers num="R_15237_9164 07_08"/><vers num="R_15237_9164 07_07"/><vers num="R_15237_9164 07_06"/><vers num="R_15237_9164 07_05"/><vers num="R_15237_9164 07_04"/><vers num="R_15237_9164 07_03"/><vers num="R_15237_9164 07_02"/><vers num="R_15237_9164 07_01"/><vers num="R_15237_9164 07_00"/></prod><prod name="JPI Netsight II Port Discovery Advance" vendor="Hitachi"><vers num="R_15237_9154 07_50"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-01" name="CVE-2006-0344" published="2006-01-20" seq="2006-0344" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Intervations FileCOPA FTP Server 1.01 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the (1) STOR and (2) RETR commands.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.nii.co.in/vuln/filecopa.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0285">ADV-2006-0285</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18550">18550</ref><ref source="BID" url="http://www.securityfocus.com/bid/16335">16335</ref><ref source="OSVDB" url="http://www.osvdb.org/22694">22694</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24257">filecopa-ftp-directory-traversal(24257)</ref></refs><vuln_soft><prod name="FileCOPA" vendor="Intervations"><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0345" published="2006-01-20" seq="2006-0345" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the search parameter to search.php.  NOTE: the id/viewprofile.php issue is already covered by CVE-2005-4058.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/40/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16306">16306</ref><ref source="OSVDB" url="http://www.osvdb.org/22740">22740</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015517">1015517</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0372.html">20060118 [eVuln] SaralBlog XSS &amp; Multiple SQL Injection Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24218">
saralblog-search-sql-injection(24218)</ref></refs><vuln_soft><prod name="saralblog" vendor="Saral Kaushik"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0346" published="2006-01-20" seq="2006-0346" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in SaralBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via a website field in a new comment to view.php, which is not properly handled in the comment function in functions.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/40/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16306">16306</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015517">1015517</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0372.html">20060118 [eVuln] SaralBlog XSS &amp; Multiple SQL Injection Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/27907">
27907</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24219">
saralblog-view-xss(24219)</ref></refs><vuln_soft><prod name="saralblog" vendor="Saral Kaushik"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0347" published="2006-01-20" seq="2006-0347" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access arbitrary files outside of the elog directory via &quot;../&quot; (dot dot) sequences in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://midas.psi.ch/elog/download/ChangeLog"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16315">16315</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0262">ADV-2006-0262</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18533">18533</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24224">elog-dotdot-directory-traversal(24224)</ref><ref source="OSVDB" url="http://www.osvdb.org/22647">22647</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-967">DSA-967</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18783">18783</ref></refs><vuln_soft><prod name="Elog Web Logbook" vendor="Stefan Ritt"><vers num="2.6.0"/><vers num="2.5.7"/><vers num="2.5.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.1"/><vers num="2.2.0"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0348" published="2006-01-20" seq="2006-0348" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the write_logfile function in ELOG before 2.6.1 allows remote attackers to cause a denial of service (server crash) via unknown attack vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://midas.psi.ch/elog/download/ChangeLog"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16315">16315</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0262">ADV-2006-0262</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18533">18533</ref><ref source="OSVDB" url="http://www.osvdb.org/22646">22646</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24221">elog-elogd-format-string(24221)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-967">DSA-967</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18783">18783</ref></refs><vuln_soft><prod name="Elog Web Logbook" vendor="Stefan Ritt"><vers num="2.6.0"/><vers num="2.5.7"/><vers num="2.5.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.1"/><vers num="2.2.0"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0349" published="2006-01-20" seq="2006-0349" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to blog.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/39/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16305">16305</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1015505">1015505</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18212">18212</ref><ref source="OSVDB" url="http://www.osvdb.org/22751">22751</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24210">eggblog-blog-sql-injection(24210)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0371.html">20060118 [eVuln] eggblog Multiple SQL Injection &amp; XSS Vulnerabilities</ref></refs><vuln_soft><prod name="Eggblog" vendor="Epic Designs"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0350" published="2006-01-20" seq="2006-0350" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/39/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16305">16305</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1015505">1015505</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18212">18212</ref><ref source="OSVDB" url="http://www.osvdb.org/22752">22752</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0371.html">20060118 [eVuln] eggblog Multiple SQL Injection &amp; XSS Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24209">
eggblog-topic-xss(24209)</ref></refs><vuln_soft><prod name="Eggblog" vendor="Epic Designs"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0351" published="2006-01-20" seq="2006-0351" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified &quot;critical denial-of-service vulnerability&quot; in MyDNS before 1.1.0 has unknown impact and attack vectors.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://mydns.bboy.net/download/changelog.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0256">ADV-2006-0256</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22636">22636</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18532">18532</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200601-16.xml">GLSA-200601-16</ref><ref source="BID" url="http://www.securityfocus.com/bid/16431">16431</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015521">1015521</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18653">18653</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24228">mydns-query-dos(24228)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-963">DSA-963</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18641">18641</ref></refs><vuln_soft><prod name="MyDNS" vendor="Don Moore"><vers num="1.0.0"/><vers num="0.11.0"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.1"/><vers num="0.10.0"/><vers num="0.9.0"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.8.3"/><vers num="0.8.2"/><vers num="0.8.1"/><vers num="0.8"/><vers num="0.7.1"/><vers num="0.7"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2006-0352" published="2006-01-20" seq="2006-0352" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of Fluffington FLog 1.01 installs users.0.dat under the web document root with insufficient access control, which might allow remote attackers to obtain sensitive information (login credentials) via a direct request.  NOTE: It was later reported that 1.1.2 is also affected.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422268/100/0/threaded">20060117 [eVuln] Flog Information Disclosure Vulnerability</ref><ref source="" url="http://evuln.com/vulns/38/summary/bt/"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456069/100/0/threaded">20070105 Flog 1.1.2 Remote Admin Password Disclosure</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31307">flog-admin-info-disclosure(31307)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24193">
flog-data-directory-insecure(24193)</ref></refs><vuln_soft><prod name="FLog" vendor="Fluffington"><vers num="1.01"/><vers num="1.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-0353" published="2006-01-22" seq="2006-0353" severity="Low" type="CVE"><desc><descript source="cve">unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed information that could be used to crack keys.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="MLIST" url="http://lists.lysator.liu.se/pipermail/lsh-bugs/2006q1/000467.html">[lsh-bugs] SECURITY: lshd leaks fd:s to user shells</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0301">ADV-2006-0301</ref><ref source="OSVDB" url="http://www.osvdb.org/22695">22695</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18564">18564</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24263">lsh-file-descriptor-leak(24263)</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-956">DSA-956</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16357">16357</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18623">18623</ref></refs><vuln_soft><prod name="lsh" vendor="GNU"><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.5" CVSS_exploit_subscore="5.1" CVSS_impact_subscore="6.9" CVSS_score="5.5" CVSS_vector="(AV:A/AC:L/Au:S/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-07-30" name="CVE-2006-0354" published="2006-01-22" seq="2006-0354" severity="Medium" type="CVE"><desc><descript source="cve">Cisco IOS before 12.3-7-JA2 on Aironet Wireless Access Points (WAP) allows remote authenticated users to cause a denial of service (termination of packet passing or termination of client connections) by sending the management interface a large number of spoofed ARP packets, which creates a large ARP table that exhausts memory, aka Bug ID CSCsc16644.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local_network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20060112-wireless.shtml">20060112 Access Point Memory Exhaustion from ARP Attacks</ref><ref source="BID" url="http://www.securityfocus.com/bid/16217">16217</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0176">ADV-2006-0176</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015483">1015483</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18430">18430</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24086">cisco-aironet-arp-dos(24086)</ref><ref source="OSVDB" url="http://www.osvdb.org/22375">22375</ref><ref source="SREASON" url="http://securityreason.com/securityalert/339">339</ref></refs><vuln_soft><prod name="Aironet" vendor="Cisco"><vers num="350 IOS"/><vers num="1400"/><vers num="1300"/><vers num="1240AG"/><vers num="1230AG"/><vers num="1200"/><vers num="1130AG"/><vers num="1100"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0355" published="2006-01-22" seq="2006-0355" severity="Medium" type="CVE"><desc><descript source="cve">Helmsman Research (aka CoolUtils) HomeFtp 1.1 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command and an NLST command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421869/100/0/threaded">20060114 [KAPDA::#21] - HomeFtp v1.1 Denial of Service</ref><ref adv="1" source="" url="http://www.kapda.ir/advisory-202.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16238">16238</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24152">
homeftp-long-command-dos(24152)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/350">350</ref></refs><vuln_soft><prod name="HomeFtp" vendor="Helmsman Research"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0356" published="2006-01-22" seq="2006-0356" severity="Medium" type="CVE"><desc><descript source="cve">Ari Pikivirta Home Ftp Server 1.0.7 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422033/100/0/threaded">20060115 Homeftp r1.0.7 Denial of Service</ref><ref adv="1" source="" url="http://www.kapda.ir/advisory-211.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24227">
homeftpserver-long-command-dos(24227)</ref></refs><vuln_soft><prod name="Home Ftp Server" vendor="Ari Pikivirta"><vers num="1.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-27" name="CVE-2006-0357" published="2006-01-22" seq="2006-0357" severity="Medium" type="CVE"><desc><descript source="cve">Grant Averett Cerberus FTP Server 2.32, and possibly earlier versions, allows remote attackers to cause an unspecified denial of service via a long string that does not contain a valid FTP command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422162/100/0/threaded">20060115 Cerberus FTP Server 2.32 Denial of Service</ref><ref source="" url="http://www.cerberusftp.com/cerberus-releasenotes.htm"></ref><ref adv="1" source="" url="http://www.kapda.ir/advisory-210.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24226">
cerberus-long-command-dos(24226)</ref></refs><vuln_soft><prod name="Cerberus FTP Server" vendor="Grant Averett"><vers num="2.32"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-27" name="CVE-2006-0358" published="2006-01-22" seq="2006-0358" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute arbitrary SQL commands via the search parameter in (1) index.php and (2) search.php. NOTE: This issue might overlap CVE-2004-0663.2.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422151/100/0/threaded">20060117 PowerPortal Cross-Site Scripting Vulnerability</ref><ref source="" url="http://web.archive.org/web/20050303003128/http://powerportal.sourceforge.net/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16279">16279</ref><ref source="OSVDB" url="http://www.osvdb.org/27958">27958</ref><ref source="OSVDB" url="http://www.osvdb.org/27957">27957</ref><ref source="SECUNIA" url="http://secunia.com/advisories/10172">10172</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24196">powerportal-search-index-xss(24196)</ref></refs><vuln_soft><prod name="PowerPortal" vendor="PowerPortal"><vers num="1.3b"/><vers num="1.3"/><vers num="1.1b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0359" published="2006-01-22" seq="2006-0359" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device crash) via SIP INVITE commands with a long header field name sent during startup and (2) cause a denial of service (device hang or crash) via SIP INVITE commands with a long header field name sent during a call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422009/100/0/threaded">20060116 CounterPath eyeBeam Handing SIP header Vulnerabilities</ref><ref source="" url="http://blog.donews.com/zwell/archive/2006/01/17/698810.aspx"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0259">ADV-2006-0259</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18516">18516</ref><ref source="BID" url="http://www.securityfocus.com/bid/16253">16253</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/446573/100/0/threaded">20060921 Re: CounterPath eyeBeam Handing SIP header Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24181">eyebeam-sip-header-bo(24181)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/354">354</ref></refs><vuln_soft><prod name="eyeBeam SIP Softphone" vendor="CounterPath"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-27" name="CVE-2006-0360" published="2006-01-22" seq="2006-0360" severity="Medium" type="CVE"><desc><descript source="cve">MPM SIP HP-180W Wireless IP Phone WE.00.17 allows remote attackers to obtain sensitive information and possibly cause a denial of service via a direct connection to UDP port 9090, which is undocumented and does not require authentication.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041437.html">20060116 MPM HP-180W VoIP wireless desktop phone undocumented port UDP/9090</ref><ref source="BID" url="http://www.securityfocus.com/bid/16285">16285</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18512">18512</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24147">
mpn-hp180w-default-port(24147)</ref></refs><vuln_soft><prod name="HP-180W VOIP WIFI Phone" vendor="MPM"><vers num="WE.00.17"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-01-15" modified="2006-06-01" name="CVE-2006-0361" published="2006-01-22" seq="2006-0361" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in addcomment.php in Bit 5 Blog 8.01 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in an &lt;a&gt; tag in the comment parameter, which strips most tags but not &lt;a&gt;.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421994/100/0/threaded">20060115 [eVuln] Bit 5 Blog JavaScript Insertion Vulnerability</ref><ref source="" url="http://evuln.com/vulns/32/exploit"></ref><ref adv="1" source="" url="http://evuln.com/vulns/32/summary/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0195">ADV-2006-0195</ref><ref source="OSVDB" url="http://www.osvdb.org/22446">22446</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18464">18464</ref><ref source="BID" url="http://www.securityfocus.com/bid/16246">16246</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24129">
bit5blog-addcomment-xss(24129)</ref></refs><vuln_soft><prod name="Bit 5 Blog" vendor="Bit 5 Blog"><vers num="8.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0362" published="2006-01-22" seq="2006-0362" severity="Medium" type="CVE"><desc><descript source="cve">TippingPoint Intrusion Prevention System (IPS) TOS before 2.1.4.6324, and TOS 2.2.x before 2.2.1.6506, allow remote attackers to cause a denial of service (CPU consumption) via an unknown vector, probably involving an HTTP request with a negative number in the Content-Length header.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://isc.sans.org/diary.php?storyid=1042"></ref><ref patch="1" source="" url="http://www.eweek.com/article2/0,1759,1912048,00.asp"></ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22504">22504</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015511">1015511</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18515">18515</ref><ref source="BID" url="http://www.securityfocus.com/bid/16299">16299</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24200">
tippingpoint-ips-http-traffic-dos(24200)</ref></refs><vuln_soft><prod name="TippingPoint IPS" vendor="3Com"><vers num="2.1.3.6323"/><vers num="2.2.0.6504"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-24" name="CVE-2006-0363" published="2006-01-22" seq="2006-0363" severity="Low" type="CVE"><desc><descript source="cve">The &quot;Remember my Password&quot; feature in MSN Messenger 7.5 stores passwords in an encrypted format under the HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\Creds registry key, which might allow local users to obtain the original passwords via a program that calls CryptUnprotectData, as demonstrated by the &quot;MSN Password Recovery.exe&quot; program.  NOTE: it could be argued that local-only password recovery is inherently insecure because the decryption methods and keys must be stored somewhere on the local system, and are thus inherently accessible with varying degrees of effort.  Perhaps this issue should not be included in CVE.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421921/100/0/threaded">20060113 Re: MSN Messenger Password Decrypter for WinXP/2003</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422283/100/0/threaded">20060117 Re: MSN Messenger Password Decrypter for WinXP/2003</ref><ref source="" url="http://www.msn-password-recovery.com/"></ref></refs><vuln_soft><prod name="MSN Messenger Service" vendor="Microsoft"><vers num="7.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-08-26" name="CVE-2006-0364" published="2006-01-22" seq="2006-0364" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via a signature containing a JavaScript URI in the SRC attribute of an IMG element, in which the URI uses SGML numeric character references without trailing semicolons, as demonstrated by &quot;javascript&quot;.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0332.html">20060118 MyBB Signature HTML Code Injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/16308">16308</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0255">ADV-2006-0255</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18544">18544</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24225">mybb-html-signature-xss(24225)</ref><ref source="OSVDB" url="http://www.osvdb.org/22628">22628</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC4"/><vers num="1.0 RC2"/><vers num="1.0 Preview Release 2"/><vers num="1.0 PR2"/><vers num="1.0 Final"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-24" name="CVE-2006-0365" published="2006-01-22" seq="2006-0365" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in XMB (aka extreme message board) allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422277/100/0/threaded">20060118 XMB Forum HTML Code Injection</ref><ref source="OSVDB" url="http://www.osvdb.org/27920">
27920</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24208">
xmbforum-imgsrc-xss(24208)</ref></refs><vuln_soft><prod name="XMB Forum" vendor="XMB Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-15" name="CVE-2006-0366" published="2006-01-22" seq="2006-0366" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Phpclanwebsite (aka PCW) allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a BBCode img tag.</descript></desc><sols><sol source="nvd">A simple fix has been released on the Main PCW site available directly at &lt;a href=&quot;http://www.phpclanwebsite.com/index.php?page=downloads&amp;func=browselist&amp;par=1&quot;&gt;http://www.phpclanwebsite.com/index.php?page=downloads&amp;func=browselist&amp;par=1
&lt;/a&gt;Please download and install imediately. </sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422265/100/0/threaded">20060117 Phpclanwebsite BBCode IMG Tag XSS Vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16300">16300</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0254">ADV-2006-0254</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18541">18541</ref></refs><vuln_soft><prod name="Phpclanwebsite" vendor="Phpclanwebsite"><vers num="1.23.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-30" name="CVE-2006-0367" published="2006-01-22" seq="2006-0367" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote authenticated users with read-only administrative privileges to obtain full administrative privileges via a &quot;crafted URL on the CCMAdmin web page.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20060118-ccmpe.shtml">20060118 Cisco Call Manager Privilege Escalation</ref><ref source="BID" url="http://www.securityfocus.com/bid/16293">16293</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0250">ADV-2006-0250</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18501">18501</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22621">22621</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015502">1015502</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24172">
cisco-callmanager-ccmadmin-gain-priv(24172)</ref></refs><vuln_soft><prod name="Call Manager" vendor="Cisco"><vers num="4.1.3 SR1"/><vers num="4.1.3 ES07"/><vers num="4.1.2 ES33"/><vers num="4.0.2a SR2b"/><vers num="4.0.2a ES40"/><vers num="4.0"/><vers num="3.3.5"/><vers num="3.3.4 ES25"/><vers num="3.3.3 ES61"/><vers num="3.3.3"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1.3a"/><vers num="3.1.2"/><vers num="3.1"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-24" name="CVE-2006-0368" published="2006-01-22" seq="2006-0368" severity="High" type="CVE"><desc><descript source="cve">Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of service (CPU and memory consumption) via a large number of open TCP connections to port 2000 and (2) cause a denial of service (fill the Windows Service Manager communication queue) via a large number of TCP connections to port 2001, 2002, or 7727.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20060118-ccmdos.shtml">20060118 Cisco Call Manager Denial of Service</ref><ref source="BID" url="http://www.securityfocus.com/bid/16295">16295</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0249">ADV-2006-0249</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18494">18494</ref><ref source="OSVDB" url="http://www.osvdb.org/22622">22622</ref><ref source="OSVDB" url="http://www.osvdb.org/22623">22623</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015503">1015503</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24180">cisco-callmanager-port-connection-dos(24180)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/359">359</ref></refs><vuln_soft><prod name="Call Manager" vendor="Cisco"><vers num="4.1.3 SR1"/><vers num="4.1.3 ES32"/><vers num="4.1.3 ES07"/><vers num="4.1.2 ES55"/><vers num="4.1.2 ES33"/><vers num="4.0.2a SR2b"/><vers num="4.0.2a ES62"/><vers num="4.0.2a ES40"/><vers num="4.0"/><vers num="3.3.5 ES30"/><vers num="3.3.5"/><vers num="3.3.4 ES25"/><vers num="3.3.3 ES61"/><vers num="3.3.3"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1.3a"/><vers num="3.1.2"/><vers num="3.1"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0369" published="2006-01-22" seq="2006-0369" severity="Low" type="CVE"><desc><descript source="cve">** DISPUTED **  MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the &quot;SELECT * FROM information_schema.views;&quot; query, which returns the query that created the VIEW.  NOTE: this issue has been disputed by third parties, saying that the availability of the schema is a normal and sometimes desired aspect of database access.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422491/100/0/threaded">20060120 MySQL 5.0 information leak?</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/422592/100/0/threaded">20060121 RE: MySQL 5.0 information leak?</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/422698/100/0/threaded">20060121 Re: MySQL 5.0 information leak?</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423228/100/0/threaded">20060123 RE: MySQL 5.0 information leak?</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423204/100/0/threaded">20060124 Re: MySQL 5.0 information leak?</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423432/100/0/threaded">20060128 Re: MySQL 5.0 information leak?</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423180/30/7310/threaded">20060122 Re: MySQL 5.0 information leak?</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="5.0.18"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-24" name="CVE-2006-0370" published="2006-01-22" seq="2006-0370" severity="Medium" type="CVE"><desc><descript source="cve">Noah Medling RCBlog 1.03 stores the data and config directories under the web root with insufficient access control, which allows remote attackers to view account names and MD5 password hashes.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422499/100/0/threaded">20060120 [eVuln] RCBlog Directory Traversal &amp; Sensitive Information Disclosure</ref><ref adv="1" source="" url="http://evuln.com/vulns/42/summary.html"></ref><ref source="" url="http://www.fluffington.com/index.php?page=rcblog"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18547">18547</ref><ref source="OSVDB" url="http://www.osvdb.org/22679">22679</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015523">1015523</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24249">rcblog-data-config-insecure-directories(24249)</ref></refs><vuln_soft><prod name="RCBlog" vendor="Noah Medling"><vers num="1.03"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-24" name="CVE-2006-0371" published="2006-01-22" seq="2006-0371" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in Noah Medling RCBlog 1.03 allows remote attackers to read arbitrary .txt files, possibly including one that stores the administrator&apos;s account name and password, via a .. (dot dot) in the post parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422499/100/0/threaded">20060120 [eVuln] RCBlog Directory Traversal &amp; Sensitive Information Disclosure</ref><ref adv="1" source="" url="http://evuln.com/vulns/42/summary.html"></ref><ref source="" url="http://www.fluffington.com/index.php?page=rcblog"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16342">16342</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18547">18547</ref><ref source="OSVDB" url="http://www.osvdb.org/22680">22680</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015523">1015523</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24248">rcblog-index-directory-traversal(24248)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425392/100/0/threaded">20060218 RCblog exploit [fun]</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/436784/30/4500/threaded">
20060611 RCblog 1.03 Directory Traversal [index.php]</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27042">
rcblog-index-file-include(27042)</ref></refs><vuln_soft><prod name="RCBlog" vendor="Noah Medling"><vers num="1.03"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-0372" published="2006-01-22" seq="2006-0372" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) blogphp_username or (2) blogphp_password parameter in a cookie.</descript></desc><sols><sol source="nvd">BlogPHP version 2.0 was released to fix the config.php exploit and is available for download at &lt;a href=&quot;http://sourceforge.net/project/showfiles.php?group_id=156043&quot;&gt;http://sourceforge.net/project/showfiles.php?group_id=156043&lt;/a&gt;.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422483/100/0/threaded">20060120 BlogPHP config.php SQL injection login bypass</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422484/100/0/threaded">20060120 BlogPHP config.php SQL injection login bypass</ref><ref source="BID" url="http://www.securityfocus.com/bid/16340">16340</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422593/100/0/threaded">20060121 BlogPHP config.php SQL injection login bypassed</ref><ref source="OSVDB" url="http://www.osvdb.org/22738">22738</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24131">
blogphp-index-bypass-security(24131)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/365">365</ref></refs><vuln_soft><prod name="BlogPHP" vendor="Insane Visions"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-24" name="CVE-2006-0373" published="2006-01-22" seq="2006-0373" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in register.aspx in Douran FollowWeb allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16302">16302</ref><ref source="OSVDB" url="http://www.osvdb.org/27918">
27918</ref></refs><vuln_soft><prod name="FollowWeb" vendor="Douran"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0374" published="2006-01-22" seq="2006-0374" severity="High" type="CVE"><desc><descript source="cve">Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-system data, by directly accessing the VxWorks WDB remote debugging ONCRPC (aka wdbrpc) on UDP 17185, (2) reflect network data using echo (TCP 7), or (3) gain access without authentication using rlogin (TCP 513).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041434.html">20060116 ACT P202S VoIP wireless phone multiple undocumented ports/services</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18514">18514</ref><ref source="BID" url="http://www.securityfocus.com/bid/16288">16288</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24149">act-p202s-default-port(24149)</ref></refs><vuln_soft><prod name="P202S" vendor="Advantage Century Telecommunication"><vers num="1.01.21 firmware 1.1.21"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-24" name="CVE-2006-0375" published="2006-01-22" seq="2006-0375" severity="Medium" type="CVE"><desc><descript source="cve">Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 on VxWorks uses a hardcoded Network Time Protocol (NTP) server in Taiwan, which could allow remote attackers to provide false time information, block access to time information, or conduct other attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041434.html">20060116 ACT P202S VoIP wireless phone multiple undocumented ports/services</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18514">18514</ref><ref source="BID" url="http://www.securityfocus.com/bid/16288">16288</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24149">
act-p202s-default-port(24149)</ref></refs><vuln_soft><prod name="P202S" vendor="Advantage Century Telecommunication"><vers num="1.01.21 firmware 1.1.21"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-0376" published="2006-01-22" seq="2006-0376" severity="High" type="CVE"><desc><descript source="cve">The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user when (1) it establishes an association with a station in ad hoc (aka peer-to-peer) mode or (2) a station in ad hoc mode establishes an association with it, which allows remote attackers to put unexpected wireless communication into place.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421868/100/0/threaded">20060114 [NMRC Advisory] Microsoft Windows Wireless Exposure on Laptops</ref><ref adv="1" source="" url="http://www.nmrc.org/pub/advise/20060114.txt"></ref><ref source="" url="http://www.theta44.org/karma/"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015489">1015489</ref><ref source="" url="http://www.securiteam.com/windowsntfocus/5YP0D2KHHO.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24157">
windows-wireless-adhoc-unauth-access(24157)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/349">349</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Home"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="SP2"/><vers num="SP3"/><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-24" name="CVE-2006-0377" published="2006-02-23" seq="2006-0377" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka &quot;IMAP injection.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.squirrelmail.org/security/issue/2006-02-15"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16756">16756</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0689">ADV-2006-0689</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015662">1015662</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18985">18985</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24849">squirrelmail-mailbox-imap-injection(24849)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-988">DSA-988</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00004.html">FEDORA-2006-133</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:049">MDKSA-2006:049</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_05_sr.html">SUSE-SR:2006:005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19131">19131</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19130">19130</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19176">19176</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-09.xml">GLSA-200603-09</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19205">19205</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0283.html">RHSA-2006:0283</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19960">19960</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:049">MDKSA-2006:049</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.4.6 rc1"/><vers num="1.4.5"/><vers num="1.4.4 RC1"/><vers num="1.4.4"/><vers num="1.4.3 RC1"/><vers num="1.4.3 r3"/><vers num="1.4.3a"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4 RC1"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-24" name="CVE-2006-0378" published="2006-01-23" seq="2006-0378" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Netrix X-Site Manager allows remote attackers to inject arbitrary web script or HTML via the product_id parameter, as originally demonstrated for a custom mp3players_details.php program.  NOTE: the name of the affected program might be installation-dependent, but it has been identified as &quot;product_details.php&quot; by some sources.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://osvdb.org/ref/22/22634-x-site.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16313">16313</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0253">ADV-2006-0253</ref><ref source="OSVDB" url="http://www.osvdb.org/22634">22634</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18537">18537</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24234">xsitemanager-productdetails-xss(24234)</ref></refs><vuln_soft><prod name="X-Site Manager" vendor="Netrix"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0379" published="2006-01-25" seq="2006-0379" severity="Low" type="CVE"><desc><descript source="cve">FreeBSD kernel 5.4-STABLE and 6.0 does not completely initialize a buffer before making it available to userland, which could allow local users to read portions of kernel memory.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:06.kmem.asc">FreeBSD-SA-06:06</ref><ref source="BID" url="http://www.securityfocus.com/bid/16373">16373</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18599">18599</ref><ref source="OSVDB" url="http://www.osvdb.org/22730">22730</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015541">1015541</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24338">bsd-buffer-initialization-disclosure(24338)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.0 Stable"/><vers num="5.4 Stable"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0380" published="2006-01-25" seq="2006-0380" severity="Low" type="CVE"><desc><descript source="cve">A logic error in FreeBSD kernel 5.4-STABLE and 6.0 causes the kernel to calculate an incorrect buffer length, which causes more data to be copied to userland than intended, which could allow local users to read portions of kernel memory.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:06.kmem.asc">FreeBSD-SA-06:06</ref><ref source="BID" url="http://www.securityfocus.com/bid/16373">16373</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18599">18599</ref><ref source="OSVDB" url="http://www.osvdb.org/22731">22731</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015541">1015541</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24340">bsd-buffer-length-disclosure(24340)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.0 Stable"/><vers num="5.4 Stable"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-31" name="CVE-2006-0381" published="2006-01-25" seq="2006-0381" severity="Medium" type="CVE"><desc><descript source="cve">A logic error in the IP fragment cache functionality in pf in FreeBSD 5.3, 5.4, and 6.0, and OpenBSD, when a &apos;scrub fragment crop&apos; or &apos;scrub fragment drop-ovl&apos; rule is being used, allows remote attackers to cause a denial of service (crash) via crafted packets that cause a packet fragment to be inserted twice.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:07.pf.asc">FreeBSD-SA-06:07</ref><ref source="BID" url="http://www.securityfocus.com/bid/16375">16375</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18609">18609</ref><ref source="" url="http://www.openbsd.org/cgi-bin/cvsweb/src/sys/net/pf_norm.c.diff?r1=1.103&amp;r2=1.104"></ref><ref source="OSVDB" url="http://www.osvdb.org/22732">22732</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015542">1015542</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24337">bsd-pf-fragment-dos(24337)</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-004.txt.asc">NetBSD-SA2006-004</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.0 Stable"/><vers num="6.0 Release"/><vers num="5.4 Releng"/><vers num="5.4 Release"/><vers num="5.4 pre"/><vers num="5.3 Stable"/><vers num="5.3 Releng"/><vers num="5.3 Release"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0382" published="2006-02-14" seq="2006-0382" severity="Low" type="CVE"><desc><descript source="cve">Apple Mac OS X 10.4.5 and allows local users to cause a denial of service (crash) via an undocumented system call.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Feb/msg00000.html">APPLE-SA-2006-02-14</ref><ref source="BID" url="http://www.securityfocus.com/bid/16654">16654</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0597">ADV-2006-0597</ref><ref source="OSVDB" url="http://www.osvdb.org/23190">23190</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015634">1015634</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18907">18907</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24682">macosx-system-call-dos(24682)</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0383" published="2006-03-02" seq="2006-0383" severity="Medium" type="CVE"><desc><descript source="cve">IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving the &quot;incorrect handling of error conditions&quot;.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html">APPLE-SA-2006-03-01</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16907">16907</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0791">ADV-2006-0791</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19064">19064</ref><ref source="OSVDB" url="http://www.osvdb.org/23643">
23643</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25025">
macosx-vpn-dos(25025)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=303382"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html">TA06-062A</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0384" published="2006-03-02" seq="2006-0384" severity="High" type="CVE"><desc><descript source="cve">automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via unspecified vectors that cause automount to &quot;mount file systems with reserved names&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html">APPLE-SA-2006-03-01</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16907">16907</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0791">ADV-2006-0791</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19064">19064</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015709">1015709</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25021">macosx-automount-execute-code(25021)</ref><ref source="OSVDB" url="http://www.osvdb.org/23640">23640</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=303382"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html">TA06-062A</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod></vuln_soft></entry><entry CVSS_base_score="1.7" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="2.9" CVSS_score="1.7" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-0386" published="2006-03-03" seq="2006-0386" severity="Low" type="CVE"><desc><descript source="cve">FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a FileVault image, which allows local users to access protected files when FileVault is enabled.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html">APPLE-SA-2006-03-01</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16907">16907</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0791">ADV-2006-0791</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19064">19064</ref><ref source="OSVDB" url="http://www.osvdb.org/23642">23642</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25024">macosx-filevault-file-access(25024)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=303382"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html">TA06-062A</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-06" name="CVE-2006-0387" published="2006-03-06" seq="2006-0387" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Safari in Mac OS X 10.4.5 and earlier, and 10.3.9 and earlier, allows remote attackers to execute arbitrary code via unspecified vectors involving a web page with crafted JavaScript, a different vulnerability than CVE-2005-4504.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html">APPLE-SA-2006-03-01</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/16907">16907</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0791">ADV-2006-0791</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19064">19064</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/176732">VU#176732</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015713">1015713</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25032">
macosx-safari-bo(25032)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=303382"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html">TA06-062A</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-0388" published="2006-03-03" seq="2006-0388" severity="Medium" type="CVE"><desc><descript source="cve">Safari in Mac OS X 10.3 before 10.3.9 and 10.4 before 10.4.5 allows remote attackers to redirect users to local files and execute arbitrary JavaScript via unspecified vectors involving HTTP redirection to local resources.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html">APPLE-SA-2006-03-01</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16907">16907</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0791">ADV-2006-0791</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19064">19064</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015713">1015713</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25038">
macosx-safari-http-redirect(25038)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=303382"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html">TA06-062A</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-0389" published="2006-03-03" seq="2006-0389" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Syndication (Safari RSS) in Mac OS X 10.4 through 10.4.5 allows remote attackers to execute arbitrary JavaScript via unspecified vectors involving RSS feeds.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html">APPLE-SA-2006-03-01</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16907">16907</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0791">ADV-2006-0791</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19064">19064</ref><ref source="OSVDB" url="http://www.osvdb.org/23649">23649</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25040">
macosx-syndication-xss(25040)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=303382"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html">TA06-062A</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry modified="2006-03-06" name="CVE-2006-0390" published="2006-03-06" reject="1" seq="2006-0390" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-4504.  Reason: This candidate is a duplicate of CVE-2005-4504.  Notes: All CVE users should reference CVE-2005-4504 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="1.7" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="2.9" CVSS_score="1.7" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0391" published="2006-03-03" seq="2006-0391" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the BOM framework in Mac OS X 10.x before 10.3.9 and 10.4 before 10.4.5 allows user-assisted attackers to overwrite or create arbitrary files via an archive that is handled by BOMArchiveHelper.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=399">20060302 Apple MacOS X BOMArchiveHelper Directory Traversal Vulnerability</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html">APPLE-SA-2006-03-01</ref><ref source="BID" url="http://www.securityfocus.com/bid/16907">16907</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0791">ADV-2006-0791</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19064">19064</ref><ref source="OSVDB" url="http://www.osvdb.org/23641">23641</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25023">
macosx-bom-directory-traversal(25023)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=303382"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html">TA06-062A</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.1"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-26" name="CVE-2006-0392" published="2006-08-02" seq="2006-0392" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Canon RAW image.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html">APPLE-SA-2006-08-01</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21253">21253</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/527236">VU#527236</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3101">ADV-2006-3101</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/28142">macosx-raw-image-bo(28142)</ref><ref source="OSVDB" url="http://www.osvdb.org/27739">27739</ref><ref source="BID" url="http://www.securityfocus.com/bid/19289">19289</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html">
TA06-214A</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.7"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-26" name="CVE-2006-0393" published="2006-08-02" seq="2006-0393" severity="Medium" type="CVE"><desc><descript source="cve">OpenSSH in Apple Mac OS X 10.4.7 allows remote attackers to cause a denial of service or determine account existence by attempting to log in using an invalid user, which causes the server to hang.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html">APPLE-SA-2006-08-01</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21253">21253</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3101">ADV-2006-3101</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/28147">macosx-openssh-nonexistent-user-dos(28147)</ref><ref source="OSVDB" url="http://www.osvdb.org/27745">27745</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016672">1016672</ref><ref source="BID" url="http://www.securityfocus.com/bid/19289">19289</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html">
TA06-214A</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.7"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.7"/></prod></vuln_soft></entry><entry modified="2006-03-02" name="CVE-2006-0394" published="2006-03-01" reject="1" seq="2006-0394" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0848.  Reason: This candidate is a duplicate of CVE-2006-0848.  Notes: All CVE users should reference CVE-2006-0848 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-08" name="CVE-2006-0395" published="2006-08-04" seq="2006-0395" severity="Medium" type="CVE"><desc><descript source="cve">The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an unsafe type, which allows user-assisted remote attackers to execute arbitrary code via crafted file types.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=303382"></ref><ref source="APPLE" url="http://lists.apple.com/archives/client-management/2006/Mar/msg00030.html">APPLE-SA-2006-03-01</ref><ref source="BID" url="http://www.securityfocus.com/bid/16907">16907</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0791">ADV-2006-0791</ref><ref source="OSVDB" url="http://www.osvdb.org/23645">23645</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19064">19064</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25027">macosx-mail-bypass-security(25027)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html">TA06-062A</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-21" name="CVE-2006-0396" published="2006-03-14" seq="2006-0396" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006-001, allows remote attackers to execute arbitrary code via a long Real Name value in an e-mail attachment sent in AppleDouble format, which triggers the overflow when the user double-clicks on an attachment.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html">APPLE-SA-2006-03-13</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=303453"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17081">17081</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0949">ADV-2006-0949</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19129">19129</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427601/100/0/threaded">20060314 DMA[2006-0313a] - &apos;Apple OSX Mail.app RFC1740 Real Name Buffer Overflow&apos;</ref><ref adv="1" source="" url="http://www.digitalmunition.com/DMA%5B2006-0313a%5D.txt"></ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015762">1015762</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/980084">VU#980084</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25209">macosx-mail-attachment-bo(25209)</ref><ref source="OSVDB" url="http://www.osvdb.org/23872">23872</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-05" name="CVE-2006-0397" published="2006-03-14" seq="2006-0397" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html">APPLE-SA-2006-03-13</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=303453"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0949">ADV-2006-0949</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19129">19129</ref><ref source="OSVDB" url="http://www.osvdb.org/23869">23869</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015760">1015760</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25269">macosx-safefiletype-command-execution(25269)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-05" name="CVE-2006-0398" published="2006-03-14" seq="2006-0398" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html">APPLE-SA-2006-03-13</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=303453"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0949">ADV-2006-0949</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19129">19129</ref><ref source="OSVDB" url="http://www.osvdb.org/23870">23870</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015760">1015760</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25269">macosx-safefiletype-command-execution(25269)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-05" name="CVE-2006-0399" published="2006-03-14" seq="2006-0399" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html">APPLE-SA-2006-03-13</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=303453"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0949">ADV-2006-0949</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19129">19129</ref><ref source="OSVDB" url="http://www.osvdb.org/23871">23871</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015760">1015760</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25269">macosx-safefiletype-command-execution(25269)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-15" name="CVE-2006-0400" published="2006-03-14" seq="2006-0400" severity="High" type="CVE"><desc><descript source="cve">CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to bypass the same-origin policy and execute Javascript in other domains via unknown vectors involving &quot;crafted archives.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html">APPLE-SA-2006-03-13</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=303453"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17082">17082</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0949">ADV-2006-0949</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19129">19129</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015763">1015763</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25208">macosx-sameorigin-policy-bypass(25208)</ref><ref source="OSVDB" url="http://www.osvdb.org/23873">23873</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-05" name="CVE-2006-0401" published="2006-04-05" seq="2006-0401" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Mac OS X before 10.4.6, when running on an Intel-based computer, allows attackers with physical access to bypass the firmware password and log on in Single User Mode via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=303567"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17364">17364</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1215">ADV-2006-1215</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19462">19462</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015859">1015859</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25620">macosx-firmware-password-bypass(25620)</ref><ref source="OSVDB" url="http://www.osvdb.org/24399">24399</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0402" published="2006-01-24" seq="2006-0402" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Zoph before 0.5pre1 allows remote attackers to execute arbitrary SQL commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=69353&amp;release_id=387320"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16347">16347</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0297">ADV-2006-0297</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18563">18563</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24264">zoph-sql-injection(24264)</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?group_id=69353&amp;release_id=387320"></ref><ref source="OSVDB" url="http://www.osvdb.org/22743">22743</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-989">DSA-989</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19153">19153</ref></refs><vuln_soft><prod name="Zoph" vendor="Jason Geiger"><vers num="0.4"/><vers num="0.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-31" name="CVE-2006-0403" published="2006-01-24" seq="2006-0403" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in e-moBLOG 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) monthy parameter to index.php or (2) login parameter to admin/index.php. NOTE: some sources have reported item 1 as involving the &quot;monthly&quot; parameter, but this is incorrect.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/43/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16344">16344</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0296">ADV-2006-0296</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015524">1015524</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18567">18567</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24245">emoblog-index-sql-injection(24245)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422938/100/0/threaded">20060122 [eVuln] e-moBLOG SQL Injection Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/22700">22700</ref><ref source="OSVDB" url="http://www.osvdb.org/22701">22701</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-January/000511.html">[VIM] 20060125 The parameter in e-moBLOG is &quot;monthy&quot; [sic]</ref><ref source="SREASON" url="http://securityreason.com/securityalert/370">370</ref></refs><vuln_soft><prod name="e-moBLOG" vendor="e-moBLOG"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-25" name="CVE-2006-0404" published="2006-01-24" seq="2006-0404" severity="Medium" type="CVE"><desc><descript source="cve">Note-A-Day Weblog 2.2 stores sensitive data under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to archive/.phpass-admin, which contains encrypted passwords.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/44/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0299">ADV-2006-0299</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18566">18566</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24270">noteaday-archive-directory-insecure(24270)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0389.html">20060122 [eVuln] Note-A-Day Weblog Sensitive Information Disclosure</ref><ref source="OSVDB" url="http://www.osvdb.org/22699">22699</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015539">1015539</ref><ref source="SREASON" url="http://securityreason.com/securityalert/371">371</ref></refs><vuln_soft><prod name="Note-A-Day Weblog" vendor="Mike Macgirvin"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-30" name="CVE-2006-0405" published="2006-01-24" seq="2006-0405" severity="Medium" type="CVE"><desc><descript source="cve">The TIFFFetchShortPair function in tif_dirread.c in libtiff 3.8.0 allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers a NULL pointer dereference, possibly due to changes in type declarations and/or the TIFFVSetField function.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://bugzilla.remotesensing.org/show_bug.cgi?id=1029"></ref><ref source="" url="http://bugzilla.remotesensing.org/show_bug.cgi?id=1034"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18587">18587</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24275">libtiff-tiffvsetfield-dos(24275)</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0302">ADV-2006-0302</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-17.xml">GLSA-200605-17</ref><ref source="BID" url="http://www.securityfocus.com/bid/18172">18172</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20345">20345</ref></refs><vuln_soft><prod name="libTIFF" vendor="libTIFF"><vers num="3.8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-05" name="CVE-2006-0406" published="2006-01-24" seq="2006-0406" severity="Medium" type="CVE"><desc><descript source="cve">search.php in MyBB 1.0.2 allows remote attackers to obtain sensitive information via a certain search request that reveals the table prefix in a SQL error message, possibly due to invalid parameters.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422227/100/0/threaded">20060114 MyBB 1.0.2 Sniffing table perfix bug in search.php</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18577">18577</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24272">mybb-search-information-disclosure(24272)</ref><ref source="OSVDB" url="http://www.osvdb.org/22736">22736</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-01-20" modified="2006-04-30" name="CVE-2006-0407" published="2006-01-24" seq="2006-0407" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter.  NOTE: the original disclosure specified the name parameter, but a correction was later provided. NOTE: followup posts have both disputed and confirmed the original claim.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://kapda.ir/advisory-236.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0298">ADV-2006-0298</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18565">18565</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423353/100/0/threaded">20060123 Azbb v1.1.00 Cross-Site Scripting</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423363/100/0/threaded">20060128 [CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/16351">16351</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24274">azbulletinboard-post-xss(24274)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427076/100/0/threaded">20060308 Re: [CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting </ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427194/100/0/threaded">20060309 Re: Re: [CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427076/30/6510/threaded">20060308 Re: [CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting</ref></refs><vuln_soft><prod name="AZ Bulletin Board" vendor="Azbb"><vers num="1.1.00"/><vers num="1.0.12"/><vers num="1.0.11"/><vers num="1.0.10"/><vers num="1.0.9"/><vers num="1.0.8"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/><vers num="1.0.0RC2"/><vers num="1.0.0RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-25" name="CVE-2006-0408" published="2006-01-24" seq="2006-0408" severity="High" type="CVE"><desc><descript source="cve">rsh utility in Sun Grid Engine (SGE) before 6.0u7_1 allows local users to gain privileges and execute arbitrary code via unspecified vectors, possibly involving command line arguments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="" url="http://gridengine.sunsource.net/project/gridengine/60patches.txt"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0308">ADV-2006-0308</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18580">18580</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015531">1015531</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24281">sge-rsh-gain-privileges(24281)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16366">16366</ref></refs><vuln_soft><prod name="Sun Grid Engine" vendor="Sun"><vers num="6.0u7"/><vers num="6.0u6"/><vers num="6.0u5"/><vers num="6.0u4"/><vers num="6.0u3"/><vers num="6.0u2"/><vers num="6.0u1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-25" name="CVE-2006-0409" published="2006-01-24" seq="2006-0409" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script or HTML via the &quot;Add Comment&quot; field in a comment popup.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/45/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16362">16362</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0309">ADV-2006-0309</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18572">18572</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24261">pixelpost-index-xss(24261)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423384/100/0/threaded">20060123 [eVuln] Pixelpost Photoblog XSS Vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015529">1015529</ref></refs><vuln_soft><prod name="Photoblog" vendor="Pixelpost"><vers num="1.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-08" name="CVE-2006-0410" published="2006-01-24" seq="2006-0410" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in ADOdb before 4.71, when using PostgreSQL, allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors involving binary strings.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=387862&amp;group_id=42718"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16364">16364</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18575">18575</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0315">ADV-2006-0315</ref><ref source="OSVDB" url="http://www.osvdb.org/22705">22705</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24314">adodb-postgresql-sql-injection(24314)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200602-02.xml">GLSA-200602-02</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0448">ADV-2006-0448</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18732">18732</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18745">18745</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1029">DSA-1029</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1030">DSA-1030</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1031">DSA-1031</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19555">19555</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19590">19590</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19591">19591</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml">GLSA-200604-07</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19691">
19691</ref></refs><vuln_soft><prod name="ADOdb" vendor="John Lim"><vers num="4.70"/><vers num="4.68"/><vers num="4.66"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-31" name="CVE-2006-0411" published="2006-01-25" seq="2006-0411" severity="High" type="CVE"><desc><descript source="cve">claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack sessions and possibly gain administrative privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/422482">20060120 Claroline 1.7.2, sso identification vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16341">16341</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0320">ADV-2006-0320</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18588">18588</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24326">claroline-cookie-bypass-security(24326)</ref></refs><vuln_soft><prod name="Claroline" vendor="Claroline"><vers num="1.7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-25" name="CVE-2006-0412" published="2006-01-25" seq="2006-0412" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in CyberShop allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0064.html">20060105 CyberShop User Login Sql Injection</ref><ref source="OSVDB" url="http://www.osvdb.org/22365">22365</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24005">cybershop-login-sql-injection(24005)</ref></refs><vuln_soft><prod name="CyberShop" vendor="Gen&amp;#xe7;Beyin Web Programlama"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-31" name="CVE-2006-0413" published="2006-01-25" seq="2006-0413" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands via the (1) discuss, (2) tim, (3) id, (4) last, and (5) limit parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16339">16339</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423129/100/0/threaded">20060122 Newsphp Multiple SQL Injection Vulnerabilities</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0341">ADV-2006-0341</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18624">18624</ref><ref source="OSVDB" url="http://www.osvdb.org/22717">22717</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24320">newsphp-index-sql-injection(24320)</ref></refs><vuln_soft><prod name="newsPHP" vendor="newsPHP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-07-12" name="CVE-2006-0414" published="2006-01-25" seq="2006-0414" severity="Medium" type="CVE"><desc><descript source="cve">Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hidden service, which eventually causes a circuit to be built through the malicious server.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://archives.seul.org/or/announce/Jan-2006/msg00001.html"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18576">18576</ref><ref source="OSVDB" url="http://www.osvdb.org/22689">22689</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24285">tor-service-information-disclosure(24285)</ref><ref source="" url="http://tor.eff.org/cvs/tor/ChangeLog"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200606-04.xml">GLSA-200606-04</ref><ref source="BID" url="http://www.securityfocus.com/bid/18323">18323</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20514">20514</ref><ref source="BID" url="http://www.securityfocus.com/bid/19795">19795</ref></refs><vuln_soft><prod name="Tor" vendor="Tor"><vers num="0.1.1.10 alpha"/><vers num="0.1.1.9 alpha"/><vers num="0.1.1.8 alpha"/><vers num="0.1.1.7 alpha"/><vers num="0.1.1.6 alpha"/><vers num="0.1.1.5 alpha"/><vers num="0.1.1.4 alpha"/><vers num="0.1.1.3 alpha"/><vers num="0.1.1.2 alpha"/><vers num="0.1.1.1 alpha"/><vers num="0.1.0.16"/><vers num="0.1.0.15"/><vers num="0.1.0.14"/><vers num="0.1.0.13"/><vers num="0.1.0.12"/><vers num="0.1.0.11"/><vers num="0.1.0.10"/><vers num="0.0.9.10"/><vers num="0.0.9.9"/><vers num="0.0.9.8"/><vers num="0.0.9.7"/><vers num="0.0.9.6"/><vers num="0.0.9.5"/><vers num="0.0.9.4"/><vers num="0.0.9.3"/><vers num="0.0.9.2"/><vers num="0.0.9.1"/><vers num="0.0.9"/><vers num="0.0.8.1"/><vers num="0.0.8"/><vers num="0.0.7.3"/><vers num="0.0.7.2"/><vers num="0.0.7.1"/><vers num="0.0.7"/><vers num="0.0.6.2"/><vers num="0.0.6.1"/><vers num="0.0.6"/><vers num="0.0.5"/><vers num="0.0.4"/><vers num="0.0.3"/><vers num="0.0.2"/><vers num="0.0.2 pre27"/><vers num="0.0.2 pre26"/><vers num="0.0.2 pre25"/><vers num="0.0.2 pre24"/><vers num="0.0.2 pre23"/><vers num="0.0.2 pre22"/><vers num="0.0.2 pre21"/><vers num="0.0.2 pre20"/><vers num="0.0.2 pre19"/><vers num="0.0.2 pre18"/><vers num="0.0.2 pre17"/><vers num="0.0.2 pre16"/><vers num="0.0.2 pre15"/><vers num="0.0.2 pre14"/><vers num="0.0.2 pre13"/><vers num="0.1.0.17"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-25" name="CVE-2006-0415" published="2006-01-25" seq="2006-0415" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in SleeperChat 0.3f and earlier allows remote attackers to inject arbitrary web script or HTML via the pseudo parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16363">16363</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015525">1015525</ref><ref source="OSVDB" url="http://www.osvdb.org/22784">22784</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24300">sleeperchat-index-xss(24300)</ref></refs><vuln_soft><prod name="SleeperChat" vendor="SleeperChat"><vers num="0.3f" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0416" published="2006-01-25" seq="2006-0416" severity="Medium" type="CVE"><desc><descript source="cve">SleeperChat 0.3f and earlier allows remote attackers to bypass authentication and create new entries via the txt parameter to (1) chat_no.php and (2) chat_if.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1015525">1015525</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24357">sleeperchat-txt-security-bypass(24357)</ref></refs><vuln_soft><prod name="SleeperChat" vendor="SleeperChat"><vers num="0.3f" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-25" name="CVE-2006-0417" published="2006-01-25" seq="2006-0417" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.php in miniBloggie 1.0 and earlier, when gpc_magic_quotes is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/47/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0310">ADV-2006-0310</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18604">18604</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24280">minibloggie-login-sql-injection(24280)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423126/100/0/threaded">20060124 [eVuln] miniBloggie Authentication Bypass</ref><ref source="BID" url="http://www.securityfocus.com/bid/16367">16367</ref><ref source="OSVDB" url="http://www.osvdb.org/22729">22729</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015534">1015534</ref></refs><vuln_soft><prod name="miniBloggie" vendor="myWebland"><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-0418" published="2006-01-25" seq="2006-0418" severity="High" type="CVE"><desc><descript source="cve">Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a crafted username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16360">16360</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423164/100/0/threaded">20060124 [ISecAuditors Advisories] Arbitrary flash code remote execution in 123flashchat</ref></refs><vuln_soft><prod name="123 Flash Chat Server" vendor="TopCMM Computing"><vers num="5.0"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-27" name="CVE-2006-0419" published="2006-01-25" seq="2006-0419" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6 allows anonymous binds to the embedded LDAP server, which allows remote attackers to read user entries or cause a denial of service (unspecified) via a large number of connections.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://dev2dev.bea.com/pub/advisory/163"></ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015528">1015528</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="9.0"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers num="8.1 SP5"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="7.0 SP6"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="9.0"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers num="8.1 SP5"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="7.0 SP6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0420" published="2006-01-25" seq="2006-0420" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Server and WebLogic Express 8.1 through SP4 and 7.0 through SP6 does not properly handle when servlets use relative forwarding, which allows remote attackers to cause a denial of service (slowdown) via unknown attack vectors that cause &quot;looping stack overflow errors.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://dev2dev.bea.com/pub/advisory/164"></ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015528">1015528</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="7.0 SP6"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="7.0 SP6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0421" published="2006-01-25" seq="2006-0421" severity="Medium" type="CVE"><desc><descript source="cve">By design, BEA WebLogic Server and WebLogic Express 7.0 and 6.1, when creating multiple domains from the same WebLogic instance on the same machine, allows administrators of any created domain to access other created domains, which could allow administrators to gain privileges that were not intended.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://dev2dev.bea.com/pub/advisory/165"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16358">16358</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0313">ADV-2006-0313</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015528">1015528</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18581">18581</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24286">weblogic-cross-domain-management(24286)</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="7.0"/><vers num="6.1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="7.0"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0422" published="2006-01-25" seq="2006-0422" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 allow remote attackers to access MBean attributes or cause an unspecified denial of service via unknown attack vectors.</descript></desc><loss_types><avail/><conf/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://dev2dev.bea.com/pub/advisory/166"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16358">16358</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0313">ADV-2006-0313</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015528">1015528</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18592">18592</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24294">weblogic-java-mbean-access(24294)</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="7.0 SP6"/><vers num="6.1 SP7"/><vers num="6.1 SP6"/><vers num="6.1 SP5"/><vers num="6.1 SP4"/><vers num="6.1 SP3"/><vers num="6.1 SP2"/><vers num="6.1 SP1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="7.0 SP6"/><vers num="6.1 SP7"/><vers num="6.1 SP5"/><vers num="6.1 SP4"/><vers num="6.1 SP3"/><vers num="6.1 SP2"/><vers num="6.1 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0423" published="2006-01-25" seq="2006-0423" severity="High" type="CVE"><desc><descript source="cve">BEA WebLogic Portal 8.1 through SP3 stores the password for the RDBMS Authentication provider in cleartext in the config.xml file, which allows attackers to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://dev2dev.bea.com/pub/advisory/167"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16358">16358</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0312">ADV-2006-0312</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015528">1015528</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24284">weblogicportal-config-info-disclosure(24284)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18593">18593</ref><ref source="BEA" url="http://dev2dev.bea.com/pub/advisory/262">BEA08-110.01</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0613">ADV-2008-0613</ref></refs><vuln_soft><prod name="WebLogic Portal" vendor="BEA Systems"><vers num="8.1"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0424" published="2006-01-25" seq="2006-0424" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 allows remote authenticated guest users to read the server log and obtain sensitive configuration information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://dev2dev.bea.com/pub/advisory/168"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16358">16358</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0313">ADV-2006-0313</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015528">1015528</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18592">18592</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24295">weblogic-server-log-disclosure(24295)</ref><ref source="OSVDB" url="http://www.osvdb.org/22776">22776</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="7.0 SP6"/><vers num="6.1 SP7"/><vers num="6.1 SP6"/><vers num="6.1 SP5"/><vers num="6.1 SP4"/><vers num="6.1 SP3"/><vers num="6.1 SP2"/><vers num="6.1 SP1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="7.0 SP6"/><vers num="6.1 SP7"/><vers num="6.1 SP5"/><vers num="6.1 SP4"/><vers num="6.1 SP3"/><vers num="6.1 SP2"/><vers num="6.1 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0425" published="2006-01-25" seq="2006-0425" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Portal 8.1 through SP4 allows remote attackers to obtain the source for a deployment descriptor file via unknown vectors.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://dev2dev.bea.com/pub/advisory/169"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16358">16358</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0312">ADV-2006-0312</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015528">1015528</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24297">weblogic-deployment-descriptor-disclosure(24297)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18593">18593</ref></refs><vuln_soft><prod name="WebLogic Portal" vendor="BEA Systems"><vers num="8.1"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0426" published="2006-01-25" seq="2006-0426" severity="High" type="CVE"><desc><descript source="cve">BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the old and new passwords in cleartext in the DefaultAuditRecorder.log file, which could allow attackers to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://dev2dev.bea.com/pub/advisory/170"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16358">16358</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0313">ADV-2006-0313</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015528">1015528</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18592">18592</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24290">weblogic-password-information-disclosure(24290)</ref><ref source="OSVDB" url="http://www.osvdb.org/22775">22775</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0427" published="2006-01-25" seq="2006-0427" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0 and 8.1 through SP5 allows malicious EJBs or servlet applications to decrypt system passwords, possibly by accessing functionality that should have been restricted.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://dev2dev.bea.com/pub/advisory/171"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16358">16358</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0313">ADV-2006-0313</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015528">1015528</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18592">18592</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24291">weblogic-servlets-obtain-information(24291)</ref><ref source="OSVDB" url="http://www.osvdb.org/22774">22774</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers num="8.1 SP5"/><vers num="9.0 SP1"/><vers num="9.0 SP2"/><vers num="9.0 SP3"/><vers num="9.0 SP4"/><vers num="9.0 SP5"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers num="8.1 SP5"/><vers num="9.0 SP1"/><vers num="9.0 SP2"/><vers num="9.0 SP3"/><vers num="9.0 SP4"/><vers num="9.0 SP5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0428" published="2006-01-25" seq="2006-0428" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in BEA WebLogic Portal 8.1 SP3 through SP5, when using Web Services Remote Portlets (WSRP), allows remote attackers to access restricted web resources via crafted URLs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://dev2dev.bea.com/pub/advisory/172"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16358">16358</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0312">ADV-2006-0312</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015528">1015528</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24293">weblogic-wsrp-gain-access(24293)</ref><ref source="OSVDB" url="http://www.osvdb.org/22767">22767</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18593">18593</ref></refs><vuln_soft><prod name="WebLogic Portal" vendor="BEA Systems"><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers num="8.1 SP5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0429" published="2006-01-25" seq="2006-0429" severity="Low" type="CVE"><desc><descript source="cve">BEA WebLogic Server and WebLogic Express 9.0 causes new security providers to appear active even if they have not been activated by a server reboot, which could cause an administrator to perform inappropriate, security-relevant actions.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://dev2dev.bea.com/pub/advisory/173"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16358">16358</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0313">ADV-2006-0313</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015528">1015528</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18592">18592</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24298">weblogic-security-provider-weakness(24298)</ref><ref source="OSVDB" url="http://www.osvdb.org/22773">22773</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="9.0"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0430" published="2006-01-25" seq="2006-0430" severity="Medium" type="CVE"><desc><descript source="cve">Certain configurations of BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6, when connection filters are enabled, cause the server to run more slowly, which makes it easier for remote attackers to cause a denial of service (server slowdown).</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://dev2dev.bea.com/pub/advisory/174"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16358">16358</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0313">ADV-2006-0313</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015528">1015528</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18592">18592</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24301">
weblogic-connection-filter-dos(24301)</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="9.0 SP1"/><vers num="9.0 SP2"/><vers num="9.0 SP3"/><vers num="9.0 SP4"/><vers num="9.0 SP5"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="7.0 SP6"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="9.0 SP1"/><vers num="9.0 SP2"/><vers num="9.0 SP3"/><vers num="9.0 SP4"/><vers num="9.0 SP5"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="7.0 SP6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0431" published="2006-01-25" seq="2006-0431" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 8.1 SP5 allows untrusted applications to obtain the server&apos;s SSL identity via unknown attack vectors.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://dev2dev.bea.com/pub/advisory/175"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16358">16358</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0313">ADV-2006-0313</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015528">1015528</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18592">18592</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24302">
weblogic-ssl-identity-exposure(24302)</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="8.1 SP5"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="8.1 SP5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0432" published="2006-01-25" seq="2006-0432" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0, when an Administrator uses the WebLogic Administration Console to add custom security policies, causes incorrect policies to be created, which prevents the server from properly protecting JNDI resources.</descript></desc><loss_types><int/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://dev2dev.bea.com/pub/advisory/176"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16358">16358</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0313">ADV-2006-0313</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015528">1015528</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18592">18592</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24299">weblogic-jdni-security-weakness(24299)</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="9.0"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0433" published="2006-02-02" seq="2006-0433" severity="Medium" type="CVE"><desc><descript source="cve">Selective Acknowledgement (SACK) in FreeBSD 5.3 and 5.4 does not properly handle an incoming selective acknowledgement when there is insufficient memory, which might allow remote attackers to cause a denial of service (infinite loop).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:08.sack.asc">FreeBSD-SA-06:08</ref><ref source="BID" url="http://www.securityfocus.com/bid/16466">16466</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22861">22861</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18696">18696</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015566">1015566</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0409">
ADV-2006-0409</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24453">
bsd-sack-handling-dos(24453)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/399">399</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.4"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0434" published="2006-01-26" seq="2006-0434" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in action.php in phpXplorer allows remote attackers to read arbitrary files via &quot;..&quot; (dot dot) sequences and null bytes in the sAction parameter, a different vulnerability than CVE-2006-0244.  NOTE: if the functionality of phpXplorer supports the upload of PHP files, then this issue would not cross privilege boundaries and would not be a vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422434/100/0/threaded">20060118 phpXplorer file inclusion biyosecurity.be</ref><ref source="BID" url="http://www.securityfocus.com/bid/16292">16292</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39982">phpxplorer-sshare-directory-traversal(39982)</ref></refs><vuln_soft><prod name="phpXplorer" vendor="phpXplorer"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-30" name="CVE-2006-0435" published="2006-01-26" seq="2006-0435" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle PL/SQL (PLSQL), as used in Database Server DS 9.2.0.7 and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0.0, E-Business Suite and Applications 11.5.10, and Collaboration Suite 10.1.1, 10.1.2.0, 10.1.2.1, and 9.0.4.2, allows attackers to bypass the PLSQLExclusion list and access excluded packages and procedures, aka Vuln# PLSQL01.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423029/100/0/threaded">20060125 Workaround for unpatched Oracle PLSQL Gateway flaw</ref><ref source="BID" url="http://www.securityfocus.com/bid/16384">16384</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0338">ADV-2006-0338</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423673/100/0/threaded">20060131 Re: Workaround for unpatched Oracle PLSQL Gateway flaw</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041742.html">20060125 Workaround for unpatched Oracle PLSQL Gateway flaw</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/169164">VU#169164</ref><ref source="OSVDB" url="http://www.osvdb.org/22719">22719</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015544">1015544</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18621">18621</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423819/100/0/threaded">20060202 The History of the Oracle PLSQL Gateway Flaw</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423822/100/0/threaded">20060202 More on the workaround for the unpatched Oracle PLSQL Gateway flaw</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424394/100/0/threaded">20060208 Re: Workaround for unpatched Oracle PLSQL Gateway flaw</ref><ref source="" url="http://www.oracle.com/technology/deploy/security/pdf/public_vuln_to_advisory_mapping.html"></ref><ref source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041899.html">
20060202 More on the workaround for the unpatched Oracle PLSQL Gateway flaw</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041898.html">
20060202 The History of the Oracle PLSQL Gateway Flaw</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24363">
oracle-plsql-command-execution(24363)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/402">402</ref><ref source="SREASON" url="http://securityreason.com/securityalert/403">403</ref></refs><vuln_soft><prod name="Oracle HTTP Server" vendor="Oracle"><vers num="1.0.2.1s for Apps"/><vers num="9.2.0"/><vers num="9.1"/><vers num="9.0.3.1"/><vers num="9.0.2.3"/><vers num="9.0.2"/><vers num="9.0.1"/><vers num="8.1.7"/><vers num="1.0.2.2 Roll up 2"/><vers num="1.0.2.2"/><vers num="1.0.2.1"/><vers num="1.0.2.0"/></prod><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="9.2.0.7"/><vers num="9.2.0.6"/><vers num="9.0.3.1"/><vers num="9.0.3"/><vers num="9.0.2.3"/><vers num="9.0.2.2"/><vers num="9.0.2.1"/><vers num="9.0.2.0.1"/><vers num="9.0.2.0.0"/><vers num="9.0.2"/><vers num="1.0.2.2.2"/><vers num="1.0.2.2"/><vers num="1.0.2.1s"/><vers num="1.0.2"/><vers num=""/></prod><prod name="Internet Application Server" vendor="Oracle"><vers num="1.0.2.1"/><vers num="1.0.2.0"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.2.1.0"/><vers num="10.1.2.0.2"/><vers num="10.1.2 .0.1"/><vers num="10.1.2"/><vers num="10.1.0.4"/><vers num="10.1.0.3.1"/><vers num="10.1.0.3"/><vers num="10.1.0.2"/><vers num="9.0.4.2"/><vers num="9.0.4.1"/><vers num="9.0.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-26" name="CVE-2006-0436" published="2006-01-26" seq="2006-0436" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="HP" url="http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00591401">HPSBUX02091</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015530">1015530</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0322">ADV-2006-0322</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18600">18600</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24318">hpux-unspecified-privilege-escalation(24318)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-025.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/18596">18596</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1453">oval:org.mitre.oval:def:1453</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1577">oval:org.mitre.oval:def:1577</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1586">oval:org.mitre.oval:def:1586</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="B.11.00"/><vers num="B.11.04"/><vers num="B.11.11"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0437" published="2006-02-06" seq="2006-0437" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as &quot;onmouseover&quot; in the (1) smile_url or (2) smile_emotion parameters, which bypasses a check for &quot;&lt;&quot; and &quot;&gt;&quot; characters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://securityreason.com/achievement_securityalert/31"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0445">ADV-2006-0445</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18693">18693</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041920.html">20060203 phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin</ref><ref source="OSVDB" url="http://www.osvdb.org/22928">22928</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24497">phpbb-referer-header-http-xss(24497)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/406">406</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.19"/><vers num="2.0.18"/><vers num="2.0.17"/><vers num="2.0.16"/><vers num="2.0.15"/><vers num="2.0.14"/><vers num="2.0.13"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.9"/><vers num="2.0.8a"/><vers num="2.0.8"/><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.6d"/><vers num="2.0.6c"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0438" published="2006-02-06" seq="2006-0438" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link to off-site Avatar or bbcode (IMG) are enabled, allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag in a user profile, as demonstrated using links to (1) admin/admin_users.php and (2) modcp.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://securityreason.com/achievement_securityalert/31"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0445">ADV-2006-0445</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18693">18693</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041920.html">20060203 phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin</ref><ref source="OSVDB" url="http://www.osvdb.org/22929">22929</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24497">phpbb-referer-header-http-xss(24497)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/406">406</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.19"/><vers num="2.0.18"/><vers num="2.0.17"/><vers num="2.0.16"/><vers num="2.0.15"/><vers num="2.0.14"/><vers num="2.0.13"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.9"/><vers num="2.0.8a"/><vers num="2.0.8"/><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.6d"/><vers num="2.0.6c"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-27" name="CVE-2006-0439" published="2006-01-26" seq="2006-0439" severity="Medium" type="CVE"><desc><descript source="cve">Text Rider 2.4 stores sensitive data in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain usernames and password hashes by directly accessing data/userlist.txt.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/46/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0321">ADV-2006-0321</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18605">18605</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24279">textrider-data-directory-insecure(24279)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423130/100/0/threaded">20060124 [eVuln] Text Rider Sensitive Information Disclosure</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015533">1015533</ref></refs><vuln_soft><prod name="Text Rider" vendor="Text Rider"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-27" name="CVE-2006-0440" published="2006-01-26" seq="2006-0440" severity="Medium" type="CVE"><desc><descript source="cve">Text Rider 2.4 allows attackers to bypass authentication and upload files without providing a valid password by obtaining the MD5 hash of the password (possibly via another vulnerability that reads it from a data file), then including the hash in a cookie.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/46/summary.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423130/100/0/threaded">20060124 [eVuln] Text Rider Sensitive Information Disclosure</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015533">1015533</ref></refs><vuln_soft><prod name="Text Rider" vendor="Text Rider"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-27" name="CVE-2006-0441" published="2006-01-26" seq="2006-0441" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Sami FTP Server 2.0.1 allows remote attackers to execute arbitrary code via a long USER command, which triggers the overflow when the log is viewed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.critical.lt/?vulnerabilities/208"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16370">16370</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0317">ADV-2006-0317</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18574">18574</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423148/100/0/threaded">20060124 SamiFTPd buffer overflow</ref><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/sami_ftp_poc.pl"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24325">samiftpserver-user-bo(24325)</ref><ref source="" url="http://www.karjasoft.com/samiftp/news"></ref></refs><vuln_soft><prod name="Sami FTP Server" vendor="KarjaSoft"><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-05" name="CVE-2006-0442" published="2006-01-26" seq="2006-0442" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in usercp.php in MyBulletinBoard (MyBB) 1.02 allow remote attackers to inject arbitrary web script or HTML via the (1) notepad parameter in a notepad action and (2) signature parameter in a editsig action.  NOTE: These are different attack vectors, and probably a different vulnerability, than CVE-2006-0218 and CVE-2006-0219.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://kapda.ir/advisory-241.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0316">ADV-2006-0316</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18603">18603</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423128/100/0/threaded">20060124 [KAPDA::#25] - MyBB 1.x Cross_Site_Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/16361">16361</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015535">1015535</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-27" name="CVE-2006-0443" published="2006-01-26" seq="2006-0443" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in archive.php in CheesyBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) realname and (2) comment parameters, or (3) via a javascript URI in the url parameter, when adding a comment.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423023/100/0/threaded">20060125 [eVuln] CheesyBlog XSS Vulnerability</ref><ref adv="1" source="" url="http://evuln.com/vulns/49/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16376">16376</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0326">ADV-2006-0326</ref><ref source="OSVDB" url="http://www.osvdb.org/22716">22716</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18610">18610</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24292">cheesyblog-archive-xss(24292)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/369">369</ref></refs><vuln_soft><prod name="CheesyBlog" vendor="CheesyBlog"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-15" name="CVE-2006-0444" published="2006-01-26" seq="2006-0444" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.1 allows remote attackers to execute arbitrary SQL commands via the (1) par parameter in the post function on the forum page and possibly the (2) poll_id parameter on the poll page.  NOTE: the poll_id vector can also allow resultant cross-site scripting (XSS) from an unquoted error message for invalid SQL syntax.</descript></desc><sols><sol source="nvd">A simple fix has been released on the Main PCW site available directly at &lt;a href=&quot;http://www.phpclanwebsite.com/index.php?page=downloads&amp;func=browselist&amp;par=1&quot;&gt;http://www.phpclanwebsite.com/index.php?page=downloads&amp;func=browselist&amp;par=1&lt;/a&gt;
Please download and install imediately.
Tech note: Filters id number (par) to contain numbers only.
</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423145/100/0/threaded">20060125 HYSA-2006-002 Phpclanwebsite 1.23.1 Multiple Vulnerabilities</ref><ref adv="1" source="" url="http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0342">ADV-2006-0342</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18597">18597</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16391">16391</ref><ref source="OSVDB" url="http://www.osvdb.org/22720">22720</ref><ref source="OSVDB" url="http://www.osvdb.org/22722">22722</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24355">phpclanwebsite-index-sql-injection(24355)</ref></refs><vuln_soft><prod name="Phpclanwebsite" vendor="Phpclanwebsite"><vers num="1.23.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-21" name="CVE-2006-0445" published="2006-01-26" seq="2006-0445" severity="Medium" type="CVE"><desc><descript source="cve">index.php in Phpclanwebsite 1.23.1 allows remote authenticated users to obtain the installation path by specifying an invalid file name to the uploader page, as demonstrated by &quot;\&quot;, which will display the full path of uploader.php.  NOTE: this might be the result of a file inclusion vulnerability.</descript></desc><sols><sol source="nvd">Please add the following to the config.php file to avoid all such exploits.

ini_set(&apos;display_errors&apos;, false);
</sol></sols><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423145/100/0/threaded">20060125 HYSA-2006-002 Phpclanwebsite 1.23.1 Multiple Vulnerabilities</ref><ref adv="1" source="" url="http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16391">16391</ref><ref source="OSVDB" url="http://www.osvdb.org/22721">22721</ref></refs><vuln_soft><prod name="Phpclanwebsite" vendor="Phpclanwebsite"><vers num="1.23.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-27" name="CVE-2006-0446" published="2006-01-26" seq="2006-0446" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in WeBWorK 2.1.3 and 2.2-pre1 allows remote privilged attackers to execute arbitrary commands as the web server via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://devel.webwork.rochester.edu/twiki/bin/view/Webwork/WeBWorKRelease2pt1pt4"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0319">ADV-2006-0319</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18594">18594</ref><ref source="BID" url="http://www.securityfocus.com/bid/16371">16371</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24322">webwork-unknown-command-execution(24322)</ref></refs><vuln_soft><prod name="WeBWorK" vendor="WeBWorK"><vers num="2.1.3"/><vers num="2.2-pre1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-27" name="CVE-2006-0447" published="2006-01-26" seq="2006-0447" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in E-Post Mail Server 4.10 and SPA-PRO Mail @Solomon 4.00 allow remote attackers to execute arbitrary code via a long username to the (1) AUTH PLAIN or (2) AUTH LOGIN SMTP commands, which is not properly handled by (a) EPSTRS.EXE or (b) SPA-RS.EXE; (3) a long username in the APOP POP3 command, which is not properly handled by (c) EPSTPOP4S.EXE or (d) SPA-POP3S.EXE; (4) a long IMAP DELETE command, which is not properly handled by (e) EPSTIMAP4S.EXE or (f) SPA-IMAP4S.EXE.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2006-1/advisory/"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0318">ADV-2006-0318</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18480">18480</ref><ref source="BID" url="http://www.securityfocus.com/bid/16379">16379</ref><ref source="OSVDB" url="http://www.osvdb.org/22761">22761</ref><ref source="OSVDB" url="http://www.osvdb.org/22762">22762</ref><ref source="OSVDB" url="http://www.osvdb.org/22763">22763</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24334">epost-imap-mailbox-dos(24334)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24333">epost-pop3-username-bo(24333)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24331">epost-smtp-username-bo(24331)</ref></refs><vuln_soft><prod name="SMTP Server" vendor="E-POST Corporation"><vers num="Enterprise 4.10"/><vers num="4.10"/></prod><prod name="SPA-PRO Mail @Soloman" vendor="E-POST Corporation"><vers num="4.00"/></prod><prod name="Mail Server" vendor="E-POST Corporation"><vers num="Enterprise 4.10"/><vers num="4.10"/></prod><prod name="SPA-PRO Mail @Solomon" vendor="E-POST Corporation"><vers num="Enterprise 4.00"/></prod><prod name="SPA-PRO SMTP @Soloman" vendor="E-POST Corporation"><vers num="4.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-27" name="CVE-2006-0448" published="2006-01-26" seq="2006-0448" severity="High" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in (1) EPSTIMAP4S.EXE and (2) SPA-IMAP4S.EXE in the IMAP service in E-Post Mail 4.05 and SPA-PRO Mail 4.05 allow remote attackers to (a) list arbitrary directories or cause a denial of service via the LIST command; or create arbitrary files via the (b) APPEND, (c) COPY, or (d) RENAME commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2006-1/advisory/"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0318">ADV-2006-0318</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18480">18480</ref><ref source="BID" url="http://www.securityfocus.com/bid/16379">16379</ref><ref source="OSVDB" url="http://www.osvdb.org/22764">22764</ref><ref source="OSVDB" url="http://www.osvdb.org/22765">22765</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24336">epost--append-copy-rename-file-creation(24336)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24335">epost-imap-list-directory-traversal(24335)</ref></refs><vuln_soft><prod name="SPA-PRO Mail @Soloman" vendor="E-POST Corporation"><vers num="4.05"/></prod><prod name="Mail Server" vendor="E-POST Corporation"><vers num="4.05"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-27" name="CVE-2006-0449" published="2006-01-26" seq="2006-0449" severity="Medium" type="CVE"><desc><descript source="cve">Early termination vulnerability in the IMAP service in E-Post Mail 4.05 and SPA-PRO Mail 4.05 allows remote attackers to cause a denial of service (infinite loop) by sending an APPEND command and disconnecting before the expected amount of data is sent.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2006-1/advisory/"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0318">ADV-2006-0318</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18480">18480</ref><ref source="BID" url="http://www.securityfocus.com/bid/16379">16379</ref><ref source="OSVDB" url="http://www.osvdb.org/22766">22766</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24341">epost-imap-append-dos(24341)</ref></refs><vuln_soft><prod name="SPA-PRO Mail @Soloman" vendor="E-POST Corporation"><vers num="4.05"/></prod><prod name="Mail Server" vendor="E-POST Corporation"><vers num="4.05"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-27" name="CVE-2006-0450" published="2006-01-26" seq="2006-0450" severity="Medium" type="CVE"><desc><descript source="cve">phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php or (2) using search.php to search in a certain way that confuses the database.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423030/100/0/threaded">20060125 HYSA-2006-001 phpBB 2.0.19 search.php and profile.php DOS Vulnerability</ref><ref source="" url="http://h4cky0u.org/viewtopic.php?t=637"></ref><ref adv="1" source="" url="http://www.h4cky0u.org/advisories/HYSA-2006-001-phpbb.txt"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24327">phpbb-search-profile-dos(24327)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/368">368</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.19"/><vers num="2.0.18"/><vers num="2.0.17"/><vers num="2.0.16"/><vers num="2.0.15"/><vers num="2.0.14"/><vers num="2.0.13"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.9"/><vers num="2.0.8a"/><vers num="2.0.8"/><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.6d"/><vers num="2.0.6c"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0451" published="2006-02-14" seq="2006-0451" severity="Medium" type="CVE"><desc><descript source="cve">Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was allocated during the ber_scanf call, as demonstrated using the ProtoVer LDAP test suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179135"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16677">16677</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18960">18960</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24794">
fedora-ber-memory-leak-dos(24794)</ref></refs><vuln_soft><prod name="Fedora Directory Server" vendor="Red Hat"><vers edition="Directory Server" num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0452" published="2006-02-14" seq="2006-0452" severity="Medium" type="CVE"><desc><descript source="cve">dn2ancestor in the LDAP component in Fedora Directory Server 1.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via a ModDN operation with a DN that contains a large number of &quot;,&quot; (comma) characters, which results in a large amount of recursion, as demonstrated using the ProtoVer LDAP test suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179137"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16677">16677</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18960">18960</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24796">
fedora-dn2ancestor-dos(24796)</ref></refs><vuln_soft><prod name="Fedora Directory Server" vendor="Red Hat"><vers edition="Directory Server" num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0453" published="2006-02-14" seq="2006-0453" severity="High" type="CVE"><desc><descript source="cve">The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain &quot;bad BER sequence&quot; that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179135"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16677">16677</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18960">18960</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24795">
fedora-ber-bad-sequence-dos(24795)</ref></refs><vuln_soft><prod name="Fedora Directory Server" vendor="Red Hat"><vers edition="Directory Server" num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0454" published="2006-02-07" seq="2006-0454" severity="Medium" type="CVE"><desc><descript source="cve">Linux kernel before 2.6.15.3 down to 2.6.12, while constructing an ICMP response in icmp_send, does not properly handle when the ip_options_echo function in icmp.c fails, which allows remote attackers to cause a denial of service (crash) via vectors such as (1) record-route and (2) timestamp IP options with the needaddr bit set and a truncated value.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113927617401569&amp;w=2">[linux-kernel] 20060207 Linux 2.6.15.3</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113927648820694&amp;w=2">[linux-kernel] 20060207 Re: Linux 2.6.15.3</ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.3"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0464">ADV-2006-0464</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_06_kernel.html">SuSE-SA:2006:006</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18788">18788</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-250-1">USN-250-1</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18861">18861</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:040">MDKSA-2006:040</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16532">16532</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18766">18766</ref><ref adv="1" patch="1" source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427981/100/0/threaded">FLSA:157459-4</ref><ref patch="1" source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2006-February/002909.html">[dailydave] 20060207 Fun with Linux (2.6.12 -&gt; 2.6.15.2)</ref><ref adv="1" patch="1" source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00037.html">FEDORA-2006-102</ref><ref adv="1" source="TRUSTIX" url="http://www.trustix.org/errata/2006/0006">2006-0006</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/18774">18774</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18784">18784</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24575">
kernel-icmp-ipoptionsecho-dos(24575)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:040">MDKSA-2006:040</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.15.3"/><vers num="2.6.15.2"/><vers num="2.6.15.1"/><vers num="2.6.15-rc7"/><vers num="2.6.15-rc6"/><vers num="2.6.15-rc5"/><vers num="2.6.15-rc4"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.15"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14"/><vers num="2.6.13-rc7"/><vers num="2.6.13-rc6"/><vers num="2.6.13-rc4"/><vers num="2.6.13-rc1"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13"/><vers num="2.6.12-rc5"/><vers num="2.6.12-rc4"/><vers num="2.6.12-rc1"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-07" name="CVE-2006-0455" published="2006-02-15" seq="2006-0455" severity="Medium" type="CVE"><desc><descript source="cve">gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded.  Note: this also occurs when running the equivalent command &quot;gpg --verify&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MLIST" url="http://marc.theaimsgroup.com/?l=gnupg-devel&amp;m=113999098729114&amp;w=2">[gnupg-devel] 20060215 [Announce] False positive signature verification in GnuPG</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=gnupg-devel&amp;m=113999098729114&amp;w=2">[gnupg-devel] 20060215 [Announce] False positive signature verification in GnuPG</ref><ref source="MLIST" url="http://lists.gnupg.org/pipermail/gnupg-announce/2006q1/000211.html">[gnupg-announce] 20060215 False positive signature verification in GnuPG</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0610">ADV-2006-0610</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18845">18845</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425289/100/0/threaded">20060215 False positive signature verification in GnuPG</ref><ref adv="1" patch="1" source="MLIST" url="http://marc.theaimsgroup.com/?l=gnupg-devel&amp;m=113999098729114&amp;w=2">[gnupg-devel] 20060215 [Announce] False positive signature verification in GnuPG</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.us.debian.org/security/2006/dsa-978">DSA-978</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2006-116.shtml">FEDORA-2006-116</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/18956.xml">18956</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:043">MDKSA-2006:043</ref><ref adv="1" source="OPENPKG" url="http://www.openpkg.org/security/OpenPKG-SA-2006.001-gnupg.html">OpenPKG-SA-2006.001</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-252-1">USN-252-1</ref><ref source="OSVDB" url="http://www.osvdb.org/23221">23221</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18934">18934</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18933">18933</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18942">18942</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18955">18955</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24744">gnupg-gpgv-improper-verification(24744)</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200602-10.xml">GLSA-200602-10</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_09_gpg.html">SuSE-SA:2006:009</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18956">18956</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18968">18968</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0008">2006-0008</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16663">16663</ref><ref adv="1" patch="1" source="MLIST" url="http://marc.theaimsgroup.com/?l=gnupg-devel&amp;m=113999098729114&amp;w=2">[gnupg-devel] 20060215 [Announce] False positive signature verification in GnuPG</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_05_sr.html">SUSE-SR:2006:005</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19130">19130</ref><ref patch="1" source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.476477">SSA:2006-072-02</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0266.html">RHSA-2006:0266</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19249">19249</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U">20060401-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19532">19532</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/433931/100/0/threaded">FLSA-2006:185355</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_13_gpg.html">SUSE-SA:2006:013</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:043">MDKSA-2006:043</ref></refs><vuln_soft><prod name="GNU Privacy Guard" vendor="GNU"><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2 rc1"/><vers num="1.2.2 r1"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3b"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-06-28" name="CVE-2006-0456" published="2006-06-27" seq="2006-0456" severity="Low" type="CVE"><desc><descript source="cve">The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref source="" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=331c46591414f7f92b1cec048009abe89892ee79"></ref><ref source="" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=331c46591414f7f92b1cec048009abe89892ee79"></ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.16-rc6"></ref><ref source="" url="http://www.mail-archive.com/kernel-svn-changes@lists.alioth.debian.org/msg01631.html"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="BID" url="http://www.securityfocus.com/bid/18687">18687</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0575.html">RHSA-2006:0575</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21465">21465</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/22417">22417</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.15.5"/><vers num="2.6.15.4"/><vers num="2.6.15.3"/><vers num="2.6.15.2"/><vers num="2.6.15.1"/><vers num="2.6.15-rc7"/><vers num="2.6.15-rc6"/><vers num="2.6.15-rc5"/><vers num="2.6.15-rc4"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.15"/><vers num="2.6.14.5"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14-rc5"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.14"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13-rc7"/><vers num="2.6.13-rc6"/><vers num="2.6.13-rc5"/><vers num="2.6.13-rc4"/><vers num="2.6.13-rc3"/><vers num="2.6.13-rc2"/><vers num="2.6.13-rc1"/><vers num="2.6.13"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12-rc6"/><vers num="2.6.12-rc5"/><vers num="2.6.12-rc4"/><vers num="2.6.12-rc3"/><vers num="2.6.12-rc2"/><vers num="2.6.12-rc1"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11-rc5"/><vers num="2.6.11-rc4"/><vers num="2.6.11-rc3"/><vers num="2.6.11-rc2"/><vers num="2.6.11-rc1"/><vers num="2.6.11"/><vers num="2.6.10-rc3"/><vers num="2.6.10-rc2"/><vers num="2.6.10-rc1"/><vers num="2.6.10"/><vers num="2.6.9-rc4"/><vers num="2.6.9-rc3"/><vers num="2.6.9-rc2"/><vers num="2.6.9-rc1"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8-rc4"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7-rc3"/><vers num="2.6.7-rc2"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc3"/><vers num="2.6.6-rc2"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5-rc3"/><vers num="2.6.5-rc2"/><vers num="2.6.5-rc1"/><vers num="2.6.5"/><vers num="2.6.4-rc3"/><vers num="2.6.4-rc2"/><vers num="2.6.4-rc1"/><vers num="2.6.4"/><vers num="2.6.3-rc3"/><vers num="2.6.3-rc2"/><vers num="2.6.3-rc1"/><vers num="2.6.3"/><vers num="2.6.2-rc3"/><vers num="2.6.2-rc2"/><vers num="2.6.2-rc1"/><vers num="2.6.2"/><vers num="2.6.1-rc2"/><vers num="2.6.1-rc1"/><vers num="2.6.1"/><vers num="2.6 test 9 CVS"/><vers num="2.6-test9"/><vers num="2.6-test8"/><vers num="2.6-test7"/><vers num="2.6-test6"/><vers num="2.6-test5"/><vers num="2.6-test4"/><vers num="2.6-test3"/><vers num="2.6-test2"/><vers num="2.6-test11"/><vers num="2.6-test10"/><vers num="2.6-test1"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="9.2" CVSS_score="7.1" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-0457" published="2006-03-13" seq="2006-0457" severity="High" type="CVE"><desc><descript source="cve">Race condition in the (1) add_key, (2) request_key, and (3) keyctl functions in Linux kernel 2.6.x allows local users to cause a denial of service (crash) or read sensitive kernel memory by modifying the length of a string argument between the time that the kernel calculates the length and when it copies the data into kernel memory.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-263-1">USN-263-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/17084">17084</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19220">19220</ref><ref source="OSVDB" url="http://www.osvdb.org/23894">23894</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:059">MDKSA-2006:059</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0575.html">RHSA-2006:0575</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21465">21465</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/22417">22417</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25354">
kernel-addkey-dos(25354)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:059">MDKSA-2006:059</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.15 rc7"/><vers num="2.6.15 rc6"/><vers num="2.6.15 rc5"/><vers num="2.6.15 rc4"/><vers num="2.6.15 rc3"/><vers num="2.6.14 rc2"/><vers num="2.6.15 rc1"/><vers num="2.6.15.5"/><vers num="2.6.15.4"/><vers num="2.6.15.3"/><vers num="2.6.15.2"/><vers num="2.6.15.1"/><vers num="2.6.15"/><vers num="2.6.14 rc4"/><vers num="2.6.14 rc3"/><vers num="2.6.14 rc1"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14"/><vers num="2.6.13 rc7"/><vers num="2.6.13 rc6"/><vers num="2.6.13 rc4"/><vers num="2.6.13 rc1"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13"/><vers num="2.6.12 rc5"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc1"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11 rc1"/><vers num="2.6.11.9"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11.10"/><vers num="2.6.11.1"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8.1.5"/><vers num="2.6.8.1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-0458" published="2006-03-06" seq="2006-0458" severity="Medium" type="CVE"><desc><descript source="cve">The DCC ACCEPT command handler in irssi before 0.8.9+0.8.10rc5-0ubuntu4.1 in Ubuntu Linux, and possibly other distributions, allows remote attackers to cause a denial of service (application crash) via certain crafted arguments in a DCC command.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-259-1">USN-259-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/16913">16913</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19090">19090</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25147">
irssi-dcc-accept-dos(25147)</ref></refs><vuln_soft><prod name="irssi" vendor="irssi"><vers num="0.8.9"/><vers num="0.8.10rc5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0459" published="2006-03-29" seq="2006-0459" severity="High" type="CVE"><desc><descript source="cve">flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a buffer overflow that might allow context-dependent attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://sourceforge.net/mailarchive/message.php?msg_id=14895090">[flex-announce] 20060222 flex 2.5.33 released</ref><ref source="" url="http://prdownloads.sourceforge.net/flex/flex-2.5.33.tar.bz2?download"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.us.debian.org/security/2006/dsa-1020">DSA-1020</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16896">16896</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0770">ADV-2006-0770</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/23440">23440</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19071">19071</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19424">19424</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24995">flex-bypass-security(24995)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-07.xml">GLSA-200603-07</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-260-1">USN-260-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19126">19126</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19228">19228</ref><ref source="MLIST" url="http://sourceforge.net/mailarchive/forum.php?thread_name=20060223020346.GA11231%40tabitha.home.tldz.org&amp;forum_name=flex-announce">[flex-announce] 20060222 flex 2.5.33 released</ref><ref source="SREASON" url="http://securityreason.com/securityalert/570">570</ref></refs><vuln_soft><prod name="Flex" vendor="Will Estes and John Millaway"><vers num="2.5.32" prev="1"/><vers num="2.5.30"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0460" published="2006-02-16" seq="2006-0460" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200602-09.xml">GLSA-200602-09</ref><ref source="BID" url="http://www.securityfocus.com/bid/16697">16697</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18914">18914</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18915">18915</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0643">ADV-2006-0643</ref><ref source="OSVDB" url="http://www.osvdb.org/23263">23263</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24764">bomberclone-error-message-bo(24764)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-997">DSA-997</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19210">19210</ref></refs><vuln_soft><prod name="BomberClone" vendor="BomberClone"><vers num="0.11.6"/><vers num="0.11.5"/><vers num="0.11.4"/><vers num="0.11.3"/><vers num="0.10.0"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.8"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0461" published="2006-01-27" seq="2006-0461" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in core.input.php in ExpressionEngine 1.4.1 allows remote attackers to inject arbitrary web script or HTML via HTTP_REFERER (referer).</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://evuln.com/vulns/48/summary.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0325">ADV-2006-0325</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423068/100/0/threaded">20060125 [eVuln] ExpressionEngine %27Referer%27 XSS Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16377">16377</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18602">18602</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24296">expressionengine-coreinput-xss(24296)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/372">372</ref></refs><vuln_soft><prod name="ExpressionEngine" vendor="pMachine"><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0462" published="2006-01-27" seq="2006-0462" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in comentarios.php in AndoNET Blog 2004.09.02 allows remote attackers to execute arbitrary SQL commands via the entrada parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/50/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0327">ADV-2006-0327</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/423162">20060126 [eVuln] AndoNET Blog SQL Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16393">16393</ref><ref source="OSVDB" url="http://www.osvdb.org/22755">22755</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18633">18633</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24309">andonetblog-index-sql-injection(24309)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/377">377</ref></refs><vuln_soft><prod name="AndoNET Blog" vendor="AndoNET"><vers num="2004.09.02"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0463" published="2006-01-27" seq="2006-0463" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in IdeoContent Manager allows remote attackers to inject arbitrary web script or HTML via the (1) goto_id parameter to index.php or (2) page parameter to news_full.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://osvdb.org/ref/22/22712-ideocontent.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22712">22712</ref><ref source="OSVDB" url="http://www.osvdb.org/22713">22713</ref></refs><vuln_soft><prod name="IdeoContent Manager" vendor="Ideosoft Design"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0464" published="2006-01-27" seq="2006-0464" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in index.php in IdeoContent Manager allow remote attackers to execute arbitrary SQL commands via the (1) goto_id or (2) mid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://osvdb.org/ref/22/22712-ideocontent.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22714">22714</ref></refs><vuln_soft><prod name="IdeoContent Manager" vendor="Ideosoft Design"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0465" published="2006-01-27" seq="2006-0465" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in risultati_ricerca.php in active121 Site Manager allows remote attackers to inject arbitrary web script or HTML via the cerca parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://osvdb.org/ref/22/22715-active121.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22715">22715</ref></refs><vuln_soft><prod name="Site Manager" vendor="active121"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0466" published="2006-01-27" seq="2006-0466" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.asp in Goldstag Content Management System allows remote attackers to inject arbitrary web script or HTML via the text parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://osvdb.org/ref/22/22711-goldstag.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22711">22711</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25198">goldstag-search-xss(25198)</ref></refs><vuln_soft><prod name="Goldstag Content Management System" vendor="Goldstag"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0467" published="2006-01-30" seq="2006-0467" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Pioneers (formerly gnocatan) before 0.9.49 allows remote attackers to cause a denial of service (application crash) via long chat messages.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350237"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0376">ADV-2006-0376</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18647">18647</ref><ref source="BID" url="http://www.securityfocus.com/bid/16429">16429</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-964">DSA-964</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18692">18692</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24383">pioneers-chat-message-dos(24383)</ref></refs><vuln_soft><prod name="Pioneers" vendor="Pioneers"><vers num="0.9.49"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-01" name="CVE-2006-0468" published="2006-01-30" seq="2006-0468" severity="High" type="CVE"><desc><descript source="cve">CommuniGate Pro Core Server before 5.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via LDAP messages with negative BER lengths, and possibly other vectors, as demonstrated by the ProtoVer LDAP test suite.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://www.stalker.com/CommuniGatePro/History.html"></ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423364/100/0/threaded">20060128 Multiple vulnerabilities in CommuniGate Pro Server</ref><ref adv="1" patch="1" source="" url="http://www.gleg.net/advisory_cg.shtml"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16407">16407</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0364">ADV-2006-0364</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18640">18640</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24409">communigate-ldap-bo(24409)</ref></refs><vuln_soft><prod name="Communigate Pro" vendor="Stalker"><vers num="5.0.6"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0"/><vers num="5.0c7"/><vers num="5.0c6"/><vers num="5.0c5"/><vers num="5.0c4"/><vers num="5.0c3"/><vers num="5.0c2"/><vers num="5.0c1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-06-01" name="CVE-2006-0469" published="2006-01-30" seq="2006-0469" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in UebiMiau 2.7.9, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423437/100/0/threaded">20060129 UebiMiau Webmail System Security Vulnerability</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18655">18655</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24375">uebimiau-html-xss(24375)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16413">16413</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0388">ADV-2006-0388</ref><ref source="" url="http://www.uebimiau.org/news.php"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/387">387</ref></refs><vuln_soft><prod name="UebiMiau" vendor="UebiMiau"><vers num="2.7.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-05" name="CVE-2006-0470" published="2006-01-31" seq="2006-0470" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in MyBulletinBoard (MyBB) 1.02 allows remote attackers to inject arbitrary web script or HTML via the (1) sortby and (2) sortordr parameters, which are not properly handled in a redirection.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2006/Jan/0414.html">20060125 MyBB 1.0.2 XSS attack in search.php redirection</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0350">ADV-2006-0350</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18617">18617</ref><ref source="" url="http://community.mybboard.net/showthread.php?tid=6418"></ref><ref source="" url="http://community.mybboard.net/attachment.php?aid=2181"></ref><ref source="OSVDB" url="http://www.osvdb.org/22750">22750</ref><ref source="BID" url="http://www.securityfocus.com/bid/16387">16387</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24466">
mybb-search-xss(24466)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/374">374</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC4"/><vers num="1.0 RC2"/><vers num="1.0 Preview Release 2"/><vers num="1.0 PR2"/><vers num="1.0 &quot;Final&quot;"/><vers num="1.0 Final"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-31" name="CVE-2006-0471" published="2006-01-31" seq="2006-0471" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the bbcode function in functions.php in my little homepage my little forum, as last modified in June 2005, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423167/100/0/threaded">20060126 [eVuln] &apos;my little homepage&apos; products [link] BBCode XSS Vulnerability</ref><ref adv="1" source="" url="http://evuln.com/vulns/51/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16395">16395</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0349">ADV-2006-0349</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18628">18628</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24310">mylittlehomepage-link-tag-xss(24310)</ref><ref source="" url="http://evuln.com/vulns/51/"></ref><ref source="OSVDB" url="http://www.osvdb.org/22856">22856</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-January/000520.html">[VIM] 20060130 My Little Homepage - source verify of different products</ref></refs><vuln_soft><prod name="my little forum" vendor="my little homepage"><vers num="2004-04-20"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-31" name="CVE-2006-0472" published="2006-01-31" seq="2006-0472" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in guestbook.php in my little homepage my little guestbook, as last modified in March 2004, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423167/100/0/threaded">20060126 [eVuln] &apos;my little homepage&apos; products [link] BBCode XSS Vulnerability</ref><ref adv="1" source="" url="http://evuln.com/vulns/51/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16395">16395</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0349">ADV-2006-0349</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18628">18628</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24310">mylittlehomepage-link-tag-xss(24310)</ref><ref source="" url="http://evuln.com/vulns/51/"></ref><ref source="OSVDB" url="http://www.osvdb.org/22855">22855</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-January/000520.html">[VIM] 20060130 My Little Homepage - source verify of different products</ref></refs><vuln_soft><prod name="My Little Guestbook" vendor="my little homepage"><vers num="2004-04-20"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-31" name="CVE-2006-0473" published="2006-01-31" seq="2006-0473" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the bbcode function in weblog.php in my little homepage my little weblog, as last modified in April 2004, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423167/100/0/threaded">20060126 [eVuln] &apos;my little homepage&apos; products [link] BBCode XSS Vulnerability</ref><ref adv="1" source="" url="http://evuln.com/vulns/51/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16395">16395</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0349">ADV-2006-0349</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18628">18628</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24310">mylittlehomepage-link-tag-xss(24310)</ref><ref source="" url="http://evuln.com/vulns/51/"></ref><ref source="OSVDB" url="http://www.osvdb.org/22753">22753</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-January/000520.html">[VIM] 20060130 My Little Homepage - source verify of different products</ref><ref source="SREASON" url="http://securityreason.com/securityalert/378">378</ref></refs><vuln_soft><prod name="My Little Weblog" vendor="my little homepage"><vers num="2004-04-20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-31" name="CVE-2006-0474" published="2006-01-31" seq="2006-0474" severity="High" type="CVE"><desc><descript source="cve">Multiple integer overflows in Shareaza 2.2.1.0 allow remote attackers to execute arbitrary code via (1) a large packet length field, which causes an overflow in the ReadBuffer function in (a) BTPacket.cpp and (b) EDPacket.cpp, or (2) a large packet, which causes a heap-based overflow in the Write function in (c) Packet.h.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423293/100/0/threaded">20060127 Shareaza P2P Remote Vulnerability</ref><ref adv="1" source="" url="http://www.hustlelabs.com/shareaza_advisory.pdf"></ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/shareaza/shareaza/BTPacket.cpp?r1=1.5&amp;r2=1.5.4.1"></ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/shareaza/shareaza/EDPacket.cpp?r1=1.15&amp;r2=1.15.2.1"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16399">16399</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0887.html">20060126 Shareaza Remote Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24342">shareaza-btpacket-bo(24342)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24343">shareaza-cedpacket-bo(24343)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24344">shareaza-cpacket-bo(24344)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/382">382</ref></refs><vuln_soft><prod name="Shareaza" vendor="Shareaza"><vers num="2.2.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-01" name="CVE-2006-0475" published="2006-01-31" seq="2006-0475" severity="Medium" type="CVE"><desc><descript source="cve">PHP-Ping 1.3 does not properly validate ping counts, which allows remote attackers to cause a denial of service (ping flood) via a negative count parameter.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://www.kapda.ir/advisory-231.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0368">ADV-2006-0368</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18645">18645</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24382">phpping-negative-count-dos(24382)</ref></refs><vuln_soft><prod name="PHP-Ping" vendor="TheWorldsEnd.net"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2006-0476" published="2006-01-31" seq="2006-0476" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with a long file name (File1 field).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/423436/100/0/threaded">20060130 Winamp 5.12 - 0day exploit - code execution through playlist</ref><ref source="" url="http://milw0rm.com/id.php?id=1458"></ref><ref source="" url="http://www.heise.de/newsticker/meldung/68981"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0361">ADV-2006-0361</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18649">18649</ref><ref source="" url="http://www.winamp.com/player/version_history.php"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423548/100/0/threaded">20060131 Re: Re: Winamp 5.12 - 0day exploit - code execution through playlist</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/604745">VU#604745</ref><ref source="BID" url="http://www.securityfocus.com/bid/16410">16410</ref><ref source="OSVDB" url="http://www.osvdb.org/22789">22789</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24361">winamp-playlist-computername-bo(24361)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-032A.html">TA06-032A</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015552">1015552</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1402">oval:org.mitre.oval:def:1402</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3422">
3422</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1458">
1458</ref><ref source="SREASON" url="http://securityreason.com/securityalert/386">386</ref><ref source="SREASON" url="http://securityreason.com/securityalert/398">398</ref></refs><vuln_soft><prod name="Winamp" vendor="Nullsoft"><vers num="5.12"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-01" name="CVE-2006-0477" published="2006-01-31" seq="2006-0477" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in git-checkout-index in GIT before 1.1.5 allows remote attackers to execute arbitrary code via an index file with a long symbolic link.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://lwn.net/Articles/169623/"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0367">ADV-2006-0367</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18643">18643</ref><ref source="BID" url="http://www.securityfocus.com/bid/16417">16417</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24360">git-gitcheckoutindex-bo(24360)</ref></refs><vuln_soft><prod name="GIT" vendor="GIT"><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1.0"/><vers num="1.0.8"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.0b"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-24" name="CVE-2006-0478" published="2006-01-31" seq="2006-0478" severity="High" type="CVE"><desc><descript source="cve">CRE Loaded 6.15 allows remote attackers to perform privileged actions, including uploading and creating arbitrary files, via a direct request to files.php.  NOTE: the vendor states &quot;The initial announcement of this risk was made on our website... and it included a patch which will close the vulnerability on all known 6.0x and 6.1x releases.  We strongly encourage users of CRE Loaded 6.x, osCMax, and other users of osCommerce who have installed HTMLArea based WYSIWYG editors and Admin Access with Levels to modify thier installations at the earliest possible moment.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0373">ADV-2006-0373</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18648">18648</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16415">16415</ref><ref source="OSVDB" url="http://www.osvdb.org/22793">22793</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24377">creloaded-files-auth-bypass(24377)</ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-February/000527.html">[VIM] 20060203 vendor ack/fix: 22793: CRE Loaded files.php Unauthenticated Arbitrary File Upload (fwd)</ref></refs><vuln_soft><prod name="CRE Loaded" vendor="CRE Loaded"><vers num="6.15"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-23" name="CVE-2006-0479" published="2006-01-31" seq="2006-0479" severity="Medium" type="CVE"><desc><descript source="cve">pmwiki.php in PmWiki 2.1 beta 20, with register_globals enabled, allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GPC variable and a GLOBALS[] variable with the same name, which causes PmWiki to unset the GLOBALS[] variable but not the GPC variable, which creates resultant vulnerabilities such as remote file inclusion and cross-site scripting (XSS).</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.ush.it/2006/01/24/pmwiki-multiple-vulnerabilities/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0375">ADV-2006-0375</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18634">18634</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0931.html">20060128 PmWiki Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16421">16421</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24368">pmwiki-multiple-xss(24368)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24366">pmwiki-path-disclosure(24366)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015550">1015550</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24367">pmwiki-file-include(24367)</ref></refs><vuln_soft><prod name="PmWiki" vendor="PmWiki"><vers num="2.1 Beta 20"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-01" name="CVE-2006-0480" published="2006-01-31" seq="2006-0480" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Articles module in sPaiz-Nuke allows remote attackers to inject arbitrary web script or HTML via the query parameter in the search file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423451/100/0/threaded">20060129 sPaiz-Nuke Cross-Site Scripting Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16412">16412</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0386">ADV-2006-0386</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18672">18672</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24389">spaiznuke-modules-xss(24389)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/384">384</ref></refs><vuln_soft><prod name="sPaiz-Nuke CMS" vendor="Spaiz"><vers num="0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0481" published="2006-01-31" seq="2006-0481" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the alpha strip capability in libpng 1.2.7 allows context-dependent attackers to cause a denial of service (crash) when the png_do_strip_filler function is used to strip alpha channels out of the image.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179455"></ref><ref source="" url="ftp://ftp.simplesystems.org/pub/libpng/png/src/libpng-1.2.8-README.txt"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0393">ADV-2006-0393</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18654">18654</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24396">libpng-pngsetstripalpha-bo(24396)</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0205.html">RHSA-2006:0205</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16626">16626</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015615">1015615</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015617">1015617</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18863">18863</ref></refs><vuln_soft><prod name="libpng" vendor="Greg Roelofs"><vers num="1.2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-01" name="CVE-2006-0482" published="2006-01-31" seq="2006-0482" severity="Low" type="CVE"><desc><descript source="cve">Linux kernel 2.6.15.1 and earlier, when running on SPARC architectures, allows local users to cause a denial of service (hang) via a &quot;date -s&quot; command, which causes invalid sign extended arguments to be provided to the get_compat_timespec function call.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="MLIST" url="http://lists.debian.org/debian-sparc/2006/01/msg00129.html">[debian-sparc] 20060128 `date -s&apos; on sparc64</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-sparc&amp;m=113861010514065&amp;w=2">[linux-sparc] 20060130 Attempts to set date with &apos;date -s&apos; hang the machine</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-sparc&amp;m=113861287813463&amp;w=2">[linux-sparc] 20060130 Re: Attempts to set date with &apos;date -s&apos; hang the machine</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0418">ADV-2006-0418</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24475">kernel-date-s-dos(24475)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1017">DSA-1017</ref><ref source="BID" url="http://www.securityfocus.com/bid/17216">17216</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19374">19374</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.15 rc7"/><vers num="2.6.15 rc6"/><vers num="2.6.15 rc5"/><vers num="2.6.15 rc4"/><vers num="2.6.15 rc3"/><vers num="2.6.14 rc2"/><vers num="2.6.15 rc1"/><vers num="2.6.15"/><vers num="2.6.14 rc4"/><vers num="2.6.14 rc3"/><vers num="2.6.14 rc1"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14"/><vers num="2.6.13 rc7"/><vers num="2.6.13 rc6"/><vers num="2.6.13 rc4"/><vers num="2.6.13 rc1"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13"/><vers num="2.6.12 rc5"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc1"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11.10"/><vers num="2.6.11.9"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc1"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers edition="PowerPC_smp" num="2.6.8.1.5"/><vers edition="PowerPC" num="2.6.8.1.5"/><vers edition="Power4_smp" num="2.6.8.1.5"/><vers edition="Power4" num="2.6.8.1.5"/><vers edition="Power3_smp" num="2.6.8.1.5"/><vers edition="Power3" num="2.6.8.1.5"/><vers edition="K7_smp" num="2.6.8.1.5"/><vers edition="K7" num="2.6.8.1.5"/><vers edition="AMD64_Xeon" num="2.6.8.1.5"/><vers edition="AMD64_K8_smp" num="2.6.8.1.5"/><vers edition="AMD64_K8" num="2.6.8.1.5"/><vers edition="AMD64" num="2.6.8.1.5"/><vers edition="686_smp" num="2.6.8.1.5"/><vers edition="686" num="2.6.8.1.5"/><vers edition="386" num="2.6.8.1.5"/><vers num="2.6.8.1.5"/><vers num="2.6.8.1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers edition="Itanium IA64 Montecito" num="2.6"/><vers edition="64-bit x86" num="2.6"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0483" published="2006-01-31" seq="2006-0483" severity="High" type="CVE"><desc><descript source="cve">Cisco VPN 3000 series concentrators running software 4.7.0 through 4.7.2.A allow remote attackers to cause a denial of service (device reload or user disconnect) via a crafted HTTP packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20060126-vpn.shtml">20060126 Cisco VPN 3000 Concentrator Vulnerable to Crafted HTTP Attack</ref><ref source="BID" url="http://www.securityfocus.com/bid/16394">16394</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0346">ADV-2006-0346</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18629">18629</ref><ref source="OSVDB" url="http://www.osvdb.org/22754">22754</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015546">1015546</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24330">cisco-vpn-http-dos(24330)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/375">375</ref></refs><vuln_soft><prod name="VPN 3015 Concentrator" vendor="Cisco"><vers num="4.7.2 A"/><vers num="4.7.2"/><vers num="4.7.1 F"/><vers num="4.7.1"/><vers num="4.7"/><vers num="4.7 REL"/></prod><prod name="VPN 3060 Concentrator" vendor="Cisco"><vers num="4.7.2 A"/><vers num="4.7.2"/><vers num="4.7.1 F"/><vers num="4.7.1"/><vers num="4.7"/><vers num="4.7 REL"/></prod><prod name="VPN 3020 Concentrator" vendor="Cisco"><vers num="4.7.2 A"/><vers num="4.7.2"/><vers num="4.7.1 F"/><vers num="4.7.1"/><vers num="4.7"/><vers num="4.7 REL"/></prod><prod name="VPN 3005 Concentrator" vendor="Cisco"><vers num="4.7.2 A"/><vers num="4.7.2"/><vers num="4.7.1 F"/><vers num="4.7.1"/><vers num="4.7"/><vers num="4.7 REL"/></prod><prod name="VPN 3080 Concentrator" vendor="Cisco"><vers num="4.7.2 A"/><vers num="4.7.1 F"/><vers num="4.7.1"/><vers num="4.7"/><vers num="4.7 REL"/></prod><prod name="VPN 3030 Concentator" vendor="Cisco"><vers num="4.7.2 A"/><vers num="4.7.2"/><vers num="4.7.1 F"/><vers num="4.7.1"/><vers num="4.7"/><vers num="4.7 REL"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0484" published="2006-01-31" seq="2006-0484" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Vis.pl, as part of the FACE CONTROL product, allows remote attackers to read arbitrary files via a .. (dot dot) in any parameter that opens a file, such as (1) s or (2) p.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423155/100/0/threaded">20060126 [HSC] Multiple transversal bug in vis</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015547">1015547</ref><ref source="" url="http://www.hackerscenter.com/archive/view.asp?id=22236"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16401">16401</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24374">facecontrol-vis-directory-traversal(24374)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/376">376</ref></refs><vuln_soft><prod name="Face Control" vendor="Elido"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-01" name="CVE-2006-0485" published="2006-01-31" seq="2006-0485" severity="Medium" type="CVE"><desc><descript source="cve">The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain other releases before 25 January 2006 does not perform Authentication, Authorization, and Accounting (AAA) command authorization checks, which may allow local users to execute IOS EXEC commands that were prohibited via the AAA configuration, aka Bug ID CSCeh73049.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-response-20060125-aaatcl.shtml">20060125 Response to AAA Command Authorization by-pass</ref><ref source="BID" url="http://www.securityfocus.com/bid/16383">16383</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0337">ADV-2006-0337</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015543">1015543</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18613">18613</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24308">
cisco-aaa-tcl-auth-bypass(24308)</ref><ref source="OSVDB" url="http://www.osvdb.org/34892">34892</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.4T"/><vers num="12.4MR"/><vers num="12.4"/><vers num="12.3YX"/><vers num="12.3YU"/><vers num="12.3YT"/><vers num="12.3YS"/><vers num="12.3YQ"/><vers num="12.3YM"/><vers num="12.3YK"/><vers num="12.3YJ"/><vers num="12.3YI"/><vers num="12.3YH"/><vers num="12.3YG"/><vers num="12.3YF"/><vers num="12.3YB"/><vers num="12.3YA"/><vers num="12.3XY"/><vers num="12.3XW"/><vers num="12.3XR"/><vers num="12.3XQ"/><vers num="12.3XM"/><vers num="12.3XK"/><vers num="12.3XJ"/><vers num="12.3XI"/><vers num="12.3XH"/><vers num="12.3XG"/><vers num="12.3XF"/><vers num="12.3XE"/><vers num="12.3XD"/><vers num="12.3XB"/><vers num="12.3XA"/><vers num="12.3T"/><vers num="12.3B"/><vers num="12.3(11)YL"/><vers num="12.3(11)YK2"/><vers num="12.3"/><vers num="12.2ZP"/><vers num="12.2ZN"/><vers num="12.2ZL"/><vers num="12.2ZJ"/><vers num="12.2ZH"/><vers num="12.2ZF"/><vers num="12.2ZE"/><vers num="12.2ZD"/><vers num="12.2ZC"/><vers num="12.2ZB"/><vers num="12.2YZ"/><vers num="12.2YY"/><vers num="12.2YX"/><vers num="12.2YW"/><vers num="12.2YU"/><vers num="12.2YT"/><vers num="12.2YN"/><vers num="12.2YM"/><vers num="12.2YL"/><vers num="12.2YK"/><vers num="12.2YH"/><vers num="12.2YE"/><vers num="12.2YD"/><vers num="12.2YC"/><vers num="12.2YB"/><vers num="12.2XW"/><vers num="12.2XV"/><vers num="12.2XU"/><vers num="12.2XT"/><vers num="12.2XS"/><vers num="12.2XQ"/><vers num="12.2N"/><vers num="12.2XM"/><vers num="12.2XL"/><vers num="12.2XK"/><vers num="12.2XJ"/><vers num="12.2XH"/><vers num="12.2XG"/><vers num="12.2XD"/><vers num="12.2XC"/><vers num="12.2XB"/><vers num="12.2XA"/><vers num="12.2SZ"/><vers num="12.2SXE"/><vers num="12.2SXD"/><vers num="12.2SXB"/><vers num="12.2SW"/><vers num="12.2SU"/><vers num="12.2S"/><vers num="12.2MX"/><vers num="12.2DX"/><vers num="12.2DD"/><vers num="12.2BY"/><vers num="12.2BW"/><vers num="12.2B"/><vers num="12.2"/><vers num="12.1YI"/><vers num="12.1YH"/><vers num="12.1YF"/><vers num="12.1YE"/><vers num="12.1YD"/><vers num="12.1YB"/><vers num="12.1YA"/><vers num="12.1XZ"/><vers num="12.1XY"/><vers num="12.1XW"/><vers num="12.1XV"/><vers num="12.1XU"/><vers num="12.1XT"/><vers num="12.1XS"/><vers num="12.1XQ"/><vers num="12.1XP"/><vers num="12.1XM"/><vers num="12.1XL"/><vers num="12.1XJ"/><vers num="12.1XI"/><vers num="12.1XH"/><vers num="12.1XE"/><vers num="12.1XA"/><vers num="12.1T"/><vers num="12.1GB"/><vers num="12.1GA"/><vers num="12.1EZ"/><vers num="12.1EC"/><vers num="12.1E"/><vers num="12.1AA"/><vers num="12.1"/><vers num="12.0XR"/><vers num="12.0XN"/><vers num="12.0XL"/><vers num="12.0XK"/><vers num="12.0XH"/><vers num="12.0T"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-01" name="CVE-2006-0486" published="2006-01-31" seq="2006-0486" severity="Medium" type="CVE"><desc><descript source="cve">Certain Cisco IOS releases in 12.2S based trains with maintenance release number 25 and later, 12.3T based trains, and 12.4 based trains reuse a Tcl Shell process across login sessions of different local users on the same terminal if the first user does not use tclquit before exiting, which may cause subsequent local users to execute unintended commands or bypass AAA command authorization checks, aka Bug ID CSCef77770.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-response-20060125-aaatcl.shtml">20060125 Response to AAA Command Authorization by-pass</ref><ref source="OSVDB" url="http://www.osvdb.org/22723">22723</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015543">1015543</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18613">18613</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24308">
cisco-aaa-tcl-auth-bypass(24308)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.4"/><vers num="12.3T"/><vers num="12.2(25)S"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-01" name="CVE-2006-0487" published="2006-01-31" seq="2006-0487" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Tumbleweed MailGate Email Firewall (EMF) 6.x allow remote attackers to (1) trigger temporarily incorrect processing of an e-mail message under &quot;extremely heavy loads&quot; and (2) cause an &quot;increased number of missed spam&quot; during &quot;spam outbreaks.&quot;</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422591/100/0/threaded">20060121 Tumbleweed EMF 6.x Processing Issues</ref></refs><vuln_soft><prod name="MailGate Email Firewall" vendor="Tumbleweed"><vers num="6.0"/><vers num="6.1"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-01" name="CVE-2006-0488" published="2006-01-31" seq="2006-0488" severity="Low" type="CVE"><desc><descript source="cve">The VDM (Virtual DOS Machine) emulation environment for MS-DOS applications in Windows 2000, Windows XP SP2, and Windows Server 2003 allows local users to read the first megabyte of memory and possibly obtain sensitive information, as demonstrated by dumper.asm.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423169/100/0/threaded">20060124 Windows mem leakage</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24471">
windows-vdm-obtain-information(24471)</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP2"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-21" name="CVE-2006-0489" published="2006-01-31" seq="2006-0489" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED ** Buffer overflow in the font command of mIRC, probably 6.16, allows local users to execute arbitrary code via a long string. NOTE: the original researcher claims that issue has been disputed by the vendor, and that the vendor stated &quot;as far as I can tell, this is neither an exploit nor a vulnerability.  The above report describes a local bug in mIRC.&quot;  It could be that this is only exploitable by the user of the application, and thus would not cross privilege boundaries unless under an otherwise restrictive environment such as a kiosk.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423192/100/0/threaded">20060124 Buffer Overflow /Font on mIRC</ref><ref source="" url="http://trout.snt.utwente.nl/ubbthreads/showflat.php?Cat=0&amp;Board=bugreports&amp;Number=118751"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423758/100/0/threaded">20060201 Re: Buffer Overflow /Font on mIRC</ref><ref source="" url="http://www.securiteam.com/windowsntfocus/5IP080AHPQ.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/22942">22942</ref><ref source="SREASON" url="http://securityreason.com/securityalert/383">383</ref></refs><vuln_soft><prod name="mIRC" vendor="Khaled Mardam-Bey"><vers num="6.16"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-01" name="CVE-2006-0490" published="2006-01-31" seq="2006-0490" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.asp in ASPThai.Net ASPThai Forums 8.0 and earlier allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the password field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423287/100/0/threaded">20060127 hello</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24359">aspthai-login-sql-injection(24359)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0372">ADV-2006-0372</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015548">1015548</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18636">18636</ref><ref source="OSVDB" url="http://www.osvdb.org/22790">22790</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113837847503661&amp;w=2">20060107 hello</ref><ref source="BID" url="http://www.securityfocus.com/bid/16404">16404</ref><ref source="SREASON" url="http://securityreason.com/securityalert/381">381</ref></refs><vuln_soft><prod name="ASPThai Forums" vendor="ASPThai.Net"><vers num="8.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-01" name="CVE-2006-0491" published="2006-01-31" seq="2006-0491" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in SZUserMgnt.class.php in SZUserMgnt 1.4 allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/53/summary.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24339">szusermgnt-username-sql-injection(24339)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423658/100/0/threaded">20060201 [eVuln] SZUserMgnt Authentication Bypass</ref><ref source="BID" url="http://www.securityfocus.com/bid/16454">16454</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0366">ADV-2006-0366</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18666">18666</ref><ref source="OSVDB" url="http://www.osvdb.org/22809">22809</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015569">1015569</ref><ref source="SREASON" url="http://securityreason.com/securityalert/396">396</ref></refs><vuln_soft><prod name="SZUserMgnt" vendor="SubZane"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-01" name="CVE-2006-0492" published="2006-01-31" seq="2006-0492" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Calendarix allow remote attackers to execute arbitrary SQL commands via (1) the catview parameter in cal_functions.inc.php and (2) the login parameter in cal_login.php.  NOTE: the catview vector might overlap CVE-2005-1865.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/52/summary.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0365">ADV-2006-0365</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24332">calendarix-multiple-sql-injection(24332)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16456">16456</ref><ref source="OSVDB" url="http://www.osvdb.org/22810">22810</ref><ref source="OSVDB" url="http://www.osvdb.org/22811">22811</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18667">18667</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015560">1015560</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423656/100/0/threaded">20060201 [eVuln] Calendarix SQL Injection &amp; Authorization Bypass Vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/394">394</ref></refs><vuln_soft><prod name="Calendarix" vendor="Vincent Hor"><vers num="0.6.2005-08-30"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-01" name="CVE-2006-0493" published="2006-01-31" seq="2006-0493" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in MG2 (formerly known as Minigal) 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the Name field in a comment associated with a picture.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423477/100/0/threaded">20060130 XSS flaw in MG2 Image Gallery (v.0.5.1)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16428">16428</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17374">17374</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24378">mg2-name-xss(24378)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/389">389</ref></refs><vuln_soft><prod name="MG2" vendor="Thomas Rybak"><vers num="0.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="6.4" CVSS_score="4.3" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-05" name="CVE-2006-0494" published="2006-01-31" seq="2006-0494" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.02 allows local users with MyBB administrative privileges to include and possibly execute arbitrary local files via directory traversal sequences and a nul (%00) character in the plugin parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423465/100/0/threaded">20060130 MyBB 1.2 Local File Incusion</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24461">
mybb-plugins-file-include(24461)</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-05" name="CVE-2006-0495" published="2006-01-31" seq="2006-0495" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Add Thread to Favorites feature in usercp2.php in MyBB (aka MyBulletinBoard) 1.02 allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer header ($url variable).</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423443/100/0/threaded">20060129 MyBB 1.2 usercp2.php [ $url ] CrossSiteScripting ( XSS )</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24392">mybb-usercp2-xss(24392)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16419">16419</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0496" published="2006-01-31" seq="2006-0496" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and possibly earlier, Mozilla Firefox 1.0.7 and possibly earlier, and Netscape 8.1 and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the -moz-binding CSS (Cascading Style Sheets) property, which does not require that the style sheet have the same origin as the web page, as demonstrated by the compromise of a large number of LiveJournal accounts.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://community.livejournal.com/lj_dev/708069.html"></ref><ref source="" url="http://www.davidpashley.com/cgi/pyblosxom.cgi/computing/livejournal-mozilla-bug.html"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=324253"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16427">16427</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0403">ADV-2006-0403</ref><ref source="OSVDB" url="http://www.osvdb.org/22924">22924</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015553">1015553</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015563">1015563</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24427">mozilla-mozbinding-xss(24427)</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113847912709062&amp;w=2">20060128 -moz-binding CSS property: more XSS fun</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7.12"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7"/><vers num="1.7 RC3"/><vers num="1.7 RC2"/><vers num="1.7 RC1"/><vers num="1.7 Beta"/><vers num="1.7 Alpha"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0497" published="2006-02-01" seq="2006-0497" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in PHP GEN before 1.4 allow remote attackers to inject arbitrary SQL commands via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.eyce.be/php_gen/NEWS"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0408">ADV-2006-0408</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18715">18715</ref><ref source="BID" url="http://www.securityfocus.com/bid/15458">15458</ref><ref source="OSVDB" url="http://www.osvdb.org/22885">22885</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24441">phpgen-multiple-sql-injection(24441)</ref></refs><vuln_soft><prod name="PHP GEN" vendor="PHP GEN"><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/><vers num="0.8"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0498" published="2006-02-01" seq="2006-0498" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHP GEN before 1.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.eyce.be/php_gen/NEWS"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0408">ADV-2006-0408</ref><ref source="OSVDB" url="http://www.osvdb.org/22884">22884</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18715">18715</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24443">phpgen-parameters-xss(24443)</ref></refs><vuln_soft><prod name="PHP GEN" vendor="PHP GEN"><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/><vers num="0.8"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0499" published="2006-02-01" seq="2006-0499" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in rlink.php in Rlink 1.0.0 module for phpBB allows remote attackers to inject arbitrary web script or HTML via the url parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16448">16448</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0390">ADV-2006-0390</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18620">18620</ref><ref source="OSVDB" url="http://www.osvdb.org/22818">22818</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24410">phpbb-rlink-xss(24410)</ref></refs><vuln_soft><prod name="Rlink" vendor="Yourboard"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0500" published="2006-02-01" seq="2006-0500" severity="High" type="CVE"><desc><descript source="cve">MyCO Guestbook 1.0 stores the admin directory under the web document root with insufficient access control, which allows remote attackers to perform unspecified privileged actions by directly accessing files via a URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423565/100/0/threaded">20060131 MyCO multiple vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24438">myco-admin-information-disclosure(24438)</ref></refs><vuln_soft><prod name="MyCO Guestbook" vendor="Punctweb"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0501" published="2006-02-01" seq="2006-0501" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in MyCO Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the Name field, when registering a user.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423565/100/0/threaded">20060131 MyCO multiple vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423696/100/0/threaded">20060201 Re: MyCO multiple vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24439">myco-name-xss(24439)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16444">16444</ref></refs><vuln_soft><prod name="MyCO Guestbook" vendor="Punctweb"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0502" published="2006-02-01" seq="2006-0502" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in loginout.php in FarsiNews 2.1 Beta 2 and earlier, with register_globals enabled, allows remote attackers to include arbitrary files via a URL in the cutepath parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423568/100/0/threaded">20060131 FarsiNews 2.1 PHP Remote File Inclusion</ref><ref adv="1" source="" url="http://www.hamid.ir/security/farsinews.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16440">16440</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0411">ADV-2006-0411</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015554">1015554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18637">18637</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24419">farsinews-loginout-file-include(24419)</ref><ref source="OSVDB" url="http://www.osvdb.org/22878">22878</ref><ref source="SREASON" url="http://securityreason.com/securityalert/390">390</ref></refs><vuln_soft><prod name="FarsiNews" vendor="FarsiNews"><vers num="2.1 Beta2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-07-24" name="CVE-2006-0503" published="2006-02-01" seq="2006-0503" severity="Medium" type="CVE"><desc><descript source="cve">IMAP service in MailEnable Professional Edition before 1.72 allows remote attackers to cause a denial of service (service crash) via unspecified vectors involving the EXAMINE command.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.mailenable.com/professionalhistory.asp"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0397">ADV-2006-0397</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18668">18668</ref><ref source="BID" url="http://www.securityfocus.com/bid/16457">16457</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015558">1015558</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24424">mailenable-imap-examine-dos(24424)</ref></refs><vuln_soft><prod name="MailEnable Professional" vendor="MailEnable"><vers num="1.71"/><vers num="1.7"/><vers num="1.6"/><vers num="1.54"/><vers num="1.53"/><vers num="1.52"/><vers num="1.51"/><vers num="1.5"/><vers num="1.2a"/><vers num="1.17"/><vers num="1.18"/><vers num="1.19"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-07-24" name="CVE-2006-0504" published="2006-02-01" seq="2006-0504" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in MailEnable Enterprise Edition before 1.2 allows remote attackers to cause a denial of service (CPU utilization) by viewing &quot;formatted quoted-printable emails&quot; via webmail.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://www.mailenable.com/enterprisehistory.asp"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/18716">18716</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24517">mailenable-webmail-dos(24517)</ref></refs><vuln_soft><prod name="MailEnable Enterprise" vendor="MailEnable"><vers num="1.1"/><vers num="1.04"/><vers num="1.03"/><vers num="1.02"/><vers num="1.01"/><vers num="1.00"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0505" published="2006-02-01" seq="2006-0505" severity="Medium" type="CVE"><desc><descript source="cve">zbattle.net Zbattle client 1.09 SR-1 beta allows remote attackers to cause an unspecified denial of service by rapidly creating and closing a game.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423431/100/0/threaded">20060128 zbattle.net</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24369">zbattle-command-dos(24369)</ref></refs><vuln_soft><prod name="Zbattle client" vendor="zbattle.net"><vers num="1.09 SR-1 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0506" published="2006-02-01" seq="2006-0506" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Nuked-klaN 1.7 allows remote attackers to inject arbitrary web script or HTML via the letter parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423454/100/0/threaded">20060130 Nuked-klaN Cross-Site Scripting Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0387">ADV-2006-0387</ref><ref source="OSVDB" url="http://www.osvdb.org/22805">22805</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18670">18670</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24387">nukedklan-index-xss(24387)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16424">16424</ref><ref source="SREASON" url="http://securityreason.com/securityalert/385">385</ref></refs><vuln_soft><prod name="Nuked-Klan" vendor="Nuked-Klan"><vers num="1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0507" published="2006-02-01" seq="2006-0507" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Easy CMS allow remote attackers to inject arbitrary web script or HTML via (1) unknown attack vectors in the administrative interface and (2) input fields of the contact form.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423442/100/0/threaded">20060129 EasyCMS vulnerable to XSS injection.</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423563/100/0/threaded">20060131 Re: EasyCMS vulnerable to XSS injection.</ref><ref source="BID" url="http://www.securityfocus.com/bid/16430">16430</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0385">ADV-2006-0385</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18673">18673</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24371">easycms-xss(24371)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424431/100/0/threaded">20060208 Re: Re: EasyCMS vulnerable to XSS injection.</ref></refs><vuln_soft><prod name="Easy CMS" vendor="Easy CMS"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0508" published="2006-02-01" seq="2006-0508" severity="Medium" type="CVE"><desc><descript source="cve">Easy CMS stores the images directory under the web document root with insufficient access control and browsing enabled, which allows remote attackers to list and possibly read images that are stored in that directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423442/100/0/threaded">20060129 EasyCMS vulnerable to XSS injection.</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18673">18673</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24373">easycms-insecure-directories(24373)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424431/100/0/threaded">20060208 Re: Re: EasyCMS vulnerable to XSS injection.</ref></refs><vuln_soft><prod name="Easy CMS" vendor="Easy CMS"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-05" name="CVE-2006-0509" published="2006-02-01" seq="2006-0509" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web script or HTML via (1) the contact_search parameter and (2) unspecified url fields.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/423547/30/0/threaded">20060130 Cerberus Helpdesk vulnerable to XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/16439">16439</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0395">ADV-2006-0395</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18657">18657</ref><ref source="OSVDB" url="http://www.osvdb.org/22843">22843</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24388">cerberus-clients-xss(24388)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/391">391</ref></refs><vuln_soft><prod name="Cerberus Helpdesk" vendor="Cerberus"><vers num="2.7"/><vers num="2.7.1 Development Release"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0510" published="2006-02-01" seq="2006-0510" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in userlogin.jsp in Daffodil CRM 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified parameters in a login action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16433">16433</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423718/100/0/threaded">20060130 Daffodil CRM - vulnerable to SQL-injection.</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0412">ADV-2006-0412</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18685">18685</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24450">daffodilcrm-userlogin-sql-injection(24450)</ref><ref source="OSVDB" url="http://www.osvdb.org/22879">22879</ref></refs><vuln_soft><prod name="Daffodil CRM" vendor="Daffodil Software"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="6.4" CVSS_score="4.3" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0511" published="2006-02-01" seq="2006-0511" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED ** Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle, which allows subsequent users to log in as the previous user and gain privileges.  NOTE: the vendor has disputed this issue, saying that &quot;This is a customer specific issue related to their Kerberos authentication single sign-on application and not a vulnerability in the Blackboard product.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423654/100/0/threaded">20060201 Blackboard Authentication Error</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/423686/100/0/threaded">20060201 Re: Blackboard Authentication Error</ref><ref source="BID" url="http://www.securityfocus.com/bid/16438">16438</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423778/100/0/threaded">20060202 Re: Blackboard Authentication Error</ref><ref source="OSVDB" url="http://www.osvdb.org/28023">28023</ref></refs><vuln_soft><prod name="Blackboard Academic Suite" vendor="Blackboard"><vers num="6.0"/></prod><prod name="Blackboard" vendor="Blackboard"><vers num="6.0"/><vers num="5.5.1"/><vers num="5.5"/><vers num="5.0.2"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0512" published="2006-02-02" seq="2006-0512" severity="Low" type="CVE"><desc><descript source="cve">PADL MigrationTools 46 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the temporary files, which are not properly created by (1) migrate_all_online.sh, (2) migrate_all_offline.sh, (3) migrate_all_netinfo_online.sh, (4) migrate_all_netinfo_offline.sh, (5) migrate_all_nis_online.sh, (6) migrate_all_nis_offline.sh, (7) migrate_all_nisplus_online.sh, and (8) migrate_all_nisplus_offline.sh.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=338920"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2427">ADV-2005-2427</ref><ref source="DEBIAN" url="http://lists.debian.org/debian-security-announce/debian-security-announce-2006/msg00281.html">DSA-1187</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22243">22243</ref></refs><vuln_soft><prod name="MigrationTools" vendor="Padl Software"><vers num="46"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-07" name="CVE-2006-0513" published="2006-02-06" seq="2006-0513" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in pkmslogout in Tivoli Web Server Plug-in 5.1.0.10 in Tivoli Access Manager (TAM) 5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423946/100/0/threaded">20060203 VSR Advisory: IBM Tivoli Access Manager - Web Server Plug-in File Retrieval Vulnerability</ref><ref adv="1" patch="1" source="" url="http://www.vsecurity.com/bulletins/advisories/2006/tam-file-retrieval.txt"></ref><ref patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg24011562">IY79724</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015582">1015582</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18725">18725</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0442">ADV-2006-0442</ref><ref source="BID" url="http://www.securityfocus.com/bid/16494">16494</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041930.html">
20060203 VSR Advisory: IBM Tivoli Access Manager - Web Server Plug-in File Retrieval Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24485">
tivoli-pkmslogout-directory-traversal(24485)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/412">412</ref></refs><vuln_soft><prod name="Tivoli Access Manager for e-business" vendor="IBM"><vers num="5.1.0.10"/><vers num="6.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-11-04" modified="2006-06-23" name="CVE-2006-0515" published="2006-05-09" seq="2006-0515" severity="High" type="CVE"><desc><descript source="cve">Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3.x before 2.3(4) and 3.x before 3.1(7), when used with Websense/N2H2, allows remote attackers to bypass HTTP access restrictions by splitting the GET method of an HTTP request into multiple packets, which prevents the request from being sent to Websense for inspection, aka bugs CSCsc67612, CSCsc68472, and CSCsd81734.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433270/100/0/threaded">20060508 VSR Advisory: WebSense content filter bypass when deployed in conjunction with Cisco filtering devices</ref><ref adv="1" patch="1" source="" url="http://www.vsecurity.com/bulletins/advisories/2006/cisco-websense-bypass.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17883">17883</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1738">ADV-2006-1738</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016039">1016039</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016040">1016040</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20044">20044</ref><ref source="CISCO" url="http://www.cisco.com/en/US/products/sw/netmgtsw/ps2032/tsd_products_security_response09186a00806824ec.html">20060508 Cisco Security Response to: PIX/ASA/FWSM Websense/N2H2 Content Filter Bypass</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-May/045899.html">
20060508 VSR Advisory: WebSense content filter bypass when deployed in conjunction with Cisco filtering devices</ref><ref source="OSVDB" url="http://www.osvdb.org/25453">
25453</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26308">
cisco-websense-content-filtering-bypass(26308)</ref></refs><vuln_soft><prod name="PIX_ASA" vendor="Cisco"><vers num="7.0.4.3"/><vers num="7.0.4"/><vers num="7.0.1.4"/><vers num="7.0"/></prod><prod name="FWSM" vendor="Cisco"><vers num="3.1"/><vers num="2.3"/></prod><prod name="PIX Firewall" vendor="Cisco"><vers num="525 6.3"/><vers num="6.3.3 (133)"/><vers num="6.3.2"/><vers num="6.3.1"/><vers num="6.3 (5)"/><vers num="6.3 (3.109)"/><vers num="6.3 (3.102)"/><vers num="6.3 (3)"/><vers num="6.3 (1)"/><vers num="6.3"/><vers num="6.2.3 (110)"/><vers num="6.2.3"/><vers num="6.2.2.111"/><vers num="6.2.2"/><vers num="6.2.1"/><vers num="6.2 (3.100)"/><vers num="6.2 (3)"/><vers num="6.2 (2)"/><vers num="6.2 (1)"/><vers num="6.2"/><vers num="6.1.5 (104)"/><vers num="6.1.5"/><vers num="6.1.4"/><vers num="6.1.3"/><vers num="6.1 (5)"/><vers num="6.1 (4)"/><vers num="6.1 (3)"/><vers num="6.1 (2)"/><vers num="6.1 (1)"/><vers num="6.1"/><vers num="6.0.4"/><vers num="6.0.3"/><vers num="6.0 (4.101)"/><vers num="6.0 (4)"/><vers num="6.0 (2)"/><vers num="6.0 (1)"/><vers num="6.0"/><vers num="5.3 (3)"/><vers num="5.3 (2)"/><vers num="5.3 (1.200)"/><vers num="5.3 (1)"/><vers num="5.3"/><vers num="5.2 (9)"/><vers num="5.2 (7)"/><vers num="5.2 (6)"/><vers num="5.2 (5)"/><vers num="5.2 (3.210)"/><vers num="5.2 (2)"/><vers num="5.2 (1)"/><vers num="5.2"/><vers num="5.1.4"/><vers num="5.1 (4.206)"/><vers num="5.1"/><vers num="5.0"/><vers num="4.4 (8)"/><vers num="4.4 (7.202)"/><vers num="4.4 (4)"/><vers num="4.4"/><vers num="4.3"/><vers num="4.2.2"/><vers num="4.2.1"/><vers num="4.2 (5)"/><vers num="4.2"/><vers num="4.1.6 b"/><vers num="4.1.6"/><vers num="4.0"/><vers num="3.1"/><vers num="3.0"/><vers num="2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0516" published="2006-02-02" seq="2006-0516" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the kernel processing in Solaris 10 64 bit platform, when running in 64-bit mode, allows local users to cause a denial of service (system panic) via unknown attack vectors.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102149-1">102149</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0394">ADV-2006-0394</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18671">18671</ref><ref source="BID" url="http://www.securityfocus.com/bid/16460">16460</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015557">1015557</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24395">solaris-x64-kernel-dos(24395)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1163">oval:org.mitre.oval:def:1163</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:219">oval:org.mitre.oval:def:219</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="64 Bit" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0517" published="2006-02-02" seq="2006-0517" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in formulaires/inc-formulaire_forum.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id_forum, (2) id_article, or (3) id_breve parameters to forum.php3; (4) unspecified vectors related to &quot;session handling&quot;; and (5) when posting &quot;petitions&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.zone-h.org/en/advisories/read/id=8650/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0398">ADV-2006-0398</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18676">18676</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423655/100/0/threaded">20060131 ZRCSA-200601: SPIP - Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/24397">24397</ref><ref source="BID" url="http://www.securityfocus.com/bid/16458">16458</ref><ref source="OSVDB" url="http://www.osvdb.org/22844">22844</ref><ref source="OSVDB" url="http://www.osvdb.org/22845">22845</ref><ref source="OSVDB" url="http://www.osvdb.org/22848">22848</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015556">1015556</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24397">spip-forum-sql-injection(24397)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0990.html">20060131 ZRCSA-200601: SPIP - Multiple Vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/395">395</ref></refs><vuln_soft><prod name="SPIP" vendor="SPIP"><vers num="1.8.2e" prev="1"/><vers num="1.9 Alpha2_5539" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0518" published="2006-02-02" seq="2006-0518" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.zone-h.org/en/advisories/read/id=8650/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0398">ADV-2006-0398</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18676">18676</ref><ref source="BID" url="http://www.securityfocus.com/bid/16461">16461</ref><ref source="OSVDB" url="http://www.osvdb.org/22849">22849</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24401">spip-index-xss(24401)</ref></refs><vuln_soft><prod name="SPIP" vendor="SPIP"><vers num="1.8.2e" prev="1"/><vers num="1.9 Alpha2_5539" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0519" published="2006-02-02" seq="2006-0519" severity="Medium" type="CVE"><desc><descript source="cve">SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to obtain sensitive information via a direct request to inc-messforum.php3, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.zone-h.org/en/advisories/read/id=8650/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0398">ADV-2006-0398</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18676">18676</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24399">spip-incmessforum-path-disclosure(24399)</ref></refs><vuln_soft><prod name="SPIP" vendor="SPIP"><vers num="1.8.2e" prev="1"/><vers num="1.9 Alpha2_5539" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0520" published="2006-02-02" seq="2006-0520" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability index.php in Dragoran Portal module 1.3 for Invision Power Board (IPB) allows remote attackers to execute arbitrary SQL commands via the site parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0396">ADV-2006-0396</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18664">18664</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24404">portal-index-sql-injection(24404)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16447">16447</ref><ref source="OSVDB" url="http://www.osvdb.org/22851">22851</ref></refs><vuln_soft><prod name="Portal module" vendor="Dragoran"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0521" published="2006-02-02" seq="2006-0521" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in results.php in BrowserCRM allows remote attackers to inject arbitrary web script or HTML via certain manipulations of the query parameter, as demonstrated using an IMG SRC tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423546/100/0/threaded">20060131 BrowserCRM vulnerable for XSS</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0391">ADV-2006-0391</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18658">18658</ref><ref source="BID" url="http://www.securityfocus.com/bid/16435">16435</ref><ref source="OSVDB" url="http://www.osvdb.org/22841">22841</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24390">browsercrm-results-xss(24390)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/393">393</ref></refs><vuln_soft><prod name="BrowserCRM" vendor="BrowserCRM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-02" name="CVE-2006-0522" published="2006-02-02" seq="2006-0522" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the Authentication Servlet in Symantec Sygate Management Server (SMS) version 4.1 build 1417 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via unknown attack vectors related to a URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://securityresponse.symantec.com/avcenter/security/Content/2006.02.01.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0402">ADV-2006-0402</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015561">1015561</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18689">18689</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24413">symantec-sms-sql-injection(24413)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16452">16452</ref><ref source="OSVDB" url="http://www.osvdb.org/22883">22883</ref></refs><vuln_soft><prod name="Sygate Management Server" vendor="Symantec"><vers num="4.1 MR 2 build 1417 English" prev="1"/><vers num="4.0 MR 1 build 1104 English"/><vers num="3.5 MR 3 build 894 English"/><vers num="4.1 MR1 build 1351 Chinese"/><vers num="4.1 GA build 1258 Japanese"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-05" name="CVE-2006-0523" published="2006-02-02" seq="2006-0523" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in global.php in MyBB before 1.03 allows remote attackers to execute arbitrary SQL commands via the templatelist variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://community.mybboard.net/showthread.php?tid=6418"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0400">ADV-2006-0400</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18678">18678</ref><ref source="OSVDB" url="http://www.osvdb.org/22903">22903</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24416">mybb-global-sql-injection(24416)</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC4"/><vers num="1.0 RC2"/><vers num="1.0 Preview Release 2"/><vers num="1.0 PR2"/><vers num="1.0 &quot;Final&quot;"/><vers num="1.0 Final"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-23" name="CVE-2006-0524" published="2006-02-02" seq="2006-0524" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in ashnews.php in Derek Ashauer ashNews 0.83 allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0955.html">20060130 ashnews Cross-Site Scripting Vulnerability</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0969.html">20060130 Re: ashnews Cross-Site Scripting Vulnerability</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0979.html">20060131 Re: ashnews Cross-Site Scripting Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16426">16426</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24365">ashnews-ashnews-xss(24365)</ref><ref source="OSVDB" url="http://www.osvdb.org/22934">22934</ref><ref source="SECUNIA" url="http://secunia.com/advisories/9331">9331</ref></refs><vuln_soft><prod name="ashNews" vendor="ashWebStudio"><vers num="0.83"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0525" published="2006-02-02" seq="2006-0525" severity="Medium" type="CVE"><desc><descript source="cve">Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center, install a large number of .EXE and .DLL files with write-access permission for the Everyone group, which allows local users to gain privileges via Trojan horse programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423587/100/0/threaded">20060131 Windows Access Control Demystified</ref><ref source="" url="http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16451">16451</ref><ref source="" url="http://www.adobe.com/support/techdocs/332644.html"></ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/953860">VU#953860</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0431">ADV-2006-0431</ref><ref source="OSVDB" url="http://www.osvdb.org/22908">22908</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015577">1015577</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015578">1015578</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015579">1015579</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18698">18698</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24464">adobe-insecure-default-permissions(24464)</ref></refs><vuln_soft><prod name="Acrobat" vendor="Adobe"><vers num="7.0.3"/><vers num="7.0.2"/><vers num="7.0.1"/><vers num="7.0"/><vers num="6.0.4"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.0.10"/><vers num="5.0.5"/><vers num="5.0"/><vers num="4.0.5a"/><vers num="4.0.5c"/><vers num="4.0.5"/><vers num="4.0"/><vers num="3.1"/><vers num="3.0"/></prod><prod name="Version Cue" vendor="Adobe"><vers num="1.0.1"/><vers num="1.0"/><vers edition="Mac OS X" num="Gold"/></prod><prod name="Acrobat Reader" vendor="Adobe"><vers num="7.0.3"/><vers num="7.0.2"/><vers num="7.0.1"/><vers num="7.0"/><vers num="6.0.4"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.1"/><vers num="5.0.10"/><vers num="5.0.5"/><vers num="5.0"/><vers edition="a" num="4.0.5"/><vers edition="c" num="4.0.5"/><vers num="4.0.5"/><vers num="4.0"/><vers num="3.0"/></prod><prod name="Premiere Pro" vendor="Adobe"><vers num="1.5"/></prod><prod name="Illustrator" vendor="Adobe"><vers num="10.0"/><vers num="9.0"/><vers num="8.0"/><vers num="7.0"/><vers num="CS"/><vers num=""/></prod><prod name="Acrobat Viewer" vendor="Adobe"><vers num="4.5"/><vers num="4.0"/></prod><prod name="InDesign" vendor="Adobe"><vers num="CS"/><vers num=""/></prod><prod name="Pagemaker" vendor="Adobe"><vers edition="Plus" num="7.0"/><vers edition="Plus" num="6.5"/><vers num="7.0"/><vers num="6.5"/></prod><prod name="PhotoShop" vendor="Adobe"><vers num="LE"/><vers num="8.0"/><vers num="7.0"/><vers num="CS2"/><vers num="CS"/></prod><prod name="Creative Suite" vendor="Adobe"><vers num="2.0"/><vers num="1.3"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0526" published="2006-02-02" seq="2006-0526" severity="High" type="CVE"><desc><descript source="cve">The default configuration of the America Online (AOL) client software allows all users to modify a certain registry value that specifies a DLL file name, which might allow local users to gain privileges via a Trojan horse program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><config/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423587/100/0/threaded">20060131 Windows Access Control Demystified</ref><ref source="" url="http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16453">16453</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/953860">VU#953860</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24498">
aol-insecure-default-permissions(24498)</ref></refs><vuln_soft><prod name="AOL Client Software" vendor="AOL"><vers edition="Security" num="9.0"/><vers edition="Optimized" num="9.0"/><vers num="9.0"/><vers edition="Plus" num="8.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0527" published="2006-02-02" seq="2006-0527" severity="High" type="CVE"><desc><descript source="cve">BIND 4 (BIND4) and BIND 8 (BIND8), if used as a target forwarder, allows remote attackers to gain privileged access via a &quot;Kashpureff-style DNS cache corruption&quot; attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00595837">HPSBTU02095</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015551">1015551</ref><ref source="BID" url="http://www.securityfocus.com/bid/16455">16455</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0399">ADV-2006-0399</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18690">18690</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24414">tru64-dns-bind-unauth-access(24414)</ref><ref adv="1" patch="1" source="HP" url="http://www.securityfocus.com/archive/1/archive/1/425083/100/0/threaded">HPSBUX02097</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015606">1015606</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-February/000551.html">[VIM] 20060216 Recent HP advisories outline BIND problems</ref><ref source="" url="http://computerworld.com/networkingtopics/networking/story/0,10801,103744,00.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/22888">22888</ref><ref source="SREASON" url="http://securityreason.com/securityalert/438">438</ref><ref source="SREASON" url="http://securityreason.com/securityalert/748">748</ref></refs><vuln_soft><prod name="Tru64 UNIX" vendor="HP"><vers num="4.0F PK8"/><vers num="4.0G PK4"/><vers num="5.1A PK6"/><vers num="5.1B2 PK4"/><vers num="5.1B3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0528" published="2006-02-02" seq="2006-0528" severity="Medium" type="CVE"><desc><descript source="cve">The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains &quot;Content-Disposition: inline&quot; in the header, and a very long line in the body, which causes the client to repeatedly crash until the e-mail message is manually removed, possibly due to a buffer overflow, as demonstrated using an XML attachment.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0925.html">20060128 gnome evolution mail client inline text file DoS issue</ref><ref source="BID" url="http://www.securityfocus.com/bid/16408">16408</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:057">MDKSA-2006:057</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-265-1">USN-265-1</ref><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_07_sr.html">SUSE-SR:2006:007</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19504">19504</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:057">MDKSA-2006:057</ref><ref source="SREASON" url="http://securityreason.com/securityalert/610">610</ref></refs><vuln_soft><prod name="Evolution" vendor="GNOME"><vers num="2.3.7"/><vers num="2.3.6.1"/><vers num="2.3.6"/><vers num="2.3.5"/><vers num="2.3.4"/><vers num="2.3.3"/><vers num="2.3.2"/><vers num="2.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0529" published="2006-02-02" seq="2006-0529" severity="Medium" type="CVE"><desc><descript source="cve">Computer Associates (CA) Message Queuing (CAM / CAFT) before 1.07 Build 220_16 and 1.11 Build 29_20, as used in multiple CA products, allows remote attackers to cause a denial of service via a crafted message to TCP port 4105.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423785/100/0/threaded">20060202 CAID 33581 - CA Message Queuing Denial of Service Vulnerabilities</ref><ref adv="1" patch="1" source="" url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33581"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0414">ADV-2006-0414</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18681">18681</ref><ref source="BID" url="http://www.securityfocus.com/bid/16475">16475</ref><ref source="OSVDB" url="http://www.osvdb.org/21146">21146</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015571">1015571</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24448">ca-cam-port4105-dos(24448)</ref><ref source="" url="http://supportconnectw.ca.com/public/ca_common_docs/camessagsecurity_notice.asp"></ref></refs><vuln_soft><prod name="CA Messaging" vendor="Computer Associates"><vers edition="AIX" num="1.07.210.0"/><vers edition="AIX" num="1.07.220.11"/><vers edition="AIX" num="1.07.220.13"/><vers edition="AIX" num="1.07.220.14"/><vers edition="AIX" num="1.07.220.15"/><vers edition="AIX" num="1.07.220.5"/><vers edition="AIX" num="1.07.220.7"/><vers edition="AIX" num="1.07.220.8"/><vers edition="AIX" num="1.11.19.0"/><vers edition="AIX" num="1.11.27.0"/><vers edition="AIX" num="1.11.27.1"/><vers edition="AIX" num="1.11.29.13"/><vers edition="AIX" num="1.11.29.14"/><vers edition="AIX" num="1.11.29.15"/><vers edition="AIX" num="1.11.29.16"/><vers edition="AIX" num="1.11.29.17"/><vers edition="AIX" num="1.11.29.18"/><vers edition="AIX" num="1.11.29.19"/><vers edition="AIX" num="1.11.29.2"/><vers edition="AIX" num="1.11.29.3"/><vers edition="AIX" num="1.11.29.4"/><vers edition="AIX" num="1.11.29.5"/><vers edition="AIX" num="1.11.29.8"/><vers edition="AIX" num="1.11.29.9"/><vers edition="AIX" num="1.05"/><vers edition="HP_UX" num="1.07.220.11"/><vers edition="HP_UX" num="1.07.220.13"/><vers edition="HP_UX" num="1.07.220.14"/><vers edition="HP_UX" num="1.07.220.15"/><vers edition="HP_UX" num="1.07.220.5"/><vers edition="HP_UX" num="1.07.220.7"/><vers edition="HP_UX" num="1.07.220.8"/><vers edition="HP_UX" num="1.11.18.0"/><vers edition="HP_UX" num="1.11.27.0"/><vers edition="HP_UX" num="1.11.27.1"/><vers edition="HP_UX" num="1.11.29.13"/><vers edition="HP_UX" num="1.11.29.14"/><vers edition="HP_UX" num="1.11.29.15"/><vers edition="HP_UX" num="1.11.29.16"/><vers edition="HP_UX" num="1.11.29.17"/><vers edition="HP_UX" num="1.11.29.18"/><vers edition="HP_UX" num="1.11.29.19"/><vers edition="HP_UX" num="1.11.29.2"/><vers edition="HP_UX" num="1.11.29.3"/><vers edition="Solaris" num="1.11.29.4"/><vers edition="HP_UX" num="1.11.29.5"/><vers edition="HP_UX" num="1.11.29.8"/><vers edition="HP_UX" num="1.11.29.9"/><vers edition="Linux" num="1.05"/><vers edition="Linux" num="1.07.220.11"/><vers edition="Linux" num="1.07.220.13"/><vers edition="Linux" num="1.07.220.14"/><vers edition="Linux" num="1.07.220.15"/><vers edition="Linux" num="1.11.28.0"/><vers edition="Linux" num="1.11.29.13"/><vers edition="Linux" num="1.11.29.14"/><vers edition="Linux" num="1.11.29.15"/><vers edition="Linux" num="1.11.29.16"/><vers edition="Linux" num="1.11.29.17"/><vers edition="Linux" num="1.11.29.18"/><vers edition="Linux" num="1.11.29.19"/><vers edition="Linux" num="1.11.29.5"/><vers edition="Linux" num="1.11.29.8"/><vers edition="Linux" num="1.11.29.9"/><vers edition="Solaris" num="1.05"/><vers edition="Solaris" num="1.07.210.0"/><vers edition="Solaris" num="1.07.220.0"/><vers edition="Solaris" num="1.07.220.11"/><vers edition="Solaris" num="1.07.220.13"/><vers edition="Solaris" num="1.07.220.14"/><vers edition="Solaris" num="1.07.220.15"/><vers edition="Solaris" num="1.07.220.5"/><vers edition="Solaris" num="1.07.220.8"/><vers edition="Solaris" num="1.07.220.9"/><vers edition="Solaris" num="1.11.19.0"/><vers edition="Solaris" num="1.11.27.0"/><vers edition="Solaris" num="1.11.27.1"/><vers edition="Solaris" num="1.11.29.13"/><vers edition="Solaris" num="1.11.29.14"/><vers edition="Solaris" num="1.11.29.15"/><vers edition="Solaris" num="1.11.29.16"/><vers edition="Solaris" num="1.11.29.17"/><vers edition="Solaris" num="1.11.29.18"/><vers edition="Solaris" num="1.11.29.19"/><vers edition="Solaris" num="1.11.29.2"/><vers edition="Solaris" num="1.11.29.3"/><vers edition="HP_UX" num="1.11.29.4"/><vers edition="Solaris" num="1.11.29.5"/><vers edition="Solaris" num="1.11.29.8"/><vers edition="Solaris" num="1.11.29.9"/><vers edition="Windows" num="1.05"/><vers edition="Windows" num="1.07.220.0"/><vers edition="Windows" num="1.07.220.10"/><vers edition="Windows" num="1.07.220.11"/><vers edition="Windows" num="1.07.220.13"/><vers edition="Windows" num="1.07.220.14"/><vers edition="Windows" num="1.07.220.15"/><vers edition="Windows" num="1.07.220.3"/><vers edition="Windows" num="1.07.220.4"/><vers edition="Windows" num="1.07.220.5"/><vers edition="Windows" num="1.07.220.6"/><vers edition="Windows" num="1.07.220.7"/><vers edition="Windows" num="1.07.220.9"/><vers edition="Windows" num="1.11.21"/><vers edition="Windows" num="1.11.22"/><vers edition="Windows" num="1.11.23"/><vers edition="Windows" num="1.11.24"/><vers edition="Windows" num="1.11.25"/><vers edition="Windows" num="1.11.26"/><vers edition="Windows" num="1.11.26.1"/><vers edition="Windows" num="1.11.26.10"/><vers edition="Windows" num="1.11.26.2"/><vers edition="Windows" num="1.11.26.6"/><vers edition="Windows" num="1.11.26.7"/><vers edition="Windows" num="1.11.26.8"/><vers edition="Windows" num="1.11.26.9"/><vers edition="Windows" num="1.11.27.1"/><vers edition="Windows" num="1.11.27.2"/><vers edition="Windows" num="1.11.27.3"/><vers edition="Windows" num="1.11.29.0"/><vers edition="Windows" num="1.11.29.13"/><vers edition="Windows" num="1.11.29.14"/><vers edition="Windows" num="1.11.29.15"/><vers edition="Windows" num="1.11.29.16"/><vers edition="Windows" num="1.11.29.17"/><vers edition="Windows" num="1.11.29.18"/><vers edition="Windows" num="1.11.29.19"/><vers edition="Windows" num="1.11.29.2"/><vers edition="Windows" num="1.11.29.3"/><vers edition="Windows" num="1.11.29.4"/><vers edition="Windows" num="1.11.29.5"/><vers edition="Windows" num="1.11.29.6"/><vers edition="Windows" num="1.11.29.7"/><vers edition="Windows" num="1.11.29.8"/><vers edition="Windows" num="1.11.29.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0530" published="2006-02-02" seq="2006-0530" severity="Medium" type="CVE"><desc><descript source="cve">Computer Associates (CA) Message Queuing (CAM / CAFT) before 1.07 Build 220_16 and 1.11 Build 29_20, as used in multiple CA products, allows remote attackers to cause a denial of service via spoofed CAM control messages.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423785/100/0/threaded">20060202 CAID 33581 - CA Message Queuing Denial of Service Vulnerabilities</ref><ref adv="1" source="" url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33581"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0414">ADV-2006-0414</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18681">18681</ref><ref source="BID" url="http://www.securityfocus.com/bid/16475">16475</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015571">1015571</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24449">ca-cam-spoofed-message-dos(24449)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/404">404</ref></refs><vuln_soft><prod name="CA Messaging" vendor="Computer Associates"><vers edition="AIX" num="1.05"/><vers edition="AIX" num="1.07.210.0"/><vers edition="AIX" num="1.07.220.11"/><vers edition="AIX" num="1.07.220.13"/><vers edition="AIX" num="1.07.220.14"/><vers edition="AIX" num="1.07.220.15"/><vers edition="AIX" num="1.07.220.5"/><vers edition="AIX" num="1.07.220.7"/><vers edition="AIX" num="1.07.220.8"/><vers edition="AIX" num="1.11.19.0"/><vers edition="AIX" num="1.11.27.0"/><vers edition="AIX" num="1.11.27.1"/><vers edition="AIX" num="1.11.29.13"/><vers edition="AIX" num="1.11.29.14"/><vers edition="AIX" num="1.11.29.15"/><vers edition="AIX" num="1.11.29.16"/><vers edition="AIX" num="1.11.29.17"/><vers edition="AIX" num="1.11.29.18"/><vers edition="AIX" num="1.11.29.19"/><vers edition="AIX" num="1.11.29.2"/><vers edition="AIX" num="1.11.29.3"/><vers edition="AIX" num="1.11.29.4"/><vers edition="AIX" num="1.11.29.5"/><vers edition="AIX" num="1.11.29.8"/><vers edition="AIX" num="1.11.29.9"/><vers edition="HP_UX" num="1.05"/><vers edition="HP_UX" num="1.07.220.11"/><vers edition="HP_UX" num="1.07.220.13"/><vers edition="HP_UX" num="1.07.220.14"/><vers edition="HP_UX" num="1.07.220.15"/><vers edition="HP_UX" num="1.07.220.5"/><vers edition="HP_UX" num="1.07.220.7"/><vers edition="HP_UX" num="1.07.220.8"/><vers edition="HP_UX" num="1.11.18.0"/><vers edition="HP_UX" num="1.11.27.0"/><vers edition="HP_UX" num="1.11.27.1"/><vers edition="HP_UX" num="1.11.29.13"/><vers edition="HP_UX" num="1.11.29.14"/><vers edition="HP_UX" num="1.11.29.15"/><vers edition="HP_UX" num="1.11.29.16"/><vers edition="HP_UX" num="1.11.29.17"/><vers edition="HP_UX" num="1.11.29.18"/><vers edition="HP_UX" num="1.11.29.19"/><vers edition="HP_UX" num="1.11.29.2"/><vers edition="HP_UX" num="1.11.29.3"/><vers edition="Solaris" num="1.11.29.4"/><vers edition="HP_UX" num="1.11.29.5"/><vers edition="HP_UX" num="1.11.29.8"/><vers edition="HP_UX" num="1.11.29.9"/><vers edition="Linux" num="1.05"/><vers edition="Linux" num="1.07.220.11"/><vers edition="Linux" num="1.07.220.13"/><vers edition="Linux" num="1.07.220.14"/><vers edition="Linux" num="1.07.220.15"/><vers edition="Linux" num="1.11.28.0"/><vers edition="Linux" num="1.11.29.13"/><vers edition="Linux" num="1.11.29.14"/><vers edition="Linux" num="1.11.29.15"/><vers edition="Linux" num="1.11.29.16"/><vers edition="Linux" num="1.11.29.17"/><vers edition="Linux" num="1.11.29.18"/><vers edition="Linux" num="1.11.29.19"/><vers edition="Linux" num="1.11.29.5"/><vers edition="Linux" num="1.11.29.8"/><vers edition="Linux" num="1.11.29.9"/><vers edition="Solaris" num="1.05"/><vers edition="Solaris" num="1.07.210.0"/><vers edition="Solaris" num="1.07.220.0"/><vers edition="Solaris" num="1.07.220.11"/><vers edition="Solaris" num="1.07.220.13"/><vers edition="Solaris" num="1.07.220.14"/><vers edition="Solaris" num="1.07.220.15"/><vers edition="Solaris" num="1.07.220.5"/><vers edition="Solaris" num="1.07.220.8"/><vers edition="Solaris" num="1.07.220.9"/><vers edition="Solaris" num="1.11.19.0"/><vers edition="Solaris" num="1.11.27.0"/><vers edition="Solaris" num="1.11.27.1"/><vers edition="Solaris" num="1.11.29.13"/><vers edition="Solaris" num="1.11.29.14"/><vers edition="Solaris" num="1.11.29.15"/><vers edition="Solaris" num="1.11.29.16"/><vers edition="Solaris" num="1.11.29.17"/><vers edition="Solaris" num="1.11.29.18"/><vers edition="Solaris" num="1.11.29.19"/><vers edition="Solaris" num="1.11.29.2"/><vers edition="Solaris" num="1.11.29.3"/><vers edition="HP_UX" num="1.11.29.4"/><vers edition="Solaris" num="1.11.29.5"/><vers edition="Solaris" num="1.11.29.8"/><vers edition="Solaris" num="1.11.29.9"/><vers edition="Windows" num="1.05"/><vers edition="Windows" num="1.07.220.0"/><vers edition="Windows" num="1.07.220.10"/><vers edition="Windows" num="1.07.220.11"/><vers edition="Windows" num="1.07.220.13"/><vers edition="Windows" num="1.07.220.14"/><vers edition="Windows" num="1.07.220.15"/><vers edition="Windows" num="1.07.220.3"/><vers edition="Windows" num="1.07.220.4"/><vers edition="Windows" num="1.07.220.5"/><vers edition="Windows" num="1.07.220.6"/><vers edition="Windows" num="1.07.220.7"/><vers edition="Windows" num="1.07.220.9"/><vers edition="Windows" num="1.11.21"/><vers edition="Windows" num="1.11.22"/><vers edition="Windows" num="1.11.23"/><vers edition="Windows" num="1.11.24"/><vers edition="Windows" num="1.11.25"/><vers edition="Windows" num="1.11.26"/><vers edition="Windows" num="1.11.26.1"/><vers edition="Windows" num="1.11.26.10"/><vers edition="Windows" num="1.11.26.2"/><vers edition="Windows" num="1.11.26.6"/><vers edition="Windows" num="1.11.26.7"/><vers edition="Windows" num="1.11.26.8"/><vers edition="Windows" num="1.11.26.9"/><vers edition="Windows" num="1.11.27.1"/><vers edition="Windows" num="1.11.27.2"/><vers edition="Windows" num="1.11.27.3"/><vers edition="Windows" num="1.11.29.0"/><vers edition="Windows" num="1.11.29.13"/><vers edition="Windows" num="1.11.29.14"/><vers edition="Windows" num="1.11.29.15"/><vers edition="Windows" num="1.11.29.16"/><vers edition="Windows" num="1.11.29.17"/><vers edition="Windows" num="1.11.29.18"/><vers edition="Windows" num="1.11.29.19"/><vers edition="Windows" num="1.11.29.2"/><vers edition="Windows" num="1.11.29.3"/><vers edition="Windows" num="1.11.29.4"/><vers edition="Windows" num="1.11.29.5"/><vers edition="Windows" num="1.11.29.6"/><vers edition="Windows" num="1.11.29.7"/><vers edition="Windows" num="1.11.29.8"/><vers edition="Windows" num="1.11.29.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-07" name="CVE-2006-0531" published="2006-02-03" seq="2006-0531" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Sun Java System Access Manager 7.0 allows local users logged in as &quot;root&quot; to bypass authentication and gain top-level administrator privileges via the amadmin CLI tool.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102140-1">102140</ref><ref source="BID" url="http://www.securityfocus.com/bid/16474">16474</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0430">ADV-2006-0430</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18699">18699</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24423">sun-jsam-admin-access(24423)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015567">1015567</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:360">oval:org.mitre.oval:def:360</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:755">oval:org.mitre.oval:def:755</ref></refs><vuln_soft><prod name="Java System Access Manager" vendor="Sun"><vers edition="Solaris x" num="7.0 2005Q4"/><vers edition="Solaris S" num="7.0 2005Q4"/><vers edition="Linux" num="7.0 2005Q4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-24" name="CVE-2006-0532" published="2006-02-03" seq="2006-0532" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in resultat.asp in SoftMaker Shop allows remote attackers to inject arbitrary web script or HTML via a strSok parameter containing a javascript: URI in an IMG SRC attribute.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/423768">20060201 SoftMaker Shop is vulnerable to XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/16471">16471</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18683">18683</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0434">ADV-2006-0434</ref><ref source="OSVDB" url="http://www.osvdb.org/22911">22911</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24451">softmakershop-image-xss(24451)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/400">400</ref></refs><vuln_soft><prod name="Shop" vendor="Media2 CMS"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0533" published="2006-02-03" seq="2006-0533" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in webmailaging.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via the numdays parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18691">18691</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0433">ADV-2006-0433</ref><ref source="OSVDB" url="http://www.osvdb.org/22906">22906</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24468">cpanel-scripts-xss(24468)</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113894933522271&amp;w=2">20060203 Re: cPanel Multiple Cross Site Scripting</ref></refs><vuln_soft><prod name="cPanel" vendor="cPanel"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-07" name="CVE-2006-0534" published="2006-02-03" seq="2006-0534" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in default.asp in CyberShop Ultimate E-commerce allow remote attackers to inject arbitrary web script or HTML via the (1) ortak or (2) kat parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423787/100/0/threaded">20060202 CyberShop Ultimate E-commerce Script Cross Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/16473">16473</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18730">18730</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24454">cybershop-xss(24454)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/401">401</ref></refs><vuln_soft><prod name="ASP Ultimate E-commerce Script" vendor="CyberShop"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0535" published="2006-02-03" seq="2006-0535" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Community Server allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.  NOTE: this candidate does not contain any actionable or distinguishing information.  Perhaps it should not be included in CVE.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16478">16478</ref></refs><vuln_soft><prod name="Community Server" vendor="CommunityServer.org"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0536" published="2006-02-03" seq="2006-0536" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.27 allows remote attackers to inject arbitrary web script or HTML via the sort parameter.  NOTE: some sources say that the affected parameter is &quot;date,&quot; but the demonstration URL shows that it is &quot;sort&quot;.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423901/100/0/threaded">20060203 Neomail Cross Site Scripting Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0449">ADV-2006-0449</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015581">1015581</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24470">neomail-neomail-script-xss(24470)</ref><ref source="OSVDB" url="http://www.osvdb.org/22978">22978</ref></refs><vuln_soft><prod name="NeoMail" vendor="NeoMail"><vers num="1.27"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-01-14" modified="2006-04-28" name="CVE-2006-0537" published="2006-02-03" seq="2006-0537" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the POP3 server in Kinesphere Corporation eXchange before 5.0.060125 allows remote attackers to execute arbitrary code via a long RCPT TO argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.frsirt.com/exploits/20060203.Exchangepop3.pl.php"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0437">ADV-2006-0437</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0041.html">20060203 Exchangepop3 rcpt buffer overflow vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/22907">22907</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015580">1015580</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18687">18687</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24477">exchangepop3-rcptto-bo(24477)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0040.html">20060203 Exchangepop3 rcpt buffer overflow vulnerability</ref><ref source="" url="http://www.milw0rm.com/exploits/1466"></ref><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/exchangepop3.pl"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16485">16485</ref><ref source="SREASON" url="http://securityreason.com/securityalert/408">408</ref></refs><vuln_soft><prod name="eXchange POP3" vendor="Kinesphere Corporation"><vers num="5.0 build 050203"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0538" published="2006-02-03" seq="2006-0538" severity="Low" type="CVE"><desc><descript source="cve">CipherTrust IronMail 5.0.1, when &quot;Denial of Service Protection&quot; is enabled, allows remote attackers to cause a denial of service (possibly CPU consumption) via a SYN flood with malformed TCP packets from multiple connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423898/100/0/threaded">20060203 IronMail-5.0.1-Denial of-Service-Protection-Lets-Remote-Users-Deny-Service</ref><ref source="BID" url="http://www.securityfocus.com/bid/16465">16465</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015555">1015555</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24445">
ironmail-tcpsyn-flood-dos(24445)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/407">407</ref></refs><vuln_soft><prod name="IronMail" vendor="CipherTrust"><vers num="5.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-05" name="CVE-2006-0539" published="2006-02-03" seq="2006-0539" severity="Medium" type="CVE"><desc><descript source="cve">The convert-fcrontab program in fcron 3.0.0 might allow local users to gain privileges via a long command-line argument, which causes Linux glibc to report heap memory corruption, possibly because a strcpy in the strdup2 function can &quot;overwrite some data.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423697/100/0/threaded">20060201 Fcrontab - memory corruption on heap.</ref><ref source="BID" url="http://www.securityfocus.com/bid/16467">16467</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0435">ADV-2006-0435</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18719">18719</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0999.html">
20060201 Fcrontab - memory corruption on heap.</ref><ref source="" url="https://bugs.trustix.org/show_bug.cgi?id=1754"></ref><ref source="" url="http://fcron.free.fr/doc/en/changes.html"></ref><ref source="" url="http://fcron.free.fr/news.php#a20060206a.xml"></ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0036">
2006-0036</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24444">
fcron-syslog-bo(24444)</ref></refs><vuln_soft><prod name="Fcron" vendor="Thibault Godouet"><vers num="3.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-06" name="CVE-2006-0540" published="2006-02-03" seq="2006-0540" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Tachyon Vanilla Guestbook 1.0 beta allow remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.evuln.com/vulns/54/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16464">16464</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24412">vanillaguestbook-messages-sql-injection(24412)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423957/100/0/threaded">20060201 [eVuln] Vanilla Guestbook Multiple XSS &amp; SQL Injection Vulnerabilities</ref></refs><vuln_soft><prod name="Vanilla Guestbook" vendor="Tachyon"><vers num="1.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-06" name="CVE-2006-0541" published="2006-02-03" seq="2006-0541" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Tachyon Vanilla Guestbook 1.0 beta allow remote attackers to inject arbitrary web script or HTML via unknown vectors related to &quot;posting new messages.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.evuln.com/vulns/54/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16464">16464</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423957/100/0/threaded">20060201 [eVuln] Vanilla Guestbook Multiple XSS &amp; SQL Injection Vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426200/100/0/threaded">20060227 Re: [eVuln] Vanilla Guestbook Multiple XSS &amp; SQL Injection Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24411">
vanillaguestbook-name-xss(24411)</ref></refs><vuln_soft><prod name="Vanilla Guestbook" vendor="Tachyon"><vers num="1.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-06" name="CVE-2006-0542" published="2006-02-03" seq="2006-0542" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in config.php in NukedWeb GuestBookHost 2005.04.25 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.evuln.com/vulns/56/summary.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24406">guestbookhost-login-sql-injection(24406)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0465">ADV-2006-0465</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18761">18761</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424714/100/0/threaded">20060209 [eVuln] GuestBookHost Authentication Bypass</ref><ref source="BID" url="http://www.securityfocus.com/bid/16545">16545</ref></refs><vuln_soft><prod name="GuestBookHost" vendor="NukedWeb"><vers num="2005-04-25"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0543" published="2006-02-03" seq="2006-0543" severity="Medium" type="CVE"><desc><descript source="cve">Cerulean Trillian 3.1.0.120 allows remote attackers to cause a denial of service (client crash) via an AIM message containing the Mac encoded Rich Text Format (RTF) escape sequences (1) \&apos;d1, (2) \&apos;d2, (3) \&apos;d3, (4) \&apos;d4, and (5) \&apos;d5.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22877">22877</ref></refs><vuln_soft><prod name="Trillian" vendor="Cerulean Studios"><vers num="3.1.0.120"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0544" published="2006-02-03" seq="2006-0544" severity="High" type="CVE"><desc><descript source="cve">urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to &quot;file://&quot; followed by a large number of &quot;-&quot; (dash of hyphen) characters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.security-protocols.com/advisory/sp-x23-advisory.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16463">16463</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Beta 2" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-20" name="CVE-2006-0545" published="2006-02-03" seq="2006-0545" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Number parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1015549">1015549</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24381">ubbthreads-showflat-sql-injection(24381)</ref><ref source="OSVDB" url="http://www.osvdb.org/22808">22808</ref><ref source="" url="http://www.cyberlords.net/advisories/cl_ubb.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16520">16520</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-03/0494.html">20060325 UBBThreads&lt;=5.5.1+6.0.2+6.0 br5+6.0.1 SQL injection</ref></refs><vuln_soft><prod name="UBB.threads" vendor="UBBCentral"><vers num="6.3"/><vers num="6.2.3"/><vers num="6.2.2"/><vers num="6.2.1"/><vers num="6.2"/><vers num="6.1.1"/><vers num="6.1"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0546" published="2006-02-03" seq="2006-0546" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in index.php in a certain application available from /v1/tr/portfoy.php on www.egeinternet.com allows remote attackers to execute arbitrary code via &quot;evilcode&quot; in the key parameter, possibly a PHP remote file include vulnerability in which the attack vector is a URL in the key parameter.  NOTE: it is not clear whether this vulnerability is associated with an online service or application service provider.  If so, then it should not be included in CVE.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423365/100/0/threaded">20060128 Ege Internet Web Desing Remote Command Exucetion</ref></refs><vuln_soft><prod name="Egeinternet" vendor="Egeinternet"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0547" published="2006-02-03" seq="2006-0547" severity="High" type="CVE"><desc><descript source="cve">Oracle Database 8i, 9i, and 10g allow remote authenticated users to execute arbitrary SQL statements in the context of the SYS user and bypass audit logging, including statements to create new privileged database accounts, via a modified AUTH_ALTER_SESSION attribute in the authentication phase of the Transparent Network Substrate (TNS) protocol.  NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle.  It is possible that this is the same issue as Oracle Vuln# DB18 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0265.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.imperva.com/application_defense_center/papers/oracle-dbms-01172006.html"></ref><ref adv="1" source="" url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf"></ref><ref adv="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html"></ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html">TA06-018A</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/871756">VU#871756</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041464.html">

20060117 Oracle DBMS - Access Control Bypass in Login</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24184">
oracle-login-command-execute(24184)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.6 r2"/><vers num="9.2.0.7 r2"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="Release 2 10.2.0.1"/><vers num="Release 1 10.1.0.3"/><vers num="Release 1 10.1.0.4"/><vers num="Release 1 10.1.0.5"/></prod><prod name="Oracle8i Database Server" vendor="Oracle"><vers num="Release 3 8.1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0548" published="2006-02-03" seq="2006-0548" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the Oracle Text component of Oracle Database 10g, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle.  It is possible that this is the same issue as Oracle Vuln# DB15 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0260.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf"></ref><ref adv="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html"></ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html">TA06-018A</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/150332">VU#150332</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">
oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="Release 1 10.1.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0549" published="2006-02-03" seq="2006-0549" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the SYS.DBMS_METADATA_UTIL package in Oracle Database 10g, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle.  It is possible that this is the same issue as Oracle Vuln# DB05 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0260.  However, there are some inconsistencies that make this unclear, and there is also a possibility that this is related to DB06, which is subsumed by CVE-2006-0259.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf"></ref><ref adv="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_metadata_util.html"></ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html">TA06-018A</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/629316">VU#629316</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">
oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="Release 1 10.1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-07" name="CVE-2006-0550" published="2006-02-03" seq="2006-0550" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in an unspecified Oracle Client utility might allow remote attackers to execute arbitrary code or cause a denial of service.  NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle.  It is possible that this is the same issue as Oracle Vuln# DBC02 from the January 2006 CPU, in which case this would be a duplicate of CVE-2006-0283.  However, there are enough inconsistencies that the mapping can not be made authoritatively.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf"></ref><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref patch="1" source="" url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html"></ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html">TA06-018A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/999268">VU#999268</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">
oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle Client" vendor="Oracle"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-07" name="CVE-2006-0551" published="2006-02-03" seq="2006-0551" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the Data Pump Metadata API in Oracle Database 10g and possibly earlier might allow remote attackers to execute arbitrary SQL commands via unknown vectors.  NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle.  It is possible that this is the same issue as Oracle Vuln# DB06 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0259 or, if it is DB05, subsumed by CVE-2006-0260.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf"></ref><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref patch="1" source="" url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html"></ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html">TA06-018A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/983340">VU#983340</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">
oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle10g Database Server Release 1" vendor="Oracle"><vers num="10.1.0.3"/><vers num="10.1.0.4"/><vers num="10.1.0.5"/></prod><prod name="Oracle10g Database Server Release 2" vendor="Oracle"><vers num="10.2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-05" name="CVE-2006-0552" published="2006-02-04" seq="2006-0552" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="OSVDB" url="http://www.osvdb.org/22549">22549</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">
oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="E-Business Suite 11i" vendor="Oracle"><vers num="11.5.9"/><vers num="11.5.8"/><vers num="11.5.7"/><vers num="11.5.6"/><vers num="11.5.5"/><vers num="11.5.4"/><vers num="11.5.3"/><vers num="11.5.2"/><vers num="11.5.1"/><vers num="11.5.10"/></prod><prod name="PeopleSoft Enterprise Portal" vendor="Oracle"><vers num="8.9"/><vers num="8.8"/><vers num="8.4"/></prod><prod name="Oracle8" vendor="Oracle"><vers num="8.0.6"/><vers num="8.1.7.4"/><vers num="8.0.6.3"/></prod><prod name="Oracle10g Enterprise Manager Grid Control" vendor="Oracle"><vers num="10.1 .0.4"/><vers num="10.1 .0.3"/></prod><prod name="Oracle8i" vendor="Oracle"><vers num="Standard 8.0.6"/><vers num="Standard 8.1.7.4"/><vers num="Standard 8.0.6.3"/><vers num="Enterprise 8.1.7.4"/></prod><prod name="Oracle 9i Collaboration Suite" vendor="Oracle"><vers num="Release 2 9.0.4 .2"/></prod><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="1.0.2.2"/><vers num="1.0.2.2 r1"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.2.0.1"/><vers num="Standard 10.1.0.5"/><vers num="Standard 10.1.0.4.2"/><vers num="Standard 10.1.0.4"/><vers num="Standard 10.1.0.3"/><vers num="Personal 10.1.0.4"/><vers num="Personal 10.1.0.3"/><vers num="Enterprise 10.1.0.4"/><vers num="Enterprise 10.1.0.3"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.2"/><vers num="9.0.4.2"/><vers num="9.0.4.1"/><vers num="10.1.2.1.0"/><vers num="10.1.2.0.2"/><vers num="10.1.2.0.1"/><vers num="Release 2 10.1.2.0.2"/><vers num="Release 2 10.1.2.0.1"/><vers num="Release 2 10.1.2.0.0"/><vers num="9.0.4"/></prod><prod name="JD Edwards EnterpriseOne" vendor="Oracle"><vers num="8.95 _F1"/><vers num="SP23_L1"/></prod><prod name="Developer Suite" vendor="Oracle"><vers num="10.1.2"/><vers num="9.0.4.2"/><vers num="9.0.4.1"/><vers num="9.0.2.1"/></prod><prod name="Workflow" vendor="Oracle"><vers num="11.5.9.5"/><vers num="11.5.1"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.7"/><vers num="Standard 9.2.0.6"/><vers num="Enterprise 9.0.1.5 FIPS"/><vers num="Enterprise 9.0.1.5"/><vers num="Enterprise 9.0.1.4"/></prod><prod name="Oracle10g Collaboration Suite" vendor="Oracle"><vers num="Release 1 10.1.2"/><vers num="Release 1 10.1.1"/><vers num="Release 1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0553" published="2006-02-14" seq="2006-0553" severity="Medium" type="CVE"><desc><descript source="cve">PostgreSQL 8.1.0 through 8.1.2 allows authenticated database users to gain additional privileges via &quot;knowledge of the backend protocol&quot; using a crafted SET ROLE to other database users, a different vulnerability than CVE-2006-0678.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="MLIST" url="http://archives.postgresql.org/pgsql-announce/2006-02/msg00008.php">[pgsql-announce] 20060214 Minor Releases 7.3 thru 8.1 Available to Fix Security Issue</ref><ref source="" url="http://www.postgresql.org/docs/8.1/static/release.html#RELEASE-8-1-3"></ref><ref adv="1" source="OPENPKG" url="http://www.openpkg.org/security/OpenPKG-SA-2006.004-postgresql.html">OpenPKG-SA-2006.004</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0605">ADV-2006-0605</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18890">18890</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425037/100/0/threaded">20060215 PostgreSQL security releases 8.1.3, 8.0.7, 7.4.12, 7.3.14</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/567452">VU#567452</ref><ref source="BID" url="http://www.securityfocus.com/bid/16649">16649</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015636">1015636</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24718">postgresql-setrole-privilege-elevation(24718)</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="8.1.0"/><vers num="8.1.1"/><vers num="8.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="1.7" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="2.9" CVSS_score="1.7" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-0554" published="2006-03-06" seq="2006-0554" severity="Low" type="CVE"><desc><descript source="cve">Linux kernel 2.6 before 2.6.15.5 allows local users to obtain sensitive information via a crafted XFS ftruncate call, which may return stale data.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref patch="1" source="kernel.org (Chris Wright)" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.5">SGI bug 942658</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0804">ADV-2006-0804</ref><ref source="BID" url="http://www.securityfocus.com/bid/16921">16921</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19083">19083</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24999">kernel-ftruncate-information-disclosure(24999)</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-263-1">USN-263-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19220">19220</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:059">MDKSA-2006:059</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:150">MDKSA-2006:150</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:059">MDKSA-2006:059</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:150">MDKSA-2006:150</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers edition="PowerPC_smp" num="2.6.8.1.5"/><vers edition="PowerPC" num="2.6.8.1.5"/><vers edition="Power4_smp" num="2.6.8.1.5"/><vers edition="Power4" num="2.6.8.1.5"/><vers edition="Power3_smp" num="2.6.8.1.5"/><vers edition="Power3" num="2.6.8.1.5"/><vers edition="K7_smp" num="2.6.8.1.5"/><vers edition="K7" num="2.6.8.1.5"/><vers edition="AMD64_Xeon" num="2.6.8.1.5"/><vers edition="AMD64_K8_smp" num="2.6.8.1.5"/><vers edition="AMD64_K8" num="2.6.8.1.5"/><vers edition="AMD64" num="2.6.8.1.5"/><vers edition="686_smp" num="2.6.8.1.5"/><vers edition="686" num="2.6.8.1.5"/><vers edition="386" num="2.6.8.1.5"/><vers num="2.6.8.1.5"/><vers num="2.6.8.1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.15 rc7"/><vers num="2.6.15 rc6"/><vers num="2.6.15 rc5"/><vers num="2.6.15 rc4"/><vers num="2.6.15 rc3"/><vers num="2.6.14 rc2"/><vers num="2.6.15 rc1"/><vers num="2.6.15"/><vers num="2.6.14 rc4"/><vers num="2.6.14 rc3"/><vers num="2.6.14 rc1"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14"/><vers num="2.6.13 rc7"/><vers num="2.6.13 rc6"/><vers num="2.6.13 rc4"/><vers num="2.6.13 rc1"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13"/><vers num="2.6.12 rc5"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc1"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11 rc1"/><vers num="2.6.11.9"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11.10"/><vers num="2.6.11.1"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers num="2.6.1"/><vers num="2.6.0"/><vers edition="Itanium IA64 Montecito" num="2.6"/><vers edition="64-bit x86" num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-0555" published="2006-03-06" seq="2006-0555" severity="Low" type="CVE"><desc><descript source="cve">The Linux Kernel before 2.6.15.5 allows local users to cause a denial of service (NFS client panic) via unknown attack vectors related to the use of O_DIRECT (direct I/O).</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.5"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0804">ADV-2006-0804</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00003.html">FEDORA-2006-131</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19083">19083</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19108">19108</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25000">kernel-odirect-dos(25000)</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-263-1">USN-263-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/16922">16922</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19220">19220</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:059">MDKSA-2006:059</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0493.html">RHSA-2006:0493</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20237">20237</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21745">21745</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:059">MDKSA-2006:059</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.15 rc7"/><vers num="2.6.15 rc6"/><vers num="2.6.15 rc5"/><vers num="2.6.15 rc4"/><vers num="2.6.15 rc3"/><vers num="2.6.14 rc2"/><vers num="2.6.15 rc1"/><vers num="2.6.15"/><vers num="2.6.14 rc4"/><vers num="2.6.14 rc3"/><vers num="2.6.14 rc1"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14"/><vers num="2.6.13 rc7"/><vers num="2.6.13 rc6"/><vers num="2.6.13 rc4"/><vers num="2.6.13 rc1"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13"/><vers num="2.6.12 rc5"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc1"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11 rc1"/><vers num="2.6.11.9"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11.10"/><vers num="2.6.11.1"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers edition="PowerPC_smp" num="2.6.8.1.5"/><vers edition="PowerPC" num="2.6.8.1.5"/><vers edition="Power4_smp" num="2.6.8.1.5"/><vers edition="Power4" num="2.6.8.1.5"/><vers edition="Power3_smp" num="2.6.8.1.5"/><vers edition="Power3" num="2.6.8.1.5"/><vers edition="K7_smp" num="2.6.8.1.5"/><vers edition="K7" num="2.6.8.1.5"/><vers edition="AMD64_Xeon" num="2.6.8.1.5"/><vers edition="AMD64_K8_smp" num="2.6.8.1.5"/><vers edition="AMD64_K8" num="2.6.8.1.5"/><vers edition="AMD64" num="2.6.8.1.5"/><vers edition="686_smp" num="2.6.8.1.5"/><vers edition="686" num="2.6.8.1.5"/><vers edition="386" num="2.6.8.1.5"/><vers num="2.6.8.1.5"/><vers num="2.6.8.1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.0"/><vers edition="Itanium IA64 Montecito" num="2.6"/><vers edition="64-bit x86" num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-0557" published="2006-03-12" seq="2006-0557" severity="Low" type="CVE"><desc><descript source="cve">sys_mbind in mempolicy.c in Linux kernel 2.6.16 and earlier does not sanity check the maxnod variable before making certain computations for the get_nodes function, which has unknown impact and attack vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref patch="1" source="kernel.org" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=636f13c174dd7c84a437d3c3e8fa66f03f7fda63">projects / linux/kernel/git/torvalds/linux-2.6.git / commit </ref><ref patch="1" source="kernel.org" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=636f13c174dd7c84a437d3c3e8fa66f03f7fda63">projects / linux/kernel/git/torvalds/linux-2.6.git / commitdiff </ref><ref patch="1" source="lkml.org" url="http://lkml.org/lkml/2006/2/27/355">[patch 18/39] [PATCH] sys_mbind sanity checking</ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=184510"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16924">16924</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015752">1015752</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:059">MDKSA-2006:059</ref><ref source="OSVDB" url="http://www.osvdb.org/23895">23895</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25204">linux-get-nodes-dos(25204)</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-281-1">USN-281-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19955">19955</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:059">MDKSA-2006:059</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.16 rc1"/><vers num="2.6.15.4"/><vers num="2.6.15.3"/><vers num="2.6.15.2"/><vers num="2.6.15.1"/><vers num="2.6.15 rc7"/><vers num="2.6.15 rc6"/><vers num="2.6.15 rc5"/><vers num="2.6.15 rc4"/><vers num="2.6.15 rc3"/><vers num="2.6.14 rc2"/><vers num="2.6.15 rc1"/><vers num="2.6.15"/><vers num="2.6.14 rc4"/><vers num="2.6.14 rc3"/><vers num="2.6.14 rc1"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14"/><vers num="2.6.13 rc7"/><vers num="2.6.13 rc6"/><vers num="2.6.13 rc4"/><vers num="2.6.13 rc1"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13"/><vers num="2.6.12 rc5"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc1"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11 rc1"/><vers num="2.6.11.9"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11.10"/><vers num="2.6.11.1"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers edition="PowerPC_smp" num="2.6.8.1.5"/><vers edition="PowerPC" num="2.6.8.1.5"/><vers edition="Power4_smp" num="2.6.8.1.5"/><vers edition="Power4" num="2.6.8.1.5"/><vers edition="Power3_smp" num="2.6.8.1.5"/><vers edition="Power3" num="2.6.8.1.5"/><vers edition="K7_smp" num="2.6.8.1.5"/><vers edition="K7" num="2.6.8.1.5"/><vers edition="AMD64_Xeon" num="2.6.8.1.5"/><vers edition="AMD64_K8_smp" num="2.6.8.1.5"/><vers edition="AMD64_K8" num="2.6.8.1.5"/><vers edition="AMD64" num="2.6.8.1.5"/><vers edition="686_smp" num="2.6.8.1.5"/><vers edition="686" num="2.6.8.1.5"/><vers edition="386" num="2.6.8.1.5"/><vers num="2.6.8.1.5"/><vers num="2.6.8.1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers edition="Itanium IA64 Montecito" num="2.6"/><vers edition="64-bit x86" num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-17" name="CVE-2006-0558" published="2006-04-14" seq="2006-0558" severity="Medium" type="CVE"><desc><descript source="cve">perfmon (perfmon.c) in Linux kernel on IA64 architectures allows local users to cause a denial of service (crash) by interrupting a task while another process is accessing the mm_struct, which triggers a BUG_ON action in the put_page_testzero function.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-ia64&amp;m=113882384921688">[linux-ia64] [PATCH 1/1] ia64: perfmon.c trips BUG_ON in put_page_testzero</ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=185082"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17482">17482</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1444">ADV-2006-1444</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19737">19737</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0774.html">RHSA-2007:0774</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26709">26709</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.16.1"/><vers num="2.6.16-rc1"/><vers num="2.6.16"/><vers num="2.6.15.4"/><vers num="2.6.15.3"/><vers num="2.6.15.2"/><vers num="2.6.15.1"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.15"/><vers num="2.6.14.5"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.14"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13-rc7"/><vers num="2.6.13-rc6"/><vers num="2.6.13-rc4"/><vers num="2.6.13-rc1"/><vers num="2.6.13"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12-rc5"/><vers num="2.6.12-rc4"/><vers num="2.6.12-rc1"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11-rc4"/><vers num="2.6.11-rc3"/><vers num="2.6.11-rc2"/><vers num="2.6.11"/><vers num="2.6.10-rc2"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1-rc2"/><vers num="2.6.1-rc1"/><vers num="2.6.1"/><vers num="2.6 test 9 CVS"/><vers num="2.6-test9"/><vers num="2.6-test8"/><vers num="2.6-test7"/><vers num="2.6-test6"/><vers num="2.6-test5"/><vers num="2.6-test4"/><vers num="2.6-test3"/><vers num="2.6-test2"/><vers num="2.6-test11"/><vers num="2.6-test10"/><vers num="2.6-test1"/><vers num="2.6"/><vers num="2.6.15.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-03" modified="2006-04-05" name="CVE-2006-0559" published="2006-04-04" seq="2006-0559" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the SMTP server for McAfee WebShield 4.5 MR2 and earlier allows remote attackers to execute arbitrary code via format strings in the domain name portion of a destination address, which are not properly handled when a bounce message is constructed.</descript></desc><sols><sol source="nvd">The vendor has released a patch (P0803), along with version 4.5 MR2 to address this issue.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429812/100/0/threaded">20060404 SYMSA-2006-002: McAfee WebShield SMTP Format String Vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16742">16742</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1219">ADV-2006-1219</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19491">19491</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015861">1015861</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25621">webshield-smtp-format-string(25621)</ref><ref source="OSVDB" url="http://www.osvdb.org/24366">24366</ref><ref source="SREASON" url="http://securityreason.com/securityalert/671">671</ref></refs><vuln_soft><prod name="WebShield" vendor="McAfee"><vers num="4.5 MR2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-08" modified="2006-05-10" name="CVE-2006-0561" published="2006-05-09" seq="2006-0561" severity="High" type="CVE"><desc><descript source="cve">Cisco Secure Access Control Server (ACS) 3.x for Windows stores ACS administrator passwords and the master key in the registry with insecure permissions, which allows local users and remote administrators to decrypt the passwords by using Microsoft&apos;s cryptographic API functions to obtain the plaintext version of the master key.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Cisco, Secure Access Control Server, 4.0.1</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/433286/100/0/threaded">20060508 SYMSA-2006-003: Cisco Secure ACS for Windows - Administrator Password Disclosure</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/433301/100/0/threaded">20060508 Re: SYMSA-2006-003: Cisco Secure ACS for Windows - Administrator Password Disclosure</ref><ref adv="1" patch="1" source="SYMANTEC" url="http://www.symantec.com/enterprise/research/SYMSA-2006-003.txt">SYMSA-2006-003</ref><ref patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sr-20060508-acs.shtml">20060508 Response to Symantec SYMSA-2006-003 Cisco Secure ACS for Windows - Administrator Password Disclosure</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16743">16743</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1741">ADV-2006-1741</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016042">1016042</ref><ref source="OSVDB" url="http://www.osvdb.org/25892">
25892</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26307">
cisco-acs-admin-password-disclosure(26307)</ref></refs><vuln_soft><prod name="Secure ACS for Windows NT" vendor="Cisco"><vers num="3.3"/><vers num="3.2"/><vers num="3.1.1"/><vers num="3.1"/><vers num="3.0.3"/><vers num="3.0.1"/><vers num="3.0"/></prod><prod name="Secure ACS for Windows Server" vendor="Cisco"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0562" published="2006-02-06" seq="2006-0562" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in problem.php in PluggedOut Blog 1.9.9c allows remote attackers to inject arbitrary web script or HTML via the data parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423948/100/0/threaded">20060204 PluggedOut Blog SQL injection and XSS</ref><ref source="" url="http://hamid.ir/security/pluggedoutblog.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0440">ADV-2006-0440</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18726">18726</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015586">1015586</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24482">pluggedoutblog-problem-xss(24482)</ref><ref source="OSVDB" url="http://www.osvdb.org/22927">22927</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-February/000530.html">[VIM] 20060206 VERIFY Pluggedout Blog 1.9.9c problem.php XSS</ref></refs><vuln_soft><prod name="PluggedOut Blog" vendor="PluggedOut"><vers num="1.9.9c"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0563" published="2006-02-06" seq="2006-0563" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in exec.php in PluggedOut Blog 1.9.9c allows remote attackers to execute arbitrary SQL commands via the entryid parameter in a comment_add action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423948/100/0/threaded">20060204 PluggedOut Blog SQL injection and XSS</ref><ref source="" url="http://hamid.ir/security/pluggedoutblog.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0440">ADV-2006-0440</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18726">18726</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015586">1015586</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24480">pluggedoutblog-exec-sql-injection(24480)</ref><ref source="OSVDB" url="http://www.osvdb.org/22926">22926</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-February/000531.html">[VIM] 20060206 VERIFY Pluggedout Blog 1.9.9c exec.php SQL injection</ref><ref source="SREASON" url="http://securityreason.com/securityalert/415">415</ref></refs><vuln_soft><prod name="PluggedOut Blog" vendor="PluggedOut"><vers num="1.9.9c"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0564" published="2006-02-06" seq="2006-0564" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via a .hhp file with a long Contents file field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://users.pandora.be/bratax/advisories/b008.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0446">ADV-2006-0446</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18740">18740</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015585">1015585</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/124460">VU#124460</ref><ref source="OSVDB" url="http://www.osvdb.org/22941">22941</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24481">
mshtmlhelp-workshop-hhp-bo(24481)</ref></refs><vuln_soft><prod name="HTML Help Workshop" vendor="Microsoft"><vers num="4.74.8702.0"/></prod><prod name="HTML Help" vendor="Microsoft"><vers edition="SDK" num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-0565" published="2006-02-06" seq="2006-0565" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in inc/backend_settings.php in Loudblog 0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the $GLOBALS[path] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423947/100/0/threaded">20060204 LoudBlog &lt;= 0.4 arbitrary remote inclusion</ref><ref source="" url="http://retrogod.altervista.org/loudblog_04_incl_xpl.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0441">ADV-2006-0441</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18722">18722</ref><ref source="OSVDB" url="http://www.osvdb.org/22921">22921</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015583">1015583</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24479">louadblog-backendsettings-file-include(24479)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16495">16495</ref><ref source="SREASON" url="http://securityreason.com/securityalert/410">410</ref><ref source="SREASON" url="http://securityreason.com/securityalert/556">556</ref></refs><vuln_soft><prod name="Loudblog" vendor="Gerrit van Aaken"><vers num="0.4" prev="1"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0566" published="2006-02-06" seq="2006-0566" severity="Medium" type="CVE"><desc><descript source="cve">The LDAP component in CommuniGate Pro Core Server 5.0.7 allows remote attackers to cause a denial of service (application crash) via LDAP messages that contain Distinguished Names (DN) fields with a large number of elements.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423968/100/0/threaded">20060204 ProtoVer LDAP vs CommuniGate Pro 5.0.7</ref><ref source="" url="http://www.gleg.net/advisory_cg2.shtml"></ref><ref source="" url="http://www.stalker.com/CommuniGatePro/History.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0444">ADV-2006-0444</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18701">18701</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015587">1015587</ref><ref source="OSVDB" url="http://www.osvdb.org/22932">22932</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24409">communigate-ldap-bo(24409)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/416">416</ref></refs><vuln_soft><prod name="CommuniGate Pro Core Server" vendor="CommuniGate"><vers num="5.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-07" name="CVE-2006-0567" published="2006-02-07" seq="2006-0567" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Files Xaraya module before 0.5.1, when the Archive Directory field on the Modify Config page is blank, allows remote attackers to access files outside of the web root via &quot;..&quot; (dot dot) sequences.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://xaraya.curtisfarnham.com/articles/Files_0.5.1_-_Security_Fix_and_other_things"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0371">ADV-2006-0371</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24393">files-archive-directory-directory-traversal(24393)</ref></refs><vuln_soft><prod name="Files Xaraya module" vendor="Curtis Farnham"><vers num="0.4.0"/><vers num="0.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0568" published="2006-02-07" seq="2006-0568" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in throw.main in Outblaze allows remote attackers to inject arbitrary web script or HTML via the file parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423915/100/0/threaded">20060203 Outblaze Cross Site Scripting Vulnerability</ref><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0024.html">20060202 Outblaze Cross Site Scripting Vulnerability</ref><ref adv="1" source="" url="http://www.morx.org/outblazeXSS.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0439">ADV-2006-0439</ref><ref source="OSVDB" url="http://www.osvdb.org/22909">22909</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18710">18710</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24476">outblaze-email-thrownmain-xss(24476)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/411">411</ref></refs><vuln_soft><prod name="Outblaze" vendor="Outblaze"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0569" published="2006-02-07" seq="2006-0569" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in user_class.php in Papoo 2.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the username field during the registration of a new account.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0438">ADV-2006-0438</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18721">18721</ref><ref source="OSVDB" url="http://www.osvdb.org/22913">22913</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24500">papoo-username-xss(24500)</ref></refs><vuln_soft><prod name="Papoo" vendor="Papoo"><vers num="2.1.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0570" published="2006-02-07" seq="2006-0570" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in phpstatus 1.0, when gpc_magic_quotes is disabled, allow remote attackers to execute arbitrary SQL commands and bypass authentication via (1) the username parameter in check.php and (2) unknown attack vectors in the administrative interface.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/61/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0450">ADV-2006-0450</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18791">18791</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424842/100/0/threaded">20060212 [eVuln] phpstatus Authentication Bypass</ref><ref source="BID" url="http://www.securityfocus.com/bid/16587">16587</ref><ref source="SREASON" url="http://securityreason.com/securityalert/427">427</ref></refs><vuln_soft><prod name="phpstatus" vendor="Hinton Design"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0571" published="2006-02-07" seq="2006-0571" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpstatus 1.0 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in the administrative interface.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/61/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0450">ADV-2006-0450</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18791">18791</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424842/100/0/threaded">20060212 [eVuln] phpstatus Authentication Bypass</ref><ref source="BID" url="http://www.securityfocus.com/bid/16587">16587</ref><ref source="SREASON" url="http://securityreason.com/securityalert/427">427</ref></refs><vuln_soft><prod name="phpstatus" vendor="Hinton Design"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0572" published="2006-02-07" seq="2006-0572" severity="High" type="CVE"><desc><descript source="cve">phpstatus 1.0 does not require passwords when using cookies to identify a user, which allows remote attackers to bypass authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/61/summary.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424842/100/0/threaded">20060212 [eVuln] phpstatus Authentication Bypass</ref><ref source="BID" url="http://www.securityfocus.com/bid/16587">16587</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18791">18791</ref><ref source="SREASON" url="http://securityreason.com/securityalert/427">427</ref></refs><vuln_soft><prod name="phpstatus" vendor="Hinton Design"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0573" published="2006-02-07" seq="2006-0573" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilies in cPanel 10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to (a) editquota.html or (b) dodelpop.html; (2) showtree parameter to (c) diskusage.html; or the (3) mon, (4) year, (5) target, or (6) domain parameter to (d) stats/detailbw.html.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0025.html">20060202 cPanel Multiple Cross Site Scripting Vulnerability</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113898556313924&amp;w=2">20060203 cPanel Multiple Cross Site Scripting Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0433">ADV-2006-0433</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18695">18695</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24468">cpanel-scripts-xss(24468)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113898556313924&amp;w=2">20060203 cPanel Multiple Cross Site Scripting Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/22936">22936</ref><ref source="OSVDB" url="http://www.osvdb.org/22937">22937</ref><ref source="OSVDB" url="http://www.osvdb.org/22938">22938</ref><ref source="OSVDB" url="http://www.osvdb.org/22939">22939</ref></refs><vuln_soft><prod name="cPanel" vendor="cPanel"><vers num="10"/><vers num="9.1"/><vers num="9.0"/><vers num="8.0"/><vers num="7.0"/><vers num="6.4.2 Stable_48"/><vers num="6.4.2"/><vers num="6.4.1"/><vers num="6.4"/><vers num="6.2"/><vers num="6.0"/><vers num="5.3"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0574" published="2006-02-07" seq="2006-0574" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in mime/handle.html in cPanel 10 allows remote attackers to inject arbitrary web script or HTML via the (1) file extension or (2) mime-type.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0062.html">20060204 cPanel 10 mime/handle.html XSS Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424148/100/0/threaded">20060205 cPanel 10 handle.html XSS Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0433">ADV-2006-0433</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18695">18695</ref><ref source="OSVDB" url="http://www.osvdb.org/22940">22940</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015589">1015589</ref></refs><vuln_soft><prod name="cPanel" vendor="cPanel"><vers num="10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-05" name="CVE-2006-0575" published="2006-02-07" seq="2006-0575" severity="Medium" type="CVE"><desc><descript source="cve">convert-fcrontab in Fcron 2.9.5 and 3.0.0 allows remote attackers to create or overwrite arbitrary files via &quot;..&quot; sequences and a symlink attack on the temporary file that is used during conversion.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113890734603201&amp;w=2">20060202 Re: Fcrontab - memory corruption on heap.</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0435">ADV-2006-0435</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18719">18719</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113890734603201&amp;w=2">20060202 Re: Fcrontab - memory corruption on heap.</ref><ref source="OSVDB" url="http://www.osvdb.org/22905">22905</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24504">fcron-dotdot-directory-traversal(24504)</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0006">2006-0006</ref><ref source="BID" url="http://www.securityfocus.com/bid/25693">25693</ref></refs><vuln_soft><prod name="Fcron" vendor="Thibault Godouet"><vers num="2.9.5"/><vers num="3.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-29" name="CVE-2006-0576" published="2006-02-07" seq="2006-0576" severity="High" type="CVE"><desc><descript source="cve">Untrusted search path vulnerability in opcontrol in OProfile 0.9.1 and earlier allows local users to execute arbitrary commands via a modified PATH that references malicious (1) which or (2) dirname programs.  NOTE: while opcontrol normally is not run setuid, a common configuration suggests accessing opcontrol using sudo.  In such a context, this is a vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424325/100/0/threaded">20060207 Arbitrary code execution via OProfile</ref><ref source="" url="http://www.redhat.com/magazine/012oct05/features/oprofile/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16536">16536</ref></refs><vuln_soft><prod name="OProfile" vendor="OProfile"><vers num="0.9.1"/><vers num="0.8.2"/><vers num="0.8.1"/><vers num="0.7.1"/><vers num="0.6.1"/><vers num="0.5.4"/><vers num="0.5.3"/><vers num="0.5.2"/><vers num="0.5.1"/><vers num="0.9"/><vers num="0.8"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0577" published="2006-02-07" seq="2006-0577" severity="High" type="CVE"><desc><descript source="cve">Lexmark X1185 printer allows local users to gain SYSTEM privileges by navigating to the &quot;Appearance&quot; dialog and selecting the &quot;Additional styles (skins) are available on the Lexmark web site&quot; option, which launches a web browser that is running with SYSTEM privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424322/100/0/threaded">20060207 Re: High Risk Vulnerability in Lexmark Printer Sharing Service</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18728">18728</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0482">ADV-2006-0482</ref><ref source="BID" url="http://www.securityfocus.com/bid/16534">16534</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24596">
lexmark-x1185-privilege-elevation(24596)</ref></refs><vuln_soft><prod name="X1185" vendor="Lexmark"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0578" published="2006-02-07" seq="2006-0578" severity="High" type="CVE"><desc><descript source="cve">Blue Coat Proxy Security Gateway OS (SGOS) 4.1.2.1 does not enforce CONNECT rules when using Deep Content Inspection, which allows remote attackers to bypass connection filters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.secumind.net/content/french/modules/news/article.php?storyid=8"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0401">ADV-2006-0401</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18622">18622</ref><ref source="" url="http://www.bluecoat.com/support/knowledge/advisory_connect_denial_ignore.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015644">1015644</ref><ref source="OSVDB" url="http://www.osvdb.org/22853">22853</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24446">proxysg-connect-bypass-security(24446)</ref></refs><vuln_soft><prod name="Proxy Security Gateway OS" vendor="Blue Coat Systems"><vers num="4.1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0579" published="2006-02-07" seq="2006-0579" severity="High" type="CVE"><desc><descript source="cve">Multiple integer overflows in (1) the new_demux_packet function in demuxer.h and (2) the demux_asf_read_packet function in demux_asf.c in MPlayer 1.0pre7try2 and earlier allow remote attackers to execute arbitrary code via an ASF file with a large packet length value. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0457">ADV-2006-0457</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18718">18718</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24531">mplayer-asf-integer-overflow(24531)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-03.xml">GLSA-200603-03</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19114">19114</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:048">MDKSA-2006:048</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:048">MDKSA-2006:048</ref></refs><vuln_soft><prod name="MPlayer" vendor="MPlayer"><vers num="1.0 pre7try2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0580" published="2006-02-07" seq="2006-0580" severity="Medium" type="CVE"><desc><descript source="cve">IBM Lotus Domino Server 7.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted packet to the LDAP port (389/TCP).</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2006-February/002896.html">[Dailydave] 20060203 ProtoVer vs Lotus Domino Server 7.0</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0458">ADV-2006-0458</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18738">18738</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015592">1015592</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24518">lotus-domino-ldap-dos(24518)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16523">16523</ref></refs><vuln_soft><prod name="Lotus Domino Server" vendor="IBM"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0581" published="2006-02-07" seq="2006-0581" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via the (1) GatewayID parameter in an add action in AddGatewaySettings.asp and (2) IP parameter in IPManager.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0460">ADV-2006-0460</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015584">1015584</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18731">18731</ref><ref source="OSVDB" url="http://www.osvdb.org/22982">22982</ref><ref source="OSVDB" url="http://www.osvdb.org/22983">22983</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24537">hosting-controller-sql-injection(24537)</ref></refs><vuln_soft><prod name="Hosting Controller" vendor="Hosting Controller"><vers num="6.1 Hotfix 2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-29" name="CVE-2006-0582" published="2006-02-07" seq="2006-0582" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in rshd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2, when storing forwarded credentials, allows attackers to overwrite arbitrary files and change file ownership via unknown vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://www.pdc.kth.se/heimdal/advisory/2006-02-06/"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0456">ADV-2006-0456</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18733">18733</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015591">1015591</ref><ref source="MLIST" url="http://www.stacken.kth.se/lists/heimdal-discuss/2006-02/msg00028.html">[heimdal-discuss] 20060206 Heimdal 0.7.2 and 0.6.6</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-977">DSA-977</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-253-1">USN-253-1</ref><ref source="OSVDB" url="http://www.osvdb.org/22986">22986</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18894">18894</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24532">heimdal-rshd-privilege-elevation(24532)</ref><ref patch="1" source="SUSE" url="http://www.securityfocus.com/archive/1/archive/1/426043/100/0/threaded">SUSE-SA:2006:011</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-247-1">USN-247-1</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16524">16524</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18806">18806</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19005">19005</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0628">ADV-2006-0628</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-14.xml">GLSA-200603-14</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19302">19302</ref></refs><vuln_soft><prod name="Heimdal" vendor="KTH"><vers num="0.7.1.3"/><vers num="0.7.1.2"/><vers num="0.7.1.1"/><vers num="0.7.1"/><vers num="0.6.5"/><vers num="0.6.4"/><vers num="0.6.3"/><vers num="0.6.2"/><vers num="0.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-0583" published="2006-02-07" seq="2006-0583" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in mailarticle.php in Clever Copy 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://retrogod.altervista.org/Clever_Copy_V3_sql_xpl.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0462">ADV-2006-0462</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015590">1015590</ref><ref source="OSVDB" url="http://www.osvdb.org/22984">22984</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18749">18749</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24545">clevercopy-mailarticle-sql-injection(24545)</ref></refs><vuln_soft><prod name="Clever Copy" vendor="Clever Copy"><vers num="3.0"/><vers num="2.0"/><vers num="2.0a"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0584" published="2006-02-07" seq="2006-0584" severity="Low" type="CVE"><desc><descript source="cve">The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack that compares output strings.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424086/100/0/threaded">20060204 PeopleSoft (Oracle) PSCipher Encryption Weakness</ref><ref source="OSVDB" url="http://www.osvdb.org/22952">22952</ref><ref source="BID" url="http://www.securityfocus.com/bid/16507">16507</ref></refs><vuln_soft><prod name="PeopleTools" vendor="PeopleSoft"><vers num="8.46.3"/><vers num="8.45.5"/><vers num="8.43"/><vers num="8.42"/><vers num="8.41"/><vers num="8.40"/><vers num="8.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0585" published="2006-02-07" seq="2006-0585" severity="Medium" type="CVE"><desc><descript source="cve">jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, which in turn calls the Javascript document.write function, which triggers a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423675/100/0/threaded">20060131 Internet Explorer remotely exploitable vulnerability in JScript&apos;s document.write() method</ref><ref source="BID" url="http://www.securityfocus.com/bid/16441">16441</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015559">1015559</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425422/30/6890/threaded">20060217 Re: Internet Explorer remotely exploitable vulnerability in JScript&apos;s document.write() method</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0 SP1"/><vers num="6.0"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/><vers num="5.0.1 SP4"/><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers num="5.0.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-0586" published="2006-02-07" seq="2006-0586" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote attackers to execute arbitary SQL commands via multiple parameters in (1) ATTACH_JOB, (2) HAS_PRIVS, and (3) OPEN_JOB functions in the SYS.KUPV$FT package; and (4) UPDATE_JOB, (5) ACTIVE_JOB, (6) ATTACH_POSSIBLE, (7) ATTACH_TO_JOB, (8) CREATE_NEW_JOB, (9) DELETE_JOB, (10) DELETE_MASTER_TABLE, (11) DETACH_JOB, (12) GET_JOB_INFO, (13) GET_JOB_QUEUES, (14) GET_SOLE_JOBNAME, (15) MASTER_TBL_LOCK, and (16) VALID_HANDLE functions in the SYS.KUPV$FT_INT package.  NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that these issues has been addressed by Oracle.  It is unclear which, if any, Oracle Vuln# identifiers apply to these issues.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041499.html">20060118 Oracle Database 10g Rel. 1 - SQL Injection in SYS.KUPV$FT</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041498.html">20060118 Oracle Database 10g Rel. 1 - SQL Injection in SYS.KUPV$FT_INT</ref><ref adv="1" source="" url="http://www.red-database-security.com/advisory/oracle_sql_injection_kupv$ft.html"></ref><ref adv="1" source="" url="http://www.red-database-security.com/advisory/oracle_sql_injection_kupv$ft_int.html"></ref><ref adv="1" source="" url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16294">16294</ref><ref source="OSVDB" url="http://www.osvdb.org/22839">22839</ref><ref source="OSVDB" url="http://www.osvdb.org/22840">22840</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24197">oracle-syskupvftint-sql-injection(24197)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422423/30/7370/threaded">20060117 Oracle Database 10g Rel. 1 - SQL Injection in SYS.KUPV$FT</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422424/30/7370/threaded">20060117 Oracle Database 10g Rel. 1 - SQL Injection in SYS.KUPV$FT_INT</ref></refs><vuln_soft><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.1.0.5"/><vers num="Standard 10.1.0.4.2"/><vers num="Standard 10.1.0.4"/><vers num="Standard 10.1.0.3.1"/><vers num="Standard 10.1.0.3"/><vers num="Standard 10.1.0.2"/><vers num="Personal 10.1.0.4"/><vers num="Personal 10.10.3.1"/><vers num="Personal 10.1.0.3"/><vers num="Personal 10.1.0.2"/><vers num="Enterprise 10.1.0.4"/><vers num="Enterprise 10.1.0.3.1"/><vers num="Enterprise 10.1.0.3"/><vers num="Enterprise 10.1.0.2"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.2.1.0"/><vers num="10.1.2.0.2"/><vers num="10.1.2.0.1"/><vers num="10.1.2"/><vers num="10.1.0.4"/><vers num="10.1.0.3.1"/><vers num="10.1.0.3"/><vers num="10.1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-29" name="CVE-2006-0587" published="2006-02-07" seq="2006-0587" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in util.php in Gallery before 1.5.2-pl2 allows remote authenticated users with trick an owner into modifying stored album data and possibly executing arbitrary code via unspecified vectors involving a crafted link to a crafted file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://gallery.menalto.com/gallery_1_5_2_pl2_security_release"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18735">18735</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0224.html">20060214 Digital Armaments Security Advisory 02.14.2006: Gallery web-based photo gallery remote file execution</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0286.html">20060216 Re: Digital Armaments Security Advisory 02.14.2006: Gallery web-based photo gallery remote file execution</ref><ref source="" url="http://www.digitalarmaments.com/2006140293402395.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/23256">23256</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015641">1015641</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24768">gallery-util-file-include(24768)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16533">16533</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22944">22944</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24538">gallery-album-data-modification(24538)</ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="1.5.2 rc2"/><vers num="1.5.1 rc2"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4.4 pl5"/><vers num="1.4.4 pl4"/><vers num="1.4.4 pl3"/><vers num="1.4.4 pl2"/><vers num="1.4.3 pl2"/><vers num="1.4.3 pl1"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4 pl2"/><vers num="1.4 pl1"/><vers num="1.4"/><vers num="1.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0588" published="2006-02-07" seq="2006-0588" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in search.php in MyTopix 1.2.3 allows remote attackers to execute arbitrary SQL commands via the (1) mid and (2) keywords parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423950/100/0/threaded">20060204 [KAPDA::#26] - MyTopix Sql Injection &amp; Path Disclosure</ref><ref adv="1" source="" url="http://kapda.ir/advisory-249.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24502">
mytopix-search-sql-injection(24502)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/413">413</ref></refs><vuln_soft><prod name="MyTopix" vendor="Jaia Interactive"><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0589" published="2006-02-07" seq="2006-0589" severity="Medium" type="CVE"><desc><descript source="cve">MyTopix 1.2.3 allows remote attackers to obtain the installation path via a direct request to logon.mod.php, which leaks the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423950/100/0/threaded">20060204 [KAPDA::#26] - MyTopix Sql Injection &amp; Path Disclosure</ref><ref adv="1" source="" url="http://kapda.ir/advisory-249.html"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/413">413</ref></refs><vuln_soft><prod name="MyTopix" vendor="Jaia Interactive"><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0590" published="2006-02-07" seq="2006-0590" severity="Medium" type="CVE"><desc><descript source="cve">MyTopix 1.2.3 allows remote attackers to obtain the installation path via an invalid hl parameter to index.php, which leads to path disclosure, possibly related to invalid SQL syntax.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423950/100/0/threaded">20060204 [KAPDA::#26] - MyTopix Sql Injection &amp; Path Disclosure</ref><ref adv="1" source="" url="http://kapda.ir/advisory-249.html"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/413">413</ref></refs><vuln_soft><prod name="MyTopix" vendor="Jaia Interactive"><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-03" name="CVE-2006-0591" published="2006-02-07" seq="2006-0591" severity="Low" type="CVE"><desc><descript source="cve">The crypt_gensalt functions for BSDI-style extended DES-based and FreeBSD-sytle MD5-based password hashes in crypt_blowfish 0.4.7 and earlier do not evenly and randomly distribute salts, which makes it easier for attackers to guess passwords from a stolen password file due to the increased number of collisions.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424260/100/0/threaded">20060207 crypt_blowfish 1.0</ref><ref source="" url="http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/glibc/crypt_blowfish/crypt_gensalt.c?only_with_tag=CRYPT_BLOWFISH_1_0"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18772">18772</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0477">ADV-2006-0477</ref><ref source="OSVDB" url="http://www.osvdb.org/23005">23005</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24590">cryptblowfish-salt-information-disclosure(24590)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0526.html">RHSA-2006:0526</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20232">20232</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc">20060602-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20782">20782</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-113.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/20653">
20653</ref></refs><vuln_soft><prod name="crypt_blowfish" vendor="Solar Designer"><vers num="0.4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-29" name="CVE-2006-0592" published="2006-02-07" seq="2006-0592" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Lexmark Printer Sharing LexBce Server Service (LexPPS), possibly 8.29 and 9.41, allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: This information is based on a vague initial disclosure; details will be updated after the grace period has ended.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424273/100/0/threaded">20060207 High Risk Vulnerability in Lexmark Printer Sharing Service</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18744">18744</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0481">ADV-2006-0481</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015593">1015593</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24581">
lexmark-lexpps-code-execution(24581)</ref></refs><vuln_soft><prod name="Printer Sharing" vendor="Lexmark"><vers num="8.29"/><vers num="9.41"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-08" name="CVE-2006-0593" published="2006-02-07" seq="2006-0593" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in PHP-Fusion before 6.00.304 allows remote attackers to inject arbitrary web script or HTML via the (1) shout_name field in shoutbox_panel.php and the (2) comments field in comments_include.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php-fusion.co.uk/news.php?readmore=307"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0463">ADV-2006-0463</ref><ref source="" url="http://www.php-fusion.co.uk/downloads.php?cat_id=3"></ref><ref source="OSVDB" url="http://www.osvdb.org/22980">22980</ref><ref source="OSVDB" url="http://www.osvdb.org/22981">22981</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18949">18949</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24548">phpfusion-multiple-xss(24548)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16548">16548</ref></refs><vuln_soft><prod name="PHP_Fusion" vendor="PHP_Fusion"><vers num="6.00.303"/><vers num="6.00.300"/><vers num="6.00.207"/><vers num="6.00.206"/><vers num="6.00.205"/><vers num="6.00.204"/><vers num="6.00.200"/><vers num="6.00.110"/><vers num="6.00.100"/><vers num="6.00.101"/><vers num="6.00.102"/><vers num="6.00.103"/><vers num="6.00.104"/><vers num="6.00.105"/><vers num="6.00.106"/><vers num="6.00.107"/><vers num="6.00.108"/><vers num="6.00.109"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-14" name="CVE-2006-0597" published="2006-02-13" seq="2006-0597" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in elogd.c in elog before 2.5.7 r1558-4 allow attackers to cause a denial of service (application crash) and possibly execute code via long &quot;revision attributes&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi/0001-r1333-Fixed-crashes-with-very-long-revisions-attributes.txt?bug=349528;msg=15;att=1"></ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-967">DSA-967</ref><ref source="BID" url="http://www.securityfocus.com/bid/16579">16579</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18783">18783</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24704">
elog-elogd-bo(24704)</ref></refs><vuln_soft><prod name="Elog Web Logbook" vendor="Stefan Ritt"><vers num="2.5.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.1"/><vers num="2.2.0"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-14" name="CVE-2006-0598" published="2006-02-13" seq="2006-0598" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in elogd.c in elog before 2.5.7 r1558-4 allows attackers to execute code via unspecified variables, when writing to the log file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi/0002-r1335-Applied-patch-from-Emiliano-to-fix-possible-buffer-overflow.txt?bug=349528;msg=15;att=2"></ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-967">DSA-967</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16579">16579</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18783">18783</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24705">
elog-elogd-log-bo(24705)</ref></refs><vuln_soft><prod name="Elog Web Logbook" vendor="Stefan Ritt"><vers num="2.5.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.1"/><vers num="2.2.0"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-14" name="CVE-2006-0599" published="2006-02-13" seq="2006-0599" severity="Medium" type="CVE"><desc><descript source="cve">The (1) elog.c and (2) elogd.c components in elog before 2.5.7 r1558-4 generate different responses depending on whether or not a username is valid, which allows remote attackers to determine valid usernames.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi/0003-r1472-Do-not-distinguish-between-invalid-user-name-and-invalid-password.txt?bug=349528;msg=15;att=3"></ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-967">DSA-967</ref><ref source="BID" url="http://www.securityfocus.com/bid/16579">16579</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18783">18783</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24706">
elog-elog-elogd-user-enumeration(24706)</ref></refs><vuln_soft><prod name="Elog Web Logbook" vendor="Stefan Ritt"><vers num="2.5.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.1"/><vers num="2.2.0"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-14" name="CVE-2006-0600" published="2006-02-13" seq="2006-0600" severity="Medium" type="CVE"><desc><descript source="cve">elog before 2.5.7 r1558-4 allows remote attackers to cause a denial of service (infinite redirection) via a request with the fail parameter set to 1, which redirects to the same request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=349528"></ref><ref source="" url="http://savannah.psi.ch/viewcvs/trunk/src/elogd.c?root=elog&amp;rev=1487&amp;view=diff&amp;r1=1487&amp;r2=1486&amp;p1=trunk/src/elogd.c&amp;p2=/trunk/src/elogd.c"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-967">DSA-967</ref><ref source="BID" url="http://www.securityfocus.com/bid/16579">16579</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18783">18783</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24707">
elog-fail-redirect-dos(24707)</ref></refs><vuln_soft><prod name="Elog Web Logbook" vendor="Stefan Ritt"><vers num="2.5.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.1"/><vers num="2.2.0"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-21" name="CVE-2006-0602" published="2006-02-08" seq="2006-0602" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Hinton Design phphg Guestbook 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to check.php or the id parameter to (2) admin/edit_smilie.php, (3) admin/add_theme.php, (4) admin/ban_ip.php, (5) admin/add_lang.php, or (6) admin/edit_filter.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/58/summary.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18758">18758</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424740/100/0/threaded">20060211 [eVuln] phphg Guestbook Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16541">16541</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0480">ADV-2006-0480</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015620">1015620</ref></refs><vuln_soft><prod name="phphg Guestbook" vendor="Hinton Design"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-21" name="CVE-2006-0603" published="2006-02-08" seq="2006-0603" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting vulnerabilities in signed.php in Hinton Design phphg Guestbook 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) location, (2) website, or (3) message parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/58/summary.html"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18758">18758</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424740/100/0/threaded">20060211 [eVuln] phphg Guestbook Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16541">16541</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0480">ADV-2006-0480</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015620">1015620</ref></refs><vuln_soft><prod name="phphg Guestbook" vendor="Hinton Design"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-21" name="CVE-2006-0604" published="2006-02-08" seq="2006-0604" severity="High" type="CVE"><desc><descript source="cve">check.php in Hinton Design phphg Guestbook 1.2 does not check the user password when authenticating via cookies, which allows remote attackers to gain unauthorized access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/58/description.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18758">18758</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424740/100/0/threaded">20060211 [eVuln] phphg Guestbook Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16541">16541</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0480">ADV-2006-0480</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015620">1015620</ref></refs><vuln_soft><prod name="phphg Guestbook" vendor="Hinton Design"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-10" name="CVE-2006-0605" published="2006-02-08" seq="2006-0605" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Unknown Domain Shoutbox 2005.07.21 allow remote attackers to inject arbitrary web script or HTML, possibly via the (1) Handle or (2) Message fields.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/55/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0476">ADV-2006-0476</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18759">18759</ref><ref source="BID" url="http://www.securityfocus.com/bid/16543">16543</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424679/100/0/threaded">20060209 [eVuln] Unknown Domain Shoutbox multiple XSS &amp; SQL Injection Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24440">
shoutbox-multiple-xss(24440)</ref></refs><vuln_soft><prod name="Shoutbox" vendor="Unknown Domain"><vers num="2005-07-21"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-12" name="CVE-2006-0606" published="2006-02-08" seq="2006-0606" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Unknown Domain Shoutbox 2005.07.21 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/55/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0476">ADV-2006-0476</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18759">18759</ref><ref source="BID" url="http://www.securityfocus.com/bid/16543">16543</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424679/100/0/threaded">20060209 [eVuln] Unknown Domain Shoutbox multiple XSS &amp; SQL Injection Vulnerabilities</ref></refs><vuln_soft><prod name="Shoutbox" vendor="Unknown Domain"><vers num="2005-07-21"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-12" name="CVE-2006-0607" published="2006-02-08" seq="2006-0607" severity="High" type="CVE"><desc><descript source="cve">check.php in Hinton Design phphd 1.0 does not check passwords when certain cookies are provided, which allows remote attackers to bypass authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/60/summary.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24510">phphd-check-security-bypass(24510)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18793">18793</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424827/100/0/threaded">20060212 [eVuln] phphd Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16586">16586</ref><ref source="OSVDB" url="http://www.osvdb.org/23026">23026</ref></refs><vuln_soft><prod name="phphd" vendor="Hinton Design"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-12" name="CVE-2006-0608" published="2006-02-08" seq="2006-0608" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Hinton Design phphd 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to check.php or (2) unknown attack vectors to scripts that display information from the database.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/60/summary.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24508">phphd-check-sql-injection(24508)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24515">phphd-multiple-sql-injection(24515)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18793">18793</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424827/100/0/threaded">20060212 [eVuln] phphd Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16586">16586</ref><ref source="OSVDB" url="http://www.osvdb.org/23025">23025</ref><ref source="OSVDB" url="http://www.osvdb.org/23028">23028</ref></refs><vuln_soft><prod name="phphd" vendor="Hinton Design"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-12" name="CVE-2006-0609" published="2006-02-08" seq="2006-0609" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in add.php in Hinton Design phphd 1.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/60/summary.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24513">phphd-add-xss(24513)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18793">18793</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424827/100/0/threaded">20060212 [eVuln] phphd Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16586">16586</ref><ref source="OSVDB" url="http://www.osvdb.org/23027">23027</ref></refs><vuln_soft><prod name="phphd" vendor="Hinton Design"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-10" name="CVE-2006-0610" published="2006-02-08" seq="2006-0610" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in 2200net Calendar system 1.2, with gpc_magic_quotes disabled, allow remote attackers to execute arbitrary SQL commands and bypass authentication via (1) the fm_data[id] parameter to calendar.php and (2) the $ad[&apos;acc&apos;] variable in adminlogin.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/62/summary.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24484">2200net-adminlogin-sql-injection(24484)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24483">2200net-calendar-sql-injection(24483)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425094/100/0/threaded">20060215 [eVuln] 2200net Calendar system SQL Injection and Authentication Bypass Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16569">16569</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0486">ADV-2006-0486</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18781">18781</ref><ref source="OSVDB" url="http://www.osvdb.org/23037">23037</ref><ref source="OSVDB" url="http://www.osvdb.org/23038">23038</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=114003781801861&amp;w=2">20060215 [eVuln] 2200net Calendar system SQL Injection and Authentication</ref></refs><vuln_soft><prod name="2200net Calendar" vendor="2200net"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-10" name="CVE-2006-0611" published="2006-02-08" seq="2006-0611" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in compose.pl in @Mail 4.3 and earlier for Windows allows remote attackers to upload arbitrary files to arbitrary locations via a .. (dot dot) in the unique parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://kb.atmail.com/view_article.php?num=374"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16470">16470</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0415">ADV-2006-0415</ref><ref source="OSVDB" url="http://www.osvdb.org/22882">22882</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18646">18646</ref></refs><vuln_soft><prod name="AtMail" vendor="AtMail"><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-10" name="CVE-2006-0612" published="2006-02-08" seq="2006-0612" severity="Medium" type="CVE"><desc><descript source="cve">Powersave daemon before 0.10.15.2 allows local users to gain privileges (unauthorized access to an X session) via unspecified vectors. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=379792&amp;group_id=124576"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0416">ADV-2006-0416</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18651">18651</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24458">powersave-daemon-gain-privileges(24458)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16469">16469</ref></refs><vuln_soft><prod name="Powersave" vendor="Powersave"><vers num="0.10.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0613" published="2006-02-08" seq="2006-0613" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Java Web Start after 1.0.1_02, as used in J2SE 5.0 Update 5 and earlier, allows remote attackers to obtain privileges via unspecified vectors involving untrusted applications.</descript></desc><loss_types><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102170-1">102170</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0468">ADV-2006-0468</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18762">18762</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/652636">VU#652636</ref><ref source="BID" url="http://www.securityfocus.com/bid/16540">16540</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015597">1015597</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24568">javawebstart-jnlp-privilege-elevation(24568)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=303658"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1398">ADV-2006-1398</ref></refs><vuln_soft><prod name="J2SE" vendor="Sun"><vers num="5.0 Update5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-09" name="CVE-2006-0614" published="2006-02-08" seq="2006-0614" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 3 and earlier, SDK and JRE 1.3.x through 1.3.1_16 and 1.4.x through 1.4.2_08 allows remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the &quot;first issue.&quot;</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102171-1">102171</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0467">ADV-2006-0467</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18760">18760</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200602-07.xml">GLSA-200602-07</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/759996">VU#759996</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015596">1015596</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18884">18884</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24561">sun-jre-reflection-privilege-elevation(24561)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0828">ADV-2006-0828</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=303658"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1398">ADV-2006-1398</ref></refs><vuln_soft><prod name="JRE" vendor="Sun"><vers num="5.0 Update 3" prev="1"/><vers num="1.4.2_08" prev="1"/><vers num="1.3.1_16" prev="1"/></prod><prod name="JDK" vendor="Sun"><vers num="5.0 Update3" prev="1"/></prod><prod name="SDK" vendor="Sun"><vers num="1.4.2_08" prev="1"/><vers num="1.3.1_16" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0615" published="2006-02-08" seq="2006-0615" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 4 and earlier, SDK and JRE 1.4.x through 1.4.2_09 allow remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the &quot;second and third issues.&quot;</descript></desc><loss_types><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102171-1">102171</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0467">ADV-2006-0467</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18760">18760</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200602-07.xml">GLSA-200602-07</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/759996">VU#759996</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015596">1015596</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18884">18884</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24561">sun-jre-reflection-privilege-elevation(24561)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0828">ADV-2006-0828</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=303658"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1398">ADV-2006-1398</ref></refs><vuln_soft><prod name="JRE" vendor="Sun"><vers num="5.0 Update 4" prev="1"/><vers num="1.4.2_09" prev="1"/></prod><prod name="JDK" vendor="Sun"><vers num="5.0 Update4" prev="1"/></prod><prod name="SDK" vendor="Sun"><vers num="1.4.2_09" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0616" published="2006-02-08" seq="2006-0616" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 4 and earlier allows remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the &quot;fourth issue.&quot;</descript></desc><loss_types><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102171-1">102171</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0467">ADV-2006-0467</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18760">18760</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200602-07.xml">GLSA-200602-07</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/759996">VU#759996</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015596">1015596</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18884">18884</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24561">sun-jre-reflection-privilege-elevation(24561)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0828">ADV-2006-0828</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=303658"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1398">ADV-2006-1398</ref></refs><vuln_soft><prod name="JRE" vendor="Sun"><vers num="5.0 Update 4" prev="1"/></prod><prod name="JDK" vendor="Sun"><vers num="5.0 Update4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0617" published="2006-02-08" seq="2006-0617" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 5 and earlier allow remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the &quot;fifth, sixth, and seventh issues.&quot;</descript></desc><loss_types><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102171-1">102171</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0467">ADV-2006-0467</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18760">18760</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200602-07.xml">GLSA-200602-07</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/759996">VU#759996</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015596">1015596</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18884">18884</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24561">sun-jre-reflection-privilege-elevation(24561)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0828">ADV-2006-0828</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=303658"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1398">ADV-2006-1398</ref></refs><vuln_soft><prod name="JRE" vendor="Sun"><vers num="5.0 Update 5" prev="1"/></prod><prod name="JDK" vendor="Sun"><vers num="5.0 Update5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-09" name="CVE-2006-0618" published="2006-02-08" seq="2006-0618" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in fontsleuth in QNX Neutrino RTOS 6.3.0 allows local users to execute arbitrary code via format string specifiers in the zeroth argument (program name).</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=380">20060207 QNX Neutrino RTOS fontsleuth Command Format String Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0474">ADV-2006-0474</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18750">18750</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015599">1015599</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24559">qnx-fontsleuth-format-string(24559)</ref><ref source="OSVDB" url="http://www.osvdb.org/22966">22966</ref><ref source="BID" url="http://www.securityfocus.com/bid/16539">16539</ref></refs><vuln_soft><prod name="Neutrino RTOS" vendor="QNX"><vers num="6.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-21" name="CVE-2006-0619" published="2006-02-08" seq="2006-0619" severity="Medium" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in QNX Neutrino RTOS 6.3.0 allow local users to execute arbitrary code via long (1) ABLPATH or (2) ABLANG environment variables in the libAP library (libAp.so.2) or (3) a long PHOTON_PATH environment variable to the setitem function in the libph library.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=381">20060207 QNX Neutrino RTOS libAp ABLPATH Buffer Overflow Vulnerability</ref><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=382">20060207 QNX Neutrino RTOS libph PHOTON_PATH Buffer Overflow Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0474">ADV-2006-0474</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18750">18750</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015599">1015599</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24558">qnx-libap-bo(24558)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24557">qnx-libph-bo(24557)</ref><ref source="OSVDB" url="http://www.osvdb.org/22964">22964</ref><ref source="OSVDB" url="http://www.osvdb.org/22965">22965</ref><ref source="BID" url="http://www.securityfocus.com/bid/16539">16539</ref></refs><vuln_soft><prod name="RTOS" vendor="QNX"><vers num="6.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-10" name="CVE-2006-0620" published="2006-02-08" seq="2006-0620" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in phfont in QNX Neutrino RTOS 6.2.1 allows local users to execute arbitrary code via unspecified manipulations of the PHFONT and PHOTON2_PATH environment variables.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref source="IDEFENSE" url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=383">20060207 QNX Neutrino RTOS phfont Race Condition Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0474">ADV-2006-0474</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18750">18750</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015599">1015599</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24555">qnx-phfont-race-condition(24555)</ref><ref source="OSVDB" url="http://www.osvdb.org/22963">22963</ref><ref source="BID" url="http://www.securityfocus.com/bid/16539">16539</ref></refs><vuln_soft><prod name="RTOS" vendor="QNX"><vers num="6.2.1A"/><vers num="6.2.1B"/><vers num="6.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-10" name="CVE-2006-0621" published="2006-02-08" seq="2006-0621" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in QNX Neutrino RTOS 6.2.0 allow local users to execute arbitrary code via a long first argument to the (1) su or (2) passwd commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="IDEFENSE" url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=388">20060207 QNX Neutrino RTOS passwd Command Buffer Overflow</ref><ref source="IDEFENSE" url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=385">20060207 QNX Neutrino RTOS su Command Buffer Overflow</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0474">ADV-2006-0474</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18750">18750</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015599">1015599</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24551">qnx-passwd-bo(24551)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24554">qnx-su-bo(24554)</ref><ref source="OSVDB" url="http://www.osvdb.org/22961">22961</ref><ref source="OSVDB" url="http://www.osvdb.org/22959">22959</ref><ref source="BID" url="http://www.securityfocus.com/bid/16539">16539</ref></refs><vuln_soft><prod name="RTOS" vendor="QNX"><vers num="6.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-21" name="CVE-2006-0622" published="2006-02-08" seq="2006-0622" severity="Medium" type="CVE"><desc><descript source="cve">QNX Neutrino RTOS 6.3.0 allows local users to cause a denial of service (hang) by supplying a &quot;break *0xb032d59f&quot; command to gdb.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=386">20060207 QNX RTOS 6.3.0 Local Denial of Service Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0474">ADV-2006-0474</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18750">18750</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015598">1015598</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24553">qnx-gdb-dos(24553)</ref><ref source="OSVDB" url="http://www.osvdb.org/22960">22960</ref><ref source="BID" url="http://www.securityfocus.com/bid/16539">16539</ref></refs><vuln_soft><prod name="RTOS" vendor="QNX"><vers num="6.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-10" name="CVE-2006-0623" published="2006-02-08" seq="2006-0623" severity="High" type="CVE"><desc><descript source="cve">QNX Neutrino RTOS 6.3.0 ships /etc/rc.d/rc.local with world-writable permissions, which allows local users to modify the file and execute arbitrary code at system startup.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=387">20060207 QNX RTOS 6.3.0 rc.local Insecure File Permissions Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0474">ADV-2006-0474</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18750">18750</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015598">1015598</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24552">qnx-rclocal-root-privileges(24552)</ref><ref source="OSVDB" url="http://www.osvdb.org/22958">22958</ref><ref source="BID" url="http://www.securityfocus.com/bid/16539">16539</ref></refs><vuln_soft><prod name="RTOS" vendor="QNX"><vers num="6.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-10" name="CVE-2006-0624" published="2006-02-08" seq="2006-0624" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in check.asp in Whomp Real Estate Manager XP 2005 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424389/100/0/threaded">20060208 Whomp Real Estate Manager XP 2005 Sql Injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/16544">16544</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0489">ADV-2006-0489</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18780">18780</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24592">whomp-login-sql-injection(24592)</ref><ref source="OSVDB" url="http://www.osvdb.org/22969">22969</ref><ref source="SREASON" url="http://securityreason.com/securityalert/418">418</ref></refs><vuln_soft><prod name="Whomp! Real Estate Manager XP 2005" vendor="Webeveyn"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-09" name="CVE-2006-0625" published="2006-02-09" seq="2006-0625" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Spip_RSS.PHP in SPIP 1.8.2g and earlier allows remote attackers to read or include arbitrary files via &quot;..&quot;  sequences in the GLOBALS[type_urls] parameter, which could then be used to execute arbitrary code via resultant direct static code injection in the file parameter to spip_acces_doc.php3.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://retrogod.altervista.org/spip_182g_shell_inj_xpl.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16556">16556</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0483">ADV-2006-0483</ref><ref source="OSVDB" url="http://www.osvdb.org/23087">23087</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015602">1015602</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24600">spip-rss-file-include(24600)</ref><ref source="OSVDB" url="http://www.osvdb.org/23086">23086</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18676">18676</ref></refs><vuln_soft><prod name="SPIP" vendor="SPIP"><vers num="1.8.2g"/><vers num="1.8.2e"/><vers num="1.8.2d"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-10" name="CVE-2006-0626" published="2006-02-09" seq="2006-0626" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier allows remote attackers to execute arbitrary SQL commands via the file parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://retrogod.altervista.org/spip_182g_shell_inj_xpl.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16551">16551</ref><ref source="OSVDB" url="http://www.osvdb.org/23087">23087</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0483">ADV-2006-0483</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015602">1015602</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18676">18676</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24599">spip-access-doc-sql-injection(24599)</ref></refs><vuln_soft><prod name="SPIP" vendor="SPIP"><vers num="1.8.2g"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-0627" published="2006-02-09" seq="2006-0627" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Clever Copy 2.0, 2.0a, and 3.0 allows remote attackers to inject arbitrary web script or HTML via the (1) Referer or (2) X-Forwarded-For headers in an HTTP request, which are not properly handled when the administrator accesses Site Stats.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/64/summary.html"></ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24524">clevercopy-script-xss(24524)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0495">ADV-2006-0495</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18790">18790</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424831/100/0/threaded">20060212 [eVuln] Clever Copy %27Referer%27 &amp; %27X-Forwarded-For%27 XSS Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16607">16607</ref></refs><vuln_soft><prod name="Clever Copy" vendor="Clever Copy"><vers num="2.0"/><vers num="2.0a"/><vers num="23.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-10" name="CVE-2006-0628" published="2006-02-10" seq="2006-0628" severity="High" type="CVE"><desc><descript source="cve">myquiz.pl in Dale Ray MyQuiz 1.01 allows remote attackers to execute arbitrary commands via shell metacharacters in the URL, which are not properly handled as part of the PATH_INFO environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423921/100/0/threaded">20060203 [eVuln] MyQuiz Arbitrary Command Execution Vulnerability</ref><ref adv="1" patch="1" source="" url="http://www.evuln.com/vulns/57/summary.html"></ref><ref patch="1" source="" url="http://www.corantodemo.net/coranto/viewnews.cgi?id=EpApAAAVkyirPGThSf&amp;style=dldetails"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424266/100/0/threaded">20060207 MyQuiz Arbitrary Command Execution Exploit (perl)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0443">ADV-2006-0443</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18737">18737</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-February/000537.html">[VIM] 20060209 Vendor ACK for MyQuiz</ref><ref source="OSVDB" url="http://www.osvdb.org/22925">22925</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24501">
myquiz-pathinfo-command-execution(24501)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/409">409</ref></refs><vuln_soft><prod name="MyQuiz" vendor="Dale Ray"><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0629" published="2006-02-10" seq="2006-0629" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in AOL Instant Messenger (AIM) 5.9.3861 allows user-assisted remote attackers to cause a denial of service (client crash) and possibly execute arbitrary code by tricking the user into requesting Buddy Info about a long screen name, which might cause a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423906/100/0/threaded">20060203 AOL Instant Messenger Version 5.9.3861 Local Buffer Overrun Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423920/100/0/threaded">20060203 Re: AOL Instant Messenger Version 5.9.3861 Local Buffer Overrun Vulnerability</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0948.html">20060129 AOL Instant Messenger 5.9.3861 Local Buffer Overrun Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24362">aim-buddy-info-bo(24362)</ref></refs><vuln_soft><prod name="Instant Messenger" vendor="AOL"><vers num="5.9.3861"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-10" name="CVE-2006-0630" published="2006-02-10" seq="2006-0630" severity="Medium" type="CVE"><desc><descript source="cve">RITLabs The Bat! before 3.0.0.15 displays certain important headers from encapsulated data in message/partial MIME messages, instead of the real headers, which is in violation of RFC2046 header merging rules and allows remote attackers to spoof the origin of e-mail by sending a fragmented message, as demonstrated using spoofed Received: and Message-ID: headers.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424129/100/0/threaded">20060206 SECURITY.NNOV: The Bat! 2.x message headers spoofing</ref><ref adv="1" source="" url="http://www.security.nnov.ru/advisories/thebatspoof.asp"></ref><ref source="" url="https://www.ritlabs.com/bt/bug_view_advanced_page.php?bug_id=0003029"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/18713">18713</ref><ref source="BID" url="http://www.securityfocus.com/bid/16515">16515</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041973.html">
20060206 SECURITY.NNOV: The Bat! 2.x message headers spoofing</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24535">
thebat-message-header-spoofing(24535)</ref></refs><vuln_soft><prod name="The Bat" vendor="RITLabs"><vers num="3.0.0.14"/><vers num="3.0.0.12"/><vers num="3.0.0.11"/><vers num="3.0.0.10"/><vers num="3.0.0.9"/><vers num="3.0.0.8"/><vers num="3.0.0.7"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0631" published="2006-02-10" seq="2006-0631" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in mailback.pl in Erik C. Thauvin mailback allows remote attackers to use mailback as a &quot;spam proxy&quot; by modifying mail headers, including recipient e-mail addresses, via newline characters in the Subject field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2006/Feb/0094.html">20060205 mailback script exploit</ref><ref source="" url="http://vc.thauvin.net/cvs/cgi/mailback/mailback.pl?view=log"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0459">ADV-2006-0459</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22955">22955</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18748">18748</ref><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2006/Feb/0154.html">20060210 Re: mailback script exploit</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24540">mailback-mail-relay(24540)</ref></refs><vuln_soft><prod name="mailback" vendor="Erik C. Thauvin"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-10" name="CVE-2006-0632" published="2006-02-10" seq="2006-0632" severity="Medium" type="CVE"><desc><descript source="cve">The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key (&quot;validation ID&quot;) that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain the key and modify passwords for existing accounts or create new accounts.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424074/100/0/threaded">20060205 Easily exploitable Pseudo Random Number generator in phpbb version 2.0.19 and under.</ref><ref source="" url="http://www.r-security.net/tutorials/view/readtutorial.php?id=4"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0461">ADV-2006-0461</ref><ref source="OSVDB" url="http://www.osvdb.org/22949">22949</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18727">18727</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24573">phpbb-weak-rnd(24573)</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.19"/><vers num="2.0.18"/><vers num="2.0.17"/><vers num="2.0.16"/><vers num="2.0.15"/><vers num="2.0.14"/><vers num="2.0.13"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.9"/><vers num="2.0.8a"/><vers num="2.0.8"/><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.6d"/><vers num="2.0.6c"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-10" name="CVE-2006-0633" published="2006-02-10" seq="2006-0633" severity="Medium" type="CVE"><desc><descript source="cve">The make_password function in ipsclass.php in Invision Power Board (IPB) 2.1.4 uses random data generated from partially predictable seeds to create the authentication code that is sent by e-mail to a user with a lost password, which might make it easier for remote attackers to guess the code and change the password for an IPB account, possibly involving millions of requests.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.r-security.net/tutorials/view/readtutorial.php?id=4"></ref><ref source="" url="http://forums.invisionpower.com/lofiversion/index.php/t200085.html"></ref></refs><vuln_soft><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0634" published="2006-02-10" seq="2006-0634" severity="Medium" type="CVE"><desc><descript source="cve">Borland C++Builder 6 (BCB6) with Update Pack 4 Enterprise edition (ent_upd4) evaluates the &quot;i&gt;sizeof(int)&quot; expression to false when i equals -1, which might introduce integer overflow vulnerabilities into applications that could be exploited by context-dependent attackers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424085/100/0/threaded">20060206 [xfocus-SD-060206]BCB compiler incorrect deal sizeof operator vulnerability</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1015588">1015588</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24514">bcb-compiler-integer-overflow(24514)</ref><ref source="OSVDB" url="http://www.osvdb.org/22953">22953</ref><ref source="" url="http://www.xfocus.net/releases/200602/a849.html"></ref></refs><vuln_soft><prod name="C++ Builder" vendor="Borland Software"><vers edition="Enterprise Update 4" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0635" published="2006-02-10" seq="2006-0635" severity="Medium" type="CVE"><desc><descript source="cve">Tiny C Compiler (TCC) 0.9.23 (aka TinyCC) evaluates the &quot;i&gt;sizeof(int)&quot; expression to false when i equals -1, which might introduce integer overflow vulnerabilities into applications that could be exploited by context-dependent attackers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424257/100/0/threaded">20060207 Re: [xfocus-SD-060206]BCB compiler incorrect deal sizeof operator vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/22956">22956</ref></refs><vuln_soft><prod name="Tiny C Compiler" vendor="Fabrice Bellard"><vers num="0.9.23"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-10" name="CVE-2006-0636" published="2006-02-10" seq="2006-0636" severity="High" type="CVE"><desc><descript source="cve">desktop.php in eyeOS 0.8.9 and earlier tests for the existence of the _SESSION variable before calling the session_start function, which allows remote attackers to execute arbitrary PHP code and possibly conduct other attacks by modifying critical assumed-immutable variables, as demonstrated using PHP code in the _SESSION[apps][eyeOptions.eyeapp][wrapup] variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424329/100/0/threaded">20060207 eyeOS &lt;= 0.8.9 Remote Code Execution</ref><ref adv="1" patch="1" source="" url="http://www.gulftech.org/?node=research&amp;article_id=00096-02072006"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0466">ADV-2006-0466</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015609">1015609</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18757">18757</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24569">eyeos-desktop-file-include(24569)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16537">16537</ref><ref source="SREASON" url="http://securityreason.com/securityalert/419">419</ref></refs><vuln_soft><prod name="eyeOS" vendor="eyeOS Project"><vers num="0.8.9"/><vers num="0.8.8"/><vers num="0.8.7"/><vers num="0.8.6"/><vers num="0.8.5 r1"/><vers num="0.8.5"/><vers num="0.8.4 r1"/><vers num="0.8.4"/><vers num="0.8.3 r2"/><vers num="0.8.3 r1"/><vers num="0.8.3"/><vers num="0.8.2 r3"/><vers num="0.8.2 r2"/><vers num="0.8.2 r1"/><vers num="0.8.2"/><vers num="0.8.1 r1"/><vers num="0.8.1"/><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-10" name="CVE-2006-0637" published="2006-02-10" seq="2006-0637" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in cram.dll in QUALCOMM Eudora WorldMail 3.0 allows remote attackers to execute arbitrary code via an IMAP APPEND command with a long message literal argument, as demonstrated by Worldmail.pl. NOTE: this is a different vector and a different manipulation than CVE-2005-4267, so it might be a different vulnerability than CVE-2005-4267.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424157/100/0/threaded">20060204 (OLD) Eudora WorldMail 3.0 Windows 2000 Remote System Exploit</ref></refs><vuln_soft><prod name="Eudora WorldMail" vendor="Qualcomm"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-05" name="CVE-2006-0638" published="2006-02-10" seq="2006-0638" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in moderation.php in MyBB (aka MyBulletinBoard) 1.0.3 allows remote authenticated users, with certain privileges for moderating and merging posts, to execute arbitrary SQL commands via the posts parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424335/100/0/threaded">20060207 [myimei]MyBB1.0.3~moderation.php~SqlInject while merging posts</ref><ref adv="1" source="" url="http://myimei.com/security/2006-02-07/mybb103moderationphpsqlinject-while-merging-posts.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0475">ADV-2006-0475</ref><ref source="OSVDB" url="http://www.osvdb.org/22957">22957</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18754">18754</ref><ref source="BID" url="http://www.securityfocus.com/bid/16538">16538</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-05" name="CVE-2006-0639" published="2006-02-10" seq="2006-0639" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in MyBB (aka MyBulletinBoard) 1.0.2 allows remote attackers with knowledge of the table prefix to inject arbitrary web script or HTML via a URL encoded value of the keywords parameter, as demonstrated by %3Cscript%3E.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424334/100/0/threaded">20060207 [myimei]MyBB 1.0.2 XSS attack in search.php</ref><ref adv="1" patch="1" source="" url="http://myimei.com/security/2006-01-14/mybb-102searchphpxss-attackandmore.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424375/100/0/threaded">20060208 Re: [myimei]MyBB 1.0.2 XSS attack in search.php</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24466">
mybb-search-xss(24466)</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-14" name="CVE-2006-0640" published="2006-02-10" seq="2006-0640" severity="Low" type="CVE"><desc><descript source="cve">Orbicule Undercover allows attackers with physical or root access to disable the protection by using the chmod command to change the permissions of the /private/etc/uc.app/Contents/MacOS/uc file, which prevents the service from being started in LaunchDaemon.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423955/100/0/threaded">20060202 Issues with security software: orbicule.com &apos;Undercover&apos;</ref></refs><vuln_soft><prod name="Undercover" vendor="Orbicule"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-14" name="CVE-2006-0641" published="2006-02-10" seq="2006-0641" severity="Low" type="CVE"><desc><descript source="cve">Orbicule Undercover uses a third-party web server to determine the IP address through which the computer is accessing the Internet, but does not document this third-party disclosure, which leads to a potential privacy leak that might allow transmission of sensitive information to an unintended remote destination.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423955/100/0/threaded">20060202 Issues with security software: orbicule.com &apos;Undercover&apos;</ref></refs><vuln_soft><prod name="Undercover" vendor="Orbicule"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-14" name="CVE-2006-0642" published="2006-02-10" seq="2006-0642" severity="Medium" type="CVE"><desc><descript source="cve">Trend Micro ServerProtect 5.58, and possibly InterScan Messaging Security Suite and InterScan Web Security Suite, have a default configuration setting of &quot;Do not scan compressed files when Extracted file count exceeds 500 files,&quot; which may be too low in certain circumstances, which allows remote attackers to bypass anti-virus checks by sending compressed archives containing many small files. NOTE: since this is related to a configuration setting that has an operational impact that might vary depending on the environment, and the product is claimed to report a message when the compressed file exceeds specified limits, perhaps this should not be included in CVE.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423896/100/0/threaded">20060203 Trend Micro ServerProtect version 5.58 can be easily circumvented via the mechanism that limits how many files to scan.</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423914/100/0/threaded">20060203 Re: Trend Micro ServerProtect version 5.58 can be easily circumvented via the mechanism that limits how many files to scan.</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423913/100/0/threaded">20060203 Re: Trend Micro ServerProtect version 5.58 can be easily circumvented via the mechanism that limits how many files to scan.</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424172/100/0/threaded">20060205 RE: Trend Micro ServerProtect version 5.58 can be easily circumvented via the mechanism that limits how many files to scan.</ref><ref adv="1" source="" url="http://www.packetstormsecurity.org/0602-advisories/Bypass.pdf"></ref><ref adv="1" source="" url="http://www.packetstormsecurity.org/filedesc/Bypass.pdf.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424598/100/0/threaded">20060206 Fwd: Trend Micro ServerProtect version 5.58 can be easily circumvented via the mechanism that limits how many files to scan.</ref><ref source="BID" url="http://www.securityfocus.com/bid/16483">16483</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24658">
serverprotect-file-scanning-bypass(24658)</ref></refs><vuln_soft><prod name="InterScan Web Security Suite" vendor="Trend Micro"><vers num=""/></prod><prod name="ServerProtect" vendor="Trend Micro"><vers num="5.58"/></prod><prod name="InterScan Messaging Security Suite" vendor="Trend Micro"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-14" name="CVE-2006-0643" published="2006-02-10" seq="2006-0643" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in WiredRed e/pop Web Conferencing 4.1.0.755 allows remote authenticated users to inject arbitrary web script or HTML via the topic name of a conference.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424419/100/0/threaded">20060208 WiredRed EPOP XSS Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16542">16542</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0505">ADV-2006-0505</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18753">18753</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24609">epop-topic-xss(24609)</ref><ref source="OSVDB" url="http://www.osvdb.org/22997">22997</ref><ref source="SREASON" url="http://securityreason.com/securityalert/421">421</ref></refs><vuln_soft><prod name="e/pop Web Conferencing" vendor="WiredRed"><vers num="4.1.0.755"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-05" name="CVE-2006-0644" published="2006-02-10" seq="2006-0644" severity="High" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in install.php in CPG-Nuke Dragonfly CMS (aka CPG Dragonfly CMS) 9.0.6.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in (1) the newlang parameter and (2) the installlang parameter in a cookie, as demonstrated by using error.php to insert malicious code into a log file, or uploading a malicious .png file, which is then included using install.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424439/100/0/threaded">20060208 CPGNuke Dragonfly 9.0.6.1 remote commands execution through arbitrary local inclusion</ref><ref source="" url="http://retrogod.altervista.org/dragonfly9.0.6.1_incl_xpl.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16546">16546</ref><ref source="" url="http://dragonflycms.org/Forums/viewtopic/p=98034.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/23058">23058</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015601">1015601</ref><ref source="" url="http://dragonflycms.org/Forums/viewtopic/p=98034.html#98034"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24660">
cpg-dragonfly-file-include(24660)</ref></refs><vuln_soft><prod name="Dragonfly CMS" vendor="CPG-Nuke"><vers num="9.0.6 .1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-14" name="CVE-2006-0645" published="2006-02-10" seq="2006-0645" severity="High" type="CVE"><desc><descript source="cve">Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3.4, and (2) GNU Shishi, allows attackers to crash the DER decoder and possibly execute arbitrary code via &quot;out-of-bounds access&quot; caused by invalid input, as demonstrated by the ProtoVer SSL test suite.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424538/100/0/threaded">20060209 ProtoVer SSL: GnuTLS</ref><ref source="" url="http://www.gleg.net/protover_ssl.shtml"></ref><ref source="" url="http://josefsson.org/gnutls/releases/libtasn1/libtasn1-0.2.18-from-0.2.17.patch"></ref><ref source="MLIST" url="http://lists.gnupg.org/pipermail/gnutls-dev/2006-February/001058.html">[gnutls-dev] 20060209 Libtasn1 0.2.18 - Tiny ASN.1 Library - Security release</ref><ref source="MLIST" url="http://lists.gnupg.org/pipermail/gnutls-dev/2006-February/001059.html">[gnutls-dev] 20060209 GnuTLS 1.2.10 - Security release</ref><ref source="MLIST" url="http://lists.gnupg.org/pipermail/gnutls-dev/2006-February/001060.html">[gnutls-dev] 20060209 GnuTLS 1.3.4 - Experimental - Security release</ref><ref source="" url="http://josefsson.org/cgi-bin/viewcvs.cgi/gnutls/tests/certder.c?view=markup"></ref><ref source="" url="http://josefsson.org/cgi-bin/viewcvs.cgi/libtasn1/NEWS?root=gnupg-mirror&amp;view=markup"></ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00043.html">FEDORA-2006-107</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:039">MDKSA-2006:039</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0207.html">RHSA-2006:0207</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0496">ADV-2006-0496</ref><ref source="OSVDB" url="http://www.osvdb.org/23054">23054</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015612">1015612</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18794">18794</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18815">18815</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18830">18830</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18832">18832</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24606">gnutls-libtasn1-der-dos(24606)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200602-08.xml">GLSA-200602-08</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-251-1">USN-251-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/16568">16568</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18918">18918</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18898">18898</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0008">2006-0008</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-986">DSA-986</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-985">DSA-985</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19080">19080</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19092">19092</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:039">MDKSA-2006:039</ref><ref source="SREASON" url="http://securityreason.com/securityalert/446">446</ref></refs><vuln_soft><prod name="libtasn1" vendor="Free Software Foundation Inc."><vers num="0.1.0"/><vers num="0.1.1"/><vers num="0.1.2"/><vers num="0.2.0"/><vers num="0.2.1"/><vers num="0.2.2"/><vers num="0.2.3"/><vers num="0.2.4"/><vers num="0.2.5"/><vers num="0.2.6"/><vers num="0.2.7"/><vers num="0.2.8"/><vers num="0.2.9"/><vers num="0.2.10"/><vers num="0.2.11"/><vers num="0.2.12"/><vers num="0.2.13"/><vers num="0.2.14"/><vers num="0.2.15"/><vers num="0.2.16"/><vers num="0.2.17"/></prod></vuln_soft></entry><entry CVSS_base_score="4.4" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.4" CVSS_score="4.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2006-0646" published="2006-02-11" seq="2006-0646" severity="Medium" type="CVE"><desc><descript source="cve">ld in SUSE Linux 9.1 through 10.0, and SLES 9, in certain circumstances when linking binaries, can leave an empty RPATH or RUNPATH, which allows local attackers to execute arbitrary code as other users via by running an ld-linked application from the current directory, which could contain an attacker-controlled library file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Feb/0003.html">SUSE-SA:2006:007</ref><ref source="BID" url="http://www.securityfocus.com/bid/16581">16581</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18811">18811</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="Professional 10.0"/><vers edition="x86_64" num="Professional 9.3"/><vers num="Professional 9.3"/><vers edition="x86_64" num="Professional 9.2"/><vers num="Professional 9.2"/><vers edition="x86_64" num="Professional 9.1"/><vers num="Professional 9.1"/><vers edition="x86_64" num="Personal 9.3"/><vers num="Personal 9.3"/><vers edition="x86_64" num="Personal 9.2"/><vers num="Personal 9.2"/><vers edition="x86_64" num="Personal 9.1"/><vers num="Personal 9.1"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0647" published="2006-02-13" seq="2006-0647" severity="Medium" type="CVE"><desc><descript source="cve">LDAP service in Sun Java System Directory Server 5.2, running on Linux and possibly other platforms, allows remote attackers to cause a denial of service (memory allocation error) via an LDAP packet with a crafted subtree search request, as demonstrated using the ProtoVer LDAP test suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2006-February/002914.html">[Dailydave] 20060208 Sun Directory Server 5.2 fun</ref><ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2006-February/002916.html">[Dailydave] 20060210 ??? Sun Directory Server 5.2 fun ???</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0492">ADV-2006-0492</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18769">18769</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015604">1015604</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24605">sun-java-ldap-dos(24605)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16550">16550</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102294-1">102294</ref></refs><vuln_soft><prod name="Java System Directory Server" vendor="Sun"><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0648" published="2006-02-13" seq="2006-0648" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to include arbitrary files via the (1) getdate and possibly other parameters used in the replace_files function in search.php and (2) $file variable as used in the parse function in functions/template.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424424/100/0/threaded">20060208 [eVuln] PHP iCalendar File Inclusion Vulnerability</ref><ref adv="1" patch="1" source="" url="http://evuln.com/vulns/70/summary.html"></ref><ref source="" url="http://phpicalendar.net/forums/viewtopic.php?t=396"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16557">16557</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0493">ADV-2006-0493</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18778">18778</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24591">phpicalendar-template-search-file-include(24591)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/420">420</ref></refs><vuln_soft><prod name="PHP iCalendar" vendor="PHP iCalendar"><vers num="2.0.1"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0649" published="2006-02-13" seq="2006-0649" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in DataparkSearch before 4.37 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.dataparksearch.org/ChangeLog"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0488">ADV-2006-0488</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18751">18751</ref><ref source="BID" url="http://www.securityfocus.com/bid/16572">16572</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24627">
dataparksearch-scripts-xss(24627)</ref></refs><vuln_soft><prod name="DataparkSearch" vendor="DataparkSearch"><vers num="4.36"/><vers num="4.35"/><vers num="4.34"/><vers num="4.33"/><vers num="4.32"/><vers num="4.31"/><vers num="4.30"/><vers num="4.29"/><vers num="4.28"/><vers num="4.27"/><vers num="4.26"/><vers num="4.25"/><vers num="4.24"/><vers num="4.23"/><vers num="4.22"/><vers num="4.21"/><vers num="4.20"/><vers num="4.19"/><vers num="4.18"/><vers num="4.17"/><vers num="4.16"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0650" published="2006-02-13" seq="2006-0650" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in multiple scripts, allows remote attackers to inject arbitrary web script or HTML via the cpaint_response_type parameter, which is displayed in a resulting error message, as demonstrated using a hex-encoded IFRAME tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424663/100/0/threaded">20060210 CPAINT AJAX Library Cross Site Scripting</ref><ref adv="1" patch="1" source="" url="http://www.gulftech.org/?node=research&amp;article_id=00097-02092006"></ref><ref source="" url="http://cpaint.booleansystems.com/forums/viewtopic.php?t=98"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0487">ADV-2006-0487</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18765">18765</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24594">cpaint-response-type-xss(24594)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16559">16559</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015608">1015608</ref></refs><vuln_soft><prod name="CPAINT" vendor="CPAINT"><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/><vers num="1.3 SP1"/><vers num="1.3 SP"/><vers num="1.3"/><vers num="1.2"/><vers num="1.01"/><vers num="1.0"/><vers num="pre1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0651" published="2006-02-13" seq="2006-0651" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in vwdev allows remote attackers to execute arbitrary SQL commands via the UID parameter in the definition Page.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16547">16547</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015594">1015594</ref><ref source="OSVDB" url="http://www.osvdb.org/22991">22991</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24583">
vwdev-uid-sql-injection(24583)</ref></refs><vuln_soft><prod name="vwdev" vendor="vwdev"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0652" published="2006-02-13" seq="2006-0652" severity="Medium" type="CVE"><desc><descript source="cve">WHMCompleteSolution (WHMCS) before 2.3 assigns incorrect permissions to &quot;resellers&quot;, which allows remote authenticated users to perform privileged actions or obtain sensitive information.  NOTE: this report is based on a vendor bug report that identified &quot;incorrect permissions.&quot;  However, the vendor did not label it a security issue, and there was no statement regarding whether or not the permissions were actually more permissive than intended.  If in fact the permissions were more restrictive than intended, then this would be a functional problem but not a vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.whmcs.com/changelog.php"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16560">16560</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0484">ADV-2006-0484</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24597">whmcs-resellers-insecure-permissions(24597)</ref></refs><vuln_soft><prod name="WHMCompleteSolution" vendor="WHMCompleteSolution"><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0653" published="2006-02-13" seq="2006-0653" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Hinton Design phpht Topsites 1.3 allow remote attackers to execute arbitrary SQL commands via multiple vectors including the username parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/59/summary.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18782">18782</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424741/100/0/threaded">20060211 [eVuln] phpht Topsites Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16562">16562</ref></refs><vuln_soft><prod name="phpht Topsites" vendor="Hinton Design"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0654" published="2006-02-13" seq="2006-0654" severity="High" type="CVE"><desc><descript source="cve">check.php in Hinton Design phpht Topsites 1.3 does not validate passwords when using cookies, which allows remote attackers to bypass authentication via unspecified cookies.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/59/summary.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18782">18782</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424741/100/0/threaded">20060211 [eVuln] phpht Topsites Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16562">16562</ref></refs><vuln_soft><prod name="phpht Topsites" vendor="Hinton Design"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0655" published="2006-02-13" seq="2006-0655" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) link_edited.php and (2) link_added.php in Hinton Design phpht Topsites 1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/59/summary.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18782">18782</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424741/100/0/threaded">20060211 [eVuln] phpht Topsites Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16562">16562</ref></refs><vuln_soft><prod name="phpht Topsites" vendor="Hinton Design"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0656" published="2006-02-13" seq="2006-0656" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in HP Systems Insight Manager 4.2 through 5.0 SP3 for Windows allows remote attackers to access arbitrary files via unspecified vectors, a different vulnerability than CVE-2005-2006.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00597967">HPSBMA02096</ref><ref source="BID" url="http://www.securityfocus.com/bid/16571">16571</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0497">ADV-2006-0497</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18789">18789</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015605">1015605</ref></refs><vuln_soft><prod name="Systems Insight Manager" vendor="HP"><vers num="5.0 SP3"/><vers num="5.0 SP2"/><vers num="5.0 SP1"/><vers num="5.0"/><vers num="4.2 SP2"/><vers num="4.2 SP1"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0657" published="2006-02-13" seq="2006-0657" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Softcomplex PHP Event Calendar 1.5 allows remote authenticated users to inject arbitrary web script or HTML, and corrupt data, via the (1) username and (2) password parameters, which are not sanitized before being written to users.php.  NOTE: while this issue was originally reported as XSS, the primary issue might be direct static code injection with resultant XSS.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/63/summary.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18792">18792</ref><ref source="BID" url="http://www.securityfocus.com/bid/16588">16588</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0507">ADV-2006-0507</ref><ref source="OSVDB" url="http://www.osvdb.org/23071">23071</ref><ref source="OSVDB" url="http://www.osvdb.org/23072">23072</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24523">phpeventcalendar-users-xss(24523)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/442">442</ref></refs><vuln_soft><prod name="PHP Event Calendar" vendor="Softcomplex"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-0658" published="2006-02-13" seq="2006-0658" severity="Medium" type="CVE"><desc><descript source="cve">Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://retrogod.altervista.org/fckeditor_22_xpl.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18767">18767</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0502">ADV-2006-0502</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/424708">20060209 runCMS &lt;= 1.3a2 possible remote code execution through the integrated FCKEditor package</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3702">
3702</ref></refs><vuln_soft><prod name="FCKeditor" vendor="FCKeditor"><vers num="2.0"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-10" name="CVE-2006-0659" published="2006-02-13" seq="2006-0659" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote attackers to execute arbitrary code via the bbPath[path] parameter in (1) class.forumposts.php and (2) forumpollrenderer.php.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that both &quot;register_globals&quot; and &quot;allow_url_fopen&quot; are enabled.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://retrogod.altervista.org/runcms_13a_xpl.html"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18800">18800</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0503">ADV-2006-0503</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/424708">20060209 runCMS &lt;= 1.3a2 possible remote code execution through the integrated FCKEditor package</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16578">16578</ref></refs><vuln_soft><prod name="RunCMS" vendor="RunCMS"><vers num="1.2"/><vers num="1.1a"/><vers num="1.1"/><vers num="1.3a2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0660" published="2006-02-13" seq="2006-0660" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary files or trigger an error message path disclosure via &quot;..&quot;  or invalid names in the archive parameter to index.php, or (2) include arbitrary files via the template parameter to show_archives.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.hamid.ir/security/farsinews2-5.txt"></ref><ref source="" url="http://forum.farsinewsteam.com/index.php?showtopic=71"></ref><ref source="" url="http://forum.farsinewsteam.com/index.php?showtopic=76"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16580">16580</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18768">18768</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424720/100/0/threaded">20060210 FarsiNews 2.5 Multiple Vulnerabilities</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0506">ADV-2006-0506</ref><ref source="OSVDB" url="http://www.osvdb.org/23020">23020</ref><ref source="OSVDB" url="http://www.osvdb.org/23021">23021</ref><ref source="OSVDB" url="http://www.osvdb.org/23022">23022</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24602">farsinews-index-directory-traversal(24602)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24598">farsinews-showarchives-file-include(24598)</ref></refs><vuln_soft><prod name="FarsiNews" vendor="FarsiNews"><vers num="2.5"/><vers num="2.1 Beta2"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-01" name="CVE-2006-0661" published="2006-02-13" seq="2006-0661" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Scriptme SmE GB Host 1.21 and SmE Blog Host allows remote attackers to inject arbitrary web script or HTML via the BBcode url tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/65/summary.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18786">18786</ref><ref source="BID" url="http://www.securityfocus.com/bid/16585">16585</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0504">ADV-2006-0504</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24543">
sme-bbcode-xss(24543)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/447">447</ref></refs><vuln_soft><prod name="SmE GB Host" vendor="Scriptme"><vers num="1.21"/></prod><prod name="SmE Blog Host" vendor="Scriptme"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0662" published="2006-02-13" seq="2006-0662" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Lotus Domino iNotes Client 6.5.4 allows remote attackers to inject arbitrary web script or HTML via email with attached html files, which are directly rendered in the browser.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2005-38/advisory/"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16340">16340</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24612">domino-webaccess-subject-xss(24612)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16577">16577</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0499">ADV-2006-0499</ref><ref source="OSVDB" url="http://www.osvdb.org/23077">23077</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015610">1015610</ref><ref source="" url="http://www-1.ibm.com/support/docview.wss?rs=475&amp;uid=swg21229919"></ref></refs><vuln_soft><prod name="Lotus Domino iNotes Client" vendor="IBM"><vers num="6.5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" discovered="2005-08-22" modified="2008-08-26" name="CVE-2006-0663" published="2006-02-13" seq="2006-0663" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using &quot;java
script:&quot;; or (3) when the Domino Web Access ActiveX control is not installed, via an email attachment filename.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product releases:
IBM, Lotus Domino iNotes Client, 6.5.5
IBM, Lotus Domino iNotes Client, 7.0.1</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/secunia_research/2005-38/advisory/">IBM Lotus Domino iNotes Client Script Insertion Vulnerabilities</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16340">16340</ref><ref patch="1" source="" url="http://www-1.ibm.com/support/docview.wss?rs=475&amp;uid=swg21229919"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16577">16577</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0499">ADV-2006-0499</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/23077">23077</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/23078">23078</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/23079">23079</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015610">1015610</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24611">domino-webaccess-attachment-xss(24611)</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24614">domino-webaccess-filename-xss(24614)</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24613">domino-webaccess-javascript-xss(24613)</ref><ref patch="1" source="" url="http://www-1.ibm.com/support/docview.wss?rs=475&amp;uid=swg21229919"></ref><ref patch="1" source="" url="http://www-1.ibm.com/support/docview.wss?rs=475&amp;uid=swg21229919"></ref><ref patch="1" source="" url="http://www-1.ibm.com/support/docview.wss?rs=475&amp;uid=swg21229919"></ref></refs><vuln_soft><prod name="Lotus Domino iNotes Client" vendor="IBM"><vers num="6.5.4"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0664" published="2006-02-13" seq="2006-0664" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in config_defaults_inc.php in Mantis before 1.0 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  An original vendor bug report is referenced, but not accessible to the general public.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16561">16561</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0485">ADV-2006-0485</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24585">mantis-configdefaultsinc-xss(24585)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1133">DSA-1133</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21400">21400</ref></refs><vuln_soft><prod name="Mantis" vendor="Mantis"><vers num="1.0.0 rc4"/><vers num="1.0.0 rc3"/><vers num="1.0.0 rc2"/><vers num="1.0.0 rc1"/><vers num="1.0.0a3"/><vers num="1.0.0a2"/><vers num="1.0.0a1"/><vers num="0.19.4"/><vers num="0.19.3"/><vers num="0.19.2"/><vers num="0.19.1"/><vers num="0.19.0 rc1"/><vers num="0.19.0a2"/><vers num="0.19.0a1"/><vers num="0.19.0a"/><vers num="0.19.0"/><vers num="0.18.3"/><vers num="0.18.2"/><vers num="0.18a1"/><vers num="0.18.0 rc1"/><vers num="0.18.0a4"/><vers num="0.18.0a3"/><vers num="0.18.0a2"/><vers num="0.18"/><vers num="0.17.5"/><vers num="0.17.4a"/><vers num="0.17.4"/><vers num="0.17.3"/><vers num="0.17.2"/><vers num="0.17.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-13" name="CVE-2006-0665" published="2006-02-13" seq="2006-0665" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  An original vendor bug report is referenced, but not accessible to the general public.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16561">16561</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0485">ADV-2006-0485</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1133">DSA-1133</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21400">21400</ref></refs><vuln_soft><prod name="Mantis" vendor="Mantis"><vers num="1.0.0 rc4"/><vers num="1.0.0 rc3"/><vers num="1.0.0 rc2"/><vers num="1.0.0 rc1"/><vers num="1.0.0a3"/><vers num="1.0.0a2"/><vers num="1.0.0a1"/><vers num="0.19.4"/><vers num="0.19.3"/><vers num="0.19.2"/><vers num="0.19.1"/><vers num="0.19.0 rc1"/><vers num="0.19.0a2"/><vers num="0.19.0a1"/><vers num="0.19.0a"/><vers num="0.19.0"/><vers num="0.18.3"/><vers num="0.18.2"/><vers num="0.18a1"/><vers num="0.18.0 rc1"/><vers num="0.18.0a4"/><vers num="0.18.0a3"/><vers num="0.18.0a2"/><vers num="0.18"/><vers num="0.17.5"/><vers num="0.17.4a"/><vers num="0.17.4"/><vers num="0.17.3"/><vers num="0.17.2"/><vers num="0.17.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-15" name="CVE-2006-0666" published="2006-02-15" seq="2006-0666" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 through 5.3.0.33 allows local users to cause a denial of service (system crash) via unknown vectors related to EMULATE_VMX.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY79595&amp;apar=only">IY79595</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16624">16624</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0573">ADV-2006-0573</ref><ref source="OSVDB" url="http://www.osvdb.org/23127">23127</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18795">18795</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24711">
aix-kernel-dos(24711)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3 L"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-0667" published="2006-03-09" seq="2006-0667" severity="Medium" type="CVE"><desc><descript source="cve">lscfg in IBM AIX 5.2 and 5.3 allows local users to modify arbitrary files via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY77624">IY77624</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY77638">IY77638</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2096">ADV-2005-2096</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015622">1015622</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-0668" published="2006-02-13" seq="2006-0668" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly in message.php in the espace_membre module.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16567">16567</ref><ref source="" url="http://www.securityfocus.com/bid/16567/exploit"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19023">19023</ref></refs><vuln_soft><prod name="PwsPHP" vendor="PwsPHP"><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-0669" published="2006-02-13" seq="2006-0669" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Multiple SQL injection vulnerabilities in archive.asp in GA&apos;s Forum Light allow remote attackers to execute arbitrary SQL commands via the (1) Forum and (2) pages parameter.  NOTE: SecurityTracker says that the vendor has disputed this issue, saying that GA Forum Light does not use an SQL database.  SecurityTracker&apos;s research indicates that the original problem could be due to a vbscript parsing error based on invalid arguments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16563">16563</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015600">1015600</ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-February/000561.html">[VIM] 20060220 vendor dispute for CVE-2006-0669</ref><ref source="OSVDB" url="http://www.osvdb.org/23085">23085</ref><ref source="OSVDB" url="http://www.osvdb.org/23509">23509</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24616">
gasforumlight-archive-sql-injection(24616)</ref></refs><vuln_soft><prod name="GA&apos;s Forum Light" vendor="GASoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-14" name="CVE-2006-0670" published="2006-02-13" seq="2006-0670" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in l2cap.c in hcidump 1.29 allows remote attackers to caues a denial of service (crash) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424133/100/0/threaded">20060206 [ Secuobs - Advisory ] Bluetooth : DoS on hcidump 1.29 + PoC</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113924625825488&amp;w=2">20060206 [ Secuobs - Advisory ] Bluetooth : DoS on hcidump</ref><ref source="" url="http://www.secuobs.com/news/05022006-bluetooth9.shtml#english"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0479">ADV-2006-0479</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18741">18741</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24533">hcidump-bluetooth-dos(24533)</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:041">MDKSA-2006:041</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-256-1">USN-256-1</ref><ref source="OSVDB" url="http://www.osvdb.org/23056">23056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18971">18971</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-990">DSA-990</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19122">19122</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:041">MDKSA-2006:041</ref><ref source="SREASON" url="http://securityreason.com/securityalert/465">465</ref></refs><vuln_soft><prod name="hcidump" vendor="BlueZ Project"><vers num="1.29"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-14" name="CVE-2006-0671" published="2006-02-13" seq="2006-0671" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Sony Ericsson K600i, V600i, W800i, and T68i cell phone allows remote attackers to caues a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet whose length field is less than the actual length of the packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113926179907655&amp;w=2">20060206 [ Secuobs - Advisory ] Bluetooth : DoS on Sony/Ericsson cell phones</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113924661724270&amp;w=2">20060206 [Full-disclosure] [ Secuobs - Advisory ] Bluetooth : DoS on</ref><ref source="" url="http://www.secuobs.com/news/05022006-bluetooth7.shtml#english"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0478">ADV-2006-0478</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18747">18747</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24534">sony-bluetooth-dos(24534)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16512">16512</ref></refs><vuln_soft><prod name="W800i" vendor="Sony Ericsson"><vers num=""/></prod><prod name="V600i" vendor="Sony Ericsson"><vers num=""/></prod><prod name="K600i" vendor="Sony Ericsson"><vers num=""/></prod><prod name="T68i" vendor="Sony Ericsson"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-21" name="CVE-2006-0672" published="2006-02-13" seq="2006-0672" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in HP PSC 1210 All-in-One Drivers before 1.0.06 has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://h10025.www1.hp.com/ewfrf/wc/softwareDownloadIndex?dlc=en&amp;lc=en&amp;os=228%20&amp;product=90764&amp;lang=en&amp;cc=us&amp;softwareitem=oj-37641-1"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16583">16583</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0498">ADV-2006-0498</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18770">18770</ref></refs><vuln_soft><prod name="PSC 1210 All-in-One" vendor="HP"><vers num=""/><vers num="1.0.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-14" name="CVE-2006-0673" published="2006-02-13" seq="2006-0673" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in cms/index.php in Magic Calendar Lite 1.02, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) $total_login and (2) $total_password parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/71/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0525">ADV-2006-0525</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24588">magiccalendar-index-sql-injection(24588)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425491/100/0/threaded">20060220 [eVuln] Magic Calendar Lite Authentication Bypass</ref><ref source="BID" url="http://www.securityfocus.com/bid/16646">16646</ref><ref source="BID" url="http://www.securityfocus.com/bid/16734">16734</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18855">18855</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015650">1015650</ref><ref source="SREASON" url="http://securityreason.com/securityalert/459">459</ref></refs><vuln_soft><prod name="Magic Calendar Lite" vendor="Reamday Enterprises"><vers num="1.02"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-14" name="CVE-2006-0674" published="2006-02-13" seq="2006-0674" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the arp command of IBM AIX 5.3 L, 5.3, 5.2.2, 5.2 L, and 5.2 allows local users to cause a denial of service (crash) via a long iftype argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY81476">IY81476</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?rs=0&amp;q1=IY81424&amp;uid=isg1IY81424&amp;loc=en_US&amp;cs=utf-8&amp;cc=us&amp;lang=en">IY81424</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16584">16584</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0531">ADV-2006-0531</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18773">18773</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24628">aix-arp-iftype-bo(24628)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3 L"/><vers num="5.3"/><vers num="5.2.2"/><vers num="5.2 L"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-14" name="CVE-2006-0675" published="2006-02-13" seq="2006-0675" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in Siteframe 5.0.1 allows remote attackers to inject arbitrary web script or HTML via the q parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://kiki91.altervista.org/exploit/siteframe5.0.1a_xss.txt"></ref><ref source="" url="http://siteframe.org/p/xss_vulnerability_in_siteframe_501"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0533">ADV-2006-0533</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18804">18804</ref><ref source="BID" url="http://www.securityfocus.com/bid/16596">16596</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24649">siteframe-search-request-xss(24649)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424844/100/0/threaded">20060212 Siteframe Beaumont 5.0.1a &lt;== Cross-Site Scripting Vulnerability</ref></refs><vuln_soft><prod name="Siteframe" vendor="Glen Campbell"><vers num="5.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-14" name="CVE-2006-0676" published="2006-02-13" seq="2006-0676" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in header.php in PHP-Nuke 6.0 to 7.8 allows remote attackers to inject arbitrary web script or HTML via the pagetitle parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.waraxe.us/advisory-44.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0542">ADV-2006-0542</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18820">18820</ref><ref source="BID" url="http://www.securityfocus.com/bid/16608">16608</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424956/100/0/threaded">20060214 [waraxe-2006-SA#044] - XSS in phpNuke 7.8 and older versions</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24650">phpnuke-header-xss(24650)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/425">425</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.9"/><vers num="7.8"/><vers num="7.7"/><vers num="7.6"/><vers num="7.3"/><vers num="7.2"/><vers num="7.1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-14" name="CVE-2006-0677" published="2006-02-14" seq="2006-0677" severity="High" type="CVE"><desc><descript source="cve">telnetd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2 allows remote unauthenticated attackers to cause a denial of service (server crash) via unknown vectors that trigger a null dereference.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://www.stacken.kth.se/lists/heimdal-discuss/2006-02/msg00028.html">[heimdal-discuss] 20060206 Heimdal 0.7.2 and 0.6.6</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-977">DSA-977</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-253-1">USN-253-1</ref><ref source="OSVDB" url="http://www.osvdb.org/23244">23244</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18894">18894</ref><ref source="SUSE" url="http://www.securityfocus.com/archive/1/archive/1/426043/100/0/threaded">SUSE-SA:2006:011</ref><ref source="BID" url="http://www.securityfocus.com/bid/16676">16676</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19005">19005</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0456">ADV-2006-0456</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0628">ADV-2006-0628</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0653">ADV-2006-0653</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18961">18961</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24763">heimdal-telnetd-dos(24763)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/449">449</ref></refs><vuln_soft><prod name="Heimdal" vendor="KTH"><vers num="0.7.1.3"/><vers num="0.7.1.2"/><vers num="0.7.1.1"/><vers num="0.7.1"/><vers num="0.6.5"/><vers num="0.6.4"/><vers num="0.6.3"/><vers num="0.6.2"/><vers num="0.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.9" CVSS_score="4.0" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0678" published="2006-02-14" seq="2006-0678" severity="Medium" type="CVE"><desc><descript source="cve">PostgreSQL 7.3.x before 7.3.14, 7.4.x before 7.4.12, 8.0.x before 8.0.7, and 8.1.x before 8.1.3, when compiled with Asserts enabled, allows local users to cause a denial of service (server crash) via a crafted SET SESSION AUTHORIZATION command, a different vulnerability than CVE-2006-0553.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="" url="http://www.postgresql.org/docs/8.1/static/release.html#RELEASE-8-1-3"></ref><ref adv="1" source="OPENPKG" url="http://www.openpkg.org/security/OpenPKG-SA-2006.004-postgresql.html">OpenPKG-SA-2006.004</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0605">ADV-2006-0605</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18890">18890</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0008">2006-0008</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-258-1">USN-258-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/16650">16650</ref><ref source="SECTRACK" url="http://www.securityfocus.com/archive/1/archive/1/425037/100/0/threaded">1015636</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19015">19015</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19035">19035</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24719">postgresql-setsessionauth-dos(24719)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/498">498</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="8.1.2"/><vers num="8.1.1"/><vers num="8.1"/><vers num="8.0.6"/><vers num="8.0.5"/><vers num="8.0.4"/><vers num="8.0.3"/><vers num="8.0.2"/><vers num="8.0.1"/><vers num="8.0"/><vers num="7.4.11"/><vers num="7.4.10"/><vers num="7.4.9"/><vers num="7.4.8"/><vers num="7.4.7"/><vers num="7.4.6"/><vers num="7.4.5"/><vers num="7.4.4"/><vers num="7.4.3"/><vers num="7.4.2"/><vers num="7.4.1"/><vers num="7.4"/><vers num="7.3.13"/><vers num="7.3.12"/><vers num="7.3.11"/><vers num="7.3.10"/><vers num="7.3.9"/><vers num="7.3.8"/><vers num="7.3.7"/><vers num="7.3.6"/><vers num="7.3.5"/><vers num="7.3.4"/><vers num="7.3.3"/><vers num="7.3.2"/><vers num="7.3.1"/><vers num="7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0679" published="2006-02-16" seq="2006-0679" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in the Your_Account module in PHP-Nuke 7.8 and earlier allows remote attackers to execute arbitrary SQL commands via the username variable (Nickname field).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0358.html">20060216 Critical SQL Injection PHPNuke &lt;= 7.8 - Your_Account module</ref><ref adv="1" source="" url="http://securityreason.com/securityalert/440"></ref><ref adv="1" source="" url="http://securityreason.com/achievement_securityalert/32"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16691">16691</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0636">ADV-2006-0636</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18931">18931</ref><ref source="OSVDB" url="http://www.osvdb.org/23259">23259</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24769">phpnuke-youraccount-sql-injection(24769)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425173/100/0/threaded">20060216 Critical SQL Injection PHPNuke &lt;= 7.8 - Your_Account module</ref></refs><vuln_soft><prod name="PHP-Nuke EV" vendor="Francisco Burzi"><vers num="7.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0680" published="2006-02-14" seq="2006-0680" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in WebGUI before 6.8.6-gamma allows remote attackers to create an account, when anonymous registration is disabled, via a certain URL.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="" url="http://www.plainblack.com/getwebgui/advisories/webgui-6.8.6-gamma-released"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0541">ADV-2006-0541</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18819">18819</ref><ref source="BID" url="http://www.securityfocus.com/bid/16612">16612</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24695">
webgui-anonymous-bypass-security(24695)</ref></refs><vuln_soft><prod name="WebGUI" vendor="Plain Black"><vers num="6.8.5 Gamma"/><vers num="6.8.4 Gamma"/><vers num="6.8.3 Gamma"/><vers num="6.8.2 Beta"/><vers num="6.8.1 Beta"/><vers num="6.7.8 gamma"/><vers num="6.7.7 Gamma"/><vers num="6.7.6 Gamma"/><vers num="6.7.5 Gamma"/><vers num="6.7.4 Gamma"/><vers num="6.7.3 Gamma"/><vers num="6.7.2 Beta"/><vers num="6.7.1 Beta"/><vers num="6.7.0 Beta"/><vers num="6.6.5 Gamma"/><vers num="6.6.4 Gamma"/><vers num="6.6.3 Gamma"/><vers num="6.6.2 Gamma"/><vers num="6.6.1 Beta"/><vers num="6.6.0 Beta"/><vers num="6.5.6 Gamma"/><vers num="6.5.5 Gamma"/><vers num="6.5.4 Gamma"/><vers num="6.5.3 Beta"/><vers num="6.5.2 Beta"/><vers num="6.5.1 Beta"/><vers num="6.5.0 Beta"/><vers num="6.4.0 Beta"/><vers num="6.3.0 Beta"/><vers num="6.2.11 Gamma"/><vers num="6.2.10 Gamma"/><vers num="6.2.9 gamma"/><vers num="6.2.8 Gamma"/><vers num="6.2.7 Gamma"/><vers num="6.2.6 Gamma"/><vers num="6.2.5 Beta"/><vers num="6.2.4 Beta"/><vers num="6.2.3 Beta"/><vers num="6.2.2 Beta"/><vers num="6.2.1 Beta"/><vers num="6.2.0 Beta"/><vers num="6.1.1"/><vers num="6.1.0"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0681" published="2006-02-14" seq="2006-0681" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in powerd.c in Power Daemon (powerd) 2.0.2 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the WHATIDO variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://gotfault.net/research/advisory/gadv-powerd.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0545">ADV-2006-0545</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18841">18841</ref><ref source="BID" url="http://www.securityfocus.com/bid/16582">16582</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24713">
powerdaemon-syslog-format-string(24713)</ref></refs><vuln_soft><prod name="Power Daemon" vendor="Power Daemon"><vers num="2.0.2"/><vers num="2.0.1.1"/><vers num="2.0.1"/><vers num="2.0.0.1"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0682" published="2006-02-14" seq="2006-0682" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in bbcodes system in e107 before 0.7.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://e107.org/comment.php?comment.news.776"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0540">ADV-2006-0540</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18816">18816</ref><ref source="BID" url="http://www.securityfocus.com/bid/16614">16614</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24625">e107-bbcode-xss(24625)</ref></refs><vuln_soft><prod name="e107" vendor="e107"><vers num="0.7.1"/><vers num="0.7"/><vers num="0.6175"/><vers num="0.6174"/><vers num="0.6173"/><vers num="0.6172"/><vers num="0.6171"/><vers num="0.617"/><vers num="0.616"/><vers num="0.615a"/><vers num="0.615"/><vers num="0.614"/><vers num="0.613"/><vers num="0.612"/><vers num="0.611"/><vers num="0.610"/><vers num="0.609"/><vers num="0.608"/><vers num="0.607"/><vers num="0.606"/><vers num="0.605"/><vers num="0.604"/><vers num="0.603"/><vers num="0.602"/><vers num="0.601"/><vers num="0.600"/><vers num="0.555 Beta"/><vers num="0.554 Beta"/><vers num="0.553 Beta"/><vers num="0.552 Beta"/><vers num="0.551 Beta"/><vers num="0.549 Beta"/><vers num="0.548 Beta"/><vers num="0.547 Beta"/><vers num="5.4 Beta6"/><vers num="5.4 Beta5"/><vers num="5.4 Beta4"/><vers num="5.4 Beta3"/><vers num="5.4 Beta1"/><vers num="5.3 Beta2"/><vers num="5.3 Beta"/><vers num="5.2"/><vers num="5.1"/><vers num="5.05"/><vers num="5.04"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-22" name="CVE-2006-0683" published="2006-02-14" seq="2006-0683" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled when the administrator uses the admin log utility to read the log file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0534">ADV-2006-0534</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18799">18799</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424816/100/0/threaded">20060211 RS-2006-1: Multiple flaws in VHCS 2.x</ref><ref source="BID" url="http://www.securityfocus.com/bid/16600">16600</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24664">
vhcs-admin-xss(24664)</ref></refs><vuln_soft><prod name="Virtual Hosting Control System" vendor="Virtual Hosting Control System"><vers num="2.4.7.1 patch v.1"/><vers num="2.4.6.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-22" name="CVE-2006-0684" published="2006-02-14" seq="2006-0684" severity="High" type="CVE"><desc><descript source="cve">change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not verify the old password when a user changes the password, which may allow remote attackers to gain unauthorized access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0534">ADV-2006-0534</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18799">18799</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424816/100/0/threaded">20060211 RS-2006-1: Multiple flaws in VHCS 2.x</ref><ref source="BID" url="http://www.securityfocus.com/bid/16600">16600</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24665">
vhcs-change-password-weakness(24665)</ref></refs><vuln_soft><prod name="Virtual Hosting Control System" vendor="Virtual Hosting Control System"><vers num="2.4.7.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-22" name="CVE-2006-0685" published="2006-02-14" seq="2006-0685" severity="High" type="CVE"><desc><descript source="cve">The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allows remote attackers to gain unauthorized access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0534">ADV-2006-0534</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18799">18799</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424816/100/0/threaded">20060211 RS-2006-1: Multiple flaws in VHCS 2.x</ref><ref source="BID" url="http://www.securityfocus.com/bid/16600">16600</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24666">
vhcs-checklogin-auth-bypass(24666)</ref></refs><vuln_soft><prod name="Virtual Hosting Control System" vendor="Virtual Hosting Control System"><vers num="2.4.7.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-22" name="CVE-2006-0686" published="2006-02-14" seq="2006-0686" severity="High" type="CVE"><desc><descript source="cve">add_user.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not check user privileges when adding a new administrative user, which allows remote attackers to gain unauthorized access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0534">ADV-2006-0534</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18799">18799</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424816/100/0/threaded">20060211 RS-2006-1: Multiple flaws in VHCS 2.x</ref><ref source="BID" url="http://www.securityfocus.com/bid/16600">16600</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24667">
vhcs-adduser-privilege-escalation(24667)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/430">430</ref></refs><vuln_soft><prod name="Virtual Hosting Control System" vendor="Virtual Hosting Control System"><vers num="2.4.7.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0687" published="2006-02-14" seq="2006-0687" severity="Medium" type="CVE"><desc><descript source="cve">process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows remote attackers to include arbitrary local files or possibly remote files via a modified includeModule and siteModInfo variable.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://retrogod.altervista.org/docmgr_0542_incl_xpl.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0544">ADV-2006-0544</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18803">18803</ref><ref source="BID" url="http://www.securityfocus.com/bid/16601">16601</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424818/100/0/threaded">20060212 DocMGR &lt;= 0.54.2 arbitrary remote inclusion</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24694">
docmgr-process-file-include(24694)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/428">428</ref></refs><vuln_soft><prod name="DocMGR" vendor="DocMGR"><vers num="0.54.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-20" name="CVE-2006-0688" published="2006-02-15" seq="2006-0688" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424549/100/0/threaded">20060209 [ECHO_ADV_27$2006] Indexu &lt;= 5.0.1 Remote File Inclusion</ref><ref source="" url="http://echo.or.id/adv/adv27-K-159-2006.txt"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18752">18752</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0494">ADV-2006-0494</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015607">1015607</ref><ref source="" url="http://echo.or.id/adv/adv26-K-159-2006.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16565">16565</ref><ref source="OSVDB" url="http://www.osvdb.org/22989">22989</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24603">indexu-application-file-include(24603)</ref></refs><vuln_soft><prod name="indexu" vendor="Nicecoder"><vers num="5.0.0"/><vers num="5.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-15" name="CVE-2006-0689" published="2006-02-15" seq="2006-0689" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Registration Form in TTS Time Tracking Software 3.0 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/69/summary.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24572">timetracking-registration-xss(24572)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425505/100/0/threaded">20060219 [eVuln] Time Tracking Software Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16630">16630</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0524">ADV-2006-0524</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18854">18854</ref></refs><vuln_soft><prod name="Time Tracking Software" vendor="Scheduling Management.com"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-15" name="CVE-2006-0690" published="2006-02-15" seq="2006-0690" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in TTS Time Tracking Software 3.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/69/summary.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24571">timetracking-multiple-sql-injection(24571)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425505/100/0/threaded">20060219 [eVuln] Time Tracking Software Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16630">16630</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0524">ADV-2006-0524</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18854">18854</ref></refs><vuln_soft><prod name="Time Tracking Software" vendor="Scheduling Management.com"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-15" name="CVE-2006-0691" published="2006-02-15" seq="2006-0691" severity="Medium" type="CVE"><desc><descript source="cve">edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbitrary data belonging to any account.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/69/summary.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24570">timetracking-edituser-auth-bypass(24570)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425505/100/0/threaded">20060219 [eVuln] Time Tracking Software Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16630">16630</ref><ref source="BID" url="http://www.securityfocus.com/bid/16731">16731</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0524">ADV-2006-0524</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18854">18854</ref></refs><vuln_soft><prod name="Time Tracking Software" vendor="Scheduling Management.com"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-11-05" name="CVE-2006-0692" published="2006-02-15" seq="2006-0692" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php.</descript></desc><sols><sol source="nvd">The vendor has supplied a patch which is available at:
http://www.hotscripts.com/Detailed/51138.html</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/67/summary.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24567">phpmysqltimesheet-multiple-sql-injection(24567)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425316/100/0/threaded">20060217 [eVuln] PHP/MYSQL Timesheet Multiple SQL Injection Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16620">16620</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0522">ADV-2006-0522</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18822">18822</ref><ref source="SREASON" url="http://securityreason.com/securityalert/451">451</ref></refs><vuln_soft><prod name="PHP/MYSQL Timesheet" vendor="Carey Briggs"><vers num="1"/><vers num="2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-15" name="CVE-2006-0693" published="2006-02-15" seq="2006-0693" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in rb_auth.php in Roberto Butti CALimba 0.99.2 beta and earlier allow remote attackers to execute arbitrary SQL commands and bypass login authentication via the (1) login and (2) password parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/68/summary.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24578">calimba-rbauth-sql-injection(24578)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425364/100/0/threaded">20060217 [eVuln] CALimba Authentication Bypass Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16632">16632</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0523">ADV-2006-0523</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18856">18856</ref><ref source="SREASON" url="http://securityreason.com/securityalert/453">453</ref></refs><vuln_soft><prod name="CALimba" vendor="Roberto Butti"><vers num="0.99.2 Beta"/><vers num="0.99.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-15" name="CVE-2006-0694" published="2006-02-15" seq="2006-0694" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the loaders (load_*.php) in Ansilove before 1.03 allows remote attackers to read arbitrary files via unspecified vectors involving &quot;converting files accessible by the webserver&quot;.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=392826"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0536">ADV-2006-0536</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18810">18810</ref><ref source="BID" url="http://www.securityfocus.com/bid/16603">16603</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24681">
ansilove-load-information-disclosure(24681)</ref></refs><vuln_soft><prod name="Ansilove" vendor="Ansilove"><vers num="1.02"/><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-15" name="CVE-2006-0695" published="2006-02-15" seq="2006-0695" severity="High" type="CVE"><desc><descript source="cve">Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them directly in the upload directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=392826"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0536">ADV-2006-0536</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18810">18810</ref><ref source="BID" url="http://www.securityfocus.com/bid/16603">16603</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24684">
ansilove-filename-code-execution(24684)</ref></refs><vuln_soft><prod name="Ansilove" vendor="Ansilove"><vers num="1.02"/><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-16" name="CVE-2006-0696" published="2006-02-15" seq="2006-0696" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Zen Cart before 1.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=392886"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0546">ADV-2006-0546</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18801">18801</ref><ref source="OSVDB" url="http://www.osvdb.org/23110">23110</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24701">zencart-multiple-sql-injection(24701)</ref></refs><vuln_soft><prod name="Zen Cart" vendor="Zen Cart"><vers num="1.2.6d"/><vers num="1.2.5d"/><vers num="1.2.4.1"/><vers num="1.2.4d"/><vers num="1.2.3d"/><vers num="1.2.2d"/><vers num="1.2.1 Patch1"/><vers num="1.2.1d"/><vers num="1.2.0d"/><vers num="1.1.4d"/><vers num="1.1.3d"/><vers num="1.1.2d"/><vers num="1.1.1d"/><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-16" name="CVE-2006-0697" published="2006-02-15" seq="2006-0697" severity="High" type="CVE"><desc><descript source="cve">Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=392886"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0546">ADV-2006-0546</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18801">18801</ref></refs><vuln_soft><prod name="Zen Cart" vendor="Zen Cart"><vers num="1.2.6d"/><vers num="1.2.5d"/><vers num="1.2.4.1"/><vers num="1.2.4d"/><vers num="1.2.3d"/><vers num="1.2.2d"/><vers num="1.2.1 Patch1"/><vers num="1.2.1d"/><vers num="1.2.0d"/><vers num="1.1.4d"/><vers num="1.1.3d"/><vers num="1.1.2d"/><vers num="1.1.1d"/><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-16" name="CVE-2006-0698" published="2006-02-15" seq="2006-0698" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerabilities in Zen Cart before 1.2.7 allow remote attackers to cause unknown impact via unspecified vectors related to &quot;other attempted exploits&quot; other than SQL injection.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=392886"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0546">ADV-2006-0546</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18801">18801</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24701">zencart-multiple-sql-injection(24701)</ref></refs><vuln_soft><prod name="Zen Cart" vendor="Zen Cart"><vers num="1.2.6d"/><vers num="1.2.5d"/><vers num="1.2.4.1"/><vers num="1.2.4d"/><vers num="1.2.3d"/><vers num="1.2.2d"/><vers num="1.2.1 Patch1"/><vers num="1.2.1d"/><vers num="1.2.0d"/><vers num="1.1.4d"/><vers num="1.1.3d"/><vers num="1.1.2d"/><vers num="1.1.1d"/><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-22" name="CVE-2006-0699" published="2006-02-15" seq="2006-0699" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://insecurity.altervista.org/index.php?m=02&amp;y=06&amp;entry=entry060213-221217"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0562">ADV-2006-0562</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18814">18814</ref><ref source="BID" url="http://www.securityfocus.com/bid/16638">16638</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24669">qwikiwiki-search-xss(24669)</ref></refs><vuln_soft><prod name="QWikiWiki" vendor="David Barrett"><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/><vers num="1.2"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0700" published="2006-02-15" seq="2006-0700" severity="Medium" type="CVE"><desc><descript source="cve">imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/424745/30/0/threaded">20060211 imageVue16.1 upload vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16594">16594</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18802">18802</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24641">imagevue-multiple-information-disclosure(24641)</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0570">ADV-2006-0570</ref></refs><vuln_soft><prod name="ImageVue" vendor="ImageVue"><vers num="0.16.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-16" name="CVE-2006-0701" published="2006-02-15" seq="2006-0701" severity="Medium" type="CVE"><desc><descript source="cve">readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/424745/30/0/threaded">20060211 imageVue16.1 upload vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16594">16594</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18802">18802</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24641">imagevue-multiple-information-disclosure(24641)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0570">ADV-2006-0570</ref></refs><vuln_soft><prod name="ImageVue" vendor="ImageVue"><vers num="0.16.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-16" name="CVE-2006-0702" published="2006-02-15" seq="2006-0702" severity="Medium" type="CVE"><desc><descript source="cve">admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter.  NOTE: due to the lack of details, the specific vulnerability type cannot be determined, although it might be due to directory traversal.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/424745/30/0/threaded">20060211 imageVue16.1 upload vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16594">16594</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18802">18802</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0570">ADV-2006-0570</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24633">
imagevue-upload-file-upload(24633)</ref></refs><vuln_soft><prod name="ImageVue" vendor="ImageVue"><vers num="0.16.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-16" name="CVE-2006-0703" published="2006-02-15" seq="2006-0703" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in index.php in imageVue 16.1 has unknown impact, probably a cross-site scripting (XSS) vulnerability involving the query string that is not quoted when inserted into style and body tags, as demonstrated using a bgcol parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/424745/30/0/threaded">20060211 imageVue16.1 upload vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16594">16594</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18802">18802</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0570">ADV-2006-0570</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/440586/100/100/threaded">20060719 Re: imageVue16.1 upload vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/450047/100/100/threaded">20061029 Re: imageVue16.1 upload vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24642">
imagevue-index-sql-injection(24642)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/429">429</ref></refs><vuln_soft><prod name="ImageVue" vendor="ImageVue"><vers num="0.16.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0704" published="2006-02-15" seq="2006-0704" severity="Low" type="CVE"><desc><descript source="cve">iE Integrator 4.4.220114, when configured without a &quot;bespoke error page&quot; in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory, which results in an error message that displays the installation path, web server name, IP, and port, session cookie information, and the IIS system username.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.irmplc.com/advisory016.htm"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0568">ADV-2006-0568</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18813">18813</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24714">
ieintegrator-error-information-disclosure(24714)</ref></refs><vuln_soft><prod name="iE Integrator" vendor="iE"><vers num="4.4.220114"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0705" published="2006-02-15" seq="2006-0705" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in a logging function as used by various SFTP servers, including (1) AttachmateWRQ Reflection for Secure IT UNIX Server before 6.0.0.9, (2) Reflection for Secure IT Windows Server before 6.0 build 38, (3) F-Secure SSH Server for Windows before 5.3 build 35, (4) F-Secure SSH Server for UNIX 3.0 through 5.0.8, (5) SSH Tectia Server 4.3.6 and earlier and 4.4.0, and (6) SSH Shell Server 3.2.9 and earlier, allows remote authenticated users to execute arbitrary commands via unspecified vectors, involving crafted filenames and the stat command.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://support.wrq.com/techdocs/1882.html"></ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/419241">VU#419241</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16625">16625</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0554">ADV-2006-0554</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0555">ADV-2006-0555</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015619">1015619</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18828">18828</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18843">18843</ref><ref source="BID" url="http://www.securityfocus.com/bid/16640">16640</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24651">sftp-logging-format-string(24651)</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-13.xml">
GLSA-200703-13</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24516">
24516</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120654385125315&amp;w=2">HPSBTU02322</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1008/references">ADV-2008-1008</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29552">29552</ref></refs><vuln_soft><prod name="Reflection for Secure IT Server" vendor="AttachmateWRQ"><vers edition="Unix" num="6.0"/><vers edition="Win" num="6.0"/></prod><prod name="F-Secure SSH Server" vendor="F-Secure"><vers num="3.1.0 Build9"/><vers num="3.1.0"/><vers num="3.0.9"/><vers num="3.0.8"/><vers num="3.0.7"/><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0.0"/><vers num="5.0"/><vers edition="Win" num="5.3"/><vers edition="Win" num="5.2"/><vers edition="Win" num="5.1"/><vers edition="Unix" num="3.2.3"/><vers edition="Unix" num="3.2.0"/><vers edition="Unix" num="3.1.0"/><vers edition="Unix" num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" discovered="2006-02-13" modified="2008-08-18" name="CVE-2006-0706" published="2006-02-15" seq="2006-0706" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in eintrag.php in G&amp;#xe4;stebuch (Gastebuch) before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the URL, which is used in the homepage parameter.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Gastebuch, Gastebuch, 1.3.3</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113986789801121&amp;w=2">20060213 XSS vulnerability in guestbook-php-script</ref><ref source="" url="http://www.php4scripte.de/index.php"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0566">ADV-2006-0566</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18849">18849</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113986789801121&amp;w=2">20060213 XSS vulnerability in guestbook-php-script</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16615">16615</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24670">gastebuch-homepage-xss(24670)</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113986789801121&amp;w=2">20060213 XSS vulnerability in guestbook-php-script</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113986789801121&amp;w=2">20060213 XSS vulnerability in guestbook-php-script</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113986789801121&amp;w=2">20060213 XSS vulnerability in guestbook-php-script</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113986789801121&amp;w=2">20060213 XSS vulnerability in guestbook-php-script</ref></refs><vuln_soft><prod name="Gastebuch" vendor="Gastebuch"><vers num="1.3.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0707" published="2006-02-15" seq="2006-0707" severity="Medium" type="CVE"><desc><descript source="cve">PyBlosxom before 1.3.2, when running on certain webservers, allows remote attackers to read arbitrary files via an HTTP request with multiple leading / (slash) characters, which is accessed using the PATH_INFO variable.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=391800"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0571">ADV-2006-0571</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18858">18858</ref><ref source="BID" url="http://www.securityfocus.com/bid/16641">16641</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24730">
pyblosxom-pathinfo-information-disclosure(24730)</ref></refs><vuln_soft><prod name="PyBlosxom" vendor="PyBlosxom"><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2006-0708" published="2006-02-15" seq="2006-0708" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containing a long URL ending in .wma, (2) a pls file containing a File1 field with a long URL ending in .wma, or (3) an m3u file with a long filename, variants of CVE-2005-3188 and CVE-2006-0476.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424903/100/0/threaded">20060213 New winamp m3u/pls .WMA &amp; .M3U Extension overflows</ref><ref source="BID" url="http://www.securityfocus.com/bid/16623">16623</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015621">1015621</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0613">ADV-2006-0613</ref><ref source="" url="http://forums.winamp.com/showthread.php?s=&amp;threadid=238648"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24741">
winamp-m3u-filename-bo(24741)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24740">
winamp-m3u-wma-bo(24740)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24739">
winamp-pls-file1-bo(24739)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/444">444</ref><ref source="SREASON" url="http://securityreason.com/securityalert/492">492</ref></refs><vuln_soft><prod name="Winamp" vendor="NullSoft"><vers num="5.13"/><vers num="5.12"/><vers num="5.11"/><vers num="5.094"/><vers num="5.093"/><vers num="5.091"/><vers num="5.09"/><vers num="5.08e"/><vers num="5.08d"/><vers num="5.08c"/><vers num="5.07"/><vers num="5.06"/><vers num="5.05"/><vers num="5.04"/><vers num="5.03"/><vers num="5.02"/><vers num="5.01"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-06" name="CVE-2006-0709" published="2006-02-15" seq="2006-0709" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Metamail 2.7-50 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via e-mail messages with a long boundary attribute, a different vulnerability than CVE-2004-0105.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=352482"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16611">16611</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0565">ADV-2006-0565</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18796">18796</ref><ref adv="1" patch="1" source="MANDRIVA" url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:047">MDKSA-2006:047</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0217.html">RHSA-2006:0217</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015654">1015654</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18987">18987</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19000">19000</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_05_sr.html">SUSE-SR:2006:005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19130">19130</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-995">DSA-995</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19226">19226</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-16.xml">GLSA-200603-16</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19304">19304</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24702">
metamail-boundary-bo(24702)</ref></refs><vuln_soft><prod name="Metamail" vendor="Metamail Corporation"><vers num="2.7.50"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-26" name="CVE-2006-0710" published="2006-02-15" seq="2006-0710" severity="High" type="CVE"><desc><descript source="cve">Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code via a crafted LDAP request, as demonstrated by ProtoVer Sample LDAP.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2006-February/002925.html">[Dailydave] 20060213 eddy 0day</ref><ref source="BID" url="http://www.securityfocus.com/bid/16635">16635</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0567">ADV-2006-0567</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18818">18818</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24700">isode-mvault-ldap-dos(24700)</ref></refs><vuln_soft><prod name="M-Vault Server" vendor="Isode"><vers num="11.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0711" published="2006-02-15" seq="2006-0711" severity="Medium" type="CVE"><desc><descript source="cve">The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2006-3/advisory/"></ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=392562&amp;group_id=2874"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0564">ADV-2006-0564</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18785">18785</ref><ref source="BID" url="http://www.securityfocus.com/bid/16651">16651</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24737">
neomail-neomailprefs-bypass-security(24737)</ref></refs><vuln_soft><prod name="NeoMail" vendor="NeoMail"><vers num="1.28" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0712" published="2006-02-15" seq="2006-0712" severity="Medium" type="CVE"><desc><descript source="cve">mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, which allows remote attackers to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.squishdot.org/1139510883"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0551">ADV-2006-0551</ref><ref source="BID" url="http://www.securityfocus.com/bid/16667">16667</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18868">18868</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24659">squishdot-mailhtml-header-injection(24659)</ref></refs><vuln_soft><prod name="Squishdot" vendor="Squishdot"><vers num="1.5.0"/><vers num="1.4.1"/><vers num="1.4.0"/><vers num="1.2.1"/><vers num="1.1.0"/><vers num="1.0.0"/><vers num="0.7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0713" published="2006-02-15" seq="2006-0713" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) lang parameter in docs/index.php and the language parameter in (2) install/install.php, (3) install/sec_stage_install.php, (4) install/third_stage_install.php, and (5) install/forth_stage_install.php.  NOTE: direct static code injection is resultant from this issue, as demonstrated by inserting PHP code into the username, which is inserted into linpha.log, which is accessible from the directory traversal.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424729/100/0/threaded">20060211 Linpha &lt;= 1.0 multiple arbitrary local inclusion</ref><ref source="" url="http://retrogod.altervista.org/linpha_10_local.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16592">16592</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0535">ADV-2006-0535</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18808">18808</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24663">
linpha-index-file-include(24663)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/426">426</ref></refs><vuln_soft><prod name="LinPHA" vendor="LinPHA"><vers num="1.0"/><vers num="0.9.4"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers num="0.9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0714" published="2006-02-15" seq="2006-0714" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the adodbpath parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424902/100/0/threaded">20060213 EGS Enterprise Groupware System 1.0 rc4 remote commands execution &amp; FlySpray 0.9.7 remote commands execution</ref><ref source="" url="http://retrogod.altervista.org/egs_10rc4_php5_incl_xpl.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16618">16618</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0569">ADV-2006-0569</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18847">18847</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24735">
flyspray-adodbpath-file-include(24735)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/432">432</ref></refs><vuln_soft><prod name="Flyspray" vendor="Flyspray"><vers num="0.9.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0715" published="2006-02-15" seq="2006-0715" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424958/100/0/threaded">20060214 XSS bugs and SQL injection in sNews</ref><ref source="BID" url="http://www.securityfocus.com/bid/16647">16647</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0297.html">20060214 XSS and SQL injection in sNews</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24674">snews-comment-xss(24674)</ref></refs><vuln_soft><prod name="sNews" vendor="Solucija"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0716" published="2006-02-15" seq="2006-0716" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424958/100/0/threaded">20060214 XSS bugs and SQL injection in sNews</ref><ref source="BID" url="http://www.securityfocus.com/bid/16647">16647</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0297.html">20060214 XSS and SQL injection in sNews</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24675">snews-index-sql-injection(24675)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/431">431</ref></refs><vuln_soft><prod name="sNews" vendor="Solucija"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0717" published="2006-02-15" seq="2006-0717" severity="Medium" type="CVE"><desc><descript source="cve">IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2006-February/002921.html">[Dailydave] 20060211 IBM Tivoli Directory Server 0day</ref><ref source="BID" url="http://www.securityfocus.com/bid/16593">16593</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0537">ADV-2006-0537</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18779">18779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24619">tivoli-directory-ldap-dos(24619)</ref><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg21230820"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015653">1015653</ref></refs><vuln_soft><prod name="Tivoli Directory Server" vendor="IBM"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-0718" published="2006-02-15" seq="2006-0718" severity="Medium" type="CVE"><desc><descript source="cve">The Internet Key Exchange version 1 (IKEv1) implementation in Avaya VSU 100, 2000, 7500, 10000, and CSU 5000, when running IPSec, allows remote attackers to cause a denial of service (crash) via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-043.htm"></ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/226364">VU#226364</ref><ref source="BID" url="http://www.securityfocus.com/bid/16613">16613</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18836">18836</ref></refs><vuln_soft><prod name="VSU 100" vendor="Avaya"><vers num="3.2.40"/></prod><prod name="CSU 5000" vendor="Avaya"><vers num="3.2.40"/></prod><prod name="VSU 2000" vendor="Avaya"><vers num="3.2.40"/></prod><prod name="VSU 7500" vendor="Avaya"><vers num="3.2.40"/></prod><prod name="VSU 10000" vendor="Avaya"><vers num="3.2.40"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0719" published="2006-02-15" seq="2006-0719" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in member_login.php in PHP Classifieds 6.18 through 6.20 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter, which is used by the E-mail address field, and (2) password parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424955/100/0/threaded">20060214 SQL injection in PHP Classifieds 6.20</ref><ref source="" url="http://www.deltascripts.com/board/viewtopic.php?id=7234"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16642">16642</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0600">ADV-2006-0600</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18881">18881</ref><ref source="SREASON" url="http://securityreason.com/securityalert/424">424</ref></refs><vuln_soft><prod name="PHP Classifieds" vendor="DeltaScripts"><vers num="6.20"/><vers num="6.19"/><vers num="6.18"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2006-0720" published="2006-02-23" seq="2006-0720" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Nullsoft Winamp 5.12 and 5.13 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted .m3u file that causes an incorrect strncpy function call when the player pauses or stops the file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.nsfocus.com/english/homepage/research/0601.htm"></ref><ref source="" url="http://forums.winamp.com/showthread.php?threadid=238648"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425888/100/0/threaded">20060223 NSFOCUS SA2006-01 : Winamp m3u File Processing Buffer Overflow Vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16785">16785</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015675">1015675</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24740">
winamp-m3u-wma-bo(24740)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/476">476</ref></refs><vuln_soft><prod name="Winamp" vendor="Nullsoft"><vers num="5.12"/><vers num="5.13"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0721" published="2006-02-16" seq="2006-0721" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_userid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://hamid.ir/security/runcms.txt"></ref><ref source="" url="http://www.runcms.org/public/modules/forum/viewtopic.php?topic_id=4003&amp;forum=18"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16652">16652</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18831">18831</ref><ref source="" url="http://www.runcms.org/public/modules/forum/viewtopic.php?topic_id=4003&amp;forum=18"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425293/100/0/threaded">20060216 RUNCMS 1.3a SQL injection</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24676">runcms-pmlite-sql-injection(24676)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0572">ADV-2006-0572</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015626">1015626</ref></refs><vuln_soft><prod name="RunCMS" vendor="RunCMS"><vers num="1.2"/><vers num="1.3a"/><vers num="1.3a2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0722" published="2006-02-16" seq="2006-0722" severity="Low" type="CVE"><desc><descript source="cve">settings.php in Reamday Enterprises Magic Downloads 1.1.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5) confirm_passwd variables, which are not initialized.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/73/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0602">ADV-2006-0602</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18877">18877</ref><ref source="BID" url="http://www.securityfocus.com/bid/16665">16665</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425601/30/6830/threaded">

20060221 [eVuln] Magic Downloads Unauthorized Data Modification</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24615">
magicdownloads-settings-access(24615)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/468">468</ref></refs><vuln_soft><prod name="Magic Downloads" vendor="Reamday Enterprises"><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2007-10-18" name="CVE-2006-0723" published="2006-02-16" seq="2006-0723" severity="Low" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in preview.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the php_script_path parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/72/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0603">ADV-2006-0603</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18878">18878</ref><ref source="BID" url="http://www.securityfocus.com/bid/16660">16660</ref><ref source="BID" url="http://www.securityfocus.com/bid/16665">16665</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24608">magicnewslite-preview-file-include(24608)</ref></refs><vuln_soft><prod name="Magic News Lite" vendor="Reamday Enterprises"><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0724" published="2006-02-16" seq="2006-0724" severity="Low" type="CVE"><desc><descript source="cve">profile.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5) confirm_passwd variables, which are not initialized.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/72/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0603">ADV-2006-0603</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18878">18878</ref><ref source="BID" url="http://www.securityfocus.com/bid/16665">16665</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24610">
magicnewslite-profile-access(24610)</ref></refs><vuln_soft><prod name="Magic News Lite" vendor="Reamday Enterprises"><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-07-17" name="CVE-2006-0725" published="2006-02-16" seq="2006-0725" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the _PX_config[manager_path] parameter.  NOTE: this is a different executable and affected version than CVE-2006-2645.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0599">ADV-2006-0599</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18883">18883</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015624">1015624</ref><ref source="BID" url="http://www.securityfocus.com/bid/16662">16662</ref><ref source="OSVDB" url="http://www.osvdb.org/23204">23204</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24697">plumecms-prepend-file-include(24697)</ref><ref source="" url="http://plume-cms.net/news/77-Security-Notice-Please-Update-Your-Prependphp-File"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27699">plumecms-frontinc-prepend-file-include(27699)</ref></refs><vuln_soft><prod name="Plume CMS" vendor="Plume CMS"><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-05" name="CVE-2006-0726" published="2006-02-16" seq="2006-0726" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in linking.php in CPG-Nuke Dragonfly CMS 9.0.6.1 allows remote attackers to inject arbitrary web script or HTML via a URI that is generated when creating a list of online users.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://dragonflycms.org/Forums/viewtopic/t=14751.html"></ref><ref source="" url="http://dragonflycms.org/Forums/viewtopic/t=14877/postdays=0/postorder=asc/start=15.html"></ref><ref source="" url="http://dragonflycms.org/cvs/html/includes/functions/linking.php?d=9.23-9.22"></ref><ref source="" url="http://dragonflycms.org/cvs/html/includes/functions/linking.php?b=9.19.2"></ref><ref source="OSVDB" url="http://www.osvdb.org/23060">23060</ref><ref source="BID" url="http://www.securityfocus.com/bid/16781">16781</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18919">18919</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0688">
ADV-2006-0688</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24842">
cpg-dragonfly-linking-xss(24842)</ref></refs><vuln_soft><prod name="Dragonfly CMS" vendor="CPG-Nuke"><vers num="9.0.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0727" published="2006-02-16" seq="2006-0727" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in mstrack.php in MusOX DF MSAnalysis (DFMSA), as used in some environments that use CPG-Nuke Dragonfly CMS, allows remote attackers to trigger path disclosure from a SQL syntax error, and possibly execute arbitrary SQL commands, via certain query data, probably involving the profile name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://dragonflycms.org/Forums/viewtopic/t=14751.html"></ref><ref source="" url="http://dragonflycms.org/Forums/viewtopic/t=14877/postdays=0/postorder=asc/start=15.html"></ref><ref source="" url="http://dragonflycms.org/cvs/html/includes/functions/linking.php?d=9.23-9.22"></ref><ref source="" url="http://dragonflycms.org/cvs/html/includes/functions/linking.php?b=9.19.2"></ref><ref source="OSVDB" url="http://www.osvdb.org/23060">23060</ref><ref source="BID" url="http://www.securityfocus.com/bid/16783">16783</ref><ref source="OSVDB" url="http://www.osvdb.org/23250">23250</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0688">
ADV-2006-0688</ref></refs><vuln_soft><prod name="DF MSAnalysis" vendor="MusOX"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0728" published="2006-02-16" seq="2006-0728" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in search.php in webSPELL 4.01.00 and earlier allows remote attackers to inject arbitrary SQL commands via the title_op parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.webspell.org/index.php?site=news_comments&amp;newsID=49&amp;lang=en"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0606">ADV-2006-0606</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18885">18885</ref><ref source="" url="http://www.webspell.org/index.php?site=news_comments&amp;newsID=49&amp;lang=en"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16673">16673</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24708">webspell-search-sql-injection(24708)</ref></refs><vuln_soft><prod name="webSPELL" vendor="webSPELL Designs"><vers num="4.01.00" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-0729" published="2006-02-16" seq="2006-0729" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in functions.php in Teca Diary PE 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) yy, (2) mm, and (3) dd parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/75/summary.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24643">tecadiary-functions-sql-injection(24643)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18876">18876</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0615">ADV-2006-0615</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015674">1015674</ref><ref source="BID" url="http://www.securityfocus.com/bid/16686">16686</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425892/30/6800/threaded">

20060223 [eVuln] Teca Diary PE SQL Injection Vulnerability</ref><ref source="SREASON" url="http://securityreason.com/securityalert/477">477</ref></refs><vuln_soft><prod name="Teca Diary" vendor="Teca Scripts"><vers num="Personal 1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-02-26" name="CVE-2006-0730" published="2006-02-16" seq="2006-0730" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) &quot;potential hangs&quot; in the APPEND command and &quot;potential crashes&quot; in (2) dovecot-auth and (3) imap/pop3-login.  NOTE: vector 2 might be related to a double free vulnerability.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="MLIST" url="http://www.dovecot.org/list/dovecot/2006-February/011367.html">[Dovecot] 20060208 1.0beta3 released</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0549">ADV-2006-0549</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18870">18870</ref><ref source="BID" url="http://www.securityfocus.com/bid/16672">16672</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24709">dovecot-append-dos(24709)</ref></refs><vuln_soft><prod name="Dovecot" vendor="Timo Sirainen"><vers num="1.0Beta2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0731" published="2006-02-16" seq="2006-0731" severity="Medium" type="CVE"><desc><descript source="cve">WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter, which loads the URL inside a frame.</descript></desc><loss_types><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425056/100/0/threaded">20060215 CYBSEC - Security Pre-Advisory: Phishing Vector in SAP BC</ref><ref adv="1" source="" url="http://www.cybsec.com/vuln/CYBSEC_Security_Pre-Advisory_Phishing_Vector_in_SAP_BC.pdf"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0611">ADV-2006-0611</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18880">18880</ref><ref source="BID" url="http://www.securityfocus.com/bid/16671">16671</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015639">1015639</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24751">sapbc-admin-spoofing(24751)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/434012/30/4980/threaded">20060515 CYBSEC - Security Advisory: Phishing Vector in SAP BC (BusinessConnector)</ref></refs><vuln_soft><prod name="Business Connector" vendor="SAP"><vers num="Core Fix 7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-02-15" modified="2006-06-01" name="CVE-2006-0732" published="2006-02-16" seq="2006-0732" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the the fullName parameter to (1) sapbc/SAP/chopSAPLog.dsp or (2) invoke/sap.monitor.rfcTrace/deleteSingle.  Details will be updated after the grace period has ended.  NOTE: SAP Business Connector is an OEM version of webMethods Integration Server.  webMethods states that this issue can only occur when the product is installed as root/admin, and if the attacker has access to a general purpose port; however, both are discouraged in the documentation.  In addition, the attacker must already have acquired administrative privileges through other means.</descript></desc><sols><sol source="nvd">Apply patches (see SAP note 906401 and 908349).</sol></sols><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425048/100/0/threaded">20060215 CYBSEC - Security Pre-Advisory: Arbitrary File Read/Delete in SAPBC</ref><ref adv="1" source="" url="http://www.cybsec.com/vuln/CYBSEC_Security_Pre-Advisory_Arbitrary_File_Read_or_Delete_in_SAP_BC.pdf"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0611">ADV-2006-0611</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18880">18880</ref><ref source="BID" url="http://www.securityfocus.com/bid/16668">16668</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015639">1015639</ref><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2006/May/0291.html">20060515 CYBSEC - Security Advisory: Arbitrary File Read/Delete in SAP BC (Business Connector)</ref><ref source="" url="http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_Arbitrary_File_Read_or_Delete_in_SAP_BC.pdf"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016122">1016122</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/434014/30/4980/threaded">
20060515 CYBSEC - Security Advisory: Arbitrary File Read/Delete in SAP BC(Business Connector)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016090">
1016090</ref></refs><vuln_soft><prod name="Business Connector" vendor="SAP"><vers num="4.6"/><vers num="4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-24" name="CVE-2006-0733" published="2006-02-16" seq="2006-0733" severity="Low" type="CVE"><desc><descript source="cve">** DISPUTED ** Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the &quot;author&apos;s website&quot; field.  NOTE: followup comments to the researcher&apos;s web log suggest that this issue is only exploitable by the same user who injects the XSS, so this might not be a vulnerability.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425043/100/0/threaded">20060214 [myimei]WordPress2.0.0~autors?website~XSS attack</ref><ref adv="1" source="" url="http://myimei.com/security/2006-02-15/wordpress200autors-websitexss-attack.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16656">16656</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24736">
wordpress-authorswebsite-xss(24736)</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0734" published="2006-02-16" seq="2006-0734" severity="Medium" type="CVE"><desc><descript source="cve">The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.6 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a backslash character at the end of a connection string to UDP port 27015.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16619">16619</ref><ref source="" url="http://aluigi.altervista.org/adv/csdos.txt"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33505">halflife-svcheckforduplicatenames-dos(33505)</ref></refs><vuln_soft><prod name="Half-Life CSTRIKE Dedicated Server" vendor="Valve Software"><vers num="1.6 Windows" prev="1"/><vers num="1.6 Linux" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0735" published="2006-02-16" seq="2006-0735" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in BBcode.pm in M. Blom HTML::BBCode 1.04 and earlier, as used in products such as My Blog before 1.65, allows remote attackers to inject arbitray Javascript via a javascript URI in an (1) img or (2) url BBcode tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425087/100/0/threaded">20060215 [eVuln] My Blog BBCode XSS Vulnerabilities</ref><ref adv="1" patch="1" source="" url="http://evuln.com/vulns/79/summary.html"></ref><ref patch="1" source="" url="http://fuzzymonkey.net/forum/viewtopic.php?t=856"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16659">16659</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425113/100/0/threaded">20060215 [eVuln] M. Blom HTML::BBCode perl module XSS Vulnerabilities</ref><ref adv="1" patch="1" source="" url="http://www.evuln.com/vulns/80/summary.html"></ref><ref source="" url="http://menno.b10m.net/perl/HTML-BBCode/Changes"></ref><ref source="" url="http://menno.b10m.net/perl/dists/HTML-BBCode-1.05.tar.gz"></ref><ref adv="1" patch="1" source="" url="http://evuln.com/vulns/80/summary.html"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18905">18905</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0614">ADV-2006-0614</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0642">ADV-2006-0642</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18925">18925</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24668">myblog-bbcode-xss(24668)</ref></refs><vuln_soft><prod name="My Blog" vendor="FuzzyMonkey"><vers num="1.0"/><vers num="1.2"/><vers num="1.21"/><vers num="1.22"/><vers num="1.23"/><vers num="1.3"/><vers num="1.31"/><vers num="1.4"/><vers num="1.5"/><vers num="1.51"/><vers num="1.52"/><vers num="1.6"/><vers num="1.61"/><vers num="1.62"/><vers num="1.63"/><vers num="1.64"/></prod><prod name="HTML-BBCode" vendor="M_Blom"><vers num="1.04"/><vers num="1.03"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0736" published="2006-02-27" seq="2006-0736" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_10_casa.html">SUSE-SA:2006:010</ref><ref source="BID" url="http://www.securityfocus.com/bid/16779">16779</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0693">ADV-2006-0693</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18995">18995</ref></refs><vuln_soft><prod name="Open Enterprise Server" vendor="Novell"><vers num="1"/></prod><prod name="Linux Desktop" vendor="Novell"><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0737" published="2006-02-16" seq="2006-0737" severity="Medium" type="CVE"><desc><descript source="cve">eStara SIP softphone allows remote attackers to cause a denial of service (crash) via a SIP OPTIONS request with a negative Expires field.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424943/100/0/threaded">20060214 eStara SIP softphone several message-processing vulnerabilities</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0607">ADV-2006-0607</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18872">18872</ref><ref source="BID" url="http://www.securityfocus.com/bid/16629">16629</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24677">
estara-neg-integer-dos(24677)</ref></refs><vuln_soft><prod name="SoftPhone" vendor="eStara"><vers num="3.0.1.47" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0738" published="2006-02-16" seq="2006-0738" severity="Medium" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in eStara SIP softphone allow remote attackers to cause a denial of service (hang) via SIP INVITE requests with format string specifiers in the SDP session description, as demonstrated using (1) the field name, (2) the o field (owner/creator and session identifier), or (3) the m field (media name and transport address).</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424943/100/0/threaded">20060214 eStara SIP softphone several message-processing vulnerabilities</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0607">ADV-2006-0607</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18872">18872</ref><ref source="BID" url="http://www.securityfocus.com/bid/16629">16629</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24678">
estara-sdp-format-string(24678)</ref></refs><vuln_soft><prod name="SoftPhone" vendor="eStara"><vers num="3.0.1.47" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-17" name="CVE-2006-0739" published="2006-02-16" seq="2006-0739" severity="Medium" type="CVE"><desc><descript source="cve">eStara SIP softphone allows remote attackers to cause a denial of service (crash) via an INVITE request with a Content-Length field that has more than 9 digits.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424943/100/0/threaded">20060214 eStara SIP softphone several message-processing vulnerabilities</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0607">ADV-2006-0607</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18872">18872</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24679">estara-content-length-dos(24679)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16629">16629</ref></refs><vuln_soft><prod name="SoftPhone" vendor="eStara"><vers num="3.0.1.47" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-0741" published="2006-03-06" seq="2006-0741" severity="Low" type="CVE"><desc><descript source="cve">Linux kernel before 2.6.15.5, when running on Intel processors, allows local users to cause a denial of service (&quot;endless recursive fault&quot;) via unknown attack vectors related to a &quot;bad elf entry address.&quot;</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.5"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0804">ADV-2006-0804</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00003.html">FEDORA-2006-131</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015724">1015724</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19083">19083</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19108">19108</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25001">kernel-elf-dos(25001)</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-263-1">USN-263-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/16925">16925</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19220">19220</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:059">MDKSA-2006:059</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0493.html">RHSA-2006:0493</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20237">20237</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1097">DSA-1097</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20671">20671</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0437.html">RHSA-2006:0437</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21136">21136</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21745">21745</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21983">21983</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:025">
MDKSA-2007:025</ref><ref source="OSVDB" url="http://www.osvdb.org/23607">
23607</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:059">MDKSA-2006:059</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:025">MDKSA-2007:025</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.15 rc7"/><vers num="2.6.15 rc6"/><vers num="2.6.15 rc5"/><vers num="2.6.15 rc4"/><vers num="2.6.15 rc3"/><vers num="2.6.14 rc2"/><vers num="2.6.15 rc1"/><vers num="2.6.15"/><vers num="2.6.14 rc4"/><vers num="2.6.14 rc3"/><vers num="2.6.14 rc1"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14"/><vers num="2.6.13 rc7"/><vers num="2.6.13 rc6"/><vers num="2.6.13 rc4"/><vers num="2.6.13 rc1"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13"/><vers num="2.6.12 rc5"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc1"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11 rc1"/><vers num="2.6.11.9"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11.10"/><vers num="2.6.11.1"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8.1.5"/><vers num="2.6.8.1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="6.9" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-0742" published="2006-03-09" seq="2006-0742" severity="Medium" type="CVE"><desc><descript source="cve">The die_if_kernel function in arch/ia64/kernel/unaligned.c in Linux kernel 2.6.x before 2.6.15.6, possibly when compiled with certain versions of gcc, has the &quot;noreturn&quot; attribute set, which allows local users to cause a denial of service by causing user faults on Itanium systems.</descript></desc><sols><sol source="nvd">This vulnerability affects all verison of Linux kernel 2.6.x before 2.6.15.6, and may be exclusive to Itanium systems.</sol></sols><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="kernel.org" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.6">ChangeLog-2.6.15.6</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0856">ADV-2006-0856</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19078">19078</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-263-1">USN-263-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/16993">16993</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19220">19220</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:059">MDKSA-2006:059</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1097">DSA-1097</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20671">20671</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0437.html">RHSA-2006:0437</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21136">21136</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0575.html">RHSA-2006:0575</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21465">21465</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21983">21983</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/22417">22417</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U">
20060402-01-U</ref><ref source="OSVDB" url="http://www.osvdb.org/23660">
23660</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19607">
19607</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25068">
kernel-dieifkernel-dos(25068)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:059">MDKSA-2006:059</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers edition="PowerPC_smp" num="2.6.8.1.5"/><vers edition="PowerPC" num="2.6.8.1.5"/><vers edition="Power4_smp" num="2.6.8.1.5"/><vers edition="Power4" num="2.6.8.1.5"/><vers edition="Power3_smp" num="2.6.8.1.5"/><vers edition="Power3" num="2.6.8.1.5"/><vers edition="K7_smp" num="2.6.8.1.5"/><vers edition="K7" num="2.6.8.1.5"/><vers edition="AMD64_Xeon" num="2.6.8.1.5"/><vers edition="AMD64_K8_smp" num="2.6.8.1.5"/><vers edition="AMD64_K8" num="2.6.8.1.5"/><vers edition="AMD64" num="2.6.8.1.5"/><vers edition="686_smp" num="2.6.8.1.5"/><vers edition="686" num="2.6.8.1.5"/><vers edition="386" num="2.6.8.1.5"/><vers num="2.6.8.1.5"/><vers num="2.6.8.1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.15 rc5"/><vers num="2.6.15 rc4"/><vers num="2.6.15 rc3"/><vers num="2.6.14 rc2"/><vers num="2.6.15 rc1"/><vers num="2.6.15"/><vers num="2.6.14 rc4"/><vers num="2.6.14 rc3"/><vers num="2.6.14 rc1"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14"/><vers num="2.6.13 rc7"/><vers num="2.6.13 rc6"/><vers num="2.6.13 rc4"/><vers num="2.6.13 rc1"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13"/><vers num="2.6.12 rc5"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc1"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11 rc1"/><vers num="2.6.11.9"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11.10"/><vers num="2.6.11.1"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers num="2.6.1"/><vers num="2.6.0"/><vers edition="Itanium IA64 Montecito" num="2.6"/><vers edition="64-bit x86" num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-0743" published="2006-03-09" seq="2006-0743" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="apache.org" url="http://issues.apache.org/jira/browse/LOG4NET-67">LOG4NET-67</ref><ref source="BID" url="http://www.securityfocus.com/bid/17095">17095</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19241">19241</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0955">ADV-2006-0955</ref><ref source="OSVDB" url="http://www.osvdb.org/23905">23905</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25196">log4net-localsyslogappender-dos(25196)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_26_sr.html">SUSE-SR:2006:026</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22932">
22932</ref></refs><vuln_soft><prod name="Apache log4net" vendor="Apache Software Foundation"><vers num="1.2.9"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-18" name="CVE-2006-0744" published="2006-04-18" seq="2006-0744" severity="Low" type="CVE"><desc><descript source="cve">Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the wrong GS.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.5"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19639">19639</ref><ref source="BID" url="http://www.securityfocus.com/bid/17541">17541</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1390">ADV-2006-1390</ref><ref source="OSVDB" url="http://www.osvdb.org/24639">24639</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19735">19735</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25869">linux-uncanonical-addr-dos(25869)</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:086">MDKSA-2006:086</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20157">20157</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0493.html">RHSA-2006:0493</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20237">20237</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-302-1">USN-302-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20716">20716</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0437.html">RHSA-2006:0437</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21136">21136</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_42_kernel.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21179">21179</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_47_kernel.html">SUSE-SA:2006:047</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:150">MDKSA-2006:150</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21745">21745</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21983">21983</ref><ref source="FEDORA" url="http://lwn.net/Alerts/180820/">
FEDORA-2006-423</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1475">
ADV-2006-1475</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21498">
21498</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:086">MDKSA-2006:086</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:150">MDKSA-2006:150</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.16.4"/><vers num="2.6.16.3"/><vers num="2.6.16.2"/><vers num="2.6.16.1"/><vers num="2.6.16"/><vers num="2.6.16-rc7"/><vers num="2.6.16-rc6"/><vers num="2.6.16-rc5"/><vers num="2.6.16-rc4"/><vers num="2.6.16-rc3"/><vers num="2.6.16-rc2"/><vers num="2.6.16-rc1"/><vers num="2.6.15.7"/><vers num="2.6.15.6"/><vers num="2.6.15.5"/><vers num="2.6.15.4"/><vers num="2.6.15.3"/><vers num="2.6.15.2"/><vers num="2.6.15.1"/><vers num="2.6.15-rc7"/><vers num="2.6.15-rc6"/><vers num="2.6.15-rc5"/><vers num="2.6.15-rc4"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.15"/><vers num="2.6.14.7"/><vers num="2.6.14.6"/><vers num="2.6.14.5"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14-rc5"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.14"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13-rc7"/><vers num="2.6.13-rc6"/><vers num="2.6.13-rc5"/><vers num="2.6.13-rc4"/><vers num="2.6.13-rc3"/><vers num="2.6.13-rc2"/><vers num="2.6.13-rc1"/><vers num="2.6.13"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12-rc6"/><vers num="2.6.12-rc5"/><vers num="2.6.12-rc4"/><vers num="2.6.12-rc3"/><vers num="2.6.12-rc2"/><vers num="2.6.12-rc1"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11.10"/><vers num="2.6.11.9"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11-rc5"/><vers num="2.6.11-rc4"/><vers num="2.6.11-rc3"/><vers num="2.6.11-rc2"/><vers num="2.6.11-rc1"/><vers num="2.6.11"/><vers num="2.6.10-rc3"/><vers num="2.6.10-rc2"/><vers num="2.6.10-rc1"/><vers num="2.6.10"/><vers num="2.6.9-final"/><vers num="2.6.9-rc4"/><vers num="2.6.9-rc3"/><vers num="2.6.9-rc2"/><vers num="2.6.9-rc1"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8-rc4"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7-rc3"/><vers num="2.6.7-rc2"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc3"/><vers num="2.6.6-rc2"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5-rc3"/><vers num="2.6.5-rc2"/><vers num="2.6.5-rc1"/><vers num="2.6.5"/><vers num="2.6.4-rc3"/><vers num="2.6.4-rc2"/><vers num="2.6.4-rc1"/><vers num="2.6.4"/><vers num="2.6.3-rc4"/><vers num="2.6.3-rc3"/><vers num="2.6.3-rc2"/><vers num="2.6.3-rc1"/><vers num="2.6.3"/><vers num="2.6.2-rc3"/><vers num="2.6.2-rc2"/><vers num="2.6.2-rc1"/><vers num="2.6.2"/><vers num="2.6.1-rc3"/><vers num="2.6.1-rc2"/><vers num="2.6.1-rc1"/><vers num="2.6.1"/><vers num="2.6 test 9 CVS"/><vers num="2.6-test9"/><vers num="2.6-test8"/><vers num="2.6-test7"/><vers num="2.6-test6"/><vers num="2.6-test5"/><vers num="2.6-test4"/><vers num="2.6-test3"/><vers num="2.6-test2"/><vers num="2.6-test11"/><vers num="2.6-test10"/><vers num="2.6-test1"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-0745" published="2006-03-20" seq="2006-0745" severity="High" type="CVE"><desc><descript source="cve">X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428183/100/0/threaded">20060320 [CVE-2006-0745] X.Org Security Advisory: privilege escalation and DoS in X11R6.9, X11R7.0</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428230/100/0/threaded">20060320 Re: [CVE-2006-0745] X.Org Security Advisory: privilege escalation and DoS in X11R6.9, X11R7.0</ref><ref adv="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:056">MDKSA-2006:056</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17169">17169</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19311">19311</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_16_xorgx11server.html">SUSE-SA:2006:016</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00026.html">FEDORA-2006-172</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102252-1">102252</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1017">ADV-2006-1017</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1028">ADV-2006-1028</ref><ref source="OSVDB" url="http://www.osvdb.org/24000">24000</ref><ref source="OSVDB" url="http://www.osvdb.org/24001">24001</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015793">1015793</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19256">19256</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19307">19307</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19316">19316</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25341">xorg-geteuid-privilege-escalation(25341)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19676">19676</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1697">oval:org.mitre.oval:def:1697</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:056">MDKSA-2006:056</ref><ref source="SREASON" url="http://securityreason.com/securityalert/606">606</ref></refs><vuln_soft><prod name="Fedora" vendor="Red Hat"><vers num="Core 5.0"/></prod><prod name="X11R7" vendor="X.Org"><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="x86_64" num="2006.0"/><vers num="2006.0"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="10.0"/></prod><prod name="X11R6" vendor="X.Org"><vers num="6.9"/></prod><prod name="SuSE Linux Professional" vendor="SuSE"><vers edition="OSS" num="10.0"/></prod><prod name="SuSE Linux Personal" vendor="SuSE"><vers edition="OSS" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-05" name="CVE-2006-0746" published="2006-03-08" seq="2006-0746" severity="High" type="CVE"><desc><descript source="cve">Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-dependent attackers to exploit vulnerabilities that were present in CVE-2005-3627.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:054">MDKSA-2006:054</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0262.html">RHSA-2006:0262</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19189">19189</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19190">19190</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1008">DSA-1008</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19264">19264</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427299/100/0/threaded">20060310 [KDE Security Advisory] kpdf of KDE 3.3.x heap based buffer overflow</ref><ref source="" url="http://www.kde.org/info/security/advisory-20060202-1.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17039">17039</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015751">1015751</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25146">kde-kpdf-patch-bo(25146)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:054">MDKSA-2006:054</ref><ref source="SREASON" url="http://securityreason.com/securityalert/566">566</ref></refs><vuln_soft><prod name="Xpdf" vendor="Xpdf"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" discovered="2006-03-02" modified="2007-08-13" name="CVE-2006-0747" published="2006-05-23" seq="2006-0747" severity="Medium" type="CVE"><desc><descript source="cve">Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file with an odd number of blue values, which causes the underflow when decrementing by 2 in a context that assumes an even number of values.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=183676"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/436836/100/0/threaded">20060612 rPSA-2006-0100-1 freetype</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1095">DSA-1095</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:099">MDKSA-2006:099</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-291-1">USN-291-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/18326">18326</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20525">20525</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20591">20591</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20638">20638</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Jun/0012.html">SUSE-SA:2006:037</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20791">20791</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0500.html">RHSA-2006:0500</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21062">21062</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U">20060701-01-U</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016522">1016522</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21135">21135</ref><ref source="" url="https://issues.rpath.com/browse/RPL-429"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21385">21385</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-176.htm"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21701">21701</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102705-1">102705</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0381">ADV-2007-0381</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23939">23939</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:099">MDKSA-2006:099</ref></refs><vuln_soft><prod name="FreeType" vendor="FreeType"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-06-23" name="CVE-2006-0748" published="2006-04-14" seq="2006-0748" severity="High" type="CVE"><desc><descript source="cve">Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via &quot;an invalid and non-sensical ordering of table-related tags&quot; that results in a negative array index.</descript></desc><sols><sol source="nvd">This vulnerability also affects Mozilla Suite before 1.7.13</sol></sols><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/22066">22066</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432103/100/0/threaded">20060426 ZDI-06-011: Mozilla Firefox Table Rebuilding Code Execution Vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19794">19794</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">GLSA-200605-09</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3391">ADV-2006-3391</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded">HPSBUX02153</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1189">oval:org.mitre.oval:def:1189</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">20051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25985">mozilla-table-rebuilding-code-execution(25985)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3748">ADV-2006-3748</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5.0.1"/><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="Preview Release"/><vers num="1.5.0.1"/><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-06-24" name="CVE-2006-0749" published="2006-04-14" seq="2006-0749" severity="High" type="CVE"><desc><descript source="cve">nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors involving a &quot;particular sequence of HTML tags&quot; that leads to memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="SREASON" url="http://securityreason.com/securityalert/729">729</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1848">oval:org.mitre.oval:def:1848</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19696">
19696</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19729">
19729</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19780">
19780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">
20051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25819">
mozilla-nshtmlcontentsink-memory-corruption(25819)</ref><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-18.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431126/100/0/threaded">20060417 ZDI-06-009: Mozilla Firefox Tag Parsing Code Execution Vulnerability</ref><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-06-009.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0328.html">RHSA-2006:0328</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/736934">VU#736934</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html">TA06-107A</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19794">19794</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html">FEDORA-2006-410</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html">FEDORA-2006-411</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19714">19714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">GLSA-200605-09</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded">HPSBTU02118</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3391">ADV-2006-3391</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5.0.1" prev="1"/><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12" prev="1"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0" prev="1"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-09-04" name="CVE-2006-0750" published="2006-02-17" seq="2006-0750" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in army.php in supersmashbrothers (SSB) Army System 2.1.0 for Invision Power Board (IPB) allows remote attackers to execute arbitrary SQL commands via the userstat parameter in an army action to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424846/100/0/threaded">20060212 Invision Power Board Army System Mod &lt;= 2.1 SQL Injection Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/16606">16606</ref><ref adv="1" source="" url="http://secubox.shadock.net/Invision_Power_Board_Army_System_Mod_2.1_and_prior_SQL_Injection_Exploit.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0561">ADV-2006-0561</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18840">18840</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24654">ipb-armysystem-sql-injection(24654)</ref></refs><vuln_soft><prod name="Army System" vendor="supersmashbrothers"><vers num="2.1.0 for IPB"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-05" name="CVE-2006-0751" published="2006-02-17" seq="2006-0751" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in the (1) Filesystem in USErspace (FUSE) client and (2) NOOFS daemon in in Network Object Oriented File System (NOOFS) before 0.9.0 have unspecified impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="MLIST" url="http://archives.neohapsis.com/archives/apps/freshmeat/2006-02/0003.html">[fm-news] 20060204 Newsletter for Friday, February 03rd 2006</ref><ref source="" url="http://freshmeat.net/projects/noofs/?branch_id=60557&amp;release_id=218852"></ref><ref source="OSVDB" url="http://www.osvdb.org/23052">23052</ref><ref source="OSVDB" url="http://www.osvdb.org/23053">23053</ref><ref source="" url="http://freshmeat.net/projects/noofs/?branch_id=60557&amp;release_id=218852"></ref></refs><vuln_soft><prod name="Network Object Oriented File System" vendor="NOOFS Team"><vers num="0.8.1"/><vers num="0.8"/><vers num="0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0752" published="2006-02-17" seq="2006-0752" severity="Medium" type="CVE"><desc><descript source="cve">Niels Provos Honeyd before 1.5 replies to certain illegal IP packet fragments that other IP stack implementations would drop, which allows remote attackers to identify IP addresses that are being simulated using honeyd.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425112/100/0/threaded">20060212 honeyd security advisory: remote detection</ref><ref source="" url="http://www.honeyd.org/adv.2006-01"></ref><ref source="" url="http://www.honeyd.org/phpBB2/viewtopic.php?t=106"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16595">16595</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0552">ADV-2006-0552</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18867">18867</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24728">
honeyd-ipfrag-obtain-information(24728)</ref></refs><vuln_soft><prod name="Honeyd" vendor="Niels Provos"><vers num="1.5a"/><vers num="1.0"/><vers num="0.8b"/><vers num="0.8a"/><vers num="0.8"/><vers num="0.7a"/><vers num="0.7"/><vers num="0.6a"/><vers num="0.6"/><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0753" published="2006-02-17" seq="2006-0753" severity="Low" type="CVE"><desc><descript source="cve">Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424959/100/0/threaded">20060214 memory leak in IE?</ref><ref source="OSVDB" url="http://www.osvdb.org/23307">23307</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24846">ie-windowstatus-dos(24846)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows XP SP2" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0754" published="2006-02-17" seq="2006-0754" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED ** dotProject 2.0.1 and earlier allows remote attackers to obtain sensitive information via direct requests with an invalid baseDir to certain PHP scripts in the db directory, which reveal the path in an error message.  NOTE: the vendor disputes this issue, saying that it could only occur if the administrator ignores the installation instructions as well as warnings generated by check.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424957/100/0/threaded">20060214 dotproject &lt;= 2.0.1 remote code execution</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/425285/100/0/threaded">20060215 Re: dotproject &lt;= 2.0.1 remote code execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/16648">16648</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0604">ADV-2006-0604</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18879">18879</ref><ref source="OSVDB" url="http://www.osvdb.org/23206">23206</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24745">
dotproject-phpinfo-check-obtain-info(24745)</ref></refs><vuln_soft><prod name="dotProject" vendor="dotProject"><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0755" published="2006-02-17" seq="2006-0755" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED ** Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary commands via the baseDir parameter in (1) db_adodb.php, (2) db_connect.php, (3) session.php, (4) vw_usr_roles.php, (5) calendar.php, (6) date_format.php, and (7) tasks/gantt.php; and the dPconfig[root_dir] parameter in (8) projects/gantt.php, (9) gantt2.php, and (10) vw_files.php.  NOTE: the vendor disputes this issue, stating that the product documentation clearly recommends that the system administrator disable register_globals, and that the check.php script warns against this setting.  Also, the vendor says that the protection.php/siteurl vector is incorrect because protection.php does not exist in the product.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424957/100/0/threaded">20060214 dotproject &lt;= 2.0.1 remote code execution</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/425285/100/0/threaded">20060215 Re: dotproject &lt;= 2.0.1 remote code execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/16648">16648</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0604">ADV-2006-0604</ref><ref source="OSVDB" url="http://www.osvdb.org/23209">23209</ref><ref source="OSVDB" url="http://www.osvdb.org/23212">23212</ref><ref source="OSVDB" url="http://www.osvdb.org/23210">23210</ref><ref source="OSVDB" url="http://www.osvdb.org/23211">23211</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18879">18879</ref><ref source="OSVDB" url="http://www.osvdb.org/23213">23213</ref><ref source="OSVDB" url="http://www.osvdb.org/23214">23214</ref><ref source="OSVDB" url="http://www.osvdb.org/23215">23215</ref><ref source="OSVDB" url="http://www.osvdb.org/23216">23216</ref><ref source="OSVDB" url="http://www.osvdb.org/23217">23217</ref><ref source="OSVDB" url="http://www.osvdb.org/23218">23218</ref><ref source="OSVDB" url="http://www.osvdb.org/23219">23219</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24738">dotproject-multiple-basedir-file-include(24738)</ref></refs><vuln_soft><prod name="dotProject" vendor="dotProject"><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0756" published="2006-02-17" seq="2006-0756" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED ** dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allows remote attackers to obtain sensitive configuration information.  NOTE: the vendor disputes this issue, saying that it could only occur if the administrator ignores the installation instructions as well as warnings generated by check.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424957/100/0/threaded">20060214 dotproject &lt;= 2.0.1 remote code execution</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/425285/100/0/threaded">20060215 Re: dotproject &lt;= 2.0.1 remote code execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/16648">16648</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0604">ADV-2006-0604</ref><ref source="OSVDB" url="http://www.osvdb.org/23207">23207</ref><ref source="OSVDB" url="http://www.osvdb.org/23208">23208</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18879">18879</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24745">
dotproject-phpinfo-check-obtain-info(24745)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/434">434</ref></refs><vuln_soft><prod name="dotProject" vendor="dotProject"><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0757" published="2006-02-17" seq="2006-0757" severity="High" type="CVE"><desc><descript source="cve">Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain parameters in (4) calendar.event.php, (5) index.php, (6) pop.download.php, (7) read.bounce.php, (8) rules.block.php, (9) language.php, and (10) certain other scripts, as demonstrated by an addressbook.update.php request with a contactgroupid value of phpinfo() preceded by facilitators.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0162.html">20060210 HiveMail &lt;= 1.3 Multiple Vulnerabilities</ref><ref source="" url="http://forum.hivemail.com/showthread.php?p=26745"></ref><ref adv="1" source="" url="http://www.gulftech.org/?node=research&amp;article_id=00098-02102006"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24618">hivemail-multiple-file-include(24618)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0527">ADV-2006-0527</ref><ref source="BID" url="http://www.securityfocus.com/bid/16591">16591</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18807">18807</ref></refs><vuln_soft><prod name="HiveMail" vendor="HiveMail"><vers num="1.3"/><vers num="1.3 RC1"/><vers num="1.3 Beta1"/><vers num="1.2.2"/><vers num="1.2.1 RC"/><vers num="1.2.1 Beta1"/><vers num="1.2 SP1"/><vers num="1.2"/><vers num="1.1.1"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0758" published="2006-02-17" seq="2006-0758" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via a URL encoded expression in the query string in (1) index.php and (2) possibly certain other scripts, which is not properly cleansed when accessed from the $_SERVER[&apos;PHP_SELF&apos;] variable.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0162.html">20060210 HiveMail &lt;= 1.3 Multiple Vulnerabilities</ref><ref source="" url="http://forum.hivemail.com/showthread.php?p=26745"></ref><ref adv="1" source="" url="http://www.gulftech.org/?node=research&amp;article_id=00098-02102006"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24622">hivemail-index-xss(24622)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0527">ADV-2006-0527</ref><ref source="BID" url="http://www.securityfocus.com/bid/16591">16591</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18807">18807</ref></refs><vuln_soft><prod name="HiveMail" vendor="HiveMail"><vers num="1.3"/><vers num="1.3 RC1"/><vers num="1.3 Beta1"/><vers num="1.2.2"/><vers num="1.2.1 RC"/><vers num="1.2.1 Beta1"/><vers num="1.2 SP1"/><vers num="1.2"/><vers num="1.1.1"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0759" published="2006-02-17" seq="2006-0759" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain parameters in (4) calendar.event.php, (5) index.php, (6) pop.download.php, (7) read.bounce.php, (8) rules.block.php, (9) language.php, and (10) certain other scripts; and allow remote authenticated users to execute arbitrary SQL commands via (11) the folderid parameter in index.php and (12) possibly other parameters in certain other scripts, because $_SERVER[&apos;PHP_SELF&apos;] is improperly handled.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0162.html">20060210 HiveMail &lt;= 1.3 Multiple Vulnerabilities</ref><ref source="" url="http://forum.hivemail.com/showthread.php?p=26745"></ref><ref adv="1" source="" url="http://www.gulftech.org/?node=research&amp;article_id=00098-02102006"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24623">hivemail-index-sql-injection(24623)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0527">ADV-2006-0527</ref><ref source="BID" url="http://www.securityfocus.com/bid/16591">16591</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18807">18807</ref><ref source="SREASON" url="http://securityreason.com/securityalert/422">422</ref></refs><vuln_soft><prod name="HiveMail" vendor="HiveMail"><vers num="1.3"/><vers num="1.3 RC1"/><vers num="1.3 Beta1"/><vers num="1.2.2"/><vers num="1.2.1 RC"/><vers num="1.2.1 Beta1"/><vers num="1.2 SP1"/><vers num="1.2"/><vers num="1.1.1"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0760" published="2006-02-17" seq="2006-0760" severity="Low" type="CVE"><desc><descript source="cve">LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP when the configuration invokes the PHP interpreter only for &quot;.php&quot; names.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://lighttpd.net/news/"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0550">ADV-2006-0550</ref><ref source="" url="http://www.lighttpd.net/news/"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18869">18869</ref><ref source="OSVDB" url="http://www.osvdb.org/23229">
23229</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24699">
lighttpd-ext-source-disclosure(24699)</ref></refs><vuln_soft><prod name="lighttpd" vendor="lighttpd"><vers num="1.4.8"/><vers num="1.4.7"/><vers num="1.4.6"/><vers num="1.4.5"/><vers num="1.4.4"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4.0"/><vers num="1.3.16"/><vers num="1.3.15"/><vers num="1.3.14"/><vers num="1.3.13"/><vers num="1.3.12"/><vers num="1.3.11"/><vers num="1.3.10"/><vers num="1.3.9"/><vers num="1.3.8"/><vers num="1.3.7"/><vers num="1.3.6"/><vers num="1.3.5"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3.0"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.1.9"/><vers num="1.1.8"/><vers num="1.1.7"/><vers num="1.1.6"/><vers num="1.1.5"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1.0"/><vers num="1.0.3"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-06-04" name="CVE-2006-0761" published="2006-02-17" seq="2006-0761" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1 might allow user-assisted remote attackers to execute arbitrary code on the server via a crafted Microsoft Word document that is opened on a wireless device.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424728/100/0/threaded">20060210 Corrupt Word file may cause buffer overflow in the Blackberry Attachment Service</ref><ref source="" url="http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/8149/8052/Support_-_Corrupt_Word_file_may_cause_buffer_overflow_in_the_BlackBerry_Attachment_Service.html?nodeid=1181753&amp;vernum=2"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16590">16590</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0530">ADV-2006-0530</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24629">blackberry-attachment-word-bo(24629)</ref></refs><vuln_soft><prod name="Blackberry Enterprise Server" vendor="RIM"><vers edition="Domino" num="4.0 SP3"/><vers edition="Domino" num="4.0 SP2"/><vers edition="Domino" num="4.0 SP1"/><vers edition="Domino" num="4.0"/><vers edition="Exchange" num="3.6.1"/><vers edition="Exchange" num="3.6 SP4 HotFix2"/><vers edition="Exchange" num="3.6 SP1a"/><vers edition="Exchange" num="3.6"/><vers num="2.2 SP4 HotFix2"/><vers num="2.2 SP4"/><vers num="2.2 SP3a"/><vers num="2.2 SP2a"/><vers num="2.2 SP2"/><vers num="2.2"/><vers edition="Novell Groupwise" num="4.0 SP3"/><vers edition="Novell Groupwise" num="4.0 SP2"/><vers edition="Novell Groupwise" num="4.0 SP1"/><vers edition="Novell Groupwise" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0762" published="2006-02-17" seq="2006-0762" severity="Medium" type="CVE"><desc><descript source="cve">WinAbility Folder Guard 4.11 allows local users to gain unauthorized access to certain capabilities of the application by renaming or moving the password file (FGuard.FGP), which disables the password requirement.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424855/100/0/threaded">20060213 Folder Guard password protection bypass</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424905/100/0/threaded">20060213 Re: Folder Guard password protection bypass</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24725">
folderguard-fguard-bypass-authentication(24725)</ref></refs><vuln_soft><prod name="Folder Guard" vendor="WinAbility"><vers num="4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0763" published="2006-02-17" seq="2006-0763" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in dowebmailforward.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via a URL encoded value in the fwd parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0129.html">20060207 Re: cPanel Multiple Cross Site Scripting Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/22971">22971</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24839">
cpanel-dowebmailforward-xss(24839)</ref></refs><vuln_soft><prod name="cPanel" vendor="cPanel"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0764" published="2006-02-17" seq="2006-0764" severity="Medium" type="CVE"><desc><descript source="cve">The Authentication, Authorization, and Accounting (AAA) capability in versions 5.0(1) and 5.0(3) of the software used by multiple Cisco Anomaly Detection and Mitigation products, when running with an incomplete TACACS+ configuration without a &quot;tacacs-server host&quot; command, allows remote attackers to bypass authentication and gain privileges, aka Bug ID CSCsd21455.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a008060519a.shtml">20060215 TACACS+ Authentication Bypass in Cisco Anomaly Detection and Mitigation Products</ref><ref source="BID" url="http://www.securityfocus.com/bid/16661">16661</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0612">ADV-2006-0612</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24689">cisco-tacacs-auth-bypass(24689)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015637">1015637</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015638">1015638</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18904">18904</ref><ref source="OSVDB" url="http://www.osvdb.org/23237">
23237</ref><ref source="SREASON" url="http://securityreason.com/securityalert/435">435</ref></refs><vuln_soft><prod name="Anomaly Guard Module" vendor="Cisco"><vers num="5.0(3)"/><vers num="5.0(1)"/></prod><prod name="Traffic Anomaly Detector" vendor="Cisco"><vers num="5.0(3)"/><vers num="5.0(1)"/></prod><prod name="Guard" vendor="Cisco"><vers num="5.0(3)"/><vers num="5.0(1)"/></prod><prod name="Traffic Anomaly Detector Module" vendor="Cisco"><vers num="5.0(3)"/><vers num="5.0(1)"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0765" published="2006-02-17" seq="2006-0765" severity="Medium" type="CVE"><desc><descript source="cve">GUI display truncation vulnerability in ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions, bypass Windows security warnings via a filename that is all uppercase and of a specific length, which truncates the malicious extension from the display and could trick a user into executing arbitrary programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425078/100/0/threaded">20060215 Mirabiliz ICQ 2002/2003/ LITE 4.0/4.1 LONG (DIRECTORY + FILENAME) EXPLOIT</ref><ref source="BID" url="http://www.securityfocus.com/bid/16655">16655</ref></refs><vuln_soft><prod name="ICQ Lite" vendor="Mirabilis"><vers num="4.1"/><vers num="4.0"/></prod><prod name="ICQ" vendor="Mirabilis"><vers num="2003b"/><vers num="2003a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0766" published="2006-02-17" seq="2006-0766" severity="Medium" type="CVE"><desc><descript source="cve">ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions and bypass Windows security warnings via a filename that ends in an assumed-safe extension such as JPG, and possibly containing other modified properties such as company name, icon, and description, which could trick a user into executing arbitrary programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425078/100/0/threaded">20060215 Mirabiliz ICQ 2002/2003/ LITE 4.0/4.1 LONG (DIRECTORY + FILENAME) EXPLOIT</ref><ref source="BID" url="http://www.securityfocus.com/bid/16655">16655</ref></refs><vuln_soft><prod name="ICQ Lite" vendor="Mirabilis"><vers num="4.1"/><vers num="4.0"/></prod><prod name="ICQ" vendor="Mirabilis"><vers num="2003b"/><vers num="2003a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-23" name="CVE-2006-0767" published="2006-02-18" seq="2006-0767" severity="Medium" type="CVE"><desc><descript source="cve">CGIWrap before 3.10 allows remote attackers to obtain sensitive information via unknown attack vectors that cause errors in scripts that reveal system information.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/showfiles.php?group_id=8209"></ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=393274&amp;group_id=8209"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0601">ADV-2006-0601</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18797">18797</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24717">cgiwrap-error-information-disclosure(24717)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16669">16669</ref></refs><vuln_soft><prod name="CGIWrap" vendor="Nathan Neulinger"><vers num="3.9"/><vers num="3.8"/><vers num="3.8 rc1"/><vers num="3.7"/><vers num="3.6.4"/><vers num="3.6.3"/><vers num="3.6.2"/><vers num="3.6.1"/><vers num="3.6"/><vers num="3.6 Beta8"/><vers num="3.6 Beta7"/><vers num="3.6 Beta6"/><vers num="3.6 Beta5"/><vers num="3.6 Beta4"/><vers num="3.6 Beta3"/><vers num="3.6 Beta2"/><vers num="3.6 Beta1"/><vers num="3.5"/><vers num="3.5 Beta"/><vers num="3.4"/><vers num="3.3"/><vers num="3.24"/><vers num="3.23"/><vers num="3.22"/><vers num="3.21"/><vers num="3.2"/><vers num="3.11"/><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-23" name="CVE-2006-0768" published="2006-02-18" seq="2006-0768" severity="Medium" type="CVE"><desc><descript source="cve">Kadu 0.4.3 allows remote attackers to cause a denial of service (application crash) via a large number of image send requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114000770431441&amp;w=2">20060215 Kadu Remote Denial Of Service Fun</ref><ref adv="1" source="" url="http://www.piotrbania.com/all/adv/kadu-fun.txt"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18824">18824</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425134/100/0/threaded">20060215 Kadu Remote Denial Of Service Fun</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0609">ADV-2006-0609</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24720">kadu-image-request-dos(24720)</ref></refs><vuln_soft><prod name="Kadu" vendor="Kadu"><vers num="0.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0769" published="2006-02-18" seq="2006-0769" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in in.rexecd in Solaris 10 allows local users to gain privileges on Kerberos systems via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102186-1">102186</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18891">18891</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0608">ADV-2006-0608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015635">1015635</ref><ref source="BID" url="http://www.securityfocus.com/bid/16658">16658</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1580">oval:org.mitre.oval:def:1580</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/q-126.shtml">
Q-126</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24680">
solaris-kerberos-command-execution(24680)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-05" name="CVE-2006-0770" published="2006-02-18" seq="2006-0770" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in calendar.php in MyBulletinBoard (MyBB) 1.0.4 allows remote attackers to inject arbitrary web script or HTML via a URL that is not sanitized before being retured as a link in &quot;advanced details&quot;.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0635">ADV-2006-0635</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18866">18866</ref><ref source="OSVDB" url="http://www.osvdb.org/23264">23264</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24748">mybb-advanceddetails-xss(24748)</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC4"/><vers num="1.0 RC2"/><vers num="1.0 Preview Release 2"/><vers num="1.0 PR2"/><vers num="1.0 &quot;Final&quot;"/><vers num="1.0 Final"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2008-03-05" name="CVE-2006-0771" published="2006-02-18" seq="2006-0771" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in PunkBuster 1.180 and earlier, as used by Soldier of Fortune II and possibly other games, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in invalid cvar values, which are not properly handled when the server kicks the player and records the reason.</descript></desc><loss_types><avail/><int/></loss_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/sof2pbfs-adv.txt"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18917">18917</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0372.html">FULLDISC:20060216 Soldier of Fortune II format string through PunkBuster 1.180</ref><ref source="BID" url="http://www.securityfocus.com/bid/16703">16703</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425286/100/0/threaded">20060216 Soldier of Fortune II format string through PunkBuster 1.180</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24792">punkbuster-cvars-format-string(24792)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/448">448</ref></refs><vuln_soft><prod name="PunkBuster" vendor="Even Balance"><vers num="1.180" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-09-04" name="CVE-2006-0772" published="2006-02-18" seq="2006-0772" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Hitachi Business Logic - Container 02-03 through 03-00-/B on Windows, and 03-00 through 03-00-/B on Linux, allows remote attackers to execute arbitrary SQL commands via unspecified vectors in the extended receiving box function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS06-002_e/index-e.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0532">ADV-2006-0532</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18817">18817</ref><ref source="OSVDB" url="http://www.osvdb.org/23099">23099</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23877">hitachi-businesslogic-input-sql-injection(23877)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16602">16602</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24621">hitachi-businesslogic-recbox-sql-injection(24621)</ref></refs><vuln_soft><prod name="Business Logic" vendor="Hitachi"><vers edition="Windows" num="03_00_B" prev="1"/><vers edition="Windows" num="02_03"/><vers edition="Linux" num="03_00_B" prev="1"/><vers edition="Linux" num="03_00"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2007-09-04" name="CVE-2006-0773" published="2006-02-18" seq="2006-0773" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Hitachi Business Logic - Container 02-03 through 03-00-/B on Windows, and 03-00 through 03-00-/B on Linux, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the extended receiving box function.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS06-002_e/index-e.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0532">ADV-2006-0532</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18817">18817</ref><ref source="BID" url="http://www.securityfocus.com/bid/16602">16602</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24620">hitachi-businesslogic-recbox-xss(24620)</ref></refs><vuln_soft><prod name="Business Logic" vendor="Hitachi"><vers edition="Windows" num="03_00_B" prev="1"/><vers edition="Windows" num="02_03"/><vers edition="Linux" num="03_00_B" prev="1"/><vers edition="Linux" num="03_00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-23" name="CVE-2006-0774" published="2006-02-18" seq="2006-0774" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in deleteSession() in DB_eSession library 1.0.2 and earlier, as used in multiple products, allows remote attackers to execute arbitrary SQL commands via the $_sess_id_set variable, which is usually derived from PHPSESSID.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424819/100/0/threaded">20060211 DB_eSession deleteSession() SQL injection</ref><ref adv="1" source="" url="http://www.gulftech.org/?node=research&amp;article_id=00099-02112006"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16598">16598</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0528">ADV-2006-0528</ref><ref source="OSVDB" url="http://www.osvdb.org/23104">23104</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18805">18805</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433132/30/5160/threaded">
20060501 Re: DB_eSession deleteSession() SQL injection</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24673">
dbesession-deletesession-sql-injection(24673)</ref></refs><vuln_soft><prod name="DB_eSession" vendor="Lawrence Osiris"><vers num="1.0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-23" name="CVE-2006-0775" published="2006-02-18" seq="2006-0775" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in show.php in BirthSys 3.1 allow remote attackers to execute arbitrary SQL commands via the $month variable.  NOTE: a vector regarding the $date parameter and data.php (date.php) was originally reported, but this appears to be in error.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/74/summary.html"></ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-February/000549.html">[VIM] 20060215 EV0074 BirthSys 3.1 SQL injection (fwd)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24617">birthsys-show-date-sql-injection(24617)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16684">16684</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0621">ADV-2006-0621</ref><ref source="OSVDB" url="http://www.osvdb.org/23185">23185</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18893">18893</ref><ref source="SREASON" url="http://securityreason.com/securityalert/467">467</ref></refs><vuln_soft><prod name="BirthSys" vendor="Ridder Roeland"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-23" name="CVE-2006-0776" published="2006-02-18" seq="2006-0776" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in guestex.pl in Teca Scripts Guestex 1.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/77/summary.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/23182">23182</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24644">guestex-script-xss(24644)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16711">16711</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0640">ADV-2006-0640</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18927">18927</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426034/100/0/threaded">20060224 [eVuln] Guestex XSS Vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015678">1015678</ref><ref source="SREASON" url="http://securityreason.com/securityalert/490">490</ref></refs><vuln_soft><prod name="Guestex" vendor="Teca Scripts"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-23" name="CVE-2006-0777" published="2006-02-18" seq="2006-0777" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in guestex.pl in Teca Scripts Guestex 1.0 allows remote attackers to execute arbitrary shell commands via the email parameter, possibly involving shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/76/summary.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/23183">23183</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24645">guestex-script-execute-code(24645)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16711">16711</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0640">ADV-2006-0640</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18927">18927</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425970/100/0/threaded">20060224 [eVuln] Guestex Shell Command Execution Vulnerability</ref><ref source="SREASON" url="http://securityreason.com/securityalert/489">489</ref></refs><vuln_soft><prod name="Guestex" vendor="Teca Scripts"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-23" name="CVE-2006-0778" published="2006-02-18" seq="2006-0778" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in XMB Forums 1.9.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) $u2u_select array parameter to u2u.inc.php and (2) $val variable (fidpw0 cookie value) in today.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425084/100/0/threaded">20060212 XMB Forums Multiple Vulnerabilities</ref><ref adv="1" source="" url="http://www.gulftech.org/?node=research&amp;article_id=00100-02122006"></ref><ref source="" url="http://www.xmbforum.com/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0529">ADV-2006-0529</ref><ref source="OSVDB" url="http://www.osvdb.org/23117">23117</ref><ref source="OSVDB" url="http://www.osvdb.org/23118">23118</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18821">18821</ref><ref source="BID" url="http://www.securityfocus.com/bid/16604">16604</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24646">
xmbforum-multiple-sql-injection(24646)</ref></refs><vuln_soft><prod name="XMB" vendor="XMB Forum"><vers num="1.9.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-23" name="CVE-2006-0779" published="2006-02-18" seq="2006-0779" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in u2u.php in XMB Forums 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter, as demonstrated using a URL-encoded iframe tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425084/100/0/threaded">20060212 XMB Forums Multiple Vulnerabilities</ref><ref adv="1" source="" url="http://www.gulftech.org/?node=research&amp;article_id=00100-02122006"></ref><ref source="" url="http://www.xmbforum.com/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0529">ADV-2006-0529</ref><ref source="OSVDB" url="http://www.osvdb.org/23119">23119</ref><ref source="BID" url="http://www.securityfocus.com/bid/16604">16604</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24647">
xmbforum-u2u-xss(24647)</ref></refs><vuln_soft><prod name="XMB" vendor="XMB Forum"><vers num="1.9.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-20" name="CVE-2006-0780" published="2006-02-19" seq="2006-0780" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in weblog.pl in PerlBlog 1.09b and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) email parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/81/summary.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24691">perlblog-weblog-xss(24691)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16707">16707</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18924">18924</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426260/100/0/threaded">20060227 [eVuln] PerlBlog Multiple Vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/508">508</ref></refs><vuln_soft><prod name="PerlBlog" vendor="PerlBlog"><vers num="1.09b"/><vers num="1.09"/><vers num="1.08"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-20" name="CVE-2006-0781" published="2006-02-19" seq="2006-0781" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to read certain files via the month parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/81/summary.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24690">perlblog-weblog-directory-traversal(24690)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16707">16707</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18924">18924</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426260/100/0/threaded">20060227 [eVuln] PerlBlog Multiple Vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/508">508</ref></refs><vuln_soft><prod name="PerlBlog" vendor="PerlBlog"><vers num="1.09b"/><vers num="1.09"/><vers num="1.08"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-20" name="CVE-2006-0782" published="2006-02-19" seq="2006-0782" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to create arbitrary files and possibly execute arbitrary code via unspecified attack vectors related to improper handling of (1) the reply parameter, possibly involving injection of (2) the name parameter and (3) the body parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/81/summary.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24692">perlblog-weblog-command-execution(24692)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16707">16707</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18924">18924</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426260/100/0/threaded">20060227 [eVuln] PerlBlog Multiple Vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/508">508</ref></refs><vuln_soft><prod name="PerlBlog" vendor="PerlBlog"><vers num="1.09b"/><vers num="1.09"/><vers num="1.08"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-20" name="CVE-2006-0783" published="2006-02-19" seq="2006-0783" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in page.php in in Siteframe Beaumont, possibly 5.0.2 or 5.0.1a, allows remote attackers to inject arbitrary web script or HTML via the comment_text parameter to the user comment page (/edit/Comment).</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425180/100/0/threaded">20060216 Siteframe Beaumont 5.0.2 &lt;== User Comment Cross-Site Scripting Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16695">16695</ref><ref source="OSVDB" url="http://www.osvdb.org/23267">23267</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18892">18892</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24836">
siteframe-comment-xss(24836)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/443">443</ref></refs><vuln_soft><prod name="Siteframe Beaumont" vendor="Siteframe"><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0.1a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-20" name="CVE-2006-0784" published="2006-02-19" seq="2006-0784" severity="Medium" type="CVE"><desc><descript source="cve">D-Link DWL-G700AP with firmware 2.00 and 2.01 allows remote attackers to cause a denial of service (CAMEO HTTP service crash) via a request composed of &quot;GET&quot; followed by a space and two newlines, possibly triggering the crash due to missing arguments.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425169/100/0/threaded">20060216 D-Link DWL-G700AP httpd DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/16690">16690</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0637">ADV-2006-0637</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18932">18932</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24762">dlink-admin-interface-dos(24762)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/441">441</ref></refs><vuln_soft><prod name="DWL-G700AP" vendor="D-Link"><vers num="2.00"/><vers num="2.01"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-20" name="CVE-2006-0785" published="2006-02-19" seq="2006-0785" severity="Medium" type="CVE"><desc><descript source="cve">Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute arbitrary local files via a direct request with a path parameter with a null character and beginning with (1) &apos;/&apos; (slash) for an absolute pathname or (2) a drive letter (such as &quot;C:&quot;), which bypasses checks for &quot;..&quot; sequences and trailing &quot;.php&quot; extensions.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425196/100/0/threaded">20060216 PHPKIT &gt;= 1.6.1r2 arbitrary local/remote inclusion (unproperly patched in previous versions)</ref><ref source="" url="http://retrogod.altervista.org/phpkit_161r2_incl_xpl.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015640">1015640</ref></refs><vuln_soft><prod name="PHPKIT" vendor="PHPKIT"><vers edition="RC2" num="1.6.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-20" name="CVE-2006-0786" published="2006-02-19" seq="2006-0786" severity="Medium" type="CVE"><desc><descript source="cve">Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attackers to conduct PHP remote file include attacks via a path parameter that specifies a (1) UNC share or (2) ftps URL, which bypasses the check for &quot;http://&quot;, &quot;ftp://&quot;, and &quot;https://&quot; URLs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425196/100/0/threaded">20060216 PHPKIT &gt;= 1.6.1r2 arbitrary local/remote inclusion (unproperly patched in previous versions)</ref><ref source="" url="http://retrogod.altervista.org/phpkit_161r2_incl_xpl.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015640">1015640</ref><ref source="SREASON" url="http://securityreason.com/securityalert/445">445</ref></refs><vuln_soft><prod name="PHPKIT" vendor="PHPKIT"><vers edition="RC2" num="1.6.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-20" name="CVE-2006-0787" published="2006-02-19" seq="2006-0787" severity="Medium" type="CVE"><desc><descript source="cve">wimpy_trackplays.php in Plaino Wimpy MP3 Player, possibly 5.2 and earlier, allows remote attackers to insert arbitrary strings into trackme.txt via the (1) trackFile, (2) trackArtist, and (3) trackTitle parameters, which can result in providing false information about songs, occupying excessive disk space with very long parameter values, and storing executable code that might be invoked through a different vulnerability.  NOTE: since this issue, as described by the original researcher, is entirely dependent on the presence of another vulnerability, it could be argued that Wimpy cannot be responsible for how its data file is processed by applications outside of its control. Since this issue might only be useful as a facilitator manipulation in another vulnerability, perhaps it should not be included in CVE.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.xorcrew.net/xpa/XPA-WimpyMP3Player.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16696">16696</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18900">18900</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24770">
wimpy-wimpytrackplays-no-auth(24770)</ref></refs><vuln_soft><prod name="Wimpy MP3" vendor="Plaino"><vers num="5.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-23" name="CVE-2006-0788" published="2006-02-19" seq="2006-0788" severity="Medium" type="CVE"><desc><descript source="cve">Kyocera 3830 (aka FS-3830N) printers have a back door that allows remote attackers to read and alter configuration settings via strings that begin with &quot;!R!SIOP0&quot;, as demonstrated using (1) a connection to to TCP port 9100 or (2) the UNIX lp command.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://evader.wordpress.com/2006/02/16/kyocera-printers/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16685">16685</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0620">ADV-2006-0620</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18896">18896</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0344.html">20060215 Kyocera Network Printers</ref><ref source="OSVDB" url="http://www.osvdb.org/23245">23245</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24772">
kyocera-fs3830n-no-auth(24772)</ref></refs><vuln_soft><prod name="FS-3830N" vendor="Kyocera"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-23" name="CVE-2006-0789" published="2006-02-19" seq="2006-0789" severity="High" type="CVE"><desc><descript source="cve">Certain unspecified Kyocera printers have a default &quot;admin&quot; account with a blank password, which allows remote attackers to access an administrative menu via a telnet session.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://evader.wordpress.com/2006/02/16/kyocera-printers/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0620">ADV-2006-0620</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18896">18896</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0344.html">20060215 Kyocera Network Printers</ref><ref source="OSVDB" url="http://www.osvdb.org/23246">23246</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24774">
kyocera-fs3830n-blank-password(24774)</ref></refs><vuln_soft><prod name="FS-3830N" vendor="Kyocera"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-20" name="CVE-2006-0790" published="2006-02-19" seq="2006-0790" severity="Medium" type="CVE"><desc><descript source="cve">Rockliffe MailSite 7.0 and earlier allows remote attackers to cause a denial of service by sending crafted LDAP packets to port 389/TCP, as demonstrated by the ProtoVer LDAP testsuite.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2006-February/002926.html">[Dailydave] 20060214 MailSite (WorldMail) fun</ref><ref source="BID" url="http://www.securityfocus.com/bid/16675">16675</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0598">ADV-2006-0598</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18888">18888</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24686">mailsite-ldap-dos(24686)</ref></refs><vuln_soft><prod name="MailSite" vendor="Rockliffe"><vers num="7.0.31"/><vers num="6.1.22"/><vers num="5.3.4"/><vers num="4.2.10"/><vers num="5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-20" name="CVE-2006-0791" published="2006-02-19" seq="2006-0791" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in DreamCost HostAdmin allows remote attackers to include arbitrary files via the $path variable, which is not initialized before use.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.xorcrew.net/xpa/XPA-HostAdmin.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16682">16682</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0618">ADV-2006-0618</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18901">18901</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0341.html">20060215 HostAdmin - Remote Command Execution Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24723">hostadmin-path-file-include(24723)</ref><ref source="OSVDB" url="http://www.osvdb.org/23241">23241</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0340.html">20060215 HostAdmin - Remote Command Execution Vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016273">1016273</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435993/30/4650/threaded">

20060605 [MajorSecurity #9]HostAdmin &lt;= 3.1 - Remote File Include Vulnerability</ref></refs><vuln_soft><prod name="HostAdmin" vendor="DreamCost"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-20" name="CVE-2006-0792" published="2006-02-19" seq="2006-0792" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in preferences.personal.php in V-webmail 1.6.2 allows remote attackers to inject abitrary web script or HTML via the newid parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0639">ADV-2006-0639</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18776">18776</ref><ref source="BID" url="http://www.securityfocus.com/bid/16706">16706</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24749">vwebmail-preferencespersonal-xss(24749)</ref><ref source="OSVDB" url="http://www.osvdb.org/23260">23260</ref></refs><vuln_soft><prod name="V-webmail" vendor="V-webmail"><vers num="1.6.2"/><vers num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-20" name="CVE-2006-0793" published="2006-02-19" seq="2006-0793" severity="Medium" type="CVE"><desc><descript source="cve">frameset.php in V-webmail 1.6.2 allows remote attackers to conduct phishing attacks by referencing arbitrary websites in the rframe parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0639">ADV-2006-0639</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18776">18776</ref><ref source="BID" url="http://www.securityfocus.com/bid/16706">16706</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24753">vwebmail-frameset-spoofing(24753)</ref><ref source="OSVDB" url="http://www.osvdb.org/23261">23261</ref></refs><vuln_soft><prod name="V-webmail" vendor="V-webmail"><vers num="1.6.2"/><vers num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-20" name="CVE-2006-0794" published="2006-02-19" seq="2006-0794" severity="Medium" type="CVE"><desc><descript source="cve">help.php in V-webmail 1.6.2 allows remote attackers to obtain the installation path via unspecified invalid parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0639">ADV-2006-0639</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18776">18776</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24754">vwebmail-help-path-disclosure(24754)</ref><ref source="OSVDB" url="http://www.osvdb.org/23262">23262</ref></refs><vuln_soft><prod name="V-webmail" vendor="V-webmail"><vers num="1.6.2"/><vers num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-0795" published="2006-02-19" seq="2006-0795" severity="Medium" type="CVE"><desc><descript source="cve">Absolute path traversal vulnerability in convert.cgi in Quirex 2.0.2 and earlier allows remote attackers to read arbitrary files, and possibly execute arbitrary code, via the (1) quiz_head, (2) quiz_foot, and (3) template variables.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/78/summary.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18926">18926</ref><ref source="BID" url="http://www.securityfocus.com/bid/16709">16709</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0641">ADV-2006-0641</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426188/100/0/threaded">20060226 [eVuln] Quirex Arbitrary File Disclosure Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24672">
quirex-convert-information-disclosure(24672)</ref></refs><vuln_soft><prod name="Quirex" vendor="Quirex"><vers num="2.0.2"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-20" name="CVE-2006-0796" published="2006-02-19" seq="2006-0796" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in default.php in Clever Copy 3.0 allows remote attackers to inject arbitrary web script or HTML via the Subject field when sending private messages (privatemessages.php). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16681">16681</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0616">ADV-2006-0616</ref><ref source="OSVDB" url="http://www.osvdb.org/23235">23235</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18873">18873</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24747">clevercopy-subject-xss(24747)</ref></refs><vuln_soft><prod name="Clever Copy" vendor="Clever Copy"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-20" name="CVE-2006-0797" published="2006-02-19" seq="2006-0797" severity="High" type="CVE"><desc><descript source="cve">Nokia N70 cell phone allows remote attackers to caues a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet whose length field is less than the actual length of the packet, possibly triggering a buffer overflow, as demonstrated using the Bluetooth Stack Smasher (BSS).</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0316.html">20060215 [ Secuobs - Advisory ] Another kind of DoS on Nokia cell phones</ref><ref source="" url="http://www.secuobs.com/news/15022006-nokia_n70.shtml#english"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16666">16666</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0538">ADV-2006-0538</ref><ref source="OSVDB" url="http://www.osvdb.org/23061">23061</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24688">nokia-bluetooth-l2cap-dos(24688)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18724">18724</ref></refs><vuln_soft><prod name="N70" vendor="Nokia"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="4.9" CVSS_score="5.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-20" name="CVE-2006-0798" published="2006-02-19" seq="2006-0798" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in the IMAP service in Macallan Mail Solution before 4.8.05.004 allow remote authenticated users to read e-mails of other users or create, modify, or delete directories via a .. (dot dot) in the argument to the (1) CREATE, (2) SELECT, (3) DELETE, or (4) RENAME commands.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2006-4/advisory/"></ref><ref source="" url="http://macallan.club.fr/MMS/index.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16704">16704</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18775">18775</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0644">ADV-2006-0644</ref><ref source="OSVDB" url="http://www.osvdb.org/23269">23269</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015647">1015647</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24761">macallan-imap-directory-traversal(24761)</ref></refs><vuln_soft><prod name="Mail Solution" vendor="Macallan"><vers num="4.8.03.025" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0799" published="2006-02-19" seq="2006-0799" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page with an anchor element with a legitimate &quot;href&quot; attribute, a form whose action points to a malicious URL, and an INPUT submit element that is modified to look like a legitimate URL.  NOTE: this issue is very similar to CVE-2004-1104, although the manipulations are slightly different.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425298/100/0/threaded">20060216 Internet Explorer Phishing mouseover issue</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425386/100/0/threaded">20060218 Re: Internet Explorer Phishing mouseover issue</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425883/100/0/threaded">20060223 Re: Internet Explorer Phishing mouseover issue</ref><ref source="OSVDB" url="http://www.osvdb.org/23609">23609</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17938">ie-ahref-status-spoofing(17938)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-0800" published="2006-02-20" seq="2006-0800" severity="Low" type="CVE"><desc><descript source="cve">Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing &quot;&lt;&quot; character, which is interpreted as a &quot;&gt;&quot; character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://securityreason.com/securityalert/454"></ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0469.html">20060219 Multiple vulnerabilities in PostNuke &lt;= 0.761</ref><ref adv="1" source="" url="http://news.postnuke.com/index.php?name=News&amp;file=article&amp;sid=2754"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16752">16752</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0673">ADV-2006-0673</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18937">18937</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24823">postnuke-user-nslanguages-xss(24823)</ref><ref patch="1" source="" url="http://news.postnuke.com/index.php?name=News&amp;file=article&amp;sid=2754"></ref><ref patch="1" source="" url="http://news.postnuke.com/index.php?name=News&amp;file=article&amp;sid=2754"></ref><ref patch="1" source="" url="http://news.postnuke.com/index.php?name=News&amp;file=article&amp;sid=2754"></ref><ref source="" url="http://news.postnuke.com/index.php?name=News&amp;file=article&amp;sid=2754"></ref><ref source="" url="http://news.postnuke.com/index.php?name=News&amp;file=article&amp;sid=2754"></ref><ref source="" url="http://news.postnuke.com/index.php?name=News&amp;file=article&amp;sid=2754"></ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.761a"/><vers num="0.761"/><vers num="0.726.3"/><vers num="0.721"/><vers num="0.703"/><vers num="0.76 RC4b"/><vers num="0.76 RC4a"/><vers num="0.76 RC4"/><vers num="0.75 RC3"/><vers num="0.75"/><vers num="0.74"/><vers num="0.73"/><vers num="0.72"/><vers num="0.71"/><vers num="0.70"/><vers num="0.64"/><vers num="0.63"/><vers num="0.62"/><vers num="0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-0801" published="2006-02-20" seq="2006-0801" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is off, allows remote attackers to execute arbitrary SQL commands via the language parameter to admin.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://securityreason.com/securityalert/454"></ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0469.html">20060219 Multiple vulnerabilities in PostNuke &lt;= 0.761</ref><ref source="" url="http://news.postnuke.com/index.php?name=News&amp;file=article&amp;sid=2754"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16752">16752</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0673">ADV-2006-0673</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18937">18937</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24827">postnuke-nslanguages-sql-injection(24827)</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.761" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-0802" published="2006-02-20" seq="2006-0802" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is enabled, allows remote attackers to inject arbitrary web script or HTML via the language parameter in a missing or translation operation.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://securityreason.com/securityalert/454"></ref><ref source="" url="http://news.postnuke.com/index.php?name=News&amp;file=article&amp;sid=2754"></ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0469.html">20060219 Multiple vulnerabilities in PostNuke &lt;= 0.761</ref><ref source="BID" url="http://www.securityfocus.com/bid/16752">16752</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0673">ADV-2006-0673</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18937">18937</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24823">postnuke-user-nslanguages-xss(24823)</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.761" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0803" published="2006-02-23" seq="2006-0803" severity="Medium" type="CVE"><desc><descript source="cve">The signature verification functionality in the YaST Online Update (YOU) script handling relies on a gpg feature that is not intended for signature verification, which prevents YOU from detecting malicious scripts or code that do not pass the signature check when gpg 1.4.x is being used.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_09_gpg.html">SUSE-SA:2006:009</ref><ref source="BID" url="http://www.securityfocus.com/bid/16889">16889</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_13_gpg.html">SUSE-SA:2006:013</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="9.3"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-23" name="CVE-2006-0804" published="2006-02-20" seq="2006-0804" severity="High" type="CVE"><desc><descript source="cve">Off-by-one error in TIN 1.8.0 and earlier might allow attackers to execute arbitrary code via unknown vectors that trigger a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="OPENPKG" url="http://www.openpkg.org/security/OpenPKG-SA-2006.005-tin.html">OpenPKG-SA-2006.005</ref><ref source="BID" url="http://www.securityfocus.com/bid/16728">16728</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0702">ADV-2006-0702</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_05_sr.html">SUSE-SR:2006:005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19130">19130</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200611-18.xml">GLSA-200611-18</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24841">
tin-offbyone-bo(24841)</ref></refs><vuln_soft><prod name="TIN" vendor="TIN"><vers num="1.8.0"/><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6.0"/><vers num="1.4.7"/><vers num="1.4.6"/><vers num="1.4.5"/><vers num="1.4.4"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4.0"/><vers num="1.2 PL2"/><vers num="1.2 PL1"/><vers num="1.2 PL0"/><vers num="1.1 PL9"/><vers num="1.1 PL8"/><vers num="1.1 PL7"/><vers num="1.1 PL6"/><vers num="1.1 PL5"/><vers num="1.1 PL4"/><vers num="1.1 PL3"/><vers num="1.1 PL2"/><vers num="1.1 PL1"/><vers num="1.1 PL0"/><vers num="1.0 PL5"/><vers num="1.0 PL4"/><vers num="1.0 PL3"/><vers num="1.0 PL2"/><vers num="1.0 PL1"/><vers num="1.0 PL0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0805" published="2006-02-20" seq="2006-0805" severity="High" type="CVE"><desc><descript source="cve">The CAPTCHA functionality in php-Nuke 6.0 through 7.9 uses fixed challenge/response pairs that only vary once per day based on the User Agent (HTTP_USER_AGENT), which allows remote attackers to bypass CAPTCHA controls by fixing the User Agent, performing a valid challenge/response, then replaying that pair in the random_num and gfx_check parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425394/100/0/threaded">20060218 [waraxe-2006-SA#045] - Bypassing CAPTCHA in phpNuke 6.x-7.9</ref><ref adv="1" source="" url="http://www.waraxe.us/advisory-45.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16722">16722</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18936">18936</ref><ref source="SREASON" url="http://securityreason.com/securityalert/455">455</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/><vers num="7.3"/><vers num="7.4"/><vers num="7.5"/><vers num="7.6"/><vers num="7.7"/><vers num="7.8"/><vers num="7.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-08" name="CVE-2006-0806" published="2006-02-20" seq="2006-0806" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHP_SELF.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425393/100/0/threaded">20060218 ADOdb Library Cross Site Scripting</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00101-02182006"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16720">16720</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0664">ADV-2006-0664</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18928">18928</ref><ref source="OSVDB" url="http://www.osvdb.org/23362">23362</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1029">DSA-1029</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1030">DSA-1030</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1031">DSA-1031</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19555">19555</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19590">19590</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19591">19591</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml">GLSA-200604-07</ref><ref source="" url="http://phpesp.cvs.sourceforge.net/phpesp/phpESP/admin/include/lib/adodb/adodb-pager.inc.php?r1=1.1&amp;r2=1.2"></ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=419843&amp;group_id=8956"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2021">ADV-2006-2021</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19691">
19691</ref><ref source="SREASON" url="http://securityreason.com/securityalert/452">452</ref></refs><vuln_soft><prod name="ADOdb" vendor="John Lim"><vers num="4.71"/><vers num="4.70"/><vers num="4.68"/><vers num="4.66"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0807" published="2006-02-20" seq="2006-0807" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in NJStar Chinese and Japanese Word Processor 4.x and 5.x before 5.10 allows user-assisted attackers to execute arbitrary code via font names in NJStar (.njx) documents.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425498/100/0/threaded">20060220 Secunia Research: NJStar Word Processor Font Name Buffer Overflow</ref><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2006-5/advisory/"></ref><ref source="" url="http://www.njstar.com/njstar/chinese/"></ref><ref source="" url="http://www.njstar.com/njstar/japanese/"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0670">ADV-2006-0670</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18702">18702</ref><ref source="BID" url="http://www.securityfocus.com/bid/16737">16737</ref><ref source="OSVDB" url="http://www.osvdb.org/23354">23354</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015649">1015649</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24773">njstar-font-name-bo(24773)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/461">461</ref></refs><vuln_soft><prod name="Japanese Word Processor" vendor="NJStar"><vers num="5.01.41108" prev="1"/></prod><prod name="Chinese Word Processor" vendor="NJStar"><vers num="5.01.41108" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-21" name="CVE-2006-0808" published="2006-02-20" seq="2006-0808" severity="Medium" type="CVE"><desc><descript source="cve">MUTE 0.4 allows remote attackers to cause a denial of service (messages not forwarded) and obtain sensitive information about a target by filling a client&apos;s mWebCache cache with malicious &quot;zombie&quot; nodes.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/mute-net/MUTE/doc/notes/notes.txt?view=markup"></ref><ref source="OSVDB" url="http://www.osvdb.org/23336">23336</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18980">18980</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24931">
mute-mwebcache-security-bypass(24931)</ref></refs><vuln_soft><prod name="MUTE" vendor="MUTE"><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0809" published="2006-02-20" seq="2006-0809" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Skate Board 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) usern parameter in (a) sendpass.php, and the (2) usern and (3) passwd parameters and (4) sf_cookie cookie in (b) login.php and (c) logged.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/84/summary.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/23301">23301</ref><ref source="OSVDB" url="http://www.osvdb.org/23302">23302</ref><ref source="OSVDB" url="http://www.osvdb.org/23303">23303</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18978">18978</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/426658/30/0/threaded">20060303 [eVuln] Skate Board Multimple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16936">16936</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24778">skateboard-sendpass-sql-injection(24778)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24779">
skateboard-authentication-bypass(24779)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/540">540</ref></refs><vuln_soft><prod name="Skate Board" vendor="Skate Board"><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-07-03" name="CVE-2006-0810" published="2006-02-20" seq="2006-0810" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in config.php in Skate Board 0.9 allows remote authenticated administrators to execute arbitrary PHP code by causing certain variables in config.php to be modified, possibly due to XSS or direct static code injection.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/84/summary.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/23304">23304</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18978">18978</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/426658/30/0/threaded">20060303 [eVuln] Skate Board Multimple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16936">16936</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24780">skateboard-config-file-include(24780)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/540">540</ref></refs><vuln_soft><prod name="Skate Board" vendor="Skate Board"><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0811" published="2006-02-20" seq="2006-0811" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in reguser.php in Skate Board 0.9 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters involved with the registration form.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/84/summary.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/23305">23305</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18978">18978</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/426658/30/0/threaded">20060303 [eVuln] Skate Board Multimple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16936">16936</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24781">skateboard-registration-xss(24781)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/540">540</ref></refs><vuln_soft><prod name="Skate Board" vendor="Skate Board"><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-16" name="CVE-2006-0812" published="2006-02-23" seq="2006-0812" severity="High" type="CVE"><desc><descript source="cve">The VisNetic AntiVirus Plug-in (DKAVUpSch.exe) for Mail Server 4.6.0.4, 4.6.1.1, and possibly other versions before 4.6.1.2, does not drop privileges before executing other programs, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2005-65/advisory/"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0701">ADV-2006-0701</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16583">16583</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425890/100/0/threaded">20060223 Secunia Research: Visnetic AntiVirus Plug-in for MailServerPrivilege Escalation</ref><ref source="BID" url="http://www.securityfocus.com/bid/16788">16788</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015670">1015670</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24928">
visnetic-av-plugin-privilege-elevation(24928)</ref></refs><vuln_soft><prod name="VisNetic AntiVirus Plug-in for Mail Server" vendor="VisNetic"><vers num="4.6.0.4"/><vers num="4.6.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0813" published="2006-02-24" seq="2006-0813" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in WinACE 2.60 allows user-assisted attackers to execute arbitrary code via a large header block in an ARJ archive.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2005-67/advisory/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16786">16786</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0709">ADV-2006-0709</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17251">17251</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425894/100/0/threaded">20060223 Secunia Research: WinACE ARJ Archive Handling Buffer Overflow</ref><ref source="OSVDB" url="http://www.osvdb.org/23383">23383</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015672">1015672</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24872">winace-arj-header-bo(24872)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/479">479</ref></refs><vuln_soft><prod name="WinACE" vendor="WinACE"><vers num="2.60"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-0814" published="2006-03-06" seq="2006-0814" severity="Medium" type="CVE"><desc><descript source="cve">response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via requests that contain trailing (1) &quot;.&quot; (dot) and (2) space characters, which are ignored by Windows, as demonstrated by PHP files.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426446/100/0/threaded">20060301 Secunia Research: Lighttpd Script Source Disclosure Vulnerability</ref><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2006-9/advisory/"></ref><ref source="" url="http://trac.lighttpd.net/trac/changeset/1005"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0782">ADV-2006-0782</ref><ref source="OSVDB" url="http://www.osvdb.org/23542">23542</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18886">18886</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24976">lighttpd-source-code-disclosure(24976)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16893">16893</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015703">1015703</ref><ref source="SREASON" url="http://securityreason.com/securityalert/523">523</ref></refs><vuln_soft><prod name="lighttpd" vendor="lighttpd"><vers num="1.4.10"/><vers num="1.4.9"/><vers num="1.4.8"/><vers num="1.4.7"/><vers num="1.4.6"/><vers num="1.4.5"/><vers num="1.4.4"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4.0"/><vers num="1.3.16"/><vers num="1.3.15"/><vers num="1.3.14"/><vers num="1.3.13"/><vers num="1.3.12"/><vers num="1.3.11"/><vers num="1.3.10"/><vers num="1.3.9"/><vers num="1.3.8"/><vers num="1.3.7"/><vers num="1.3.6"/><vers num="1.3.5"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3.0"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.1.9"/><vers num="1.1.8"/><vers num="1.1.7"/><vers num="1.1.6"/><vers num="1.1.5"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1.0"/><vers num="1.0.3"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-22" name="CVE-2006-0815" published="2006-03-06" seq="2006-0815" severity="Medium" type="CVE"><desc><descript source="cve">NetworkActiv Web Server 3.5.15 allows remote attackers to read script source code via a crafted URL with a &quot;/&quot; (forward slash) after the file extension.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426461/100/0/threaded">20060301 Secunia Research: NetworkActiv Web Server Script Source DisclosureVulnerability</ref><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2006-10/advisory"></ref><ref source="" url="http://www.networkactiv.com/WebServer.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0783">ADV-2006-0783</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18947">18947</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24979">networkactiv-script-source-disclosure(24979)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16895">16895</ref></refs><vuln_soft><prod name="NetworkActiv Web Server" vendor="NetworkActiv"><vers num="3.5.15"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-0816" published="2006-03-24" seq="2006-0816" severity="Medium" type="CVE"><desc><descript source="cve">Orion Application Server before 2.0.7, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the extension of a URL.</descript></desc><sols><sol source="nvd">Update to version 2.0.7 or contact the vendor for a patch.</sol></sols><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2006-11/advisory/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1055">ADV-2006-1055</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18950">18950</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428601/100/0/threaded">20060323 Secunia Research: Orion Application Server JSP Source DisclosureVulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17204">17204</ref><ref source="OSVDB" url="http://www.osvdb.org/24053">24053</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015823">1015823</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25405">orion-jsp-source-disclosure(25405)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1455.html">20060323 Secunia Research: Orion Application Server JSP Source Disclosure Vulnerability</ref></refs><vuln_soft><prod name="Orion Application Server" vendor="Orion*"><vers num="2.06" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-02-21" modified="2006-07-21" name="CVE-2006-0817" published="2006-07-21" seq="2006-0817" severity="Medium" type="CVE"><desc><descript source="cve">Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer before 8.5.0.5 allows remote attackers to include arbitrary files via a full Windows path and drive letter in the (1) language parameter in accounts/inc/include.php and (2) lang_settings parameter in admin/inc/include.php, which is not properly sanitized by the securepath function, a related issue to CVE-2005-4556.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2006-12/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2006-14/advisory/"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/19002">19002</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2825">ADV-2006-2825</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18953">18953</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18966">18966</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/440297/100/0/threaded">20060717 Secunia Research: IceWarp Web Mail Two File InclusionVulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/440302/100/0/threaded">20060717 Secunia Research: VisNetic Mail Server Two File InclusionVulnerabilities</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016513">1016513</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016514">1016514</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27773">visnetic-include-file-include(27773)</ref><ref source="OSVDB" url="http://www.osvdb.org/27328">27328</ref></refs><vuln_soft><prod name="VisNetic Mail Server" vendor="Deerfield"><vers num="8.3.5"/></prod><prod name="Web Mail" vendor="IceWarp"><vers num="5.6.0"/></prod><prod name="Mail Server" vendor="MERAK"><vers edition="Windows" num="8.3.8r"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-02-21" modified="2006-07-21" name="CVE-2006-0818" published="2006-07-21" seq="2006-0818" severity="Medium" type="CVE"><desc><descript source="cve">Absolute path directory traversal vulnerability in (1) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (2) VisNetic MailServer before 8.5.0.5 allows remote authenticated users to include arbitrary files via a modified language parameter and a full Windows or UNC pathname in the lang_settings parameter to mail/index.html, which is not properly sanitized by the validatefolder PHP function, possibly due to an incomplete fix for CVE-2005-4558.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2006-12/advisory/"></ref><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2006-14/advisory/"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/19002">19002</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2825">ADV-2006-2825</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18953">18953</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18966">18966</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/440297/100/0/threaded">20060717 Secunia Research: IceWarp Web Mail Two File InclusionVulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/440302/100/0/threaded">20060717 Secunia Research: VisNetic Mail Server Two File InclusionVulnerabilities</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016513">1016513</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016514">1016514</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27780">visnetic-language-file-include(27780)</ref></refs><vuln_soft><prod name="VisNetic Mail Server" vendor="Deerfield"><vers num="8.3.5"/></prod><prod name="Web Mail" vendor="IceWarp"><vers num="5.6.0"/></prod><prod name="Mail Server" vendor="MERAK"><vers edition="Windows" num="8.3.8r"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-0819" published="2006-03-13" seq="2006-0819" severity="High" type="CVE"><desc><descript source="cve">Dwarf HTTP Server 1.3.2 allows remote attackers to obtain the source code of JSP files via (1) dot, (2) space, (3) slash, or (4) NULL characters in the filename extension of an HTTP request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427478/100/0/threaded">20060313 Secunia Research: Dwarf HTTP Server Source Disclosure andCross-Site Scripting</ref><ref adv="1" patch="1" source="secunia.com" url="http://secunia.com/secunia_research/2006-13/advisory">Dwarf HTTP Server Source Disclosure and Cross-Site Scripting</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0937">ADV-2006-0937</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18962">18962</ref><ref source="BID" url="http://www.securityfocus.com/bid/17123">17123</ref><ref source="OSVDB" url="http://www.osvdb.org/23836">23836</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015779">1015779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25178">dwarfhttp-extension-information-disclosure(25178)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/576">576</ref></refs><vuln_soft><prod name="Dwarf HTTP Server" vendor="GNOME"><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-0820" published="2006-03-13" seq="2006-0820" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Dwarf HTTP Server 1.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified error messages.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427478/100/0/threaded">20060313 Secunia Research: Dwarf HTTP Server Source Disclosure andCross-Site Scripting</ref><ref adv="1" patch="1" source="secunia.com" url="http://secunia.com/secunia_research/2006-13/advisory">Dwarf HTTP Server Source Disclosure and Cross-Site Scripting</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0937">ADV-2006-0937</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18962">18962</ref><ref source="BID" url="http://www.securityfocus.com/bid/17123">17123</ref><ref source="OSVDB" url="http://www.osvdb.org/23837">23837</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015779">1015779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25179">dwarfhttp-url-xss(25179)</ref></refs><vuln_soft><prod name="Dwarf HTTP Server" vendor="GNOME"><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0821" published="2006-02-21" seq="2006-0821" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in BXCP 0.299 allows remote attackers to execute arbitrary SQL commands via the tid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/id.php?id=1513"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0660">ADV-2006-0660</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18929">18929</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24783">bxcp-tid-sql-injection(24783)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1513">

1513</ref></refs><vuln_soft><prod name="BXCP" vendor="BXCP"><vers num="0.299"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0822" published="2006-02-21" seq="2006-0822" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in EmuLinker Kaillera Server before 0.99.17 allows remote attackers to cause a denial of service (probably resource consumption) via a crafted packet that causes a &quot;ghost game&quot; to be left on the server.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=394690&amp;group_id=127754"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0665">ADV-2006-0665</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18938">18938</ref><ref source="BID" url="http://www.securityfocus.com/bid/16733">16733</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24784">
emulinker-packet-handling-dos(24784)</ref></refs><vuln_soft><prod name="EmuLinker Kaillera Server" vendor="EmuLinker Kaillera Server"><vers num="0.98.5"/><vers num="0.98.2"/><vers num="0.97.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0823" published="2006-02-21" seq="2006-0823" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to inject arbitrary SQL commands via the (1) userid variable to users.php or (2) sessid variable to lib-sessions.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00102-02192006"></ref><ref source="" url="http://www.geeklog.net/article.php/geeklog-1.4.0sr1"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0661">ADV-2006-0661</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18920">18920</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425506/100/0/threaded">20060219 Geeklog Remote Code Execution</ref><ref source="OSVDB" url="http://www.osvdb.org/23348">23348</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24775">geeklog-users-sessions-sql-injection(24775)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16755">16755</ref></refs><vuln_soft><prod name="Geeklog" vendor="Geeklog"><vers num="1.4.0"/><vers num="1.3.11 sr3"/><vers num="1.3.11 sr2"/><vers num="1.3.11 sr1"/><vers num="1.3.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0824" published="2006-02-21" seq="2006-0824" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in lib-common.php in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to include arbitrary local files and execute arbitrary code via (1) absolute paths in unspecified parameters and (2) the language cookie, as demonstrated for code execution using error.log.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00102-02192006"></ref><ref patch="1" source="" url="http://www.geeklog.net/article.php/geeklog-1.4.0sr1"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0661">ADV-2006-0661</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18920">18920</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425506/100/0/threaded">20060219 Geeklog Remote Code Execution</ref><ref source="OSVDB" url="http://www.osvdb.org/23349">23349</ref><ref source="BID" url="http://www.securityfocus.com/bid/16755">16755</ref></refs><vuln_soft><prod name="Geeklog" vendor="Geeklog"><vers num="1.4.0"/><vers num="1.3.11 sr3"/><vers num="1.3.11 sr2"/><vers num="1.3.11 sr1"/><vers num="1.3.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0825" published="2006-02-21" seq="2006-0825" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allow remote attackers to bypass authentication or gain &quot;unauthorized network access&quot; via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0668">ADV-2006-0668</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18952">18952</ref><ref source="BID" url="http://www.securityfocus.com/bid/16726">16726</ref><ref source="OSVDB" url="http://www.osvdb.org/23359">23359</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015648">1015648</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24804">xerox-workcentre-auth-bypass(24804)</ref></refs><vuln_soft><prod name="WorkCentre Pro" vendor="Xerox"><vers num="232"/><vers num="238"/><vers num="245"/><vers num="255"/><vers num="265"/><vers num="275"/></prod><prod name="WorkCentre" vendor="Xerox"><vers num="232"/><vers num="238"/><vers num="245"/><vers num="255"/><vers num="265"/><vers num="275"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0826" published="2006-02-21" seq="2006-0826" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote attackers to cause a denial of service via a crafted Postscript request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0668">ADV-2006-0668</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18952">18952</ref><ref source="BID" url="http://www.securityfocus.com/bid/16723">16723</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015648">1015648</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24805">xerox-workcentre-postscript-dos(24805)</ref></refs><vuln_soft><prod name="WorkCentre Pro" vendor="Xerox"><vers num="232"/><vers num="238"/><vers num="245"/><vers num="255"/><vers num="265"/><vers num="275"/></prod><prod name="WorkCentre" vendor="Xerox"><vers num="232"/><vers num="238"/><vers num="245"/><vers num="255"/><vers num="265"/><vers num="275"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0827" published="2006-02-21" seq="2006-0827" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0668">ADV-2006-0668</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18952">18952</ref><ref source="BID" url="http://www.securityfocus.com/bid/16727">16727</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24806">xerox-workcentre-xss(24806)</ref></refs><vuln_soft><prod name="WorkCentre Pro" vendor="Xerox"><vers num="232"/><vers num="238"/><vers num="245"/><vers num="255"/><vers num="265"/><vers num="275"/></prod><prod name="WorkCentre" vendor="Xerox"><vers num="232"/><vers num="238"/><vers num="245"/><vers num="255"/><vers num="265"/><vers num="275"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0828" published="2006-02-21" seq="2006-0828" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote attackers to &quot;reduce effectiveness of security features&quot; via unknown attack vectors.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0668">ADV-2006-0668</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18952">18952</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015648">1015648</ref></refs><vuln_soft><prod name="WorkCentre Pro" vendor="Xerox"><vers num="232"/><vers num="238"/><vers num="245"/><vers num="255"/><vers num="265"/><vers num="275"/></prod><prod name="WorkCentre" vendor="Xerox"><vers num="232"/><vers num="238"/><vers num="245"/><vers num="255"/><vers num="265"/><vers num="275"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0829" published="2006-02-21" seq="2006-0829" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in E-Blah Platinum 9.7 allows remote attackers to inject arbitrary web script or HTML via the referer (HTTP_REFERER), which is not sanitized when the log file is viewed by the administrator using &quot;Click Log&quot;.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://evuln.com/vulns/83/summary.html"></ref><ref patch="1" source="" url="http://www.eblah.com/forum/m-1140116897/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16713">16713</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0638">ADV-2006-0638</ref><ref source="OSVDB" url="http://www.osvdb.org/23299">23299</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18992">18992</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426582/100/0/threaded">20060302 [eVuln] E-Blah Platinum &apos;Referer&apos; XSS Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24777">eblah-httpreferer-xss(24777)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/528">528</ref></refs><vuln_soft><prod name="Platinum" vendor="E-Blah"><vers num="9.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0830" published="2006-02-21" seq="2006-0830" severity="High" type="CVE"><desc><descript source="cve">The scripting engine in Internet Explorer allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary code via a web page that contains a recurrent call to an infinite loop in Javascript or VBscript, which consumes the stack, as demonstrated by resetting the &quot;location&quot; variable within the loop.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425283/100/0/threaded">20060216 Stack overflow vulnerability in Internet Explorer exploitable trough VBScript and JScript scripting engines.</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/425378/100/0/threaded">20060218 Re: Stack overflow vulnerability in Internet Explorer exploitable trough VBScript and JScript scripting engines.</ref><ref source="BID" url="http://www.securityfocus.com/bid/16687">
16687</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24788">
ie-script-engine-stack-dos(24788)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-23" name="CVE-2006-0831" published="2006-02-21" seq="2006-0831" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in index.php in Tasarim Rehberi allows remote attackers to execute arbitrary PHP code via a URL in the (1) sayfaadi or (2) sayfa parameter.  NOTE: this might be a site-specific issue.  If so, it should not be included in CVE.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425389/100/0/threaded">20060218 Tasarim Rehberi Index.PHP Remote Command Exucetion</ref></refs><vuln_soft><prod name="Tasarim Rehberi" vendor="Tasarim Rehberi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0832" published="2006-02-21" seq="2006-0832" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in admin.asp in WPC.easy allow remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425395/100/0/threaded">20060218 SLQ Injection vulnerability in WPCeasy</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0662">ADV-2006-0662</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18945">18945</ref><ref source="BID" url="http://www.securityfocus.com/bid/16721">16721</ref><ref source="SREASON" url="http://securityreason.com/securityalert/456">456</ref></refs><vuln_soft><prod name="WPC.easy" vendor="WPC.easy"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0833" published="2006-02-21" seq="2006-0833" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Barracuda Directory 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) Add URL and (2) Suggest Category module.  NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0674">ADV-2006-0674</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18965">18965</ref><ref source="BID" url="http://www.securityfocus.com/bid/16746">16746</ref><ref source="OSVDB" url="http://www.osvdb.org/23372">23372</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24807">barracuda-multiple-xss(24807)</ref></refs><vuln_soft><prod name="Barracuda Directory" vendor="BoonEx"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0834" published="2006-02-21" seq="2006-0834" severity="High" type="CVE"><desc><descript source="cve">Uniden UIP1868P VoIP Telephone and Router has a default password of admin for the web-based configuration utility, which allows remote attackers to obtain sensitive information on the device such as telephone numbers called, and possibly connect to other hosts.  NOTE: it is possible that this password was configured by a reseller, not the original vendor; if so, then this is not a vulnerability in the product.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425362/100/0/threaded">20060216 Uniden UIP1868P (VoIP phone/gateway) default easy-to-guess password vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24786">
uniden-uip1868p-default-account(24786)</ref></refs><vuln_soft><prod name="UIP1868P" vendor="Uniden"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0835" published="2006-02-21" seq="2006-0835" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in dropbase.php in MitriDAT Web Calendar Pro allows remote attackers to modify internal SQL queries and cause a denial of service (inaccessible database) via the tabls parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0340.html">20060215 Web Calendar Pro - Denial of Service SQL Injection Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24729">webcalendarpro-dropbase-sql-injection(24729)</ref><ref source="" url="http://www.xorcrew.net/xpa/XPA-WebCalendarPro.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16789">16789</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0700">ADV-2006-0700</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18902">18902</ref></refs><vuln_soft><prod name="Web Calendar Pro" vendor="MitriDAT"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0836" published="2006-02-21" seq="2006-0836" severity="Low" type="CVE"><desc><descript source="cve">Mozilla Thunderbird 1.5 allows user-assisted attackers to cause an unspecified denial of service by tricking the user into importing an LDIF file with a long field into the address book, as demonstrated by a long homePhone field.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0399.html">20060217 Mozila Thunderbird 1.5 Address Book DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/16716">16716</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425602/100/0/threaded">20060221 Mozila Thunderbird 1.5 Address Book DoS</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24810">
thunderbird-address-book-dos(24810)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/469">469</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-0837" published="2006-02-21" seq="2006-0837" severity="Low" type="CVE"><desc><descript source="cve">IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 has world-readable permissions for (1) /etc/neusecure.conf, (2) /opt/NeuSecure/etc/cms-3.0.236.buildconf, and (3) /opt/NeuSecure/bin/ns_archiver.log, which allows local users to read sensitive information such as passwords.  NOTE: IBM has privately confirmed to CVE that a fix is available for these issues.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425304/100/0/threaded">20060216 Password disclosure and remote access in Netcool/NeuSecure Security information management platform</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0364.html">20060216 Password disclosure and remote access in Netcool/NeuSecure Security information management platform</ref><ref source="BID" url="http://www.securityfocus.com/bid/16700">16700</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015642">1015642</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18922">18922</ref><ref source="OSVDB" url="http://www.osvdb.org/23270">23270</ref><ref source="OSVDB" url="http://www.osvdb.org/23271">23271</ref><ref source="BID" url="http://www.securityfocus.com/bid/16693">16693</ref><ref source="OSVDB" url="http://www.osvdb.org/23914">23914</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24785">
netcool-neosecure-config-weak-permission(24785)</ref></refs><vuln_soft><prod name="Netcool_NeuSecure" vendor="Micromuse"><vers num="3.0.236"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-0838" published="2006-02-21" seq="2006-0838" severity="Low" type="CVE"><desc><descript source="cve">IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 stores cleartext passwords in the (1) CMS_DBPASS, (2) CMSM_DBPASS, and (3) RPT_DBPASS fields in /etc/neusecure.conf, and in (4) /opt/NeuSecure/bin/ns_archiver.log, which allows local users to gain privileges.  NOTE: IBM has privately confirmed to CVE that a fix is available for these issues.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425304/100/0/threaded">20060216 Password disclosure and remote access in Netcool/NeuSecure Security information management platform</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0364.html">20060216 Password disclosure and remote access in Netcool/NeuSecure Security information management platform</ref><ref source="BID" url="http://www.securityfocus.com/bid/16698">16698</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015642">1015642</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18922">18922</ref><ref source="OSVDB" url="http://www.osvdb.org/23270">23270</ref><ref source="OSVDB" url="http://www.osvdb.org/23271">23271</ref><ref source="BID" url="http://www.securityfocus.com/bid/16693">16693</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24785">
netcool-neosecure-config-weak-permission(24785)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24787">
netcool-neosecure-plaintext-password(24787)</ref></refs><vuln_soft><prod name="Netcool_NeuSecure" vendor="Micromuse"><vers num="3.0.236"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-24" name="CVE-2006-0839" published="2006-02-21" seq="2006-0839" severity="Medium" type="CVE"><desc><descript source="cve">The frag3 preprocessor in Sourcefire Snort 2.4.3 does not properly reassemble certain fragmented packets with IP options, which allows remote attackers to evade detection of certain attacks, possibly related to IP option lengths.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425290/100/0/threaded">20060217 SNORT Incorrect fragmented packet reassembly</ref><ref source="BID" url="http://www.securityfocus.com/bid/16705">16705</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18959">18959</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24811">
snort-frag3-detection-bypass(24811)</ref></refs><vuln_soft><prod name="Snort" vendor="Sourcefire"><vers num="2.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0840" published="2006-02-21" seq="2006-0840" severity="Medium" type="CVE"><desc><descript source="cve">manage_user_page.php in Mantis 1.00rc4 and earlier does not properly handle a sort parameter containing a &apos; (quote) character, which allows remote attackers to trigger a SQL error that may be repeatedly reported to a user who makes subsequent web accesses with the MANTIS_MANAGE_COOKIE cookie.  NOTE: this issue might be the same as vector 2 in CVE-2005-4519.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425046/100/0/threaded">20060215 [BuHa-Security] Multiple Vulnerabilities in Mantis 1.00rc4</ref><ref adv="1" patch="1" source="" url="http://morph3us.org/advisories/20060214-mantis-100rc4.txt"></ref><ref patch="1" source="" url="http://sourceforge.net/project/showfiles.php?group_id=14963&amp;package_id=12175&amp;release_id=386059"></ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=386059&amp;group_id=14963"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16657">16657</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24726">
mantis-manageuserpagesql-injection(24726)</ref></refs><vuln_soft><prod name="Mantis" vendor="Mantis"><vers num="1.0.0 rc4" prev="1"/><vers num="1.0.0 rc3"/><vers num="1.0.0 rc2"/><vers num="1.0.0 rc1"/><vers num="1.0.0a3"/><vers num="1.0.0a2"/><vers num="1.0.0a1"/><vers num="0.9.1"/><vers num="0.9.0"/><vers num="0.9"/><vers num="0.19.4"/><vers num="0.19.3"/><vers num="0.19.2"/><vers num="0.19.1"/><vers num="0.19.0 rc1"/><vers num="0.19.0a2"/><vers num="0.19.0a1"/><vers num="0.19.0a"/><vers num="0.19.0"/><vers num="0.18a1"/><vers num="0.18.3"/><vers num="0.18.2"/><vers num="0.18.1"/><vers num="0.18.0 rc1"/><vers num="0.18.0a4"/><vers num="0.18.0a3"/><vers num="0.18.0a2"/><vers num="0.18.0a1"/><vers num="0.18.0"/><vers num="0.18"/><vers num="0.17.4a"/><vers num="0.17.0"/><vers num="0.17"/><vers num="0.16.0"/><vers num="0.16"/><vers num="0.15.2"/><vers num="0.15.1"/><vers num="0.15.0"/><vers num="0.15"/><vers num="0.14.8"/><vers num="0.14.7"/><vers num="0.14.6"/><vers num="0.14.5"/><vers num="0.14.4"/><vers num="0.14.3"/><vers num="0.14.2"/><vers num="0.14.1"/><vers num="0.14.0"/><vers num="0.14"/><vers num="0.13.1"/><vers num="0.13.0"/><vers num="0.13"/><vers num="0.12.0"/><vers num="0.12"/><vers num="0.11.1"/><vers num="0.11.0"/><vers num="0.11"/><vers num="0.10.2"/><vers num="0.10.1"/><vers num="0.10.0"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0841" published="2006-02-21" seq="2006-0841" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Mantis 1.00rc4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) hide_status, (2) handler_id, (3) user_monitor, (4) reporter_id, (5) view_type, (6) show_severity, (7) show_category, (8) show_status, (9) show_resolution, (10) show_build, (11) show_profile, (12) show_priority, (13) highlight_changed, (14) relationship_type, and (15) relationship_bug parameters in (a) view_all_set.php; the (16) sort parameter in (b) manage_user_page.php; the (17) view_type parameter in (c) view_filters_page.php; and the (18) title parameter in (d) proj_doc_delete.php.  NOTE: item 17 might be subsumed by CVE-2005-4522.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425046/100/0/threaded">20060215 [BuHa-Security] Multiple Vulnerabilities in Mantis 1.00rc4</ref><ref adv="1" patch="1" source="" url="http://morph3us.org/advisories/20060214-mantis-100rc4.txt"></ref><ref source="" url="http://sourceforge.net/project/showfiles.php?group_id=14963&amp;package_id=12175&amp;release_id=386059"></ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=386059&amp;group_id=14963"></ref><ref source="OSVDB" url="http://www.osvdb.org/23248">23248</ref><ref source="OSVDB" url="http://www.osvdb.org/22487">22487</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1133">DSA-1133</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21400">21400</ref><ref source="BID" url="http://www.securityfocus.com/bid/16657">16657</ref></refs><vuln_soft><prod name="Mantis" vendor="Mantis"><vers num="1.0.0 rc4"/><vers num="1.0.0 rc3"/><vers num="1.0.0 rc2"/><vers num="1.0.0 rc1"/><vers num="1.0.0a3"/><vers num="1.0.0a2"/><vers num="1.0.0a1"/><vers num="0.9.1"/><vers num="0.9.0"/><vers num="0.9"/><vers num="0.19.4"/><vers num="0.19.3"/><vers num="0.19.2"/><vers num="0.19.1"/><vers num="0.19.0 rc1"/><vers num="0.19.0a2"/><vers num="0.19.0a1"/><vers num="0.19.0a"/><vers num="0.19.0"/><vers num="0.18a1"/><vers num="0.18.3"/><vers num="0.18.2"/><vers num="0.18.1"/><vers num="0.18.0 rc1"/><vers num="0.18.0a4"/><vers num="0.18.0a3"/><vers num="0.18.0a2"/><vers num="0.18.0a1"/><vers num="0.18.0"/><vers num="0.18"/><vers num="0.17.4a"/><vers num="0.17.0"/><vers num="0.17"/><vers num="0.16.0"/><vers num="0.16"/><vers num="0.15.2"/><vers num="0.15.1"/><vers num="0.15.0"/><vers num="0.15"/><vers num="0.14.8"/><vers num="0.14.7"/><vers num="0.14.6"/><vers num="0.14.5"/><vers num="0.14.4"/><vers num="0.14.3"/><vers num="0.14.2"/><vers num="0.14.1"/><vers num="0.14.0"/><vers num="0.14"/><vers num="0.13.1"/><vers num="0.13.0"/><vers num="0.13"/><vers num="0.12.0"/><vers num="0.12"/><vers num="0.11.1"/><vers num="0.11.0"/><vers num="0.11"/><vers num="0.10.2"/><vers num="0.10.1"/><vers num="0.10.0"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" discovered="2006-02-16" modified="2008-08-18" name="CVE-2006-0842" published="2006-02-21" seq="2006-0842" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Calacode @Mail 4.3 allows remote attackers to inject arbitrary web script or HTML via a modified javascript: string in the SRC attribute of an IMG element in an e-mail message, as demonstrated by &quot;java	script:.&quot;  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><sols><sol source="nvd">Successful exploitation of this issue requires a victim user has @Mail configured to display images in email messages.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16683">16683</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0617">ADV-2006-0617</ref><ref source="OSVDB" url="http://www.osvdb.org/23236">23236</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18874">18874</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24742">@mail-html-image-xss(24742)</ref></refs><vuln_soft><prod name="@mail Webmail System" vendor="CalaCode"><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0843" published="2006-02-21" seq="2006-0843" severity="Medium" type="CVE"><desc><descript source="cve">Leif M. Wright&apos;s Blog 3.5 stores the config file and other txt files under the web root with insufficient access control, which allows remote attackers to read the administrator&apos;s password.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/82/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16712">16712</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18923">18923</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24752">
webblog-txt-obtain-information(24752)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/522">522</ref></refs><vuln_soft><prod name="Web Blog" vendor="Leif M. Wright"><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0844" published="2006-02-21" seq="2006-0844" severity="High" type="CVE"><desc><descript source="cve">Leif M. Wright&apos;s Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, probably by setting the blogAdmin cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/82/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16714">16714</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18923">18923</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24755">
webblog-cookie-auth-bypass(24755)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/522">522</ref></refs><vuln_soft><prod name="Web Blog" vendor="Leif M. Wright"><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0845" published="2006-02-21" seq="2006-0845" severity="Medium" type="CVE"><desc><descript source="cve">Leif M. Wright&apos;s Blog 3.5 allows remote authenticated users with administrative privileges to execute arbitrary programs, including shell commands, by configuring the sendmail path to a malicious pathname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/82/summary.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18923">18923</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24757">
webblog-sendmail-command-execution(24757)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/522">522</ref></refs><vuln_soft><prod name="Web Blog" vendor="Leif M. Wright"><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0846" published="2006-02-21" seq="2006-0846" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Leif M. Wright&apos;s Blog 3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Referer and (2) User-Agent HTTP headers, which are stored in a log file and not sanitized when the administrator views the &quot;Log&quot; page, possibly using the ViewCommentsLog function.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.evuln.com/vulns/82/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16715">16715</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18923">18923</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24758">
webblog-headers-xss(24758)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/522">522</ref></refs><vuln_soft><prod name="Web Blog" vendor="Leif M. Wright"><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-22" name="CVE-2006-0847" published="2006-02-21" seq="2006-0847" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the staticfilter component in CherryPy before 2.1.1 allows remote attackers to read arbitrary files via &quot;..&quot; sequences in unspecified vectors.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=384316&amp;group_id=56099"></ref><ref patch="1" source="" url="http://groups.google.com/group/cherrypy-announce/browse_thread/thread/92b2972f774fe6df/2f63afc9433dc306#2f63afc9433dc306"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16760">16760</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0677">ADV-2006-0677</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24809">cherrypy-staticfilter-directory-traversal(24809)</ref><ref source="" url="http://www.cherrypy.org/"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/18944">18944</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-16.xml">GLSA-200605-16</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20344">20344</ref></refs><vuln_soft><prod name="CherryPy" vendor="CherryPy"><vers num="2.1.0"/><vers num="2.1.0 rc2"/><vers num="2.1.0 rc1"/><vers num="2.1.0 Beta"/><vers num="2.0.0"/><vers num="2.0.0a1"/><vers num="0.10"/><vers num="0.10 rc1"/><vers num="0.10 Beta"/><vers num="0.9"/><vers num="0.9 rc1"/><vers num="0.9 gamma"/><vers num="0.9 Beta"/><vers num="0.8"/><vers num="0.8 Beta"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0848" published="2006-02-22" seq="2006-0848" severity="Medium" type="CVE"><desc><descript source="cve">The &quot;Open &apos;safe&apos; files after downloading&quot; option in Safari on Apple Mac OS X allows remote user-assisted attackers to execute arbitrary commands by tricking a user into downloading a __MACOSX folder that contains metadata (resource fork) that invokes the Terminal, which automatically interprets the script using bash, as demonstrated using a ZIP file that contains a script with a safe file extension.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.mathematik.uni-ulm.de/numerik/staff/lehn/macosx.html"></ref><ref source="" url="http://www.heise.de/english/newsticker/news/69862"></ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-053A.html">TA06-053A</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/999708">VU#999708</ref><ref source="" url="http://www.frsirt.com/exploits/20060222.safari_safefiles_exec.pm.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16736">16736</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0671">ADV-2006-0671</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18963">18963</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015652">1015652</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24808">macosx-zip-command-execution(24808)</ref><ref source="OSVDB" url="http://www.osvdb.org/23510">23510</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=303382"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html">TA06-062A</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-23" name="CVE-2006-0850" published="2006-02-22" seq="2006-0850" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in include/includes/user/login.php in ilchClan before 1.05g allows remote attackers to execute arbitrary SQL commands via the login_name parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.ilch.de/news-134.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0676">ADV-2006-0676</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18951">18951</ref><ref source="OSVDB" url="http://www.osvdb.org/23370">23370</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24830">ilchclan-login-sql-injection(24830)</ref></refs><vuln_soft><prod name="ilchClan" vendor="ilch.de"><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/><vers num="0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-23" name="CVE-2006-0851" published="2006-02-22" seq="2006-0851" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the forum module of ilchClan 1.05g and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter, when creating a newpost.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/id.php?id=1516"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0672">ADV-2006-0672</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18951">18951</ref><ref source="BID" url="http://www.securityfocus.com/bid/16735">16735</ref><ref source="OSVDB" url="http://www.osvdb.org/23369">23369</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24829">ilchclan-index-sql-injection(24829)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1516">

1516</ref></refs><vuln_soft><prod name="ilchClan" vendor="ilch.de"><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/><vers num="0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-23" name="CVE-2006-0852" published="2006-02-22" seq="2006-0852" severity="High" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in write.php in Admbook 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via the X-Forwarded-For HTTP header field, which is inserted into content-data.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/id.php?id=1512"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0663">ADV-2006-0663</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18930">18930</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24771">admbook-index-command-execution(24771)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16753">16753</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1512">

1512</ref></refs><vuln_soft><prod name="Admbook" vendor="devScripts"><vers num="1.2.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-0853" published="2006-02-22" seq="2006-0853" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the IMAP service of TrueNorth Internet Anywhere (IA) eMailserver 5.3.4 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long SEARCH argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425586/100/0/threaded">20060220 [AJECT] TrueNorth IA eMailserver 5.3.4 buffer overflow vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16744">16744</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0686">ADV-2006-0686</ref><ref source="OSVDB" url="http://www.osvdb.org/23377">23377</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015664">1015664</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18986">18986</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24812">ia-emailserver-imap-bo(24812)</ref></refs><vuln_soft><prod name="IA eMailServer" vendor="TrueNorth Software"><vers num="Corporate 5.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0854" published="2006-02-22" seq="2006-0854" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in common.php in Intensive Point iUser Ecommerce allows remote attackers to include arbitrary files via a URL in the include_path variable, which is not initialized before being used.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0339.html">20060215 iUser Ecommerce - Remote Command Execution Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24724">iuser-ecommerce-file-include(24724)</ref><ref source="" url="http://www.xorcrew.net/xpa/XPA-iUser.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0699">ADV-2006-0699</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18903">18903</ref><ref source="BID" url="http://www.securityfocus.com/bid/16787">16787</ref><ref source="OSVDB" url="http://www.osvdb.org/23429">23429</ref></refs><vuln_soft><prod name="iUser Ecommerce" vendor="Intensive Point"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-02-03" modified="2006-08-28" name="CVE-2006-0855" published="2006-02-23" seq="2006-0855" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the fullpath function in misc.c for zoo 2.10 and earlier, as used in products such as Barracuda Spam Firewall, allows user-assisted attackers to execute arbitrary code via a crafted ZOO file that causes the combine function to return a longer string than expected.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425887/100/0/threaded">20060223 zoo contains exploitable buffer overflows</ref><ref source="BID" url="http://www.securityfocus.com/bid/16790">16790</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0705">ADV-2006-0705</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015668">1015668</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19002">19002</ref><ref adv="1" source="" url="http://www.guay-leroux.com/projects/zoo-advisory.txt"></ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-05.xml">GLSA-200603-05</ref><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_05_sr.html">SUSE-SR:2006:005</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19130">19130</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19148">19148</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-991">DSA-991</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19166">19166</ref><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_06_sr.html">SUSE-SR:2006:006</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19408">19408</ref><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0061.html">20060403 Barracuda ZOO archiver security bug leads to remote compromise</ref><ref adv="1" source="" url="http://www.guay-leroux.com/projects/barracuda-advisory-ZOO.txt"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1220">ADV-2006-1220</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015866">1015866</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19514">19514</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24904">
zoo-misc-bo(24904)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/546">546</ref></refs><vuln_soft><prod name="zoo" vendor="Rahul Dhesi"><vers num="2.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-01" name="CVE-2006-0856" published="2006-02-23" seq="2006-0856" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.php in Scriptme SmE GB Host 1.21 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the Username parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425317/100/0/threaded">20060216 [eVuln] SmE GB Host Authentication Bypass Vulnerability</ref><ref adv="1" source="" url="http://www.evuln.com/vulns/66/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16609">16609</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18823">18823</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0543">
ADV-2006-0543</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24544">
smegbhost-login-sql-injection(24544)</ref></refs><vuln_soft><prod name="SmE GB Host" vendor="Scriptme"><vers num="1.21"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-01" name="CVE-2006-0857" published="2006-02-23" seq="2006-0857" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Chatbox Plugin 1.0 in e107 0.7.2 allows remote attackers to inject arbitrary HTML or web script via a Chatbox, as demonstrated using a SCRIPT element.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425388/100/0/threaded">20060218 e107 CMS 0.7.2 Chatbox plugin XSS vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16719">16719</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24815">
e107-chatbox-xss(24815)</ref></refs><vuln_soft><prod name="e107" vendor="e107"><vers num="0.7.2"/></prod><prod name="Chatbox Plugin" vendor="e107"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-01" name="CVE-2006-0858" published="2006-02-23" seq="2006-0858" severity="High" type="CVE"><desc><descript source="cve">Unquoted Windows search path vulnerability in (1) snsmcon.exe, (2) the autostartup mechanism, and (3) an unspecified installation component in StarForce Safe&apos;n&apos;Sec Personal + Anti-Spyware 2.0 and earlier, and possibly other StarForce Safe&apos;n&apos;Sec products, might allow local users to gain privileges via a malicious &quot;program&quot; file in the C: folder.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425504/100/0/threaded">20060219 [TZO-062006] Safe&apos;nVulnerable</ref><ref source="" url="http://secdev.zoller.lu/research/safnsec.htm"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16762">16762</ref></refs><vuln_soft><prod name="Safe&apos;n&apos;Sec Personal + Anti-Spyware" vendor="StarForce"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-0859" published="2006-02-23" seq="2006-0859" severity="Medium" type="CVE"><desc><descript source="cve">Michael Salzer Guestbox 0.6, and other versions before 0.8, allows remote attackers to post an admin comment to a guestbook entry via a certain modified form, possibly related to the nummer parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425495/100/0/threaded">20060220 Guestbox XSS/an admin bypass</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426663/100/0/threaded">20060302 Re: Guestbox XSS/an admin bypass</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0675">ADV-2006-0675</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18946">18946</ref><ref source="OSVDB" url="http://www.osvdb.org/23374">23374</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24797">
guestbox-admin-access(24797)</ref></refs><vuln_soft><prod name="Guestbox" vendor="Michael Salzer"><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-0860" published="2006-02-23" seq="2006-0860" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Michael Salzer Guestbox 0.6, and other versions before 0.8, allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags that follow a &quot;http://&quot; string, which bypasses a regular expression check, and (2) other unspecified attack vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425495/100/0/threaded">20060220 Guestbox XSS/an admin bypass</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426663/100/0/threaded">20060302 Re: Guestbox XSS/an admin bypass</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16751">16751</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0675">ADV-2006-0675</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18946">18946</ref><ref source="OSVDB" url="http://www.osvdb.org/23375">23375</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24798">guestbox-gbshow-xss(24798)</ref></refs><vuln_soft><prod name="Guestbox" vendor="Michael Salzer"><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-0861" published="2006-02-23" seq="2006-0861" severity="Medium" type="CVE"><desc><descript source="cve">Michael Salzer Guestbox 0.6, and other versoins before 0.8, allows remote attackers to obtain the source IP addresses of guestbook entries via a direct request to /gb/gblog.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425495/100/0/threaded">20060220 Guestbox XSS/an admin bypass</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/23376">23376</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24799">guestbox-gblog-obtain-information(24799)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426663/100/0/threaded">20060302 Re: Guestbox XSS/an admin bypass</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0675">ADV-2006-0675</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18946">18946</ref><ref source="SREASON" url="http://securityreason.com/securityalert/460">460</ref></refs><vuln_soft><prod name="Guestbox" vendor="Michael Salzer"><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-27" name="CVE-2006-0862" published="2006-02-23" seq="2006-0862" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in InfoVista PortalSE 2.0 Build 20087 on Solaris 8 without the IV00038969 hotfix allows remote attackers to read arbitrary files via a crafted URL.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425779/100/0/threaded">20060222 IRM 017: Multiple Vulnerabilities in Infovista Portal SE</ref><ref source="" url="http://www.irmplc.com/advisory017.htm"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16776">16776</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0695">ADV-2006-0695</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18994">18994</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015669">1015669</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24893">
vistaportal-parameter-directory-traversal(24893)</ref></refs><vuln_soft><prod name="PortalSE" vendor="InfoVista"><vers num="2.0 Build 20087"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-27" name="CVE-2006-0863" published="2006-02-23" seq="2006-0863" severity="Medium" type="CVE"><desc><descript source="cve">InfoVista PortalSE 2.0 Build 20087 on Solaris 8 allows remote attackers to obtain sensitive information by specifying a nonexistent server in the server field, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425779/100/0/threaded">20060222 IRM 017: Multiple Vulnerabilities in Infovista Portal SE</ref><ref adv="1" source="" url="http://www.irmplc.com/advisory017.htm"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16776">16776</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0695">ADV-2006-0695</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18994">18994</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015669">1015669</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24894">
vistaportal-server-path-disclosure(24894)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/473">473</ref></refs><vuln_soft><prod name="PortalSE" vendor="InfoVista"><vers num="2.0 Build 20087"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-27" name="CVE-2006-0864" published="2006-02-23" seq="2006-0864" severity="High" type="CVE"><desc><descript source="cve">filescan in Global Hauri ViRobot 2.0 20050817 does not verify the Cookie HTTP header, which allows remote attackers to gain administrative privileges via an arbitrary cookie value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425788/100/0/threaded">20060222 [INetCop Security Advisory] Global Hauri Virobot cookie exploit</ref><ref source="" url="http://x82.inetcop.org/h0me/adv1sor1es/INCSA.2006-0x82-028-VIROBOT.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16768">16768</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0691">ADV-2006-0691</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18974">18974</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015658">1015658</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24850">virobot-filescan-auth-bypass(24850)</ref></refs><vuln_soft><prod name="ViRobot" vendor="Hauri"><vers num="2.0 2005-08-17"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-27" name="CVE-2006-0865" published="2006-02-23" seq="2006-0865" severity="Medium" type="CVE"><desc><descript source="cve">PunBB 1.2.10 and earlier allows remote attackers to cause a denial of service (resource consumption) by registering many user accounts quickly.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425630/100/0/threaded">20060219 PunBB 1.2.10 Multiple DoS Vulnerabilities</ref><ref source="" url="http://www.neosecurityteam.net/advisories/Advisory-15.txt"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24837">
punbb-register-ip-dos(24837)</ref></refs><vuln_soft><prod name="PunBB" vendor="PunBB"><vers num="1.2.10"/><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1.5"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0 Beta3"/><vers num="1.0 Beta2"/><vers num="1.0 Beta1a"/><vers num="1.0 Beta1"/><vers num="1.0 alpha"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-27" name="CVE-2006-0866" published="2006-02-23" seq="2006-0866" severity="Medium" type="CVE"><desc><descript source="cve">PunBB 1.2.10 and earlier allows remote attackers to conduct brute force guessing attacks for an account&apos;s password, which may be as short as 4 characters.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425630/100/0/threaded">20060219 PunBB 1.2.10 Multiple DoS Vulnerabilities</ref><ref source="" url="http://www.neosecurityteam.net/advisories/Advisory-15.txt"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24838">
punbb-login-bruteforce(24838)</ref></refs><vuln_soft><prod name="PunBB" vendor="PunBB"><vers num="1.2.10"/><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1.5"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0 Beta3"/><vers num="1.0 Beta2"/><vers num="1.0 Beta1a"/><vers num="1.0 Beta1"/><vers num="1.0 alpha"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-27" name="CVE-2006-0867" published="2006-02-23" seq="2006-0867" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in certain versions of South River (aka SRT) WebDrive, possibly version 6.08 build 1131 and version 8, allows remote attackers to cause a denial of service (application crash and persistent erratic behavior) via a long string in the name entry field.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425785/100/0/threaded">20060222 South River WebDrive Buffer Overflow Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24903">
webdrive-name-bo(24903)</ref></refs><vuln_soft><prod name="WebDrive" vendor="South River"><vers num="6.08 build 1131"/><vers num="8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-24" name="CVE-2006-0868" published="2006-02-23" seq="2006-0868" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before 1.3.0r4, allow remote attackers to &quot;falsify authentication credentials,&quot; related to the &quot;underlying storage containers.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425796/100/0/threaded">20060222 Multiple Injection Vulnerabilities in PHP PEAR::Auth Module</ref><ref patch="1" source="Pear" url="http://pear.php.net/package/Auth/download/1.2.4">Package Information: Auth 1.2.4</ref><ref patch="1" source="Pear" url="http://pear.php.net/package/Auth/download/1.3.0r4">Package Information: Auth 1.3.0r4</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/16758">16758</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0696">ADV-2006-0696</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015666">1015666</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19008">19008</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24854">auth-multiple-injections(24854)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-13.xml">GLSA-200603-13</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19301">19301</ref></refs><vuln_soft><prod name="XML_RPC" vendor="PEAR"><vers num="1.3.0RC3"/><vers num="1.3.0RC2"/><vers num="1.3.0RC1"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2.0RC7"/><vers num="1.2.0RC6"/><vers num="1.2.0RC5"/><vers num="1.2.0RC4"/><vers num="1.2.0RC3"/><vers num="1.2.0RC2"/><vers num="1.2.0RC1"/><vers num="1.2.0"/><vers num="1.1.0"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0869" published="2006-02-23" seq="2006-0869" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the &quot;remember me&quot; feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425711/100/0/threaded">20060221 PEAR LiveUser File Access Vulnerabilities</ref><ref adv="1" source="" url="http://www.gulftech.org/?node=research&amp;article_id=00103-02212006"></ref><ref patch="1" source="" url="http://pear.php.net/package/LiveUser/download/"></ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00103-02212006"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16761">16761</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0697">ADV-2006-0697</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015659">1015659</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24852">liveuser-liveuser-file-access(24852)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24853">liveuser-liveuser-file-deletion(24853)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/466">466</ref></refs><vuln_soft><prod name="PEAR LiveUser" vendor="PEAR"><vers num="0.16.8"/><vers num="0.16.7"/><vers num="0.16.6"/><vers num="0.16.5"/><vers num="0.16.4"/><vers num="0.16.3"/><vers num="0.16.2"/><vers num="0.16.1"/><vers num="0.16.0"/><vers num="0.15.1"/><vers num="0.15.0"/><vers num="0.14.0"/><vers num="0.13.3"/><vers num="0.13.2"/><vers num="0.13.1"/><vers num="0.13.0"/><vers num="0.12.0"/><vers num="0.11.1"/><vers num="0.11.0"/><vers num="0.10.0"/><vers num="0.9"/><vers num="0.8.1"/><vers num="0.8"/><vers num="0.7"/><vers num="0.6.1"/><vers num="0.6"/><vers num="0.5.1"/><vers num="0.5"/><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-0870" published="2006-02-23" seq="2006-0870" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in pages.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.  NOTE: version 2.3 was later reported to be vulnerable as well.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425599/100/0/threaded">20060220 MiniNuke CMS System all versions (pages.asp) SQL Injection</ref><ref source="" url="http://www.nukedx.com/?viewdoc=9"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16730">16730</ref><ref source="OSVDB" url="http://www.osvdb.org/23438">23438</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18439">18439</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24803">mininuke-pages-sql-injection(24803)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428361/100/0/threaded">20060321 Mini-Nuke&lt;=1.8.2 SQL injection (6)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431602/100/0/threaded">20060420 Mini-NUKE v2.3&lt;&lt;--- SQL Injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/17636">17636</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431714/100/0/threaded">20060421 Re: Mini-NUKE v2.3&lt;&lt;--- SQL Injection</ref></refs><vuln_soft><prod name="Mini-Nuke CMS" vendor="Mini-Nuke"><vers num="1.8.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-0871" published="2006-02-24" seq="2006-0871" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read and include arbitrary files via the mos_change_template parameter.  NOTE: CVE-2006-1794 has been assigned to the SQL injection vector.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://source.mambo-foundation.org/view/news/Announcements/Security_Patch_Released/"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18935">18935</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16775">16775</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0719">ADV-2006-0719</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0463.html">20060224 Mambo Multiple Vulnerabilities</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00104-02242006"></ref><ref source="OSVDB" url="http://www.osvdb.org/23505">23505</ref><ref source="SREASON" url="http://securityreason.com/securityalert/493">493</ref></refs><vuln_soft><prod name="Mambo" vendor="Mambo"><vers edition="h" num="4.5.3h"/><vers num="4.5.3h"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-24" name="CVE-2006-0872" published="2006-02-24" seq="2006-0872" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in init.inc.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the lang parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://retrogod.altervista.org/cpg_143_adv.html"></ref><ref source="" url="http://retrogod.altervista.org/cpg_143_incl_xpl.html"></ref><ref patch="1" source="" url="http://coppermine-gallery.net/forum/index.php?topic=28062.0"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0669">ADV-2006-0669</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015646">1015646</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18941">18941</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/425387">20060218 Coppermine Photo Gallery &lt;=1.4.3 remote code execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/16718">16718</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24814">
coppermine-init-file-include(24814)</ref></refs><vuln_soft><prod name="Coppermine Photo Gallery" vendor="Coppermine"><vers num="1.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-24" name="CVE-2006-0873" published="2006-02-24" seq="2006-0873" severity="Medium" type="CVE"><desc><descript source="cve">Absolute path traversal vulnerability in docs/showdocs.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via the f parameter, and possibly remote files using UNC share pathnames.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://retrogod.altervista.org/cpg_143_adv.html"></ref><ref patch="1" source="" url="http://coppermine-gallery.net/forum/index.php?topic=28062.0"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0669">ADV-2006-0669</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015646">1015646</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18941">18941</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/425387">20060218 Coppermine Photo Gallery &lt;=1.4.3 remote code execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/16718">16718</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24816">
coppermine-showdoc-file-include(24816)</ref></refs><vuln_soft><prod name="Coppermine Photo Gallery" vendor="Coppermine"><vers num="1.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-05" name="CVE-2006-0874" published="2006-02-24" seq="2006-0874" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Intensive Point iUser Ecommerce before 2.2 have unspecified vectors and impact, as addressed by &quot;Urgent secure fixes&quot;.  NOTE: this might be a duplicate of CVE-2006-0854, but the vendor announcement for this issue (from January 8, 2005) is too vague to be sure, and CVE-2006-0854 does not provide version information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="" url="http://www.intensivepoint.com/iuser-document.shtml"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16787">16787</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19003">19003</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24906">iuser-ecommerce-undisclosed(24906)</ref></refs><vuln_soft><prod name="iUser Ecommerce" vendor="Intensive Point"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-24" name="CVE-2006-0875" published="2006-02-24" seq="2006-0875" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in ratefile.php in RunCMS 1.3a5 allows remote attackers to inject arbitrary web script or HTML via the lid parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425775/100/0/threaded">20060222 [KAPDA::#27] - Runcms 1.x Cross_Site_Scripting vulnerability</ref><ref adv="1" source="" url="http://kapda.ir/advisory-267.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16769">16769</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0694">ADV-2006-0694</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015663">1015663</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18997">18997</ref><ref source="OSVDB" url="http://www.osvdb.org/23388">23388</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24871">runcms-ratefile-xss(24871)</ref></refs><vuln_soft><prod name="RunCMS" vendor="RunCMS"><vers num="1.2"/><vers num="1.1a"/><vers num="1.1"/><vers num="1.3a2"/><vers num="1.3a"/><vers num="1.3a5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-24" name="CVE-2006-0876" published="2006-02-24" seq="2006-0876" severity="Medium" type="CVE"><desc><descript source="cve">POPFile before 0.22.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving character sets within e-mail messages.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://popfile.sourceforge.net/cgi-bin/wiki.pl?ReleaseNotes/0.22.4"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0698">ADV-2006-0698</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18975">18975</ref><ref source="BID" url="http://www.securityfocus.com/bid/16792">16792</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1061">DSA-1061</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20205">20205</ref></refs><vuln_soft><prod name="POPFile" vendor="POPFile"><vers num="0.21.2"/><vers num="0.20.1"/><vers num="0.19.1"/><vers num="0.18.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-24" name="CVE-2006-0877" published="2006-02-24" seq="2006-0877" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in Easy Forum 2.5 allows remote attackers to inject arbitrary web script or HTML via the image variable.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/85/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0706">ADV-2006-0706</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18996">18996</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24831">easyforum-join-xss(24831)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426760/100/0/threaded">20060304 [eVuln] Easy Forum XSS Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16958">16958</ref><ref source="OSVDB" url="http://www.osvdb.org/23430">23430</ref><ref source="" url="http://hot-things.net/forum/show.php?f=2&amp;topic=20060224080919"></ref></refs><vuln_soft><prod name="Easy Forum" vendor="Easy Forum"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-24" name="CVE-2006-0878" published="2006-02-24" seq="2006-0878" severity="Medium" type="CVE"><desc><descript source="cve">Noah&apos;s Classifieds 1.3 allows remote attackers to obtain the installation path via a direct request to include files, as demonstrated by classifieds/gorum/category.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425783/100/0/threaded">20060222 [KAPDA::#29]Noah&apos;s classifieds multiple vulnerabilities</ref><ref adv="1" source="" url="http://www.kapda.ir/advisory-268.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0703">ADV-2006-0703</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015667">1015667</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24898">
noahs-category-path-disclosure(24898)</ref></refs><vuln_soft><prod name="Noah&apos;s Classifieds" vendor="PhpOutsourcing"><vers num="1.3"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-24" name="CVE-2006-0879" published="2006-02-24" seq="2006-0879" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the search tool in Noah&apos;s Classifieds 1.3 allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425783/100/0/threaded">20060222 [KAPDA::#29]Noah&apos;s classifieds multiple vulnerabilities</ref><ref adv="1" source="" url="http://www.kapda.ir/advisory-268.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16773">16773</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0703">ADV-2006-0703</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015667">1015667</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24896">
noahs-search-sql-injection(24896)</ref></refs><vuln_soft><prod name="Noah&apos;s Classifieds" vendor="PhpOutsourcing"><vers num="1.3"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-24" name="CVE-2006-0880" published="2006-02-24" seq="2006-0880" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah&apos;s Classifieds 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) inf parameter; or, when register_globals is enabled, the (2) upperTemplate and (3) lowerTemplate parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425783/100/0/threaded">20060222 [KAPDA::#29]Noah&apos;s classifieds multiple vulnerabilities</ref><ref adv="1" source="" url="http://www.kapda.ir/advisory-268.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16772">16772</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0703">ADV-2006-0703</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015667">1015667</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24895">
noahs-indexphp-xss(24895)</ref></refs><vuln_soft><prod name="Noah&apos;s Classifieds" vendor="PhpOutsourcing"><vers num="1.3"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-24" name="CVE-2006-0881" published="2006-02-24" seq="2006-0881" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah&apos;s Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demonstrated using the lowerTemplate parameter to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425783/100/0/threaded">20060222 [KAPDA::#29]Noah&apos;s classifieds multiple vulnerabilities</ref><ref adv="1" source="" url="http://www.kapda.ir/advisory-268.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16780">16780</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0703">ADV-2006-0703</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015667">1015667</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24899">
noahs-gorumlib-file-include(24899)</ref></refs><vuln_soft><prod name="Noah&apos;s Classifieds" vendor="PhpOutsourcing"><vers num="1.3"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-24" name="CVE-2006-0882" published="2006-02-24" seq="2006-0882" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in include.php in Noah&apos;s Classifieds 1.3 allows remote attackers to include arbitrary local files via the otherTemplate parameter to index.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425783/100/0/threaded">20060222 [KAPDA::#29]Noah&apos;s classifieds multiple vulnerabilities</ref><ref adv="1" source="" url="http://www.kapda.ir/advisory-268.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16778">16778</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0703">ADV-2006-0703</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015667">1015667</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24900">
noahs-include-directory-traversal(24900)</ref></refs><vuln_soft><prod name="Noah&apos;s Classifieds" vendor="PhpOutsourcing"><vers num="1.3"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-0883" published="2006-03-06" seq="2006-0883" severity="Medium" type="CVE"><desc><descript source="cve">OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child process terminates during PAM authentication, which allows remote attackers to cause a denial of service (client connection refusal) by connecting multiple times to the SSH server, waiting for the password prompt, then disconnecting.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:09.openssh.asc">FreeBSD-SA-06:09</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16892">16892</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0805">ADV-2006-0805</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015706">1015706</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25116">
openssh-openpam-dos(25116)</ref><ref source="" url="http://bugzilla.mindrot.org/show_bug.cgi?id=839"></ref><ref source="OSVDB" url="http://www.osvdb.org/23797">
23797</ref><ref source="SREASON" url="http://securityreason.com/securityalert/520">520</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.4 Releng"/><vers num="5.4 Release"/><vers num="5.4 pre"/><vers num="5.3 Stable"/><vers num="5.3 Releng"/><vers num="5.3 Release"/><vers num="5.3"/><vers num="5.4 Stable"/></prod><prod name="OpenSSH" vendor="OpenBSD"><vers num="3.8.1 p1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0884" published="2006-02-24" seq="2006-0884" severity="Medium" type="CVE"><desc><descript source="cve">The WYSIWYG rendering engine (&quot;rich mail&quot; editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425786/100/0/threaded">20060222 Mozilla Thunderbird : Remote Code Execution &amp; Denial of Service</ref><ref source="BID" url="http://www.securityfocus.com/bid/16770">16770</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015665">1015665</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:052">MDKSA-2006:052</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">GLSA-200605-09</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-21.html"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="OSVDB" url="http://www.osvdb.org/23653">23653</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2024">oval:org.mitre.oval:def:2024</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">
20051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25983">
mozilla-inline-fwd-code-execution(25983)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:052">MDKSA-2006:052</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-0885" published="2006-02-25" seq="2006-0885" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in show_news.php in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the show parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://myimei.com/security/2006-02-20/cutenews141addcommentforprotectedusernamesxss-attack.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0685">ADV-2006-0685</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18981">18981</ref><ref source="OSVDB" url="http://www.osvdb.org/23400">23400</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/425583">20060221 [myimei]CuteNews1.4.1~ Add Comment For Protected UserNames~ XSS Attack</ref><ref source="BID" url="http://www.securityfocus.com/bid/16740">16740</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24835">
cutenews-shownews-xss(24835)</ref></refs><vuln_soft><prod name="CuteNews" vendor="CutePHP"><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0886" published="2006-02-25" seq="2006-0886" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in register.php in DEV web management system 1.5 allows remote attackers to inject arbitrary web script or HTML via the &quot;City/Region&quot; field (mesto variable).  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0723">ADV-2006-0723</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18714">18714</ref><ref source="BID" url="http://www.securityfocus.com/bid/16812">16812</ref><ref source="OSVDB" url="http://www.osvdb.org/23468">23468</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24875">dev-cityregion-xss(24875)</ref></refs><vuln_soft><prod name="Dev Web Management System" vendor="Dev"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-06-08" name="CVE-2006-0887" published="2006-02-25" seq="2006-0887" severity="High" type="CVE"><desc><descript source="cve">Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib distribution is available on the server, allows remote attackers to execute arbitrary PHP code by including a base64-encoded representation of the code in a cookie.  NOTE: this description was significantly updated on 20060605 to reflect new details after an initial vague advisory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=31885&amp;release_id=396091"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0720">ADV-2006-0720</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16902">16902</ref><ref source="BID" url="http://www.securityfocus.com/bid/16801">16801</ref><ref source="OSVDB" url="http://www.osvdb.org/23466">23466</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24873">phplib-code-execution(24873)</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00107-03052006"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016123">1016123</ref></refs><vuln_soft><prod name="PHPLIB" vendor="PHPLib Team"><vers num="7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-27" name="CVE-2006-0888" published="2006-02-25" seq="2006-0888" severity="Low" type="CVE"><desc><descript source="cve">index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unspecified denial of service by registering a large number of users.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/id.php?id=1489"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16616">16616</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1489">

1489</ref></refs><vuln_soft><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-27" name="CVE-2006-0889" published="2006-02-25" seq="2006-0889" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Calcium 3.10.1 allows remote attackers to inject arbitrary web script or HTML via the EventText parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0724">ADV-2006-0724</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19007">19007</ref><ref source="BID" url="http://www.securityfocus.com/bid/16851">16851</ref><ref source="OSVDB" url="http://www.osvdb.org/23471">23471</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24907">
calcium-eventtext-xss(24907)</ref></refs><vuln_soft><prod name="Calcium" vendor="Brown Bear Software"><vers num="3.10.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0890" published="2006-02-25" seq="2006-0890" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in SpeedProject Squeez 5.1, as used in (1) ZipStar 5.1 and (2) SpeedCommander 11.01.4450, allows remote attackers to overwrite arbitrary files via unspecified manipulations in a (1) JAR or (2) ZIP archive.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425973/100/0/threaded">20060224 SpeedCommander 11.0 &amp; ZipStar 5.1 &amp; Squeez 5.1 Directory traversal</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0731">ADV-2006-0731</ref><ref source="OSVDB" url="http://www.osvdb.org/23465">23465</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19006">19006</ref><ref source="BID" url="http://www.securityfocus.com/bid/16807">16807</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24909">
speedproject-zip-jar-directory-traversal(24909)</ref></refs><vuln_soft><prod name="ZipStar" vendor="SpeedProject"><vers num="5.1"/></prod><prod name="SpeedCommander" vendor="SpeedProject"><vers num="11.01 Build4450"/></prod><prod name="Squeez" vendor="SpeedProject"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-27" name="CVE-2006-0891" published="2006-02-25" seq="2006-0891" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in NOCC Webmail 1.0 allow remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing NULL (%00) byte in (1) the _SESSION[&apos;nocc_theme&apos;] parameter in (a) html/footer.php; and (2) the lang and (3) theme parameters and the (4) Accept-Language HTTP header field, when force_default_lang is disabled, in (b) index.php, as demonstrated by injecting PHP code into a profile and accessing it using the lang parameter in index.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html">20060223 NOCC Webmail &lt;= 1.0 multiple vulnerabilities</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16921">16921</ref><ref source="OSVDB" url="http://www.osvdb.org/23416">23416</ref><ref source="" url="http://retrogod.altervista.org/noccw_10_incl_xpl.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16793">16793</ref><ref source="OSVDB" url="http://www.osvdb.org/23417">23417</ref><ref source="OSVDB" url="http://www.osvdb.org/23418">23418</ref><ref source="OSVDB" url="http://www.osvdb.org/23419">23419</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015671">1015671</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24934">
nocc-index-file-include(24934)</ref></refs><vuln_soft><prod name="NOCC" vendor="NOCC"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-27" name="CVE-2006-0892" published="2006-02-25" seq="2006-0892" severity="High" type="CVE"><desc><descript source="cve">NOCC Webmail 1.0 stores e-mail attachments in temporary files with predictable filenames, which makes it easier for remote attackers to execute arbitrary code by accessing the e-mail attachment via directory traversal vulnerabilities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html">20060223 NOCC Webmail &lt;= 1.0 multiple vulnerabilities</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16921">16921</ref><ref source="" url="http://retrogod.altervista.org/noccw_10_incl_xpl.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16793">16793</ref><ref source="OSVDB" url="http://www.osvdb.org/23420">23420</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015671">1015671</ref></refs><vuln_soft><prod name="NOCC" vendor="NOCC"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-27" name="CVE-2006-0893" published="2006-02-25" seq="2006-0893" severity="Medium" type="CVE"><desc><descript source="cve">NOCC Webmail 1.0 allows remote attackers to obtain sensitive information via a direct request to (1) the profiles directory, which leaks e-mail addresses contained in filenames of profiles, and (2) the tmp directory, which lists names of uploaded attachments.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html">20060223 NOCC Webmail &lt;= 1.0 multiple vulnerabilities</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16921">16921</ref><ref source="" url="http://retrogod.altervista.org/noccw_10_incl_xpl.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16793">16793</ref><ref source="OSVDB" url="http://www.osvdb.org/23420">23420</ref><ref source="OSVDB" url="http://www.osvdb.org/23422">23422</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015671">1015671</ref></refs><vuln_soft><prod name="NOCC" vendor="NOCC"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-27" name="CVE-2006-0894" published="2006-02-25" seq="2006-0894" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in NOCC Webmail 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the html_error_occurred parameter in error.php, (2) html_filter_select parameter in filter_prefs.php, (3) html_no_mail parameter in no_mail.php, the (4) page_line, (5) prev, and (6) next parameters in html_bottom_table.php, and the (7) _SESSION[&apos;nocc_theme&apos;] parameter in footer.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html">20060223 NOCC Webmail &lt;= 1.0 multiple vulnerabilities</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16921">16921</ref><ref source="" url="http://retrogod.altervista.org/noccw_10_incl_xpl.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16793">16793</ref><ref source="OSVDB" url="http://www.osvdb.org/23423">23423</ref><ref source="OSVDB" url="http://www.osvdb.org/23424">23424</ref><ref source="OSVDB" url="http://www.osvdb.org/23425">23425</ref><ref source="OSVDB" url="http://www.osvdb.org/23426">23426</ref><ref source="OSVDB" url="http://www.osvdb.org/23427">23427</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015671">1015671</ref></refs><vuln_soft><prod name="NOCC" vendor="NOCC"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-27" name="CVE-2006-0895" published="2006-02-25" seq="2006-0895" severity="Medium" type="CVE"><desc><descript source="cve">NOCC Webmail 1.0 allows remote attackers to obtain the installation path via a direct request to html/header.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html">20060223 NOCC Webmail &lt;= 1.0 multiple vulnerabilities</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16921">16921</ref><ref source="" url="http://retrogod.altervista.org/noccw_10_incl_xpl.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16793">16793</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015671">1015671</ref><ref source="SREASON" url="http://securityreason.com/securityalert/478">478</ref></refs><vuln_soft><prod name="NOCC" vendor="NOCC"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0896" published="2006-02-25" seq="2006-0896" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Sources/Register.php in Simple Machine Forum (SMF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For HTTP header field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/86/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0726">ADV-2006-0726</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19004">19004</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426824/100/0/threaded">20060306 [eVuln] Simple Machines Forum - SMF %27X-Forwarded-For%27 XSS Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16841">16841</ref><ref source="OSVDB" url="http://www.osvdb.org/23480">23480</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-April/000682.html">[VIM] 20060410 VEndor ACK: Simple Machines Forum Register.php X-Forwarded-For XSS</ref><ref source="" url="http://www.simplemachines.org/community/index.php?topic=78841.0"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24915">
smf-register-xss(24915)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/545">545</ref></refs><vuln_soft><prod name="Simple Machines Forum" vendor="Simple Machines"><vers num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-0897" published="2006-02-25" seq="2006-0897" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  SQL injection vulnerability in VCS Virtual Program Management Intranet (VPMi) Enterprise 3.3 allows remote attackers to execute arbitrary SQL commands via the UpdateID0 parameter to Service_Requests.asp.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  NOTE: the vendor has disputed this issue, saying that &quot;[we] have a behind the scenes complex state management system that uses a combination of keys placed in JavaScript and Session State (server side) that protects against the type of SQL injection you describe.  We have tested for many of the cases and have not found it to be an issue.&quot;  Further investigation suggests that the original researcher might have triggered errors using invalid field values, which is not proof of SQL injection; however, the vendor did not receive a response from the original researcher.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16798">16798</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0725">ADV-2006-0725</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18842">18842</ref><ref source="OSVDB" url="http://www.osvdb.org/23479">23479</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24885">vpmi-servicerequests-sql-injection(24885)</ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-March/000598.html">[VIM] 20060310 vendor dispute: VCS</ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-March/000599.html">[VIM] 20060310 Re: vendor dispute: VCS</ref></refs><vuln_soft><prod name="VPMi Enterprise" vendor="Virtual Communication Services"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-27" name="CVE-2006-0898" published="2006-02-25" seq="2006-0898" severity="Low" type="CVE"><desc><descript source="cve">Crypt::CBC Perl module 2.16 and earlier, when running in RandomIV mode, uses an initialization vector (IV) of 8 bytes, which results in weaker encryption when used with a cipher that requires a larger block size than 8 bytes, such as Rijndael.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425966/100/0/threaded">20060223 Vulnerability in Crypt::CBC Perl module, versions &lt;= 2.16</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16802">16802</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18755">18755</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-996">DSA-996</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19187">19187</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-15.xml">GLSA-200603-15</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19303">19303</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_38_security.html">SUSE-SR:2006:015</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20899">20899</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24954">
crypt-cbc-header-weak-encryption(24954)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/488">488</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</ref></refs><vuln_soft><prod name="Crypt CBC" vendor="Lincoln D. Stein"><vers num="2.16" prev="1"/><vers num="2.15"/><vers num="2.14"/><vers num="2.13"/><vers num="2.12"/><vers num="2.11"/><vers num="2.10"/><vers num="2.09"/><vers num="2.08"/><vers num="2.07"/><vers num="2.05"/><vers num="2.04"/><vers num="2.03"/><vers num="2.02"/><vers num="2.01"/><vers num="2.00"/><vers num="1.25"/><vers num="1.24"/><vers num="1.22"/><vers num="1.21"/><vers num="1.20"/><vers num="1.10"/><vers num="1.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2006-0899" published="2006-02-27" seq="2006-0899" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via &quot;..&quot; (dot dot) sequences in the template parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Milworm.com" url="http://milw0rm.com/id.php?id=1533">milw0rm.com [2006-02-26]</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0754">ADV-2006-0754</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19026">19026</ref><ref source="" url="http://retrogod.altervista.org/4images_171_adv.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16855">16855</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426468/100/0/threaded">20060301 4images &lt;=1.7.1 remote code execution</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1533">1533</ref><ref source="OSVDB" url="http://www.osvdb.org/23529">23529</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24938">4images-template-file-include(24938)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/518">518</ref></refs><vuln_soft><prod name="Image Gallery Management System" vendor="4Images"><vers num="1.7.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-01" name="CVE-2006-0900" published="2006-02-27" seq="2006-0900" severity="High" type="CVE"><desc><descript source="cve">nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demonstrated by the ProtoVer NFS test suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2006-February/002982.html">[Dailydave] 20060226 fun with FreeBSD kernel</ref><ref source="BID" url="http://www.securityfocus.com/bid/19017">19017</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19017">19017</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:10.nfs.asc">FreeBSD-SA-06:10</ref><ref source="BID" url="http://www.securityfocus.com/bid/16838">16838</ref><ref source="OSVDB" url="http://www.osvdb.org/23511">23511</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24918">freebsd-nfsd-kernel-dos(24918)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/521">521</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0901" published="2006-02-27" seq="2006-0901" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the hsfs filesystem in Solaris 8, 9, and 10 allows unspecified attackers to cause a denial of service (panic) or execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102161-1">102161</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16826">16826</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19042">19042</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0756">ADV-2006-0756</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015680">1015680</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1628">oval:org.mitre.oval:def:1628</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24911">
solaris-hsfs-privilege-elevation(24911)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="10.0"/><vers edition="SPARC" num="10.0"/><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-0903" published="2006-02-27" seq="2006-0903" severity="Medium" type="CVE"><desc><descript source="cve">MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function.  NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null character, this is not an issue for mysql_query.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="" url="http://rst.void.ru/papers/advisory39.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0752">ADV-2006-0752</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19034">19034</ref><ref source="BID" url="http://www.securityfocus.com/bid/16850">16850</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015693">1015693</ref><ref source="" url="http://bugs.mysql.com/bug.php?id=17667"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:064">MDKSA-2006:064</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19502">19502</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-274-1">USN-274-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19814">19814</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1071">DSA-1071</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1073">DSA-1073</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20241">20241</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20253">20253</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1079">DSA-1079</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20333">20333</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0544.html">RHSA-2006:0544</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20625">20625</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-274-2">USN-274-2</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0653.html">

20060225 mysql &lt;= 5.0.18</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0083.html">
RHSA-2007:0083</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24966">
mysql-query-log-bypass-security(24966)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:064">MDKSA-2006:064</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="5.0.18"/><vers num="5.0.17"/><vers num="5.0.16"/><vers num="5.0.15"/><vers num="5.0.14"/><vers num="5.0.13"/><vers num="5.0.12"/><vers num="5.0.11"/><vers num="5.0.10"/><vers num="5.0.9"/><vers num="5.0.8"/><vers num="5.0.7"/><vers num="5.0.6"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3 Beta"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0.0 alpha"/><vers num="4.1.19"/><vers num="4.1.18"/><vers num="4.1.17"/><vers num="4.1.16"/><vers num="4.1.15"/><vers num="4.1.14"/><vers num="4.1.13"/><vers num="4.1.12"/><vers num="4.1.11"/><vers num="4.1.10"/><vers num="4.1.9"/><vers num="4.1.8"/><vers num="4.1.7"/><vers num="4.1.6"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3 beta"/><vers num="4.1.3.0"/><vers num="4.1.2 alpha"/><vers num="4.1.0 alpha"/><vers num="4.1.0.0"/><vers num="4.0.27"/><vers num="4.0.26"/><vers num="4.0.25"/><vers num="4.0.24"/><vers num="4.0.23"/><vers num="4.0.21"/><vers num="4.0.20"/><vers num="4.0.19"/><vers num="4.0.18"/><vers num="4.0.17"/><vers num="4.0.16"/><vers num="4.0.15"/><vers num="4.0.14"/><vers num="4.0.13"/><vers num="4.0.12"/><vers num="4.0.11 gamma"/><vers num="4.0.11"/><vers num="4.0.10"/><vers num="4.0.9 gamma"/><vers num="4.0.9"/><vers num="4.0.8 gamma"/><vers num="4.0.8"/><vers num="4.0.7 gamma"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5a"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1"/><vers num="4.0.0"/><vers num="3.23.59"/><vers num="3.23.58"/><vers num="3.23.57"/><vers num="3.23.56"/><vers num="3.23.55"/><vers num="3.23.54"/><vers num="3.23.53"/><vers num="3.23.52"/><vers num="3.23.51"/><vers num="3.23.50"/><vers num="3.23.49"/><vers num="3.23.48"/><vers num="3.23.47"/><vers num="3.23.46"/><vers num="3.23.45"/><vers num="3.23.44"/><vers num="3.23.43"/><vers num="3.23.42"/><vers num="3.23.41"/><vers num="3.23.40"/><vers num="3.23.39"/><vers num="3.23.38"/><vers num="3.23.37"/><vers num="3.23.36"/><vers num="3.23.35"/><vers num="3.23.34"/><vers num="3.23.33"/><vers num="3.23.32"/><vers num="3.23.31"/><vers num="3.23.30"/><vers num="3.23.29"/><vers num="3.23.28 gamma"/><vers num="3.23.27"/><vers num="3.23.26"/><vers num="3.23.25"/><vers num="3.23.24"/><vers num="3.23.23"/><vers num="3.23.22"/><vers num="3.23.21"/><vers num="3.23.20 Beta"/><vers num="3.23.19"/><vers num="3.23.18"/><vers num="3.23.17"/><vers num="3.23.16"/><vers num="3.23.15"/><vers num="3.23.14"/><vers num="3.23.13"/><vers num="3.23.12"/><vers num="3.23.11"/><vers num="3.23.10"/><vers num="3.23.9"/><vers num="3.23.8"/><vers num="3.23.7"/><vers num="3.23.6"/><vers num="3.23.5"/><vers num="3.23.4"/><vers num="3.23.3"/><vers num="3.23.2"/><vers num="3.23.1"/><vers num="3.23.0 alpha"/><vers num="3.23"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-0905" published="2006-03-23" seq="2006-0905" severity="High" type="CVE"><desc><descript source="cve">A &quot;programming error&quot; in fast_ipsec in FreeBSD 4.8-RELEASE through 6.1-STABLE and NetBSD 2 through 3 does not properly update the sequence number associated with a Security Association, which allows packets to pass sequence number checks and allows remote attackers to capture IPSec packets and conduct replay attacks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:11.ipsec.asc">FreeBSD-SA-06:11</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17191">17191</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015809">1015809</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19366">19366</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25398">bsd-ipsec-replay(25398)</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-011.txt.asc">NetBSD-SA2006-011</ref><ref source="OSVDB" url="http://www.osvdb.org/24068">24068</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.0 Stable"/><vers num="6.0 Release"/><vers num="5.4 Releng"/><vers num="5.4 Release"/><vers num="5.4 pre"/><vers num="5.3 Stable"/><vers num="5.3 Releng"/><vers num="5.3 Release"/><vers num="5.3"/><vers num="5.2.1 Release"/><vers num="5.2 Releng"/><vers num="5.2 Release"/><vers num="5.2"/><vers num="5.1 Releng"/><vers num="5.1 Release Alpha"/><vers num="5.1 p5 Release"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.0 Releng"/><vers num="5.0 p14 Release"/><vers num="5.0 alpha"/><vers num="5.0"/><vers num="4.11 Stable"/><vers num="4.11 Releng"/><vers num="4.11 p3 Release"/><vers num="4.10 Releng"/><vers num="4.10 p8 Release"/><vers num="4.10 Release"/><vers num="4.10"/><vers num="4.9 Releng"/><vers num="4.9 pre"/><vers num="4.9"/><vers num="4.8 Releng"/><vers num="4.8 p7 Release"/><vers num="4.8 pre"/><vers num="4.8"/><vers num="5.4 Stable"/><vers num="4.10 pre"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0906" published="2006-02-27" seq="2006-0906" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in D3Jeeb Pro 3 allows remote attackers to execute arbitrary SQL commands via the catid parameter in (1) fastlinks.php and (2) catogary.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426197/100/0/threaded">20060226 2 SQL Injection in d3jeeb</ref><ref source="BID" url="http://www.securityfocus.com/bid/16853">16853</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0757">ADV-2006-0757</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015687">1015687</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19062">19062</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24941">
d3jeeb-catid-sql-injection(24941)</ref></refs><vuln_soft><prod name="D3Jeeb Pro" vendor="Top Line"><vers num="3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0907" published="2006-02-27" seq="2006-0907" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in PHP-Nuke before 7.8 Patched 3.2 allows remote attackers to execute arbitrary SQL commands via encoded /%2a (/*) sequences in the query string, which bypasses regular expressions that are intended to protect against SQL injection, as demonstrated via the kala parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426083/100/0/threaded">20060225 [waraxe-2006-SA#047] - Evading sql-injection filters in phpNuke 7.8</ref><ref adv="1" source="" url="http://www.waraxe.us/advisory-47.html"></ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="7.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0908" published="2006-02-27" seq="2006-0908" severity="High" type="CVE"><desc><descript source="cve">PHP-Nuke 7.8 Patched 3.2 allows remote attackers to bypass SQL injection protection mechanisms via /%2a (/*) sequences with the &quot;ad_click&quot; word in the query string, as demonstrated via the kala parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426083/100/0/threaded">20060225 [waraxe-2006-SA#047] - Evading sql-injection filters in phpNuke 7.8</ref><ref adv="1" source="" url="http://www.waraxe.us/advisory-47.html"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/497">497</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="7.8 Patched 3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0909" published="2006-02-28" seq="2006-0909" severity="Medium" type="CVE"><desc><descript source="cve">Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to view sensitive information via a direct request to multiple PHP scripts that include the full path in error messages, including (1) PEAR/Text/Diff/Renderer/inline.php, (2) PEAR/Text/Diff/Renderer/unified.php, (3) PEAR/Text/Diff3.php, (4) class_db.php, (5) class_db_mysql.php, and (6) class_xml.php in the ips_kernel/ directory; (7) mysql_admin_queries.php, (8) mysql_extra_queries.php, (9) mysql_queries.php, and (10) mysql_subsm_queries.php in the sources/sql directory; (11) sources/acp_loaders/acp_pages_components.php; (12) sources/action_admin/member.php and (13) sources/action_admin/paysubscriptions.php; (14) login.php, (15) messenger.php, (16) moderate.php, (17) paysubscriptions.php, (18) register.php, (19) search.php, (20) topics.php, (21) and usercp.php in the sources/action_public directory; (22) bbcode/class_bbcode.php, (23) bbcode/class_bbcode_legacy.php, (24) editor/class_editor_rte.php, (25) editor/class_editor_std.php, (26) post/class_post.php, (27) post/class_post_edit.php, (28) post/class_post_new.php, (29) and post/class_post_reply.php in the sources/classes directory; (30) sources/components_acp/registration_DEPR.php; (31) sources/handlers/han_paysubscriptions.php; (32) func_usercp.php; (33) search_mysql_ftext.php, and (34) search_mysql_man.php in the sources/lib/ directory; and (35) convert/auth.php.bak, (36) external/auth.php, and (37) ldap/auth.php in the sources/loginauth directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425713/100/0/threaded">20060221 Invision Power Board 2.1.4 Multiple Vulnerabilities</ref><ref adv="1" source="" url="http://neosecurityteam.net/advisories/Advisory-16.txt"></ref><ref adv="1" source="" url="http://neosecurityteam.net/index.php?action=advisories&amp;id=16"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24840">invisionpowerboard-multiple-info-disclosure(24840)</ref><ref adv="1" source="" url="http://neosecurityteam.net/index.php?action=advisories&amp;id=16"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466275/100/0/threaded">
20070419 IPB (Invision Power Board) Full Path Disclusure</ref></refs><vuln_soft><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.1.4"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1.0"/><vers num="2.1 RC1"/><vers num="2.1 BETA5"/><vers num="2.1 BETA4"/><vers num="2.1 BETA3"/><vers num="2.1 BETA2"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0910" published="2006-02-28" seq="2006-0910" severity="Medium" type="CVE"><desc><descript source="cve">Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to list directory contents via a direct request to multiple directories, including (1) sources/loginauth/convert/, (2) sources/portal_plugins/, (3) cache/skin_cache/cacheid_2/, (4) ips_kernel/PEAR/, (5) ips_kernel/PEAR/Text/, (6) ips_kernel/PEAR/Text/Diff/, (7) ips_kernel/PEAR/Text/Diff/Renderer/, (8) style_images/1/folder_rte_files/, (9) style_images/1/folder_js_skin/, (10) style_images/1/folder_rte_images/, and (11) upgrade/ and its subdirectories.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425713/100/0/threaded">20060221 Invision Power Board 2.1.4 Multiple Vulnerabilities</ref><ref adv="1" source="" url="http://neosecurityteam.net/advisories/Advisory-16.txt"></ref><ref adv="1" source="" url="http://neosecurityteam.net/index.php?action=advisories&amp;id=16"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24840">invisionpowerboard-multiple-info-disclosure(24840)</ref></refs><vuln_soft><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.1.4"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1.0"/><vers num="2.1 RC1"/><vers num="2.1 BETA5"/><vers num="2.1 BETA4"/><vers num="2.1 BETA3"/><vers num="2.1 BETA2"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-0911" published="2006-02-28" seq="2006-0911" severity="Medium" type="CVE"><desc><descript source="cve">NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumption) via crafted requests to Login.asp, possibly involving the (1) &quot;In]&quot; and (2) &quot;b;tnLogIn&quot; parameters, or (3) malformed btnLogIn parameters, possibly involving missing &quot;[&quot; (open bracket) or &quot;[&quot; (closing bracket) characters, as demonstrated by &quot;&amp;btnLogIn=[Log&amp;In]=&amp;&quot; or &quot;&amp;b;tnLogIn=[Log&amp;In]=&amp;&quot; in the URL.  NOTE: due to the lack of diagnosis by the original researcher, the precise nature of the vulnerability is unclear.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425780/100/0/threaded">20060222 IpSwitch WhatsUp Professional 2006 DoS</ref><ref adv="1" source="" url="http://zur.homelinux.com/Advisories/ipswitch_dos.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16771">16771</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0704">ADV-2006-0704</ref><ref source="OSVDB" url="http://www.osvdb.org/23494">23494</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24864">whatsup-nmservice-dos(24864)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/472">472</ref></refs><vuln_soft><prod name="WhatsUp" vendor="Ipswitch"><vers num="Professional 2006"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0912" published="2006-02-28" seq="2006-0912" severity="Medium" type="CVE"><desc><descript source="cve">Oreka before 0.5 allows remote attackers to cause a denial of service (application crash) via a &quot;certain RTP sequence.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://oreka.sourceforge.net/"></ref><ref source="OSVDB" url="http://www.osvdb.org/23300">23300</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0812">ADV-2006-0812</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19095">19095</ref><ref source="BID" url="http://www.securityfocus.com/bid/16937">16937</ref></refs><vuln_soft><prod name="Oreka" vendor="Oreka"><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="4.9" CVSS_score="5.5" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0913" published="2006-02-28" seq="2006-0913" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows remote authenticated users with administrative privileges to execute arbitrary SQL commands via the whinedays parameter, as accessible from editparams.cgi.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425584/100/0/threaded">20060221 [BUGZILLA] Security Advisory for Bugzilla 2.20, 2.21.1, and 2.18.4</ref><ref adv="1" patch="1" source="Mozilla.org" url="https://bugzilla.mozilla.org/show_bug.cgi?id=312498">Bugzilla Bug 312498</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/16738">16738</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18979">18979</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24819">bugzilla-editparams-sql-injection(24819)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0692">ADV-2006-0692</ref><ref source="OSVDB" url="http://www.osvdb.org/23378">23378</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.21.1"/><vers num="2.21"/><vers num="2.20 rc2"/><vers num="2.20 rc1"/><vers num="2.20"/><vers num="2.19.3"/><vers num="2.19.2"/><vers num="2.19.1"/><vers num="2.19"/><vers num="2.18.4"/><vers num="2.18.3"/><vers num="2.18.2"/><vers num="2.18.1"/><vers num="2.18 rc3"/><vers num="2.18 rc2"/><vers num="2.18 rc1"/><vers num="2.17.7"/><vers num="2.17.6"/><vers num="2.17.5"/><vers num="2.17.4"/><vers num="2.17.3"/><vers num="2.17.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="4.9" CVSS_score="5.5" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:P)" CVSS_version="2.0" modified="2008-06-20" name="CVE-2006-0914" published="2006-02-28" seq="2006-0914" severity="Medium" type="CVE"><desc><descript source="cve">Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote attackers to trigger a SQL error.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425584/100/0/threaded">20060221 [BUGZILLA] Security Advisory for Bugzilla 2.20, 2.21.1, and 2.18.4</ref><ref adv="1" patch="1" source="Mozilla.org" url="https://bugzilla.mozilla.org/show_bug.cgi?id=312498">Bugzilla Bug 312498</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0692">ADV-2006-0692</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42802">bugzilla-duplicates-sql-injection(42802)</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.16.10"/><vers num="2.18.4"/><vers num="2.18.3"/><vers num="2.18.2"/><vers num="2.18.1"/><vers num="2.18 rc2"/><vers num="2.18 rc1"/><vers num="2.18"/><vers num="2.17.7"/><vers num="2.17.6"/><vers num="2.17.5"/><vers num="2.17.4"/><vers num="2.17"/><vers num="2.20 rc2"/><vers num="2.20 rc1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-01" name="CVE-2006-0915" published="2006-02-28" seq="2006-0915" severity="High" type="CVE"><desc><descript source="cve">Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which allows remote attackers to trigger a SQL error.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="mozilla.org" url="https://bugzilla.mozilla.org/show_bug.cgi?id=313441">Bugzilla Bug 313441</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0692">ADV-2006-0692</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.16.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0916" published="2006-02-28" seq="2006-0916" severity="High" type="CVE"><desc><descript source="cve">Bugzilla 2.19.3 through 2.20 does not properly handle &quot;//&quot; sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user&apos;s browser to send the form data to another domain.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425584/100/0/threaded">20060221 [BUGZILLA] Security Advisory for Bugzilla 2.20, 2.21.1, and 2.18.4</ref><ref adv="1" patch="1" source="mozilla.org" url="https://bugzilla.mozilla.org/show_bug.cgi?id=325079">Bugzilla Bug 325079</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/16745">16745</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18979">18979</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24821">bugzilla-login-data-redirection(24821)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0692">ADV-2006-0692</ref><ref source="SREASON" url="http://securityreason.com/securityalert/464">464</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.21.2"/><vers num="2.21.1"/><vers num="2.21"/><vers num="2.20 rc2"/><vers num="2.20 rc1"/><vers num="2.20"/><vers num="2.19.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2006-0917" published="2006-02-28" seq="2006-0917" severity="Low" type="CVE"><desc><descript source="cve">Melange Chat Server (aka M-Chat), when accessed via a web browser, automatically sends cookies and other sensitive information for a server to any port specified in the associated link, which allows local users on that server to read the cookies from HTTP headers and possibly gain sensitive information, such as credentials, by setting up a listening port and reading the credentials when the victim clicks on the link.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425589/100/0/threaded">20060221 grab cookie information with Melange Chat Server 1.10</ref><ref source="" url="http://www.oh2600.com/forum/viewtopic.php?t=43"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16747">16747</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18984">18984</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24868">melange-chat-command-information-disclosure(24868)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/463">463</ref></refs><vuln_soft><prod name="Melange Chat System" vendor="Melange"><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0918" published="2006-02-28" seq="2006-0918" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in RITLabs The Bat! 3.60.07 allows remote attackers to execute arbitrary code via a long Subject field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425936/100/0/threaded">20060223 NSA Group Security Advisory NSAG-&amp;sup1;198-23.02.2006 Vulnerability The Bat v. 3.60.07</ref><ref source="" url="http://www.nsag.ru/vuln/953.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16797">16797</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18989">18989</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0717">ADV-2006-0717</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24882">thebat-subject-bo(24882)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/485">485</ref></refs><vuln_soft><prod name="The Bat" vendor="RITLabs"><vers num="3.60.07"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0919" published="2006-02-28" seq="2006-0919" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php (aka the login page) in Oi! Email Marketing System 3.0 (aka Oi! 3) allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425924/100/0/threaded">20060223 HYSA-2006-003 Oi! Email Marketing 3.0 SQL Injection</ref><ref adv="1" source="" url="http://www.h4cky0u.org/advisories/HYSA-2006-003-oi-email.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0718">ADV-2006-0718</ref><ref source="OSVDB" url="http://www.osvdb.org/23462">23462</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18993">18993</ref></refs><vuln_soft><prod name="Email Marketing System" vendor="Oi"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="1.7" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="2.9" CVSS_score="1.7" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0920" published="2006-02-28" seq="2006-0920" severity="Low" type="CVE"><desc><descript source="cve">Oi! Email Marketing System 3.0 (aka Oi! 3) stores the server&apos;s FTP password in cleartext on a Configuration web page, which allows local users with superadministrator privileges, or attackers who have obtained access to the web page, to view the password.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425924/100/0/threaded">20060223 HYSA-2006-003 Oi! Email Marketing 3.0 SQL Injection</ref><ref adv="1" source="" url="http://www.h4cky0u.org/advisories/HYSA-2006-003-oi-email.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16794">16794</ref><ref source="SREASON" url="http://securityreason.com/securityalert/483">483</ref></refs><vuln_soft><prod name="Email Marketing System" vendor="Oi"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0921" published="2006-02-28" seq="2006-0921" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackers to list and create arbitrary directories via a .. (dot dot) in the CurrentFolder parameter to (1) GetFoldersAndFiles and (2) CreateFolder.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425937/100/0/threaded">20060223 NSA Group Security Advisory NSAG-&amp;sup1;195-23.02.2006 Vulnerability FCKeditor 2.0 FC</ref><ref source="" url="http://www.nsag.ru/vuln/952.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/434559/30/4890/threaded">
20060519 Re: NSA Group Security Advisory NSAG-&amp;sup1;195-23.02.2006 Vulnerability FCKeditor 2.0 FC</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24878">
fckeditor-connector-obtain-information(24878)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/484">484</ref></refs><vuln_soft><prod name="FCKeditor" vendor="FCKeditor"><vers num="2.0 FC"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-30" name="CVE-2006-0922" published="2006-02-28" seq="2006-0922" severity="Medium" type="CVE"><desc><descript source="cve">CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results in an absolute path traversal vulnerability in FileUpload in connector.php (aka upload.php) that allows remote attackers to upload arbitrary files via a modified CurrentFolder parameter in a direct request to admin/filemanager/upload.php.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425931/100/0/threaded">20060223 NSA Group Security Advisory NSAG-&amp;#xb9;197-23.02.2006 Vulnerability CubeCart 3.0.0 ? 3.0.6</ref><ref source="" url="http://www.cubecart.com/site/forums/index.php?showtopic=14817"></ref><ref patch="1" source="" url="http://www.cubecart.com/site/forums/index.php?showtopic=14825"></ref><ref source="" url="http://www.cubecart.com/site/forums/index.php?showtopic=14960"></ref><ref patch="1" source="" url="http://www.cubecart.com/site/forums/index.php?showtopic=14972"></ref><ref source="" url="http://www.nsag.ru/vuln/892.html"></ref><ref source="" url="http://www.cubecart.com/site/forums/index.php?showtopic=14704"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16796">16796</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24883">cubecart-connector-file-include(24883)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/482">482</ref></refs><vuln_soft><prod name="CubeCart" vendor="Devellion"><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0.0 Final"/><vers num="3.0.0 Beta"/><vers num="3.0.0 Alpha-2"/><vers num="3.0.0 Alpha-RGF"/><vers num="3.0.0 Alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0923" published="2006-02-28" seq="2006-0923" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MyPHPNuke (MPN) 1.88 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the letter parameter in reviews.php and (2) the dcategory parameter in download.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425983/100/0/threaded">20060224 Advisory: MyPHPNuke &lt;= 1.8.8 multiple XSS vulnerabilities</ref><ref adv="1" source="" url="http://www.nukedx.com/?viewdoc=12"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16815">16815</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0750">ADV-2006-0750</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19052">19052</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24887">myphpnuke-reviews-download-xss(24887)</ref><ref source="" url="http://www.myphpnuke.com/article.php?sid=1035&amp;mode=thread&amp;order=0"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/491">491</ref></refs><vuln_soft><prod name="myPHPNuke" vendor="myPHPNuke"><vers num="1.8.8" prev="1"/><vers num="1.8.8_8 RC2"/><vers num="1.8.8_7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-31" name="CVE-2006-0924" published="2006-02-28" seq="2006-0924" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Brown Bear iCal 3.10 allows remote attackers to inject arbitrary web script or HTML via the Calendar Text field when a new event is added.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><sols><sol source="nvd">This vulnerability affects Brown Bear iCal version 3.10 and previous.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0727">ADV-2006-0727</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19001">19001</ref><ref source="BID" url="http://www.securityfocus.com/bid/16845">16845</ref><ref source="OSVDB" url="http://www.osvdb.org/23472">23472</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24919">
ical-calendartext-xss(24919)</ref></refs><vuln_soft><prod name="iCal" vendor="Brown Bear Software"><vers num="3.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0925" published="2006-02-28" seq="2006-0925" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the IMAP4rev1 server in Alt-N MDaemon 8.1.1 and possibly 8.1.4 allows remote attackers to cause a denial of service (CPU consumption) by creating and then listing folders whose names contain format string specifiers.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.nsag.ru/vuln/888.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0729">ADV-2006-0729</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18921">18921</ref><ref source="BID" url="http://www.securityfocus.com/bid/16854">16854</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24916">
mdaemon-imap-foldername-dos(24916)</ref></refs><vuln_soft><prod name="MDaemon" vendor="Alt-N"><vers num="8.1.1"/><vers num="8.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0926" published="2006-02-28" seq="2006-0926" severity="Low" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in Allume StuffIt Standard and Deluxe 9.0, ZipMagic Deluxe 9.0, and StuffIt Expander 9.0.0.21 Engine 9.0.0.21 allow remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425972/100/0/threaded">20060224 StuffIt and ZipMagic Family of products Directory traversal</ref><ref source="" url="http://www.hamid.ir/security/stuffit.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16806">16806</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0732">ADV-2006-0732</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19010">19010</ref><ref source="OSVDB" url="http://www.osvdb.org/23463">23463</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24886">stuffit-zipmagic-archive-directory-traversal(24886)</ref></refs><vuln_soft><prod name="ZipMagic Deluxe" vendor="SmithMicro"><vers num="9.0"/></prod><prod name="StuffIt Expander" vendor="SmithMicro"><vers num="9.0.0.21 Engine 9.0.0.21"/></prod><prod name="StuffIt Deluxe" vendor="SmithMicro"><vers num="9.0"/></prod><prod name="StuffIt Standard" vendor="SmithMicro"><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0927" published="2006-02-28" seq="2006-0927" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b) jgs_galerie_scroll.php, and the (2) katid parameter in (c) jgs_galerie_slideshow.php.</descript></desc><sols><sol source="nvd">Vulnerability affects JGS-XA, JGS-Gallery Addon versions 4.0.0 and previous.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425981/100/0/threaded">20060224 Advisory: Woltlab Burning Board 2.x (JGS-Gallery MOD &lt;= 4.0)multiple XSS vulnerabilities</ref><ref adv="1" source="nukedx.com" url="http://www.nukedx.com/?viewdoc=11">nukedx.com</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/16810">16810</ref><ref source="BID" url="http://www.securityfocus.com/bid/16843">16843</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24888">wbb-jgsgallerymod-xss(24888)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0615.html">20060224 Advisory: Woltlab Burning Board 2.x (JGS-Gallery MOD &lt;= 4.0) multiple XSS vulnerabilities</ref></refs><vuln_soft><prod name="JGS-Gallery Addon" vendor="JGS-XA"><vers num="4.0"/></prod><prod name="Burning Board" vendor="WoltLab"><vers num="2.3.1"/><vers num="2.3.0"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.1"/><vers num="2.1.5"/><vers num="2.0.3"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-27" name="CVE-2006-0928" published="2006-02-28" seq="2006-0928" severity="Medium" type="CVE"><desc><descript source="cve">The POP3 Server in ArGoSoft Mail Server Pro 1.8 allows remote attackers to obtain sensitive information via the _DUMP command, which reveals the operating system, registered user, and registration code.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425968/100/0/threaded">20060224 NSA Group Security Advisory NSAG-&amp;#xb9;198-23.02.2006 Vulnerability ArGoSoft Mail Server Pro</ref><ref source="" url="http://www.nsag.ru/vuln/879.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16808">16808</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0733">ADV-2006-0733</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18990">18990</ref></refs><vuln_soft><prod name="ArGoSoft Mail Server" vendor="ArGoSoft"><vers edition="Pro" num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-27" name="CVE-2006-0929" published="2006-02-28" seq="2006-0929" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the IMAP server in ArGoSoft Mail Server Pro 1.8.8.1 allows remote authenticated users to create arbitrary folders via a .. (dot dot) in the RENAME command.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425969/100/0/threaded">20060224 NSA Group Security Advisory NSAG-&amp;#xb9;200-24.02.2006 Vulnerability ArGoSoft Mail Server Pro IMAP</ref><ref source="" url="http://www.nsag.ru/vuln/878.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16809">16809</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0733">ADV-2006-0733</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18990">18990</ref></refs><vuln_soft><prod name="ArGoSoft Mail Server" vendor="ArGoSoft"><vers edition="Pro" num="1.8.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-27" name="CVE-2006-0930" published="2006-02-28" seq="2006-0930" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Webmail in ArGoSoft Mail Server Pro 1.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the UIDL parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.nsag.ru/vuln/877.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0733">ADV-2006-0733</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18990">18990</ref><ref source="SREASON" url="http://securityreason.com/securityalert/487">487</ref></refs><vuln_soft><prod name="ArGoSoft Mail Server" vendor="ArGoSoft"><vers edition="Pro" num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-04-09" name="CVE-2006-0931" published="2006-02-28" seq="2006-0931" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a TAR archive.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425967/100/0/threaded">20060224 Archive_Tar v 1.2(Tested) (Tar file management class) Directory traversal</ref><ref adv="1" source="" url="http://www.hamid.ir/security/phptar.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16805">16805</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0728">ADV-2006-0728</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19011">19011</ref><ref source="OSVDB" url="http://www.osvdb.org/23481">23481</ref><ref source="" url="http://pear.php.net/bugs/bug.php?id=6933"></ref><ref source="" url="http://pear.php.net/package/Archive_Tar/download/"></ref></refs><vuln_soft><prod name="PEAR Archive_Tar" vendor="PEAR"><vers num="1.2" prev="1"/><vers num="1.3.0" prev="1"/><vers num="1.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0932" published="2006-02-28" seq="2006-0932" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a ZIP archive.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425967/100/0/threaded">20060224 Archive_Tar v 1.2(Tested) (Tar file management class) Directory traversal</ref><ref adv="1" source="" url="http://www.hamid.ir/security/phpzip.txt"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426153/100/0/threaded">20060225 Archive_Zip (Zip file management class) Directory traversal</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24972">
ziplib-directory-traversal(24972)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/486">486</ref></refs><vuln_soft><prod name="PEAR Archive_Zip" vendor="PEAR"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0933" published="2006-02-28" seq="2006-0933" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in PHPX 3.5.9 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a url XCode tag in a posted message.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16799">16799</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0722">ADV-2006-0722</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18688">18688</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24874">phpx-xcode-tag-xss(24874)</ref></refs><vuln_soft><prod name="PHPX" vendor="PHPX"><vers num="3.5.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-20" name="CVE-2006-0934" published="2006-02-28" seq="2006-0934" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in webinsta Limbo 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the message field in the Contact Form.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16811">16811</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0721">ADV-2006-0721</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18723">18723</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24877">webinsta-limbo-contact-form-xss(24877)</ref><ref source="" url="http://osvdb.org/ref/23/23469-limbo.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/23469">23469</ref></refs><vuln_soft><prod name="Limbo CMS" vendor="Limbo CMS"><vers num="1.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0935" published="2006-02-28" seq="2006-0935" severity="Low" type="CVE"><desc><descript source="cve">Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz.</descript></desc><loss_types><avail/></loss_types><range><network/><user_init/></range><refs><ref source="MLIST" url="http://archives.neohapsis.com/archives/dailydave/2006-q1/0179.html">[Dailydave] 20060221 word dos 4fun</ref><ref source="BID" url="http://www.securityfocus.com/bid/16782">16782</ref></refs><vuln_soft><prod name="Word" vendor="Microsoft"><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0936" published="2006-02-28" seq="2006-0936" severity="Medium" type="CVE"><desc><descript source="cve">Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a dangerous file extension and a trailing %00.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://nsag.ru/vuln/894.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19014">19014</ref><ref source="BID" url="http://www.securityfocus.com/bid/16823">16823</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426077/100/0/threaded">20060225 NSA Group Security Advisory NSAG-&amp;sup1;202-25.02.2006 Vulnerability WEBSITE GENERATOR 3.3</ref></refs><vuln_soft><prod name="Website Generator" vendor="Free Host Shop"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-02" name="CVE-2006-0937" published="2006-02-28" seq="2006-0937" severity="Medium" type="CVE"><desc><descript source="cve">U.N.U. Mailgust 1.9 allows remote attackers to obtain sensitive information via a direct request to index.php with method=showfullcsv, which reveals the POP3 server configuration, including account name and password.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://nsag.ru/vuln/890.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18998">18998</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24890">mailgust-index-info-disclosure(24890)</ref></refs><vuln_soft><prod name="MailGust" vendor="UNU Networks"><vers num="1.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-01" name="CVE-2006-0938" published="2006-02-28" seq="2006-0938" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the RefererURL parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426076/100/0/threaded">20060225 Advisory: eZ publish &lt;= 3.7.3 (imagecatalogue module) XSSvulnerability</ref><ref source="" url="http://www.nukedx.com/?viewdoc=16"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16817">16817</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015683">1015683</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24956">
ezpublish-referrerurl-xss(24956)</ref></refs><vuln_soft><prod name="eZ publish" vendor="eZ systems"><vers num="3.7.3"/><vers num="3.7.2"/><vers num="3.7.1"/><vers num="3.7.0"/><vers num="3.6.5"/><vers num="3.6.4"/><vers num="3.6.3"/><vers num="3.6.2"/><vers num="3.6.1"/><vers num="3.6.0"/><vers num="3.5.8"/><vers num="3.5.7"/><vers num="3.5.6"/><vers num="3.5.5"/><vers num="3.5.4"/><vers num="3.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-0939" published="2006-02-28" seq="2006-0939" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id or (2) action parameter to (a) basket.php, or (3) id or (4) page parameter to (b) cat.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/426082">20060225 SQL Injection in DCI-Taskeen</ref><ref source="BID" url="http://www.securityfocus.com/bid/16828">16828</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015685">1015685</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24963">
dci-taskeen-multiple-scripts-sql-injection(24963)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/495">495</ref></refs><vuln_soft><prod name="DCI-Taskeen" vendor="DCI-Designs"><vers num="1.03"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-01" name="CVE-2006-0940" published="2006-02-28" seq="2006-0940" severity="High" type="CVE"><desc><descript source="cve">Multiple direct static code injection vulnerabilities in savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to execute arbitrary PHP code via variables that are written to settings.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/87/summary.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/23482">23482</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19047">19047</ref><ref source="BID" url="http://www.securityfocus.com/bid/16857">16857</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0755">ADV-2006-0755</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426985/100/0/threaded">20060307 [eVuln] ShoutLIVE PHP Code Execution &amp; Multiple XSS Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24897">
shoutlive-savesettings-file-include(24897)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/557">557</ref></refs><vuln_soft><prod name="ShoutLIVE" vendor="Cynical Games"><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-01" name="CVE-2006-0941" published="2006-02-28" seq="2006-0941" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in post.php in ShoutLIVE 1.1.0 allow remote attackers to inject arbitrary web script or HTML via certain variables when posting new messages.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/87/summary.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/23483">23483</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19047">19047</ref><ref source="BID" url="http://www.securityfocus.com/bid/16857">16857</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0755">ADV-2006-0755</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426985/100/0/threaded">20060307 [eVuln] ShoutLIVE PHP Code Execution &amp; Multiple XSS Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24901">
shoutlive-post-xss(24901)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/557">557</ref></refs><vuln_soft><prod name="ShoutLIVE" vendor="Cynical Games"><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-01" name="CVE-2006-0942" published="2006-02-28" seq="2006-0942" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the aff_news_form parameter, a different vulnerability than CVE-2005-1509.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/PwsPHP_SQL_Inj.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16567">16567</ref><ref source="OSVDB" url="http://www.osvdb.org/28444">28444</ref></refs><vuln_soft><prod name="PwsPHP" vendor="PwsPHP"><vers num="1.2.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-01" name="CVE-2006-0943" published="2006-02-28" seq="2006-0943" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the sondages module in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426084/100/0/threaded">20060225 PwsPHP Injection SQL on Index.php</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426183/100/0/threaded">20060226 Re: PwsPHP Injection SQL on Index.php</ref><ref source="" url="http://www.pwsphp.com/index.php?mod=news&amp;ac=commentaires&amp;id=278"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015684">1015684</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0748">ADV-2006-0748</ref><ref source="SREASON" url="http://securityreason.com/securityalert/496">496</ref></refs><vuln_soft><prod name="PwsPHP" vendor="PwsPHP"><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-01" name="CVE-2006-0944" published="2006-02-28" seq="2006-0944" severity="High" type="CVE"><desc><descript source="cve">Archangel Weblog 0.90.02 allows remote attackers to bypass authentication by setting the ba_admin cookie to 1.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426184/100/0/threaded">20060226 Archangel Weblog 0.90.02 Admin Authentication Bypass &amp; Remote File Inclusion</ref><ref source="BID" url="http://www.securityfocus.com/bid/16848">16848</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015689">1015689</ref><ref source="OSVDB" url="http://www.osvdb.org/23620">23620</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24984">archangel-admin-auth-bypass(24984)</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3859">
3859</ref></refs><vuln_soft><prod name="Archangel Weblog" vendor="Archangel Management"><vers num="0.90.02"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2006-0945" published="2006-02-28" seq="2006-0945" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in admin/index.php in Archangel Weblog 0.90.02 allows remote authenticated administrators to execute arbitrary PHP code via a URL ending in a NULL (%00) in the index parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426184/100/0/threaded">20060226 Archangel Weblog 0.90.02 Admin Authentication Bypass &amp; Remote File Inclusion</ref><ref source="BID" url="http://www.securityfocus.com/bid/16848">16848</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015689">1015689</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25142">archangel-index-file-include(25142)</ref><ref source="OSVDB" url="http://www.osvdb.org/23621">23621</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24984">archangel-admin-auth-bypass(24984)</ref></refs><vuln_soft><prod name="Archangel Weblog" vendor="Archangel Management"><vers num="0.90.02"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-01" name="CVE-2006-0946" published="2006-02-28" seq="2006-0946" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter to the LocalNetwork page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/426186">20060226 Thomson SpeedTouch 500 modems vulnerable to XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/16839">16839</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0765">ADV-2006-0765</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015688">1015688</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19069">19069</ref><ref source="OSVDB" url="http://www.osvdb.org/23527">23527</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24977">
speedtouch-localnetwork-xss(24977)</ref></refs><vuln_soft><prod name="SpeedTouch" vendor="Thomson"><vers num="585 5.3.2.6.0"/><vers num="580 5.3.2.6.0"/><vers num="576 5.3.2.6.0"/><vers num="546 5.3.2.6.0"/><vers num="536 5.3.2.6.0"/><vers num="530 5.3.2.6.0"/><vers num="516 5.3.2.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-01" name="CVE-2006-0947" published="2006-02-28" seq="2006-0947" severity="High" type="CVE"><desc><descript source="cve">Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the &quot;31&quot; parameter in a NewUser function, which is not filtered by the modem when creating the account, but cannot be deleted by the administrator, possibly due to cleansing that occurs in the administrator interface.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/426186">20060226 Thomson SpeedTouch 500 modems vulnerable to XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/16839">16839</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0765">ADV-2006-0765</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015688">1015688</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19069">19069</ref></refs><vuln_soft><prod name="SpeedTouch" vendor="Thomson"><vers num="585 5.3.2.6.0"/><vers num="580 5.3.2.6.0"/><vers num="576 5.3.2.6.0"/><vers num="546 5.3.2.6.0"/><vers num="536 5.3.2.6.0"/><vers num="530 5.3.2.6.0"/><vers num="516 5.3.2.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-22" name="CVE-2006-0948" published="2006-08-21" seq="2006-0948" severity="High" type="CVE"><desc><descript source="cve">AOL 9.0 Security Edition revision 4184.2340, and probably other versions, uses insecure permissions (Everyone/Full Control) for the &quot;America Online 9.0&quot; directory, which allows local users to gain privileges by replacing critical files.</descript></desc><sols><sol source="nvd">AOL has released fixes to address this issue. These fixes can be automatically applied by logging in to the service.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/19583">19583</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/443622/100/0/threaded">20060818 Secunia Research: AOL Insecure Default Directory Permissions</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3317">ADV-2006-3317</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016717">1016717</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18734">18734</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/28445">aol-default-insecure-permissions(28445)</ref><ref source="" url="http://secunia.com/secunia_research/2006-08"></ref><ref source="OSVDB" url="http://www.osvdb.org/27995">
27995</ref><ref source="SREASON" url="http://securityreason.com/securityalert/1416">1416</ref></refs><vuln_soft><prod name="AOL" vendor="AOL"><vers num="9.0 4184.2340"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-0949" published="2006-03-06" seq="2006-0949" severity="Medium" type="CVE"><desc><descript source="cve">RaidenHTTPD 1.1.47 allows remote attackers to obtain source code of script files, including PHP, via crafted requests involving (1) &quot;.&quot; (dot), (2) space, and (3) &quot;/&quot; (slash) characters.</descript></desc><sols><sol source="nvd">This vulnerability affects RaidenHTTPD, RaidenHTTPD version 1.1.47 and may affect all previous versions.</sol></sols><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/secunia_research/2006-15/advisory/">RaidenHTTPD Script Source Disclosure Vulnerability</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0807">ADV-2006-0807</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/23616">23616</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19032">19032</ref><ref source="BID" url="http://www.securityfocus.com/bid/16934">16934</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25037">raidenhttpd-extension-obtain-information(25037)</ref></refs><vuln_soft><prod name="RaidenHTTPD" vendor="RaidenHTTPD"><vers num="1.1.47"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0950" published="2006-03-13" seq="2006-0950" severity="Low" type="CVE"><desc><descript source="cve">unalz 0.53 allows user-assisted attackers to overwrite arbitrary files via an ALZ archive with &quot;..&quot; (dot dot) sequences in a filename.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427475/100/0/threaded">20060313 Secunia Research: unalz Filename Handling Directory TraversalVulnerability</ref><ref source="" url="http://secunia.com/secunia_research/2006-16/"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0938">ADV-2006-0938</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19063">19063</ref><ref source="BID" url="http://www.securityfocus.com/bid/17105">17105</ref><ref source="OSVDB" url="http://www.osvdb.org/23835">23835</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25171">unalz-archive-directory-traversal(25171)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015780">1015780</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114226632422033&amp;w=2">20060313 Secunia Research: unalz Filename Handling</ref><ref source="SREASON" url="http://securityreason.com/securityalert/575">575</ref></refs><vuln_soft><prod name="unalz" vendor="unalz"><vers num="0.53"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-02" modified="2006-04-10" name="CVE-2006-0951" published="2006-04-07" seq="2006-0951" severity="High" type="CVE"><desc><descript source="cve">The GUI (nod32.exe) in NOD32 2.5 runs with SYSTEM privileges when the scheduler runs a scheduled on-demand scan, which allows local users to execute arbitrary code during a scheduled scan via unspecified attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="" url="http://secunia.com/secunia_research/2006-17/advisory/"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19054">19054</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1242">
ADV-2006-1242</ref><ref source="OSVDB" url="http://www.osvdb.org/24394">
24394</ref></refs><vuln_soft><prod name="NOD32 Antivirus" vendor="Eset Software"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="1.7" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="2.9" CVSS_score="1.7" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0956" published="2006-03-02" seq="2006-0956" severity="Low" type="CVE"><desc><descript source="cve">nuauth in NuFW before 1.0.21 does not properly handle blocking TLS sockets, which allows remote authenticated users to cause a denial of service (service hang) by flooding packets at the authentication server.</descript></desc><sols><sol source="nvd">This vulnerability affects NuFW, NuFW Firewall versions 1.0.20 and previous.</sol></sols><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="nufw.org" url="http://www.nufw.org/+NuFW-1-21-minor-security-fix+.html">NuFW 1.0.21, minor security fix</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0762">ADV-2006-0762</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19046">19046</ref><ref source="BID" url="http://www.securityfocus.com/bid/16868">16868</ref></refs><vuln_soft><prod name="NuFW Firewall" vendor="NuFW"><vers num="1.0.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0957" published="2006-03-02" seq="2006-0957" severity="High" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to execute arbitrary PHP code via the (1) X-Forwarded-For and (2) Client-Ip HTTP headers, which are stored in Data/flood.db.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://evuln.com/vulns/89/summary.html"></ref><ref source="" url="http://soft.zoneo.net/freeForum/changes.php"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0759">ADV-2006-0759</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19020">19020</ref><ref source="BID" url="http://www.securityfocus.com/bid/16877">16877</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427321/100/0/threaded">20060310 [eVuln] FreeForum PHP Code Execution &amp; Multiple XSS Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16871">16871</ref></refs><vuln_soft><prod name="freeForum" vendor="ZoneO-Soft"><vers num="1.2"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0958" published="2006-03-02" seq="2006-0958" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) subject parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://evuln.com/vulns/89/summary.html"></ref><ref source="" url="http://soft.zoneo.net/freeForum/changes.php"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0759">ADV-2006-0759</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19020">19020</ref><ref source="BID" url="http://www.securityfocus.com/bid/16877">16877</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427321/100/0/threaded">20060310 [eVuln] FreeForum PHP Code Execution &amp; Multiple XSS Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24925">
freeforum-func-xss(24925)</ref></refs><vuln_soft><prod name="freeForum" vendor="ZoneO-Soft"><vers num="1.2"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-05" name="CVE-2006-0959" published="2006-03-02" seq="2006-0959" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands by setting the comma variable value via the comma parameter in a cookie.  NOTE: 1.04 has also been reported to be affected.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426320/100/0/threaded">20060228 MyBB 1.3 NewSQL Injection</ref><ref source="" url="http://www.milw0rm.com/id.php?id=1539"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0774">ADV-2006-0774</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19061">19061</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426653/100/0/threaded">20060303 MyBB 1.04 Perl Exploit</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24953">mybb-misc-sql-injection(24953)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16631">16631</ref><ref source="OSVDB" url="http://www.osvdb.org/23554">23554</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1539">
1539</ref><ref source="SREASON" url="http://securityreason.com/securityalert/512">512</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0.4"/><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0960" published="2006-03-02" seq="2006-0960" severity="Medium" type="CVE"><desc><descript source="cve">uConfig agent in Compex NetPassage WPE54G router allows remote attackers to cause a denial of service (unresposiveness) via crafted datagrams to UDP port 7778.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://www.security.nnov.ru/Ldocument605.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16894">16894</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0780">ADV-2006-0780</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015690">1015690</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19037">19037</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24968">netpassage-udp-dos(24968)</ref></refs><vuln_soft><prod name="NetPassage WPE54G" vendor="Compex"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-0961" published="2006-03-02" seq="2006-0961" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in yazdir.asp in Cilem Hiber 1.1 allows remote attackers to execute arbitrary SQL commands via the haber_id parameter.  NOTE: this product has also been referred to as &quot;Cilem News,&quot; although that does not appear to be the proper name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114079912721723&amp;w=2">20060224 Advisory: CilemNews System &lt;= 1.1 Remote SQL</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0449.html">20060224 Advisory: CilemNews System &lt;= 1.1 Remote SQL Injection Vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015677">1015677</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114079912721723&amp;w=2">20060224 Advisory: CilemNews System &lt;= 1.1 Remote SQL</ref><ref source="" url="http://milw0rm.com/exploits/1562"></ref><ref adv="1" source="" url="http://www.nukedx.com/?viewdoc=10"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0881">ADV-2006-0881</ref><ref source="OSVDB" url="http://www.osvdb.org/23618">23618</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19157">19157</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24920">cilemnews-sql-injection(24920)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16813">16813</ref></refs><vuln_soft><prod name="Cilem Haber" vendor="Cilem"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0962" published="2006-03-02" seq="2006-0962" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in vuBB 0.2 allows remote attackers to execute arbitrary SQL commands via the pass parameter in a cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/id.php?id=1543"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0799">ADV-2006-0799</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19084">19084</ref><ref source="BID" url="http://www.securityfocus.com/bid/16930">16930</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25019">vubb-index-sql-injection(25019)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1543">

1543</ref></refs><vuln_soft><prod name="VUBB" vendor="VUBB"><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0963" published="2006-03-02" seq="2006-0963" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in STLport 5.0.2 might allow local users to execute arbitrary code via (1) long locale environment variables to a strcpy function call in c_locale_glibc2.c and (2) long arguments to unspecified functions in num_put_float.cpp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=397543"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0800">ADV-2006-0800</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19051">19051</ref><ref source="BID" url="http://www.securityfocus.com/bid/16928">16928</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25159">
stlport-strcpy-local-bo(25159)</ref></refs><vuln_soft><prod name="STLport" vendor="STLport"><vers num="5.0.1"/><vers num="5.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0964" published="2006-03-02" seq="2006-0964" severity="Medium" type="CVE"><desc><descript source="cve">Client Firewall in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to bypass firewall program execution rules by replacing an allowed program with an arbitrary program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426480/100/0/threaded">20060301 NCP VPN/PKI Client - various Bugs</ref><ref source="BID" url="http://www.securityfocus.com/bid/16906">16906</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html">20060301 NCP VPN/PKI Client - various Bugs</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19082">19082</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25242">
ncp-client-firewall-bypass-security(25242)</ref></refs><vuln_soft><prod name="Secure Client" vendor="NCP Network CommunicationS"><vers num="8.11 Build 146"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0965" published="2006-03-02" seq="2006-0965" severity="Medium" type="CVE"><desc><descript source="cve">NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to bypass security protections and configure privileged options via a long argument to ncpmon.exe, which provides access to alternate privileged menus, possibly due to a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426480/100/0/threaded">20060301 NCP VPN/PKI Client - various Bugs</ref><ref source="BID" url="http://www.securityfocus.com/bid/16906">16906</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html">20060301 NCP VPN/PKI Client - various Bugs</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19082">19082</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25243">
ncp-ncpmon-bo(25243)</ref></refs><vuln_soft><prod name="Secure Client" vendor="NCP Network Communications"><vers num="8.11 Build 146"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0966" published="2006-03-02" seq="2006-0966" severity="Low" type="CVE"><desc><descript source="cve">NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users cause a denial of service (CPU consumption) via a large number of arguments to ncprwsnt.exe, possibly due to a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426480/100/0/threaded">20060301 NCP VPN/PKI Client - various Bugs</ref><ref source="BID" url="http://www.securityfocus.com/bid/16906">16906</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html">20060301 NCP VPN/PKI Client - various Bugs</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19082">19082</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25248">
ncp-ncprwsnt-dos(25248)</ref></refs><vuln_soft><prod name="Secure Client" vendor="NCP Network Communications"><vers num="8.11 Build 146"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0967" published="2006-03-02" seq="2006-0967" severity="Low" type="CVE"><desc><descript source="cve">NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users cause a denial of service (memory usage and cpu utilization) via a flood of arbitrary UDP datagrams to ports 0 to 65000.  NOTE: this issue was reported as a buffer overflow, but that term usually does not apply in flooding attacks.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426480/100/0/threaded">20060301 NCP VPN/PKI Client - various Bugs</ref><ref source="BID" url="http://www.securityfocus.com/bid/16906">16906</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html">20060301 NCP VPN/PKI Client - various Bugs</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19082">19082</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25249">
ncp-udp-dos(25249)</ref></refs><vuln_soft><prod name="Secure Client" vendor="NCP Network Communications"><vers num="8.11 Build 146"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0968" published="2006-03-02" seq="2006-0968" severity="High" type="CVE"><desc><descript source="cve">The ncprwsnt service in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to execute arbitrary code by modifying the connect.bat script, which is automatically executed by the service after a connection is established.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426480/100/0/threaded">20060301 NCP VPN/PKI Client - various Bugs</ref><ref source="BID" url="http://www.securityfocus.com/bid/16906">16906</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html">20060301 NCP VPN/PKI Client - various Bugs</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19082">19082</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25251">
ncp-connect-command-execution(25251)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/524">524</ref></refs><vuln_soft><prod name="Secure Client" vendor="NCP Network Communications"><vers num="8.11 Build 146"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-22" name="CVE-2006-0969" published="2006-03-03" seq="2006-0969" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in Top sites de PixelArtKingdom allows remote attackers to include and execute arbitrary files via the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426249/100/0/threaded">20060227 PixelArtKingdom TopSites Remote Command Exucetion</ref><ref source="SREASON" url="http://securityreason.com/securityalert/507">507</ref></refs><vuln_soft><prod name="Top Sites" vendor="PixelArtKingdom"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0970" published="2006-03-03" seq="2006-0970" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426214/100/0/threaded">20060227 Knowledgebases Remote Command Exucetion</ref><ref source="OSVDB" url="http://www.osvdb.org/3228">3228</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24989">
activecampaign-index-command-execution(24989)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/505">505</ref></refs><vuln_soft><prod name="SupportTrio" vendor="ActiveCampaign"><vers num=""/></prod><prod name="General" vendor="ActiveCampaign"><vers num=""/></prod><prod name="iSalient" vendor="ActiveCampaign"><vers num=""/></prod><prod name="visualEdit" vendor="ActiveCampaign"><vers num=""/></prod><prod name="1-2-All" vendor="ActiveCampaign"><vers num=""/></prod><prod name="KnowledgeBuilder" vendor="ActiveCampaign"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0971" published="2006-03-03" seq="2006-0971" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Lionel Reyero DirectContact 0.3b allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426250/100/0/threaded">20060227 directory traversal in DirectContact 0.3b</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/042560.html">20060227 directory traversal in DirectContact 0.3b</ref><ref source="" url="http://www3.autistici.org/fdonato/advisory/DirectContact0.3b-adv.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0761">ADV-2006-0761</ref><ref source="OSVDB" url="http://www.osvdb.org/23519">23519</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015686">1015686</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19053">19053</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24930">directcontact-dotdot-dir-traversal(24930)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427464/100/0/threaded">20060312 directory traversal Fixed in DirectContact 0.3c</ref><ref source="BID" url="http://www.securityfocus.com/bid/16849">16849</ref><ref source="SREASON" url="http://securityreason.com/securityalert/506">506</ref></refs><vuln_soft><prod name="DirectContact" vendor="Lionel Reyero"><vers num="0.3b"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0972" published="2006-03-03" seq="2006-0972" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in news.php in Tony Baird Fantastic News 2.1.1 allows remote attackers to execute arbitrary SQL commands via the page parameter.  NOTE: the category vector is already covered by CVE-2005-3846.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426195/100/0/threaded">20060226 2 SQL Injection in Fantastic News</ref><ref source="BID" url="http://www.securityfocus.com/bid/16842">16842</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24943">
fantasticnews-news-sql-injection(24943)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/501">501</ref></refs><vuln_soft><prod name="Fantastic News" vendor="Fscripts"><vers num="2.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0973" published="2006-03-03" seq="2006-0973" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in topics.php in Appalachian State University phpWebSite 0.10.2 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milworm.com" url="http://www.milw0rm.com/id.php?id=1525">phpWebSite topic SQL-Injection</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/16825">16825</ref><ref source="BID" url="http://www.securityfocus.com/data/vulnerabilities/exploits/phpWebSite-topic-sql-inj.pl">16825</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430870/100/0/threaded">20060412 phpWebSite 0.10.? (topics.php) Remote SQL Injection Exploit</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435009/100/0/threaded">20060523 sql injection in phpWebSite 0.8.3</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1525">
1525</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25799">
phpwebsite-topics-sql-injection(25799)</ref></refs><vuln_soft><prod name="phpWebsite" vendor="phpWebsite"><vers num="0.10.2"/><vers num="0.10.1"/><vers num="0.10"/><vers num="0.9.3.4"/><vers num="0.9.3.3"/><vers num="0.9.3.2"/><vers num="0.9.3.1"/><vers num="0.9.3"/><vers num="0.8.3"/><vers num="0.8.2"/><vers num="0.7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0974" published="2006-03-03" seq="2006-0974" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML via the err_txt parameter.</descript></desc><sols><sol source="nvd">This vulnerability affects Battleaxe Software, bttlxeForum versions 2.0 and previous</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0548.html">20060226 bttlxeForum 2.* XSS Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16821">16821</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0776">ADV-2006-0776</ref><ref source="OSVDB" url="http://www.osvdb.org/23540">23540</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19043">19043</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24981">bttlxeforum-failure-xss(24981)</ref></refs><vuln_soft><prod name="bttlxeForum" vendor="Battleaxe Software"><vers num="2.0"/></prod></vuln_soft></entry><entry modified="2006-03-31" name="CVE-2006-0975" published="2006-03-03" reject="1" seq="2006-0975" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0459.  Reason: This candidate is a reservation duplicate of CVE-2006-0459.  Notes: All CVE users should reference CVE-2006-0459 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-03-05" name="CVE-2006-0976" published="2006-03-03" seq="2006-0976" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in scan_lang_insert.php in Boris Herbiniere-Seve SPiD 1.3.1 allows remote attackers to read arbitrary files via the lang parameter.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426073/100/0/threaded">20060225 NSA Group Security Advisory NSAG-&amp;#xb9;201-25.02.2006 Vulnerability SPiD v1.3.1</ref><ref source="" url="http://www.nsag.ru/vuln/955.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16822">16822</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0766">ADV-2006-0766</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19033">19033</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24955">spid-scanlanginsert-file-include(24955)</ref></refs><vuln_soft><prod name="SPiD" vendor="SPiD"><vers num="1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0977" published="2006-03-03" seq="2006-0977" severity="Medium" type="CVE"><desc><descript source="cve">Craig Morrison Mail Transport System Professional (aka MTS Pro) acts as an open relay when configured to relay all mail through an external SMTP server, which allows remote attackers to relay mail by connecting to the MTS Pro server, then sending a MAIL FROM that specifies a domain that is local to the server.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426181/100/0/threaded">20060225 Mail Transport System Professional--Open Relay Hole</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0786">ADV-2006-0786</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19067">19067</ref><ref source="BID" url="http://www.securityfocus.com/bid/16840">16840</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24985">
mts-mail-relay(24985)</ref></refs><vuln_soft><prod name="MTS Pro" vendor="Craig Morrison"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-27" name="CVE-2006-0978" published="2006-03-03" seq="2006-0978" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the View Headers (aka viewheaders) functionality in ArGoSoft Mail Server Pro 1.8.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the Subject header, (2) the From header, and (3) certain other unspecified headers.</descript></desc><sols><sol source="nvd">This vulnerability affects ArGoSoft, Mail Server Pro version 1.8.8.5, and may affect all previous versions.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426206/100/0/threaded">20060227 Secunia Research: ArGoSoft Mail Server Pro viewheaders ScriptInsertion</ref><ref adv="1" source="Secunia.com" url="http://secunia.com/secunia_research/2006-6/advisory/">Secunia Research 27/02/2006 advisory</ref><ref source="BID" url="http://www.securityfocus.com/bid/16834">16834</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0751">ADV-2006-0751</ref><ref source="OSVDB" url="http://www.osvdb.org/23512">23512</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18991">18991</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24945">
argosoft-mailserverpro-viewheaders-xss(24945)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/504">504</ref></refs><vuln_soft><prod name="ArGoSoft Mail Server" vendor="ArGoSoft"><vers edition="Pro" num="1.8.8.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0979" published="2006-03-03" seq="2006-0979" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the local weblog publisher in Nidelven IT Issue Dealer before 0.9.96 has unknown impact and attack vectors.</descript></desc><sols><sol source="nvd">This vulnerability affects Nidelven IT, Issue Dealer versions 0.9.95 and previous.</sol></sols><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="issuedealer.com" url="http://issuedealer.com/changes/">N/A</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/23502">23502</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19018">19018</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24929">issuedealer-unpublished-issue-disclosure(24929)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16884">16884</ref></refs><vuln_soft><prod name="Issue Dealer" vendor="Nidelven IT"><vers num="0.9.95"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0980" published="2006-03-03" seq="2006-0980" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Jay Eckles CGI Calendar 2.7 allow remote attackers to inject arbitrary web script or HTML via the year parameter in (1) index.cgi and (2) viewday.cgi.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426198/100/0/threaded">20060226 CGI Calendar XSS Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0764">ADV-2006-0764</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19066">19066</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24946">
cgicalendar-index-viewday-xss(24946)</ref></refs><vuln_soft><prod name="CGI Calendar" vendor="Jay Eckles"><vers num="2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-06-26" name="CVE-2006-0981" published="2006-03-03" seq="2006-0981" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in e-merge WinAce 2.6 and earlier allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.</descript></desc><sols><sol source="nvd">This vulnerability affects e-merge, WinAce versions 2.6 and previous.</sol></sols><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425971/100/0/threaded">20060224 WinAce Archiver v2.6 Directory traversal</ref><ref adv="1" source="hamid.ir" url="http://www.hamid.ir/security/winace.txt">WinAce Archiver v2.6  Directory traversal</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/16800">16800</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0730">ADV-2006-0730</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/23464">23464</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19013">19013</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24902">winace-rar-tar-directory-traversal(24902)</ref></refs><vuln_soft><prod name="e-merge WinAce" vendor="e-merge"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0982" published="2006-03-03" seq="2006-0982" severity="Medium" type="CVE"><desc><descript source="cve">The on-access scanner for McAfee Virex 7.7 for Macintosh, in some circumstances, might not activate when malicious content is accessed from the web browser, and might not prevent the content from being saved, which allows remote attackers to bypass virus protection, as demonstrated using the EICAR test file.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426348/100/0/threaded">20060228 Virex on-access scanning unreliable</ref></refs><vuln_soft><prod name="Virex" vendor="McAfee"><vers edition="Macintosh" num="7.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0983" published="2006-03-03" seq="2006-0983" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in QwikiWiki 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426319/100/0/threaded">20060228 QwikiWiki v1.4 XSS Vulnerability</ref><ref patch="1" source="sourceforge.net" url="http://sourceforge.net/forum/forum.php?forum_id=438526">438526</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/16874">16874</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24950">qwikiwiki-index-xss(24950)</ref><ref source="OSVDB" url="http://www.osvdb.org/23700">23700</ref><ref source="SREASON" url="http://securityreason.com/securityalert/510">510</ref></refs><vuln_soft><prod name="QwikiWiki" vendor="David Barrett"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0984" published="2006-03-03" seq="2006-0984" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in inc_header.php in EJ3 TOPo 2.2.178 allows remote attackers to inject arbitrary web script or HTML via the gTopNombre parameter.</descript></desc><sols><sol source="nvd">This vulnerability affects EJ3, TOPo version 2.2.178, and possibly all previous versions.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426318/100/0/threaded">20060228 EJ3 TOPo - Cross Site Scripting Vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/16879">16879</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0775">ADV-2006-0775</ref><ref source="OSVDB" url="http://www.osvdb.org/23541">23541</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19070">19070</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24980">topo-incheader-xss(24980)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/511">511</ref></refs><vuln_soft><prod name="TOPo" vendor="EJ3"><vers num="2.2.178"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0985" published="2006-03-03" seq="2006-0985" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the &quot;post comment&quot; functionality of WordPress 2.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) website, and (3) comment parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426304/100/0/threaded">20060227 WordPress 2.0.1 Multiple Vulnerabilities</ref><ref adv="1" patch="1" source="NST" url="http://NeoSecurityTeam.net/advisories/Advisory-17.txt">Advisory-17</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426504/100/0/threaded">20060228 FW: WordPress 2.0.1 Multiple Vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426574/100/0/threaded">20060302 Re: FW: WordPress 2.0.1 Multiple Vulnerabilities</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0777">ADV-2006-0777</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19050">19050</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24957">
wordpress-wpcommentspost-xss(24957)</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0.1"/><vers num="2.0"/><vers num="1.5.1.3"/><vers num="1.5.1.2"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.2"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0986" published="2006-03-03" seq="2006-0986" severity="Medium" type="CVE"><desc><descript source="cve">WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) default-filters.php, (2) template-loader.php, (3) rss-functions.php, (4) locale.php, (5) wp-db.php, and (6) kses.php in the wp-includes/ directory; and (7) edit-form-advanced.php, (8) admin-functions.php, (9) edit-link-form.php, (10) edit-page-form.php, (11) admin-footer.php, and (12) menu.php in the wp-admin directory; and possibly (13) list directory contents of the wp-includes directory.  NOTE: the vars.php, edit-form.php, wp-settings.php, and edit-form-comment.php vectors are already covered by CVE-2005-4463.  The menu-header.php vector is already covered by CVE-2005-2110.  Other vectors might be covered by CVE-2005-1688.  NOTE: if the typical installation of WordPress does not list any site-specific files to wp-includes, then vector [13] is not an exposure.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426304/100/0/threaded">20060227 WordPress 2.0.1 Multiple Vulnerabilities</ref><ref adv="1" patch="1" source="NST" url="http://NeoSecurityTeam.net/advisories/Advisory-17.txt">Advisory-17</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426504/100/0/threaded">20060228 FW: WordPress 2.0.1 Multiple Vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426574/100/0/threaded">20060302 Re: FW: WordPress 2.0.1 Multiple Vulnerabilities</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0777">ADV-2006-0777</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19050">19050</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0.1"/><vers num="2.0"/><vers num="1.5.1.3"/><vers num="1.5.1.2"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.2"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0987" published="2006-03-03" seq="2006-0987" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of ISC BIND, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.</descript></desc><sols><sol source="nvd">This vulnerability affects ISC, BIND versions 9.3.2 and previous.</sol></sols><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426368/100/0/threaded">20060228 recursive DNS servers DDoS as a growing DDoS problem</ref><ref source="The Measurement Factory" url="http://dns.measurement-factory.com/surveys/sum1.html">The Measurement Factory DNS Survey</ref><ref adv="1" patch="1" source="US-CERT" url="http://www.us-cert.gov/reading_room/DNS-recursion121605.pdf">DNS-recursion121605</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="9.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-03" name="CVE-2006-0988" published="2006-03-03" seq="2006-0988" severity="High" type="CVE"><desc><descript source="cve">The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.</descript></desc><sols><sol source="nvd">This vulnerability affects all versions of Windows 2000 -and- Windows Server 2003.</sol></sols><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426368/100/0/threaded">20060228 recursive DNS servers DDoS as a growing DDoS problem</ref><ref source="The Measurement Factory" url="http://dns.measurement-factory.com/surveys/sum1.html">The Measurement Factory DNS Survey Executive Summary</ref><ref adv="1" patch="1" source="US-CERT" url="http://www.us-cert.gov/reading_room/DNS-recursion121605.pdf">DNS-recursion121605</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-0989" published="2006-03-27" seq="2006-0989" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the volume manager daemon (vmd) in Veritas NetBackup Enterprise Server 5.0 through 6.0 and DataCenter and BusinesServer 4.5FP and 4.5MP allows attackers to execute arbitrary code via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-06-005.html"></ref><ref source="" url="http://securityresponse.symantec.com/avcenter/security/Content/2006.03.27.html"></ref><ref adv="1" source="" url="http://seer.support.veritas.com/docs/281521.htm"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428944/100/0/threaded">20060327 ZDI-06-005: Symantec VERITAS NetBackup Volume Manager Buffer Overflow</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/880801">VU#880801</ref><ref source="BID" url="http://www.securityfocus.com/bid/17264">17264</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1124">ADV-2006-1124</ref><ref source="OSVDB" url="http://www.osvdb.org/24172">24172</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015832">1015832</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25471">netbackup-vmd-sscanf-bo(25471)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/639">639</ref></refs><vuln_soft><prod name="NetBackup Enterprise Server" vendor="Veritas"><vers num="6.0"/><vers num="5.1"/><vers num="5.0"/></prod><prod name="NetBackup BusinesServer" vendor="Veritas"><vers num="4.5.0 FP"/><vers num="4.5.0 MP"/></prod><prod name="NetBackup DataCenter" vendor="Veritas"><vers num="4.5.0 FP"/><vers num="4.5.0 MP"/></prod><prod name="NetBackup Server" vendor="Veritas"><vers num="6.0"/><vers num="5.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-0990" published="2006-03-27" seq="2006-0990" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the NetBackup Catalog daemon (bpdbm) in Veritas NetBackup Enterprise Server 5.0 through 6.0 and DataCenter and BusinesServer 4.5FP and 4.5MP allows attackers to execute arbitrary code via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-06-006.html"></ref><ref patch="1" source="" url="http://securityresponse.symantec.com/avcenter/security/Content/2006.03.27.html"></ref><ref adv="1" source="" url="http://seer.support.veritas.com/docs/281521.htm"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428992/100/0/threaded">20060327 SYM06-006, Veritas NetBackup: Multiple Overflow Vulnerabilities in NetBackup Daemons</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428988/100/0/threaded">20060327 ZDI-06-006: Symantec VERITAS NetBackup Database Manager Buffer Overflow</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/744137">VU#744137</ref><ref source="BID" url="http://www.securityfocus.com/bid/17264">17264</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1124">ADV-2006-1124</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015832">1015832</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19417">19417</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25472">netbackup-bpdbm-sprintf-bo(25472)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/642">642</ref></refs><vuln_soft><prod name="NetBackup Enterprise Server" vendor="Veritas"><vers num="6.0"/><vers num="5.1"/><vers num="5.0"/></prod><prod name="NetBackup BusinesServer" vendor="Veritas"><vers num="4.5.0 FP"/><vers num="4.5.0 MP"/></prod><prod name="NetBackup DataCenter" vendor="Veritas"><vers num="4.5.0 FP"/><vers num="4.5.0 MP"/></prod><prod name="NetBackup Server" vendor="Veritas"><vers num="6.0"/><vers num="5.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.1" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-21" name="CVE-2006-0991" published="2006-03-27" seq="2006-0991" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the NetBackup Sharepoint Services server daemon (bpspsserver) on NetBackup 6.0 for Windows allows remote attackers to execute arbitrary code via crafted &quot;Request Service&quot; packets to the vnetd service (TCP port 13724).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.tippingpoint.com/security/advisories/TSRT-06-01.html"></ref><ref patch="1" source="" url="http://securityresponse.symantec.com/avcenter/security/Content/2006.03.27.html"></ref><ref source="" url="http://seer.support.veritas.com/docs/281521.htm"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428979/100/0/threaded">20060327 TSRT-06-01: Symantec VERITAS NetBackup vnetd Buffer Overflow Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17264">17264</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/377441">VU#377441</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1124">ADV-2006-1124</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015832">1015832</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19417">19417</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25473">netbackup-vnetd-bo(25473)</ref></refs><vuln_soft><prod name="NetBackup Enterprise Server" vendor="Veritas"><vers num="6.0"/><vers num="5.1"/><vers num="5.0"/></prod><prod name="NetBackup BusinesServer" vendor="Veritas"><vers num="4.5.0 FP"/><vers num="4.5.0 MP"/></prod><prod name="NetBackup DataCenter" vendor="Veritas"><vers num="4.5.0 FP"/><vers num="4.5.0 MP"/></prod><prod name="NetBackup Server" vendor="Veritas"><vers num="6.0"/><vers num="5.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-16" modified="2006-04-15" name="CVE-2006-0992" published="2006-04-14" seq="2006-0992" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute arbitrary code via a long Accept-Language value without a comma or semicolon.  NOTE: due to a typo, the original ZDI advisory accidentally referenced CVE-2006-0092.  This is the correct identifier.</descript></desc><sols><sol source="nvd">Upgrade to GroupWise Messenger, 2.0 Public Beta 2 to fix this issue.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430911/100/0/threaded">20060413 ZDI-06-008: Novell GroupWise Messenger Accept-Language Buffer Overflow</ref><ref adv="1" patch="1" source="Zero Day Initiative" url="http://www.zerodayinitiative.com/advisories/ZDI-06-008.html">ZDI-06-008</ref><ref patch="1" source="Novell" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?10100861.htm">TID10100861 </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17503">17503</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1355">ADV-2006-1355</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015911">1015911</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19663">19663</ref><ref source="" url="http://cirt.dk/advisories/cirt-42-advisory.txt"></ref><ref source="" url="http://metasploit.blogspot.com/2006/04/exploit-development-groupwise_14.html"></ref><ref source="" url="http://www.milw0rm.com/exploits/1679"></ref><ref source="OSVDB" url="http://www.osvdb.org/24617">24617</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25828">
groupwise-accept-language-bo(25828)</ref></refs><vuln_soft><prod name="GroupWise Messenger" vendor="Novell"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-10" name="CVE-2006-0993" published="2006-05-09" seq="2006-0993" severity="Medium" type="CVE"><desc><descript source="cve">The web management interface in 3Com TippingPoint SMS Server before 2.2.1.4478 does not restrict access to certain directories, which might allow remote attackers to obtain potentially sensitive information such as configuration settings.</descript></desc><sols><sol source="nvd">Upgrade to 3Com TippingPoint SMS Server version 2.2.1.4478</sol></sols><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433432/100/0/threaded">20060509 ZDI-06-013: 3Com TippingPoint SMS Server Information Disclosure Vulnerability</ref><ref adv="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-06-013.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1752">ADV-2006-1752</ref><ref source="" url="http://www.3com.com/securityalert/alerts/3COM-06-002.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/25360">25360</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016051">1016051</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20058">20058</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26338">tippingpoint-sms-information-disclosure(26338)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17935">17935</ref><ref source="SREASON" url="http://securityreason.com/securityalert/870">870</ref></refs><vuln_soft><prod name="TippingPoint SMS Server" vendor="3Com"><vers num="2.2.1.4477" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-16" name="CVE-2006-0994" published="2006-05-10" seq="2006-0994" severity="High" type="CVE"><desc><descript source="cve">Multiple Sophos Anti-Virus products, including Anti-Virus for Windows 5.x before 5.2.1 and 4.x before 4.05, when cabinet file inspection is enabled, allows remote attackers to execute arbitrary code via a CAB file with &quot;invalid folder count values,&quot; which leads to heap corruption.</descript></desc><sols><sol source="nvd">The vendor has issued a fixed version</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433272/100/0/threaded">20060508 ZDI-06-012: Sophos Anti-Virus CAB Unpacking Code Execution Vulnerability</ref><ref adv="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-06-013.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17876">17876</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1730">ADV-2006-1730</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016041">1016041</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20028">20028</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-May/045897.html">
20060508 ZDI-06-012: Sophos Anti-Virus CAB Unpacking Code Execution Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26305">
sophos-cab-parsing-bo(26305)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/869">869</ref></refs><vuln_soft><prod name="Sophos Anti-Virus" vendor="Sophos"><vers num="5.2.0" prev="1"/><vers num="4.04" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-06" name="CVE-2006-0995" published="2006-03-03" seq="2006-0995" severity="Medium" type="CVE"><desc><descript source="cve">EMC Dantz Retrospect 7 backup client 7.0.107, and other versions before 7.0.109, and 6.5 before 6.5.138 allows remote attackers to cause a denial of service (client termination and loss of backup service) via a malformed packet to TCP port 497, which triggers an assert error.</descript></desc><sols><sol source="nvd">This vulnerability affects EMC Dantz, Retrospect versions 7.0.x (all 7.0.x versions previous to 7.0.109) as well as versions 6.5.x (all 6.5.x versions previous to 6.5.138)</sol></sols><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?type=vulnerabilities">20060302 EMC Dantz Retrospect 7 Backup client DoS Vulnerability</ref><ref adv="1" patch="1" source="EMC Dantz Knowledgebase" url="http://kb.dantz.com/article.asp?article=8361&amp;p=2">Retrospect client security update</ref><ref source="BID" url="http://www.securityfocus.com/bid/16933">16933</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0811">ADV-2006-0811</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015714">1015714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19097">19097</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25143">
retrospect-backup-packet-dos(25143)</ref></refs><vuln_soft><prod name="Retrospect" vendor="EMC Dantz"><vers num="7.0"/><vers num="6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-05-05" name="CVE-2006-0996" published="2006-04-10" seq="2006-0996" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.</descript></desc><loss_types><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430449/100/0/threaded">20060408 phpinfo() Cross Site Scripting PHP 5.1.2 and 4.4.2</ref><ref patch="1" source="MLIST" url="http://marc.theaimsgroup.com/?l=php-cvs&amp;m=114374620416389&amp;w=2">[php-cvs] 20060330 cvs: php-src /ext/standard info.c</ref><ref source="" url="http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/info.c"></ref><ref patch="1" source="" url="http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/info.c?r1=1.260&amp;r2=1.261"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17362">17362</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/044981.html">20060408 phpinfo() Cross Site Scripting PHP 5.1.2 and 4.4.2</ref><ref source="" url="http://securityreason.com/achievement_securityalert/34"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015879">1015879</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19599">19599</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1290">ADV-2006-1290</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0276.html">RHSA-2006:0276</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19832">19832</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:074">MDKSA-2006:074</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0501.html">RHSA-2006:0501</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20222">20222</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/05-05-2006.html">SUSE-SA:2006:024</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200605-08.xml">GLSA-200605-08</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2685">ADV-2006-2685</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20951">20951</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-320-1">USN-320-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21252">21252</ref><ref source="" url="http://www.php.net/ChangeLog-4.php#4.4.3"></ref><ref source="OSVDB" url="http://www.osvdb.org/24484">24484</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25702">php-phpinfo-long-array-xss(25702)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21564">21564</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0549.html">RHSA-2006:0549</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">20060501-01-U</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19775">19775</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19979">19979</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20052">20052</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20210">20210</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21125">21125</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:074">MDKSA-2006:074</ref><ref source="SREASON" url="http://securityreason.com/securityalert/675">675</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.1.2"/><vers num="4.4.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-0997" published="2006-03-23" seq="2006-0997" severity="Medium" type="CVE"><desc><descript source="cve">The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) permits encryption with a NULL key, which results in cleartext communication that allows remote attackers to read an SSL protected session by sniffing network traffic.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?10100633.htm"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17176">17176</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1043">ADV-2006-1043</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015799">1015799</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19324">19324</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25380">netware-nile-ssl-cleartext(25380)</ref><ref source="OSVDB" url="http://www.osvdb.org/24046">24046</ref></refs><vuln_soft><prod name="Netware" vendor="Novell"><vers num="6.5 SP4"/><vers num="6.5 SP1.1b"/><vers num="6.5 SP1.1a"/><vers num="6.5 SP3"/><vers num="6.5 SP2"/><vers num="6.5 SP1"/><vers num="6.5"/></prod><prod name="Open Enterprise Server" vendor="Novell"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-0998" published="2006-03-23" seq="2006-0998" severity="Medium" type="CVE"><desc><descript source="cve">The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) sometimes selects a weak cipher instead of an available stronger cipher, which makes it easier for remote attackers to sniff and decrypt an SSL protected session.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?10100633.htm"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1043">ADV-2006-1043</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015799">1015799</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19324">19324</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25381">netware-nile-weak-encryption(25381)</ref><ref source="OSVDB" url="http://www.osvdb.org/24047">24047</ref></refs><vuln_soft><prod name="Netware" vendor="Novell"><vers num="6.5 SP4"/><vers num="6.5 SP1.1b"/><vers num="6.5 SP1.1a"/><vers num="6.5 SP3"/><vers num="6.5 SP2"/><vers num="6.5 SP1"/><vers num="6.5"/></prod><prod name="Open Enterprise Server" vendor="Novell"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-0999" published="2006-03-23" seq="2006-0999" severity="Medium" type="CVE"><desc><descript source="cve">The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) allows a client to force the server to use weak encryption by stating that a weak cipher is required for client compatibility, which might allow remote attackers to decrypt contents of an SSL protected session.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?10100633.htm"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1043">ADV-2006-1043</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015799">1015799</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19324">19324</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25382">netware-nile-forced-weak-encryption(25382)</ref><ref source="OSVDB" url="http://www.osvdb.org/24048">24048</ref></refs><vuln_soft><prod name="Netware" vendor="Novell"><vers num="6.5 SP4"/><vers num="6.5 SP1.1b"/><vers num="6.5 SP1.1a"/><vers num="6.5 SP3"/><vers num="6.5 SP2"/><vers num="6.5 SP1"/><vers num="6.5"/></prod><prod name="Open Enterprise Server" vendor="Novell"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-06" name="CVE-2006-1000" published="2006-03-06" seq="2006-1000" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Pentacle In-Out Board 3.0 and earlier allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) newsid parameter to newsdetailsview.asp and (2) password parameter to login.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426074/100/0/threaded">20060225 Advisory: Pentacle In-Out Board &lt;= 6.03 (login.asp) AuthencationByPass Vulnerability</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426075/100/0/threaded">20060225 Advisory: Pentacle In-Out Board &lt;= 6.03 (newsdetailsview.aspnewsid) Remote SQL Injection Vulnerability</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114088057718972&amp;w=2">20060225 Advisory: Pentacle In-Out Board &lt;= 6.03</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114088050601395&amp;w=2">20060225 Advisory: Pentacle In-Out Board &lt;= 6.03</ref><ref adv="1" source="nukedx.com" url="http://www.nukedx.com/?viewdoc=13">Advisory 13: Pentacle In-Out Board &lt;= 6.03 </ref><ref adv="1" source="nukedx.com" url="http://www.nukedx.com/?viewdoc=14">Advisory 14: Pentacle In-Out Board &lt;= 6.03 </ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/16818">16818</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0749">ADV-2006-0749</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1015682">1015682</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19024">19024</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/042525.html">20060225 Advisory: Pentacle In-Out Board &lt;= 6.03 (newsdetailsview.asp newsid) Remote SQL Injection Vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/042524.html">20060225 Advisory: Pentacle In-Out Board &lt;= 6.03 (login.asp) Authencation ByPass Vulnerability</ref></refs><vuln_soft><prod name="Pentacle In-Out Board" vendor="G2Soft"><vers num="6.03"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-06" name="CVE-2006-1001" published="2006-03-06" seq="2006-1001" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the board module in LanSuite LanParty Intranet System 2.0.6 and 2.1.0 beta allows remote attackers to execute arbitrary SQL commands via the fid parameter.</descript></desc><sols><sol source="nvd">This vulnerability affects Lansuite, LanParty Intranet System version 2.1 (Beta) &amp; LanSuite, LanParty Intranet System versions 2.0.6 and previous.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="milw0rm.com" url="http://milw0rm.com/id.php?id=1526">1526</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/16836">16836</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0747">ADV-2006-0747</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19048">19048</ref><ref source="OSVDB" url="http://www.osvdb.org/23533">23533</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24940">lansuite-fid-sql-injection(24940)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1526">

1526</ref></refs><vuln_soft><prod name="LanParty Intranet System" vendor="Lansuite"><vers num="2.1"/><vers num="2.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-14" name="CVE-2006-1002" published="2006-03-06" seq="2006-1002" severity="High" type="CVE"><desc><descript source="cve">NETGEAR WGT624 Wireless DSL router has a default account of super_username &quot;Gearguy&quot; and super_passwd &quot;Geardog&quot;, which allows remote attackers to modify the configuration.  NOTE: followup posts have suggested that this might not occur with all WGT624 routers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426187/100/0/threaded">20060226 NETGEAR WGT624 ? Wireless DSL router default user name/password vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426313/100/0/threaded">20060227 Re: NETGEAR WGT624 Wireless DSL router default user name/password vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16835">16835</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431026/30/5580/threaded">20060413 Re: Re: NETGEAR WGT624 Wireless DSL router default user name/password vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24926">netgear-wgt624-default-account(24926)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485396/100/0/threaded">20071220 Re: Re: NETGEAR WGT624 Wireless DSL router default user name/password vulnerability</ref></refs><vuln_soft><prod name="WGT624" vendor="NetGear"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-1003" published="2006-03-06" seq="2006-1003" severity="Medium" type="CVE"><desc><descript source="cve">The backup configuration option in NETGEAR WGT624 Wireless Firewall Router stores sensitive information in cleartext, which allows remote attackers to obtain passwords and gain privileges.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/426185">20060227 NETGEAR WGT624 ? Wireless DSL Firewall/Router vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16837">16837</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24927">
netgear-wgt624-cleartext-config(24927)</ref></refs><vuln_soft><prod name="WGT624" vendor="NetGear"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-1004" published="2006-03-06" seq="2006-1004" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in agencyprofile.asp in Parodia 6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the AG_ID parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0763">ADV-2006-0763</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19025">19025</ref><ref source="OSVDB" url="http://www.osvdb.org/23548">23548</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24971">parodia-agencyprofile-xss(24971)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16865">16865</ref></refs><vuln_soft><prod name="Parodia" vendor="CactuSoft"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-1005" published="2006-03-06" seq="2006-1005" severity="Medium" type="CVE"><desc><descript source="cve">agencyprofile.asp in Parodia 6.2 and earlier might allow remote attackers to obtain sensitive information by triggering an SQL error via an invalid AG_ID parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript></desc><sols><sol source="nvd">This vulnerability affects CactuSoft, Parodia version 6.2, and may affect all previous versions as well.</sol></sols><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19025">19025</ref></refs><vuln_soft><prod name="Parodia" vendor="CactuSoft"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1006" published="2006-03-06" seq="2006-1006" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in sendcard.php in sendcard before 3.3.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="sourceforge.net" url="http://sourceforge.net/forum/forum.php?forum_id=544749">Summary: sendcard 3.3.0 released </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16900">16900</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0778">ADV-2006-0778</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19056">19056</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24978">sendcard-unspecified-sql-injection(24978)</ref></refs><vuln_soft><prod name="Sendcard" vendor="Sendcard"><vers num="3.2.3"/><vers num="3.2.2"/><vers num="3.2.1"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1007" published="2006-03-06" seq="2006-1007" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in N8cms 1.1 and 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) dir and (2) page_id parameter to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://biyosecurity.be/bugs/n8cms.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0779">ADV-2006-0779</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19068">19068</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24974">n8cms-index-sql-injection(24974)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427222/100/0/threaded">20060309 n8cms 1.1 &amp; 1.2 version Sql &amp;#304;njection And XSS</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25125">n8cms-sql-injection(25125)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16858">16858</ref></refs><vuln_soft><prod name="N8cms SiteSuite CMS" vendor="Nathan Landry"><vers num="1.1"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1008" published="2006-03-06" seq="2006-1008" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in N8cms 1.1 and 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) dir and (2) page_id parameter to (a) index.php and (3) userid parameter to (b) mailto.php.  NOTE: it is possible that issues 1 and 2 are resultant from SQL injection.</descript></desc><sols><sol source="nvd">This vulnerability may affect all versions of Nathan Landry, n8cms.</sol></sols><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Liz0ziM" url="http://biyosecurity.be/bugs/n8cms.txt">n8cms 1.1 &amp; 1.2  version</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0779">ADV-2006-0779</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19068">19068</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24975">n8cms-mailto-xss(24975)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427222/100/0/threaded">20060309 n8cms 1.1 &amp; 1.2 version Sql &amp;#304;njection And XSS</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25126">n8cms--xss(25126)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16858">16858</ref><ref source="SREASON" url="http://securityreason.com/securityalert/562">562</ref></refs><vuln_soft><prod name="N8cms SiteSuite CMS" vendor="Nathan Landry"><vers num="1.2"/><vers num="1.12"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-1009" published="2006-03-06" seq="2006-1009" severity="Medium" type="CVE"><desc><descript source="cve">M4 Project enigma-suite before 0.73.3 (Windows) has a default password of &quot;nominal&quot; for the &quot;enigma-client&quot; account, which allows local users to gain access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://www.bytereef.org/m4-project-blog.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/23572">23572</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19077">19077</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0787">ADV-2006-0787</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24993">enigma-suite-default-acoount(24993)</ref></refs><vuln_soft><prod name="enigma-suite" vendor="M4 Project"><vers num="0.73.2"/><vers num="0.73.1"/><vers num="0.73"/><vers num="0.72"/><vers num="0.71"/><vers num="0.70"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-1010" published="2006-03-06" seq="2006-1010" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in socket/request.c in CrossFire before 1.9.0, when oldsocketmode is enabled, allows remote attackers to cause a denial of service (segmentation fault) and possibly execute code by sending the server a large request.</descript></desc><sols><sol source="nvd">This vulnerability affects CrossFire versions 1.8.0 and previous.</sol></sols><loss_types><avail/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/poc/crossfirebof.zip">CrossFire &lt;= 1.8.0 oldsocketmode buffer-overflow 0.1</ref><ref patch="1" source="Sourceforge.net" url="http://cvs.sourceforge.net/viewcvs.py/crossfire/crossfire/socket/request.c?r1=1.80&amp;r2=1.81">N/A</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0760">ADV-2006-0760</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19044">19044</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24932">crossfire-oldsocketmode-bo(24932)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16883">16883</ref><ref source="OSVDB" url="http://www.osvdb.org/23549">23549</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1001">DSA-1001</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19194">19194</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-11.xml">GLSA-200604-11</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19785">19785</ref></refs><vuln_soft><prod name="CrossFire" vendor="CrossFire"><vers num="1.8.0"/><vers num="1.7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-1011" published="2006-03-06" seq="2006-1011" severity="Low" type="CVE"><desc><descript source="cve">LetterMerger 1.2 stores user information in Access database files with insecure permissions, which allows local users to obtain sensitive information.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16917">16917</ref><ref source="OSVDB" url="http://www.osvdb.org/23599">23599</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19074">19074</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25020">lettermerger-files-disclose-information(25020)</ref></refs><vuln_soft><prod name="LetterMerger" vendor="Peters Software"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-1012" published="2006-03-06" seq="2006-1012" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execute arbitrary SQL commands via the User-Agent field in an HTTP header for a comment.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-01.xml">GLSA-200603-01</ref><ref source="BID" url="http://www.securityfocus.com/bid/16950">16950</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19109">19109</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19123">19123</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25321">
wordpress-comment-sql-injection(25321)</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="1.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-1013" published="2006-03-06" seq="2006-1013" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in index.php in SMartBlog (aka SMBlog) 1.2 allows remote attackers to include and execute arbitrary PHP files via (1) the pg parameter and (2) a query string without a parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426498/100/0/threaded">20060301 SMBlog Remote Command Exucetion</ref><ref source="BID" url="http://www.securityfocus.com/bid/16905">16905</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25220">
smartblog-index-file-include(25220)</ref></refs><vuln_soft><prod name="SMartBlog" vendor="SMartBlog"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.2" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="4.9" CVSS_score="3.2" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-1014" published="2006-03-06" seq="2006-1014" severity="Low" type="CVE"><desc><descript source="cve">Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail.  NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.</descript></desc><sols><sol source="nvd">This vulnerability affects all versions of PHP from 4.0.x through 5.1.x </sol></sols><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426342/100/0/threaded">20060228 (PHP) mb_send_mail security bypass</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0772">ADV-2006-0772</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18694">18694</ref><ref source="OSVDB" url="http://www.osvdb.org/23534">23534</ref><ref source="BID" url="http://www.securityfocus.com/bid/16878">16878</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/05-05-2006.html">SUSE-SA:2006:024</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19979">
19979</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.1.0"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0.0 RC3"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC1"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta1"/><vers num="5.0.0"/><vers num="5.0 candidate 3"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 1"/><vers num="4.4.1"/><vers num="4.4.0"/><vers num="4.3.9"/><vers num="4.3.8"/><vers num="4.3.7"/><vers num="4.3.6"/><vers num="4.3.5"/><vers num="4.3.4"/><vers num="4.3.3"/><vers num="4.3.11"/><vers num="4.3.10"/><vers edition="Dev" num="4.2"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1015" published="2006-03-06" seq="2006-1015" severity="Medium" type="CVE"><desc><descript source="cve">Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments.  NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426497/100/0/threaded">20060301 Re: (PHP) mb_send_mail security bypass</ref><ref source="BID" url="http://www.securityfocus.com/bid/16878">16878</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/05-05-2006.html">SUSE-SA:2006:024</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19979">
19979</ref><ref source="SREASON" url="http://securityreason.com/securityalert/517">517</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.1.2"/><vers num="5.1.1"/><vers num="5.1.0"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0.0 RC3"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC1"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta1"/><vers num="5.0.0"/><vers num="5.0 candidate 3"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 1"/><vers num="4.4.2"/><vers num="4.4.1"/><vers num="4.4.0"/><vers num="4.3.11"/><vers num="4.3.10"/><vers num="4.3.9"/><vers num="4.3.8"/><vers num="4.3.7"/><vers num="4.3.6"/><vers num="4.3.5"/><vers num="4.3.4"/><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.3"/><vers num="4.2.2"/><vers num="4.2.1"/><vers num="4.2.0"/><vers edition="Dev" num="4.2"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1.0"/><vers num="4.0.7 RC3"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC1"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3 pl1"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1 pl2"/><vers num="4.0.1 pl1"/><vers num="4.0.1"/><vers num="4.0.0"/><vers num="3.0.18"/><vers num="3.0.17"/><vers num="3.0.16"/><vers num="3.0.15"/><vers num="3.0.14"/><vers num="3.0.13"/><vers num="3.0.12"/><vers num="3.0.11"/><vers num="3.0.10"/><vers num="3.0.9"/><vers num="3.0.8"/><vers num="3.0.7"/><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1016" published="2006-03-06" seq="2006-1016" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Windows XP before SP1, allows remote attackers to execute arbitrary code via JavaScript that calls IsComponentInstalled with a long first argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://metasploit.com/projects/Framework/exploits.html#ie_iscomponentinstalled"></ref><ref source="" url="http://www.metasploit.com/projects/Framework/modules/exploits/ie_iscomponentinstalled.pm"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24923">ie-iscomponentinstalled-bo(24923)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16870">16870</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-05" name="CVE-2006-1017" published="2006-03-06" seq="2006-1017" severity="High" type="CVE"><desc><descript source="cve">The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426339/100/0/threaded">20060228 (PHP) imap functions bypass safemode and open_basedir restrictions</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0772">ADV-2006-0772</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18694">18694</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24964">php-imap-restriction-bypass(24964)</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:122">MDKSA-2006:122</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21050">21050</ref><ref source="" url="http://bugs.php.net/bug.php?id=37265"></ref><ref source="" url="http://www.php.net/ChangeLog-5.php#5.1.5"></ref><ref source="" url="http://www.php.net/release_5_1_5.php"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21546">21546</ref><ref source="OSVDB" url="http://www.osvdb.org/23535">
23535</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:122">MDKSA-2006:122</ref><ref source="SREASON" url="http://securityreason.com/securityalert/516">516</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.1.2"/><vers num="5.1.1"/><vers num="5.1.0"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0.0 RC3"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC1"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta1"/><vers num="5.0.0"/><vers num="5.0 candidate 3"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 1"/><vers num="4.4.2"/><vers num="4.4.1"/><vers num="4.4.0"/><vers num="4.3.11"/><vers num="4.3.10"/><vers num="4.3.9"/><vers num="4.3.8"/><vers num="4.3.7"/><vers num="4.3.6"/><vers num="4.3.5"/><vers num="4.3.4"/><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.3"/><vers num="4.2.2"/><vers num="4.2.1"/><vers num="4.2.0"/><vers edition="Dev" num="4.2"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1.0"/><vers num="4.0.7 RC3"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC1"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3 pl1"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1 pl2"/><vers num="4.0.1 pl1"/><vers num="4.0.1"/><vers num="4.0.0"/><vers num="3.0.18"/><vers num="3.0.17"/><vers num="3.0.16"/><vers num="3.0.15"/><vers num="3.0.14"/><vers num="3.0.13"/><vers num="3.0.12"/><vers num="3.0.11"/><vers num="3.0.10"/><vers num="3.0.9"/><vers num="3.0.8"/><vers num="3.0.7"/><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/><vers num="5.1.4"/><vers num="5.1.3"/><vers num="4.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1018" published="2006-03-06" seq="2006-1018" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in poems.php in DCI-Designs Dawaween 1.03 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426622/100/0/threaded">20060302 sql in Dawaween V 1.03</ref><ref source="BID" url="http://www.securityfocus.com/bid/16909">16909</ref><ref source="OSVDB" url="http://www.osvdb.org/23827">23827</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25163">
dawaween-poems-sql-injection(25163)</ref></refs><vuln_soft><prod name="Dawaween" vendor="DCI-Designs"><vers num="1.03"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1019" published="2006-03-06" seq="2006-1019" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in fce.php in UKiBoard 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a BBCode url tag when using the show_post function.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information, some of which reference a source URL that appears to be for an unrelated issue.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16912">16912</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24990">ukiboard-fce-xss(24990)</ref></refs><vuln_soft><prod name="UKiBoard" vendor="UKiWEB"><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1020" published="2006-03-06" seq="2006-1020" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in forumlib.php in Johnny_Vegas Vegas Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the postid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/90/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0790">ADV-2006-0790</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427470/100/0/threaded">20060313 [eVuln] Vegas Forum SQL Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17079">17079</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19219">19219</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25167">
vegasforum-forumlib-sql-injection(25167)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/574">574</ref></refs><vuln_soft><prod name="Vegas Forum" vendor="Johnny_Vegas"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1021" published="2006-03-06" seq="2006-1021" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in sol_menu.php in PeHePe Uyelik Sistemi (aka PeHePe MemberShip Management System) 3 allows remote attackers to inject arbitrary web script or HTML via the kuladi parameter ($kul_adi variable).</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426363/100/0/threaded">20060228 PEHEPE Membership Management System Multiple Vulnerabilities</ref><ref source="" url="http://yns.zaxaz.com/2006/02/28/pehepe-membership-management-system-multiple-vulnerabilities/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0781">ADV-2006-0781</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19055">19055</ref><ref source="BID" url="http://www.securityfocus.com/bid/16885">16885</ref></refs><vuln_soft><prod name="MemberShip Management System" vendor="PeHePe"><vers num="3"/></prod><prod name="Uyelik Sistemi" vendor="PeHePe"><vers num="3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-1022" published="2006-03-06" seq="2006-1022" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in sol_menu.php in PeHePe Uyelik Sistemi (aka PeHePe MemberShip Management System) 3 allows remote attackers to include and execute arbitrary PHP code via a URL in the uye_klasor parameter, along with a misafir[] parameter that is set to UYE_SEVIYE.</descript></desc><sols><sol source="nvd">This vulnerability affects PeHePe, Membership Management System (a.k.a Uyelik Sistemi) versions 3.0 and previous.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426363/100/0/threaded">20060228 PEHEPE Membership Management System Multiple Vulnerabilities</ref><ref adv="1" source="Yns WeBlog" url="http://yns.zaxaz.com/2006/02/28/pehepe-membership-management-system-multiple-vulnerabilities/">pehepe-membership-management-system-multiple-vulnerabilities</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0781">ADV-2006-0781</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19055">19055</ref><ref source="BID" url="http://www.securityfocus.com/bid/16887">16887</ref><ref source="OSVDB" url="http://www.osvdb.org/23567">23567</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24970">pehepe-uyeklasor-command-execution(24970)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/515">515</ref></refs><vuln_soft><prod name="Membership Management System" vendor="PeHePe"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-1023" published="2006-03-06" seq="2006-1023" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in HP System Management Homepage (SMH) 2.0.0 through 2.1.4 on Windows allows remote attackers to access certain files via unspecified vectors.</descript></desc><sols><sol source="nvd">This vulnerability affects all versions of HP, System Management Homepage from 2.0.0 through 2.1.4.  This vulnarebility is only present in the following Windows OS environments: Microsoft Windows 2000, 2003, 2003 for x64, 2003 for Itanium and also Windows XP.</sol></sols><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="HP" url="http://www.securityfocus.com/archive/1/archive/1/426345/100/0/threaded">SSRT061118</ref><ref patch="1" source="HP" url="http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00601530">HPSBMA02099</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0769">ADV-2006-0769</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015692">1015692</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19059">19059</ref><ref source="BID" url="http://www.securityfocus.com/bid/16876">16876</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24996">
hp-system-managemenet-homepage-dir-traversal(24996)</ref></refs><vuln_soft><prod name="System Management Homepage" vendor="HP"><vers num="2.1.4"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-1024" published="2006-03-06" seq="2006-1024" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in MgrLogin.asp in Addsoft StoreBot 2005 Professional allows remote attackers to execute arbitrary SQL commands via the Pwd parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><sols><sol source="nvd">This vulnerability affects all versions of AddSoft, StoreBot 2005 Professional Edition.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16897">16897</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0784">ADV-2006-0784</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/23575">23575</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19019">19019</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24987">storebot-mgrlogin-sql-injection(24987)</ref></refs><vuln_soft><prod name="StoreBot" vendor="Sun"><vers num="2005"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1025" published="2006-03-06" seq="2006-1025" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in manage.asp in Addsoft StoreBot 2002 Standard allows remote attackers to inject arbitrary web script or HTML via the ShipMethod parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16898">16898</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0785">ADV-2006-0785</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/23574">23574</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19060">19060</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24986">storebot-manage-xss(24986)</ref></refs><vuln_soft><prod name="StoreBot" vendor="Sun"><vers edition="Standard" num="2002"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-1026" published="2006-03-06" seq="2006-1026" severity="High" type="CVE"><desc><descript source="cve">JFacets before 0.2 allows remote attackers to gain privileges as any account via a GET request with a modified account profileID.</descript></desc><sols><sol source="nvd">This vulnerability affects JFacets versions prior to 0.2.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Sourceforge.net" url="http://sourceforge.net/project/shownotes.php?group_id=154666&amp;release_id=396824">jfacets-0.2</ref><ref source="Sourceforge.net" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1439037&amp;group_id=154666&amp;atid=792697">[1439037] Security issue</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0767">ADV-2006-0767</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19031">19031</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24958">jfacets-auth-authentication-bypass(24958)</ref></refs><vuln_soft><prod name="JFacets" vendor="JFacets"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-1027" published="2006-03-06" seq="2006-1027" severity="Medium" type="CVE"><desc><descript source="cve">feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to obtain sensitive information via a &quot;/&quot; (slash) in the feed parameter to index.php, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426538/100/0/threaded">20060302 JOOMLA CMS 1.0.7 DoS &amp; path disclosing</ref><ref patch="1" source="joomla.org" url="http://www.joomla.org/content/view/938/78/">1.0.8 Changelog  </ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25028">joomla-multiple-disclose-path(25028)</ref><ref source="OSVDB" url="http://www.osvdb.org/23815">23815</ref><ref source="SREASON" url="http://securityreason.com/securityalert/527">527</ref></refs><vuln_soft><prod name="Joomla" vendor="Joomla"><vers num="1.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-1028" published="2006-03-06" seq="2006-1028" severity="High" type="CVE"><desc><descript source="cve">feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to cause a denial of service (stressed file cache) by creating many files via filenames in the feed parameter to index.php.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426538/100/0/threaded">20060302 JOOMLA CMS 1.0.7 DoS &amp; path disclosing</ref><ref patch="1" source="joomla.org" url="http://www.joomla.org/content/view/938/78/">1.0.8 Changelog </ref><ref source="SECUNIA" url="http://secunia.com/advisories/19105">19105</ref><ref source="OSVDB" url="http://www.osvdb.org/23817">23817</ref><ref source="SREASON" url="http://securityreason.com/securityalert/527">527</ref></refs><vuln_soft><prod name="Joomla" vendor="Joomla"><vers num="1.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1029" published="2006-03-06" seq="2006-1029" severity="Medium" type="CVE"><desc><descript source="cve">The cross-site scripting (XSS) countermeasures in class.inputfilter.php in Joomla! 1.0.7 allow remote attackers to cause a denial of service via a crafted mosmsg parameter to index.php with a malformed sequence of multiple tags, as demonstrated using &quot;&lt;&lt;&gt;AAA&lt;&gt;&lt;&gt;&quot;, possibly due to nested or empty tags.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426538/100/0/threaded">20060302 JOOMLA CMS 1.0.7 DoS &amp; path disclosing</ref><ref source="joomla.org" url="http://www.joomla.org/content/view/938/78/">1.0.8 Changelog  </ref><ref source="OSVDB" url="http://www.osvdb.org/23816">23816</ref></refs><vuln_soft><prod name="Joomla" vendor="Joomla"><vers num="1.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-07" name="CVE-2006-1030" published="2006-03-06" seq="2006-1030" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in mod_templatechooser in Joomla! 1.0.7 allows remote attackers to obtain sensitive information via an unspecified attack vector that reveals the path.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="joomla.org" url="http://www.joomla.org/content/view/938/78/">1.0.8 Changelog  </ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0818">ADV-2006-0818</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19105">19105</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25028">joomla-multiple-disclose-path(25028)</ref><ref source="OSVDB" url="http://www.osvdb.org/23818">23818</ref></refs><vuln_soft><prod name="Joomla" vendor="Joomla"><vers num="1.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2006-1031" published="2006-03-07" seq="2006-1031" severity="High" type="CVE"><desc><descript source="cve">config/config_inc.php in iGENUS Webmail 2.02 and earlier allows remote attackers to include arbitrary local files via the SG_HOME parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://retrogod.altervista.org/igenus_202_xpl_pl.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0753">ADV-2006-0753</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19036">19036</ref><ref source="OSVDB" url="http://www.osvdb.org/23530">23530</ref><ref source="BID" url="http://www.securityfocus.com/bid/16829">16829</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24935">igenus-sg-home-file-include(24935)</ref></refs><vuln_soft><prod name="iGENUS Webmail" vendor="iGENUS"><vers num="2.02"/><vers num="2.01"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1032" published="2006-03-07" seq="2006-1032" severity="High" type="CVE"><desc><descript source="cve">Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, exoops, and possibly other programs, allows remote attackers to execute arbitrary PHP code via the base64 tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/426193">20060226 phpRPC Library Remote Code Execution</ref><ref adv="1" source="" url="http://www.gulftech.org/?node=research&amp;article_id=00105-02262006"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16833">16833</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015691">1015691</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19028">19028</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19058">19058</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0745">
ADV-2006-0745</ref><ref source="SREASON" url="http://securityreason.com/securityalert/502">502</ref></refs><vuln_soft><prod name="phpRPC" vendor="phpRPC"><vers num="0.9"/><vers num="0.8"/><vers num="0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1033" published="2006-03-07" seq="2006-1033" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) uname, (2) error, (3) profile or (4) the username filed parameter to the (a) Your_Account module, (5) catid, (6) sid, (7) Story Text or (8) Extended text text fields in the (b) News module, (9) month, (10) year or (11) sa parameter to the (c) Stories_Archive module, (12) show, (13) cid, (14) ratetype, or (15) orderby parameter to the (d) Web_Links module, (16) op, or (17) pollid parameter to the (e) Surveys module, (18) c parameter to the (f) Downloads module, (19) meta, or (20) album parameter to the (g) coppermine module, or the search box in the (21) Search, (22) Stories_Archive, (23) Downloads, and (24) Topics module.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://lostmon.blogspot.com/2006/02/multiple-cross-site-scripting-in.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16784">16784</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0688">ADV-2006-0688</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015661">1015661</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18940">18940</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24843">
cpg-dragonfly-multiple-xss(24843)</ref></refs><vuln_soft><prod name="Dragonfly CMS" vendor="CPG-Nuke"><vers num="9.0.6.0"/><vers num="9.0.5.0"/><vers num="9.0.4.0"/><vers num="9.0.3.0"/><vers num="9.0.2.0"/><vers num="9.0.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1034" published="2006-03-07" seq="2006-1034" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning Board (wBB) allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to galerie_index.php and possibly (2) galerie_onfly.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. The second vector might not be XSS.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16843">16843</ref></refs><vuln_soft><prod name="Burning Board" vendor="Woltlab"><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3.3"/><vers num="2.3.1"/><vers num="2.2.2"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta 5"/><vers num="2.0 Beta 4"/><vers num="2.0 Beta 3"/><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1035" published="2006-03-07" seq="2006-1035" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers to access diagnostics tests via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-OracleDiag0206.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16844">16844</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/298958">VU#298958</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19076">19076</ref></refs><vuln_soft><prod name="Diagnostics" vendor="Oracle"><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.10 CU2"/><vers num="11i 11.5.10 CU1"/><vers num="11i 11.5.10"/><vers num="11i 11.5.9"/><vers num="11i 11.5.8"/><vers num="11i 11.5.7"/><vers num="11i 11.5.6"/><vers num="11i 11.5.5"/><vers num="11i 11.5.4"/><vers num="11i 11.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1036" published="2006-03-07" seq="2006-1036" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in the Oracle Diagnostics module 2.2 and earlier have unknown impact and attack vectors, related to &quot;permissions.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="integrigy.com" url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-OracleDiag0206.pdf">SecurityAnalysis-OracleDiag0206</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16844">16844</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19076">19076</ref></refs><vuln_soft><prod name="Diagnostics" vendor="Oracle"><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1037" published="2006-03-07" seq="2006-1037" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via uknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-OracleDiag0206.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16844">16844</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19076">19076</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25259">
oracle-diagnostics-sql-injection(25259)</ref></refs><vuln_soft><prod name="Diagnostics" vendor="Oracle"><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.10 CU2"/><vers num="11i 11.5.10 CU1"/><vers num="11i 11.5.10"/><vers num="11i 11.5.9"/><vers num="11i 11.5.8"/><vers num="11i 11.5.7"/><vers num="11i 11.5.6"/><vers num="11i 11.5.5"/><vers num="11i 11.5.4"/><vers num="11i 11.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1038" published="2006-03-07" seq="2006-1038" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SecureCRT 5.0.4 and earlier and SecureFX 3.0.4 and earlier allows remote attackers to have an unknown impact when a Unicode string is converted to a &quot;narrow&quot; string.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.vandyke.com/products/securecrt/history.txt"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0806">ADV-2006-0806</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19040">19040</ref><ref source="" url="http://www.vandyke.com/products/securefx/history.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16935">16935</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25092">
securecrt-securefx-string-bo(25092)</ref></refs><vuln_soft><prod name="SecureFX" vendor="Van Dyke Technologies"><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/><vers num="3.0 Beta 7"/><vers num="3.0 Beta 6"/><vers num="3.0 Beta 5"/><vers num="3.0 Beta 4"/><vers num="3.0 Beta 3"/><vers num="3.0 Beta 2"/><vers num="3.0 Beta 1"/></prod><prod name="SecureCRT" vendor="Van Dyke Technologies"><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0"/><vers num="5.0 Beta 6"/><vers num="5.0 Beta 5"/><vers num="5.0 Beta 4"/><vers num="5.0 Beta 3"/><vers num="5.0 Beta 2"/><vers num="5.0 Beta 1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2006-1039" published="2006-03-07" seq="2006-1039" severity="Medium" type="CVE"><desc><descript source="cve">SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive authentication information, or have other impacts, via a &quot;;%20&quot; followed by encoded HTTP headers.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426449/100/0/threaded">20060301 SAP Web Application Server http request url parsing vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0810">ADV-2006-0810</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19085">19085</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015702">1015702</ref><ref source="BID" url="http://www.securityfocus.com/bid/18006">18006</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25003">sap-was-url-obtain-information(25003)</ref></refs><vuln_soft><prod name="SAP Web Application Server" vendor="SAP"><vers num="6.40"/><vers num="6.20"/><vers num="6.10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-1040" published="2006-03-07" seq="2006-1040" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in vBulletin 3.0.12 and 3.5.3 allows remote attackers to inject arbitrary web script or HTML via the email field, which is injected in profile.php but not sanitized in sendmsg.php.</descript></desc><sols><sol source="nvd">This vulnerability affects all versions of Jelsoft, vBulletin between 3.0.12 and 3.5.3</sol></sols><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426537/100/0/threaded">20060302 [KAPDA::#26]vBulletin.3.5.3~3.0.12-XSS</ref><ref adv="1" patch="1" source="Kapda" url="http://www.kapda.ir/advisory-266.html">vBulletin 3.0.12-3.5.3 Cross_Site_Scripting</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426589/100/0/threaded">20060302 vBulletin3.0.12&amp;3.5.3~is_valid_email()~XSS Attack</ref><ref source="" url="http://www.vbulletin.com/forum/showthread.php?postid=1079030"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0808">ADV-2006-0808</ref><ref source="OSVDB" url="http://www.osvdb.org/23614">23614</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19100">19100</ref><ref source="BID" url="http://www.securityfocus.com/bid/16919">16919</ref></refs><vuln_soft><prod name="vBulletin" vendor="Jelsoft"><vers num="3.5.3"/><vers num="3.0.12"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1041" published="2006-03-07" seq="2006-1041" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Gregarius 0.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) rss_query parameter to search.php or (2) tag parameter to tags.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426656/100/0/threaded">20060303 Gregarius 0.5.2 XSS and SQL Injection Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16939">16939</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0819">ADV-2006-0819</ref><ref source="OSVDB" url="http://www.osvdb.org/23678">23678</ref><ref source="OSVDB" url="http://www.osvdb.org/23679">23679</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19102">19102</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25058">gregarius-multiple-xss(25058)</ref></refs><vuln_soft><prod name="Gregarius" vendor="Gregarius"><vers num="0.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1042" published="2006-03-07" seq="2006-1042" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Gregarius 0.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) folder parameter to feed.php or (2) rss_query parameter to search.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426656/100/0/threaded">20060303 Gregarius 0.5.2 XSS and SQL Injection Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16939">16939</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0819">ADV-2006-0819</ref><ref source="OSVDB" url="http://www.osvdb.org/23680">23680</ref><ref source="OSVDB" url="http://www.osvdb.org/23681">23681</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19102">19102</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25059">gregarius-feed-sql-injection(25059)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/537">537</ref></refs><vuln_soft><prod name="Gregarius" vendor="Gregarius"><vers num="0.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-1043" published="2006-03-07" seq="2006-1043" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Microsoft Visual Studio 6.0 and Microsoft Visual InterDev 6.0 allows user-assisted attackers to execute arbitrary code via a long DataProject field in a (1) Visual Studio Database Project File (.dbp) or (2) Visual Studio Solution (.sln).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426767/100/0/threaded">20060304 Visual Studio 6.0 Buffer Overflow Vulnerability</ref><ref source="frsirt.com" url="http://www.frsirt.com/exploits/20060305.ms-visual-dbp.c.php">Microsoft Visual Studio &apos;dbp&apos; File Handling Buffer Overflow Proof of Concept Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/16953">16953</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0825">ADV-2006-0825</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1015721">1015721</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426830/100/0/threaded">20060305 Microsoft Visual Studio 6.0 Sp6 Malformed .dbp File BoF Exploit</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19081">19081</ref><ref source="OSVDB" url="http://www.osvdb.org/23711">23711</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25148">visualstudio-dataproject-bo(25148)</ref></refs><vuln_soft><prod name="Visual Studio" vendor="Microsoft"><vers num="6.0 SP5"/><vers num="6.0 SP4"/><vers num="6.0 SP3"/><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/></prod><prod name="Visual InterDev" vendor="Microsoft"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1044" published="2006-03-07" seq="2006-1044" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via unknown attack vectors related to the WA CGI.  NOTE: technical details will be released after the grace period has ended on 20060603.</descript></desc><sols><sol source="nvd">This vulnerability affects L-Soft, Listserv (LITE and HPO) 14.4 and all prior versions that are installed with the web archive interface.</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426770/100/0/threaded">20060304 Critical Risk Vulnerability in L-Soft Listserv</ref><ref patch="1" source="lsoft.com" url="http://www.lsoft.com/manuals/1.8e/relnotes/LISTSERV14.5-Release-Notes.html#wasecurityalert">WA Security Alert</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16951">16951</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0824">ADV-2006-0824</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015722">1015722</ref><ref source="" url="http://www.ngssoftware.com/advisories/listserv_3.txt"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/841132">VU#841132</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19106">19106</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25168">
listserv-wa-cgi-bo(25168)</ref></refs><vuln_soft><prod name="Listserv" vendor="L-Soft"><vers num="14.4"/><vers num="14.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1045" published="2006-03-07" seq="2006-1045" severity="Low" type="CVE"><desc><descript source="cve">The HTML rendering engine in Mozilla Thunderbird 1.5, when &quot;Block loading of remote images in mail messages&quot; is enabled, does not properly block external images from inline HTML attachments, which could allow remote attackers to obtain sensitive information, such as application version or IP address, when the user reads the email and the external image is accessed.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/426347">20060228 Mozilla Thunderbird : Multiple Information Disclosure Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16881">16881</ref><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-26.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">GLSA-200605-09</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1975">oval:org.mitre.oval:def:1975</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">
20051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24959">
thunderbird-inline-information-disclosure(24959)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref><ref source="SREASON" url="http://securityreason.com/securityalert/514">514</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-16" name="CVE-2006-1046" published="2006-03-07" seq="2006-1046" severity="Medium" type="CVE"><desc><descript source="cve">server.cpp in Monopd 0.9.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a string containing a large number of characters that are escaped when Monopd produces XML output.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://aluigi.altervista.org/adv/monopdx-adv.txt"></ref><ref source="" url="http://www.robertjohnkaper.com/downloads/atlantik/monopd-0.9.3-dosfix.diff"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0844">ADV-2006-0844</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19133">19133</ref><ref source="BID" url="http://www.securityfocus.com/bid/16981">16981</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25161">
monopd-string-dos(25161)</ref></refs><vuln_soft><prod name="Monopd" vendor="Monopd"><vers num="0.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1047" published="2006-03-07" seq="2006-1047" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the &quot;Remember Me login functionality&quot; in Joomla! 1.0.7 and earlier has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://www.joomla.org/content/view/938/78/"></ref></refs><vuln_soft><prod name="Joomla" vendor="Joomla"><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1048" published="2006-03-07" seq="2006-1048" severity="Medium" type="CVE"><desc><descript source="cve">Joomla! 1.0.7 and earlier allows attackers to bypass intended access restrictions and gain certain privileges via certain attack vectors related to the (1) Weblink, (2) Polls, (3) Newsfeeds, (4) Weblinks, (5) Content, (6) Content Section, (7) Content Category, (8) Contact items, or (9) Contact Search, (10) Content Search, (11) Newsfeed Search, or (12) Weblink Search.</descript></desc><sols><sol source="nvd">This vulnerability affects Joomla! versions 1.0.7 and previous.</sol></sols><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="joomla.org" url="http://www.joomla.org/content/view/938/78/">1.0.8 Changelog </ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0818">ADV-2006-0818</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19105">19105</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25033">joomla-multiple-bypass-security(25033)</ref><ref source="OSVDB" url="http://www.osvdb.org/23822">
23822</ref></refs><vuln_soft><prod name="Joomla" vendor="Joomla"><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1049" published="2006-03-07" seq="2006-1049" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in the Admin functionality in Joomla! 1.0.7 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.joomla.org/content/view/938/78/"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0818">ADV-2006-0818</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19105">19105</ref><ref source="OSVDB" url="http://www.osvdb.org/23819">23819</ref></refs><vuln_soft><prod name="Joomla" vendor="Joomla"><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2006-1050" published="2006-03-07" seq="2006-1050" severity="Low" type="CVE"><desc><descript source="cve">** DISPUTED **  Kwik-Pay Payroll 4.2.20, and possibly other versions, stores the KwikPay.mdb database file with insecure permissions, which allows local users to obtain sensitive information such as employment and payment data.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  NOTE: the vendor has disputed this vulnerability, stating that &quot;The kwikpay.mdb file supplied with kwikpay is a template for the database structure of user databases created by kwikpay and to store a demonstration payroll. It does not contain any sensitive user information.  When a user payroll database is opened, the encryption of the database is checked and if the database is not encrypted, the user is prompted to encrypt the database, but the choice is the customers.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/23617">23617</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19075">19075</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25114">kwikpay-payroll-insecure-permissions(25114)</ref></refs><vuln_soft><prod name="Kwik-Pay Payroll" vendor="Kwik-Pay"><vers num="4.2.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1051" published="2006-03-07" seq="2006-1051" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Akarru Social BookMarking Engine before 0.4.3.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors, possibly involving the username parameter to akarru.lib/users.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=398713&amp;group_id=155783"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16989">16989</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0841">ADV-2006-0841</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19112">19112</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25115">
akarru-users-sql-injection(25115)</ref></refs><vuln_soft><prod name="Social BookMarking Engine" vendor="Akarru"><vers num="0.4.3.3"/><vers num="0.4.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-11" modified="2006-05-05" name="CVE-2006-1052" published="2006-05-05" seq="2006-1052" severity="Low" type="CVE"><desc><descript source="cve">The selinux_ptrace logic in hooks.c in SELinux for Linux 2.6.6 allows local users with ptrace permissions to change the tracer SID to an SID of another process.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="MLIST" url="http://marc.theaimsgroup.com/?l=selinux&amp;m=114226465106131&amp;w=2">[selinux] 20060313 [SECURITY] SELinux ptrace bug (CVE-2006-1052)</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=git-commits-head&amp;m=114210002712363&amp;w=2">[git-commits-head] 20060311 [PATCH] selinux: tracer SID fix</ref><ref source="" url="http://selinuxnews.org/wp/index.php/2006/03/13/security-ptrace-bug-cve-2006-1052/"></ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-281-1">USN-281-1</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17830">17830</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19955">19955</ref><ref source="OSVDB" url="http://www.osvdb.org/25232">25232</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:086">MDKSA-2006:086</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20157">20157</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0575.html">RHSA-2006:0575</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21465">21465</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1184">DSA-1184</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22093">22093</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/22417">22417</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:086">MDKSA-2006:086</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.9 rc4"/><vers num="2.6.9 rc3"/><vers num="2.6.9 rc2"/><vers num="2.6.9 rc1"/><vers num="2.6.9 final"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8 rc4"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers edition="PowerPC_smp" num="2.6.8.1.5"/><vers edition="PowerPC" num="2.6.8.1.5"/><vers edition="Power4_smp" num="2.6.8.1.5"/><vers edition="Power4" num="2.6.8.1.5"/><vers edition="Power3_smp" num="2.6.8.1.5"/><vers edition="Power3" num="2.6.8.1.5"/><vers edition="K7_smp" num="2.6.8.1.5"/><vers edition="K7" num="2.6.8.1.5"/><vers edition="AMD64_Xeon" num="2.6.8.1.5"/><vers edition="AMD64_K8_smp" num="2.6.8.1.5"/><vers edition="AMD64_K8" num="2.6.8.1.5"/><vers edition="AMD64" num="2.6.8.1.5"/><vers edition="686_smp" num="2.6.8.1.5"/><vers edition="686" num="2.6.8.1.5"/><vers edition="386" num="2.6.8.1.5"/><vers num="2.6.8.1.5"/><vers num="2.6.8.1"/><vers num="2.6.8"/><vers num="2.6.7 rc3"/><vers num="2.6.7 rc2"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc3"/><vers num="2.6.6 rc2"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.17 rc1"/><vers num="2.6.17"/><vers num="2.6.16 rc7"/><vers num="2.6.16 rc6"/><vers num="2.6.16 rc5"/><vers num="2.6.16 rc4"/><vers num="2.6.16 rc3"/><vers num="2.6.16 rc2"/><vers num="2.6.16 rc1"/><vers num="2.6.16.8"/><vers num="2.6.16.7"/><vers num="2.6.16.4"/><vers num="2.6.16.3"/><vers num="2.6.16.2"/><vers num="2.6.16.12"/><vers num="2.6.16.1"/><vers num="2.6.16"/><vers num="2.6.15 rc7"/><vers num="2.6.15 rc6"/><vers num="2.6.15 rc5"/><vers num="2.6.15 rc4"/><vers num="2.6.15 rc3"/><vers num="2.6.14 rc2"/><vers num="2.6.15 rc1"/><vers num="2.6.15.7"/><vers num="2.6.15.6"/><vers num="2.6.15.5"/><vers num="2.6.15.4"/><vers num="2.6.15.3"/><vers num="2.6.15.2"/><vers num="2.6.15.1"/><vers num="2.6.15 rc2"/><vers num="2.6.15"/><vers num="2.6.14 rc5"/><vers num="2.6.14 rc4"/><vers num="2.6.14 rc3"/><vers num="2.6.14 rc1"/><vers num="2.6.14.7"/><vers num="2.6.14.6"/><vers num="2.6.14.5"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14"/><vers num="2.6.13 rc7"/><vers num="2.6.13 rc6"/><vers num="2.6.13 rc5"/><vers num="2.6.13 rc4"/><vers num="2.6.13 rc3"/><vers num="2.6.13 rc2"/><vers num="2.6.13 rc1"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13"/><vers num="2.6.12 rc6"/><vers num="2.6.12 rc5"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc3"/><vers num="2.6.12 rc2"/><vers num="2.6.12 rc1"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12"/><vers num="2.6.11 rc5"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11 rc1"/><vers num="2.6.11.9"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11.10"/><vers num="2.6.11.1"/><vers edition="x86_64" num="2.6.11"/><vers num="2.6.11"/><vers num="2.6.10 rc3"/><vers num="2.6.10 rc2"/><vers num="2.6.10 rc1"/><vers num="2.6.10"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.0"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers edition="Itanium IA64 Montecito" num="2.6"/><vers edition="64-bit x86" num="2.6"/><vers num="2.6"/></prod></vuln_soft></entry><entry modified="2006-05-30" name="CVE-2006-1054" published="2006-05-26" reject="1" seq="2006-1054" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-1861.  Reason: This candidate is a reservation duplicate of CVE-2006-1861.  Notes: All CVE users should reference CVE-2006-1861 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-05" name="CVE-2006-1055" published="2006-04-05" seq="2006-1055" severity="Medium" type="CVE"><desc><descript source="cve">The fill_write_buffer function in sysfs/file.c in Linux kernel 2.6.12 up to versions before 2.6.17-rc1 does not zero terminate a buffer when a length of PAGE_SIZE or more is requested, which might allow local users to cause a denial of service (crash) by causing an out-of-bounds read.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="Kernel.org" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=6e0dd741a89be35defa05bd79f4211c5a2762825"></ref><ref patch="1" source="Kernel.org" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=6e0dd741a89be35defa05bd79f4211c5a2762825;hp=597a7679dd83691be2f3a53e1f3f915b4a7f6eba"></ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0020">2006-0020</ref><ref source="BID" url="http://www.securityfocus.com/bid/17402">17402</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1273">ADV-2006-1273</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19495">19495</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-281-1">USN-281-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19955">19955</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-302-1">USN-302-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20716">20716</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref><ref source="FEDORA" url="http://lwn.net/Alerts/180820/">
FEDORA-2006-423</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1475">
ADV-2006-1475</ref><ref source="OSVDB" url="http://www.osvdb.org/24443">
24443</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19735">
19735</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25693">
linux-fillwritebuffer-dos(25693)</ref></refs><vuln_soft><prod name="Linux Kernel" vendor="Linux"><vers num="2.6.17"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.16-rc1"/><vers num="2.6.15-rc7"/><vers num="2.6.15-rc6"/><vers num="2.6.15-rc5"/><vers num="2.6.15-rc4"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.15.5"/><vers num="2.6.15.4"/><vers num="2.6.15.3"/><vers num="2.6.15.2"/><vers num="2.6.15.1"/><vers num="2.6.15"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.14.5"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14"/><vers num="2.6.13-rc7"/><vers num="2.6.13-rc6"/><vers num="2.6.13-rc4"/><vers num="2.6.13-rc1"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13"/><vers num="2.6.12-rc5"/><vers num="2.6.12-rc4"/><vers num="2.6.12-rc1"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1056" published="2006-04-20" seq="2006-1056" severity="Low" type="CVE"><desc><descript source="cve">The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one process to determine portions of the state of floating point instructions of other processes, which can be leveraged to obtain sensitive information such as cryptographic keys.  NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processers in a security-relevant fashion that was not addressed by the kernels.</descript></desc><sols><sol source="nvd">Upgrade to Linux Kernel version 2.6.16.9 :
http://www.kernel.org/</sol></sols><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:14.fpu.asc">FreeBSD-SA-06:14</ref><ref source="" url="http://security.freebsd.org/advisories/FreeBSD-SA-06:14-amd.txt"></ref><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.9"></ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=187910"></ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=114548768214478&amp;w=2">[linux-kernel] 20060419 RE: Linux 2.6.16.9</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1426">ADV-2006-1426</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19724">19724</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19715">19715</ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=187911"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17600">17600</ref><ref source="OSVDB" url="http://www.osvdb.org/24807">24807</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015966">1015966</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25871">amd-fpu-information-disclosure(25871)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1097">DSA-1097</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20671">20671</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-302-1">USN-302-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20716">20716</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0579.html">RHSA-2006:0579</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21035">21035</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0437.html">RHSA-2006:0437</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21136">21136</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0575.html">RHSA-2006:0575</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21465">21465</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21983">21983</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/22417">22417</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451404/100/0/threaded">20061113 VMSA-2006-0006 - VMware ESX Server 2.5.3 Upgrade Patch 4</ref><ref source="" url="http://kb.vmware.com/kb/2533126"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4353">ADV-2006-4353</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451419/100/200/threaded">20061113 VMSA-2006-0005 - VMware ESX Server 2.5.4 Upgrade Patch 1</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451417/100/200/threaded">20061113 VMSA-2006-0007 - VMware ESX Server 2.1.3 Upgrade Patch 2</ref><ref source="" url="http://www.vmware.com/download/esx/esx-213-200610-patch.html"></ref><ref source="" url="http://www.vmware.com/download/esx/esx-254-200610-patch.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4502">ADV-2006-4502</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22875">22875</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22876">22876</ref><ref source="FEDORA" url="http://lwn.net/Alerts/180820/">
FEDORA-2006-423</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1475">
ADV-2006-1475</ref><ref source="OSVDB" url="http://www.osvdb.org/24746">
24746</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19735">
19735</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451421/100/0/threaded">20061113 VMSA-2006-0009 - VMware ESX Server 3.0.0 AMD fxsave/restore issue</ref></refs><vuln_soft><prod name="Linux Kernel" vendor="Linux"><vers num="2.6.16.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-05" name="CVE-2006-1057" published="2006-04-24" seq="2006-1057" severity="Low" type="CVE"><desc><descript source="cve">Race condition in daemon/slave.c in gdm before 2.14.1 allows local users to gain privileges via a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=188303"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1040">DSA-1040</ref><ref patch="1" source="FEDORA" url="https://www.redhat.com/archives/fedora-announce-list/2006-April/msg00160.html">FEDORA-2006-338</ref><ref source="" url="http://cvs.gnome.org/viewcvs/gdm2/daemon/slave.c?r1=1.260&amp;r2=1.261"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17635">17635</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1465">ADV-2006-1465</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-278-1">USN-278-1</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:083">MDKSA-2006:083</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26092">
gdm-slavec-symlink(26092)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0286.html">
RHSA-2007:0286</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:083">MDKSA-2006:083</ref></refs><vuln_soft><prod name="GDM" vendor="GNOME"><vers num="2.14"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-04" name="CVE-2006-1058" published="2006-04-04" seq="2006-1058" severity="Low" type="CVE"><desc><descript source="cve">BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://bugs.busybox.net/view.php?id=604"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17330">17330</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19477">19477</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25569">busybox-passwd-weak-security(25569)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0244.html">
RHSA-2007:0244</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25098">
25098</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-250.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/25848">25848</ref></refs><vuln_soft><prod name="BusyBox" vendor="BusyBox"><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-26" name="CVE-2006-1059" published="2006-03-30" seq="2006-1059" severity="Low" type="CVE"><desc><descript source="cve">The winbindd daemon in Samba 3.0.21 to 3.0.21c writes the machine trust account password in cleartext in log files, which allows local users to obtain the password and spoof the server in the domain.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429370/100/0/threaded">20060330 [SECURITY] Samba 3.0.21-3.0.21c: Exposure of machine account credentials in winbindd log files</ref><ref patch="1" source="" url="http://us1.samba.org/samba/security/CAN-2006-1059.html"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19455">19455</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00114.html">FEDORA-2006-259</ref><ref source="BID" url="http://www.securityfocus.com/bid/17314">17314</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1179">ADV-2006-1179</ref><ref source="OSVDB" url="http://www.osvdb.org/24263">24263</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015850">1015850</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19468">19468</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25575">samba-logfile-account-cleartext(25575)</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0018">2006-0018</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19539">19539</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="3.0.21"/><vers num="3.0.21a"/><vers num="3.0.21b"/><vers num="3.0.21c"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-1060" published="2006-04-11" seq="2006-1060" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in zgv before 5.8 and xzgv before 0.8 might allow user-assisted attackers to execute arbitrary code via a JPEG image with more than 3 output components, such as a CMYK or YCCK color space, which causes less memory to be allocated than required.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_08_sr.html">SUSE-SR:2006:008</ref><ref source="BID" url="http://www.securityfocus.com/bid/17409">17409</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1288">ADV-2006-1288</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19572">19572</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19571">19571</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1037">DSA-1037</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1038">DSA-1038</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19731">19731</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19757">19757</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19779">19779</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19790">19790</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25718">
xzgv-jpeg-bo(25718)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/756">756</ref></refs><vuln_soft><prod name="xzgv" vendor="xzgv"><vers num="0.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1061" published="2006-03-20" seq="2006-1061" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in cURL and libcURL 7.15.0 through 7.15.2 allows remote attackers to execute arbitrary commands via a TFTP URL (tftp://) with a valid hostname and a long path.</descript></desc><sols><sol source="nvd">Update to version 7.15.3.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://curl.haxx.se/docs/adv_20060320.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1008">ADV-2006-1008</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19271">19271</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1326.html">20060320 [SSAG#001] :: cURL tftp:// URL Buffer Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/17154">17154</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25318">curl-tftp-bo(25318)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00048.html">FEDORA-2006-189</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-19.xml">GLSA-200603-19</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0016">2006-0016</ref><ref source="OSVDB" url="http://www.osvdb.org/23982">23982</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19335">19335</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19344">19344</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19371">19371</ref></refs><vuln_soft><prod name="curl" vendor="Daniel Stenberg"><vers num="7.15.0"/><vers num="7.15.1"/><vers num="7.15.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1062" published="2006-03-07" seq="2006-1062" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in lurker.cgi for Lurker 2.0 and earlier allows attackers to read arbitrary files via unknown vectors.</descript></desc><sols><sol source="nvd">This vulnerability affects all versions of Lurker from 0.1a through 0.2</sol></sols><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MLIST" url="http://terpstra.ca/lurker/message/20060302.130003.4c5c2680.en.html">[Lurker-users] 20060302 Serious security vulnerabilities found</ref><ref patch="1" source="sourceforge.net" url="http://sourceforge.net/project/shownotes.php?release_id=399034&amp;group_id=8168">Release Name: 2.1</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0850">ADV-2006-0850</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19136">19136</ref><ref source="OSVDB" url="http://www.osvdb.org/23694">23694</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-999">DSA-999</ref><ref source="BID" url="http://www.securityfocus.com/bid/17003">17003</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19145">19145</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25149">
lurker-lurker-information-disclosure(25149)</ref></refs><vuln_soft><prod name="Lurker" vendor="Lurker"><vers num="0.1a"/><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1063" published="2006-03-07" seq="2006-1063" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Lurker 2.0 and earlier allows remote attackers to create or overwrite files in any writable directory that is named &quot;mbox&quot;.</descript></desc><sols><sol source="nvd">This vulnarability affects all verions of Lurker from 0.1a through 0.2
</sol></sols><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" source="MLIST" url="http://terpstra.ca/lurker/message/20060302.130003.4c5c2680.en.html">[Lurker-users] 20060302 Serious security vulnerabilities found</ref><ref patch="1" source="sourceforge.net" url="http://sourceforge.net/project/shownotes.php?release_id=399034&amp;group_id=8168">Release Name: 2.1</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0850">ADV-2006-0850</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19136">19136</ref><ref source="OSVDB" url="http://www.osvdb.org/23695">23695</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-999">DSA-999</ref><ref source="BID" url="http://www.securityfocus.com/bid/17003">17003</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19145">19145</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25153">
lurker-mbox-error(25153)</ref></refs><vuln_soft><prod name="Lurker" vendor="Lurker"><vers num="0.1a"/><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1064" published="2006-03-07" seq="2006-1064" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Lurker 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript></desc><sols><sol source="nvd">This vulnerability affects all verions of Lurker from 0.1a through 2.0</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="MLIST" url="http://terpstra.ca/lurker/message/20060302.130003.4c5c2680.en.html">[Lurker-users] 20060302 Serious security vulnerabilities found</ref><ref patch="1" source="sourceforge.net" url="http://sourceforge.net/project/shownotes.php?release_id=399034&amp;group_id=8168">Release Name: 2.1</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0850">ADV-2006-0850</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19136">19136</ref><ref source="OSVDB" url="http://www.osvdb.org/23696">23696</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-999">DSA-999</ref><ref source="BID" url="http://www.securityfocus.com/bid/17003">17003</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19145">19145</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25154">
lurker-unspecified-xss(25154)</ref></refs><vuln_soft><prod name="Lurker" vendor="Lurker"><vers num="0.1a"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-08" name="CVE-2006-1065" published="2006-03-07" seq="2006-1065" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in search.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to execute arbitrary SQL commands via the forums[] parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426631/100/0/threaded">20060302 MyBB 1.0.4 New SQL Injection</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19061">19061</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25018">mybb-search-sql-injection(25018)</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.04"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1066" published="2006-03-26" seq="2006-1066" severity="Low" type="CVE"><desc><descript source="cve">Linux kernel 2.6.16-rc2 and earlier, when running on x86_64 systems with preemption enabled, allows local users to cause a denial of service (oops) via multiple ptrace tasks that perform single steps, which can cause corruption of the DEBUG_STACK stack during the do_debug function call.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1017">DSA-1017</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113932292516359&amp;w=2">[linux-kernel] 20060207 [PATCH] arch/x86_64/kernel/traps.c PTRACE_SINGLESTEP oops</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17216">17216</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/24098">24098</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19374">19374</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113932292516359&amp;w=2">[linux-kernel] 20060207 [PATCH] arch/x86_64/kernel/traps.c PTRACE_SINGLESTEP oops</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-281-1">USN-281-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19955">19955</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:151">MDKSA-2006:151</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21614">21614</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:151">MDKSA-2006:151</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.15.4"/><vers num="2.6.15.1"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.15"/><vers num="2.6.14.5"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.14"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13-rc7"/><vers num="2.6.13-rc6"/><vers num="2.6.13-rc4"/><vers num="2.6.13-rc1"/><vers num="2.6.13"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12-rc5"/><vers num="2.6.12-rc4"/><vers num="2.6.12-rc1"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11rc4"/><vers num="2.6.11-rc3"/><vers num="2.6.11-rc2"/><vers num="2.6.11"/><vers num="2.6.10-rc2"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1-rc2"/><vers num="2.6.1-rc1"/><vers num="2.6.1"/><vers num="2.6 test 9 CVS"/><vers num="2.6-test9"/><vers num="2.6-test8"/><vers num="2.6-test7"/><vers num="2.6-test6"/><vers num="2.6-test5"/><vers num="2.6-test4"/><vers num="2.6-test3"/><vers num="2.6-test2"/><vers num="2.6-test11"/><vers num="2.6-test10"/><vers num="2.6-test1"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1067" published="2006-03-07" seq="2006-1067" severity="Medium" type="CVE"><desc><descript source="cve">Linksys WRT54G routers version 5 (running VXWorks) allow remote attackers to cause a denial of service by sending a malformed DCC SEND string to an IRC channel, which causes an IRC connection reset, possibly related to the masquerading code for NAT environments, and as demonstrated via (1) a DCC SEND with a single long argument, or (2) a DCC SEND with IP, port, and filesize arguments with a 0 value.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426761/100/0/threaded">20060303 linksys router + irc DoS</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/426863/100/0/threaded">20060306 Re: linksys router + irc DoS</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426934/100/0/threaded">20060306 RE: linksys router + irc DoS</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426756/100/0/threaded">20060304 Various router DoS</ref><ref source="" url="http://www.hm2k.org/news/1141413208.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16954">
16954</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25230">
multiple-vendor-dccsend-dos(25230)</ref></refs><vuln_soft><prod name="WRT54G" vendor="Linksys"><vers num="5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1068" published="2006-03-07" seq="2006-1068" severity="Medium" type="CVE"><desc><descript source="cve">Netgear 614 and 624 routers, possibly running VXWorks, allow remote attackers to cause a denial of service by sending a malformed DCC SEND string to an IRC channel, which causes an IRC connection reset, possibly related to the masquerading code for NAT environments, and as demonstrated via (1) a DCC SEND with a single long argument, or (2) a DCC SEND with IP, port, and filesize arguments with a 0 value.</descript></desc><sols><sol source="nvd">This vulnerability may affects NetGear Router models 614 and 624 (including WGR614, WGT624, WGT624SC, WGU624, and possibly others) and is most likely related to VXWorks.</sol></sols><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426761/100/0/threaded">20060303 linksys router + irc DoS</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/426863/100/0/threaded">20060306 Re: linksys router + irc DoS</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426934/100/0/threaded">20060306 RE: linksys router + irc DoS</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426756/100/0/threaded">20060304 Various router DoS</ref><ref source="hm2k.org" url="http://www.hm2k.org/news/1141413208.html">yet another irc related bug - netgear edition</ref><ref source="BID" url="http://www.securityfocus.com/bid/16954">
16954</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25230">
multiple-vendor-dccsend-dos(25230)</ref></refs><vuln_soft><prod name="NetGear Router" vendor="NetGear"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1069" published="2006-03-07" seq="2006-1069" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the session handling for Geeklog 1.4.x before 1.4.0sr2, 1.3.11 before 1.3.11sr5, 1.3.9 before 1.3.9sr5, and possibly earlier versions allows attackers to gain privileges as arbitrary users via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.geeklog.net/article.php/geeklog-1.4.0sr2"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0851">ADV-2006-0851</ref><ref source="BID" url="http://www.securityfocus.com/bid/17010">17010</ref></refs><vuln_soft><prod name="Geeklog" vendor="Geeklog"><vers num="1.4.0 sr1"/><vers num="1.4.0"/><vers num="1.3.11 sr4"/><vers num="1.3.11 sr3"/><vers num="1.3.11 sr2"/><vers num="1.3.11 sr1"/><vers num="1.3.11"/><vers num="1.3.9 sr4"/><vers num="1.3.9 sr3"/><vers num="1.3.9 sr2"/><vers num="1.3.9 sr1"/><vers num="1.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1070" published="2006-03-07" seq="2006-1070" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in dv_gbook.php in DVguestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the f parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://biyosecurity.be/bugs/dvguestbook.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16968">16968</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0842">ADV-2006-0842</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19098">19098</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25049">dvguestbook-index-dvgbook-xss(25049)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427214/100/0/threaded">20060309 DVguestbook 1.0 And 1.2.2 Cross Site Scripting</ref></refs><vuln_soft><prod name="DVGuestbook" vendor="DVGuestbook"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1071" published="2006-03-07" seq="2006-1071" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in DVguestbook 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://biyosecurity.be/bugs/dvguestbook.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16968">16968</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0843">ADV-2006-0843</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19099">19099</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25049">dvguestbook-index-dvgbook-xss(25049)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427214/100/0/threaded">20060309 DVguestbook 1.0 And 1.2.2 Cross Site Scripting</ref></refs><vuln_soft><prod name="DVGuestbook" vendor="DVGuestbook"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-11" name="CVE-2006-1072" published="2006-03-07" seq="2006-1072" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Daverave Simplog 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a blog post.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426769/100/0/threaded">20060304 Simplog &lt;= 1.0.2 Vulnerabilities</ref><ref source="" url="http://notlegal.ws/simplogsploit.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16965">16965</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25066">
simplog-post-xss(25066)</ref></refs><vuln_soft><prod name="Simplog" vendor="Simplog"><vers num="1.0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-11" name="CVE-2006-1073" published="2006-03-07" seq="2006-1073" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in Daverave Simplog 1.0.2 and earlier allows remote attackers to include or read arbitrary .txt files via the (1) act and (2) blogid parameters.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426769/100/0/threaded">20060304 Simplog &lt;= 1.0.2 Vulnerabilities</ref><ref source="" url="http://notlegal.ws/simplogsploit.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0839">ADV-2006-0839</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19115">19115</ref><ref source="BID" url="http://www.securityfocus.com/bid/16965">16965</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25067">
simplog-index-traverse-directories(25067)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/542">542</ref></refs><vuln_soft><prod name="Simplog" vendor="Simplog"><vers num="1.0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1074" published="2006-03-08" seq="2006-1074" severity="Medium" type="CVE"><desc><descript source="cve">Jason Boettcher Liero Xtreme 0.62b and earlier allow remote attackers to cause a denial of service (application crash or hang) via a long argument to the connect command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426864/100/0/threaded">20060306 Multiple vulnerabilities in Liero Xtreme 0.62b</ref><ref adv="1" source="" url="http://aluigi.altervista.org/adv/lieroxxx-adv.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0849">ADV-2006-0849</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19079">19079</ref><ref source="BID" url="http://www.securityfocus.com/bid/16992">16992</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25185">
liero-connect-dos(25185)</ref></refs><vuln_soft><prod name="Liero Xtreme" vendor="Jason Boettcher"><vers num="0.62b"/><vers num="0.56b Pack 1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1075" published="2006-03-08" seq="2006-1075" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the visualization function in Jason Boettcher Liero Xtreme 0.62b and earlier allows remote attackers to execute arbitrary code via format string specifiers in (1) a nickname, (2) a dedicated server name, or (3) a mapname in a level (aka .lxl) file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426864/100/0/threaded">20060306 Multiple vulnerabilities in Liero Xtreme 0.62b</ref><ref adv="1" source="" url="http://aluigi.altervista.org/adv/lieroxxx-adv.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0849">ADV-2006-0849</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19079">19079</ref><ref source="BID" url="http://www.securityfocus.com/bid/16990">16990</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25187">
liero-visualization-format-string(25187)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/549">549</ref></refs><vuln_soft><prod name="Liero Xtreme" vendor="Jason Boettcher"><vers num="0.62b"/><vers num="0.56b Pack 1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1076" published="2006-03-08" seq="2006-1076" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execute arbitrary SQL commands via the st parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426875/100/0/threaded">20060306 SQL injection in Invision Power Board v2.1.5</ref><ref source="BID" url="http://www.securityfocus.com/bid/16971">16971</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430357/100/0/threaded">20060405 Re: SQL injection in Invision Power Board v2.1.5</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25254">
invision-index-sql-injection(25254)</ref></refs><vuln_soft><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-1077" published="2006-03-08" seq="2006-1077" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the commentary in Evo-Dev evoBlog allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter and (2) other unspecified parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426826/100/0/threaded">20060306 evoBlog Remote Name tag Script injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/16983">16983</ref><ref source="OSVDB" url="http://www.osvdb.org/23826">23826</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431869/100/0/threaded">20060423 Re: evoBlog Remote Name tag Script injection</ref><ref source="SREASON" url="http://securityreason.com/securityalert/544">544</ref></refs><vuln_soft><prod name="evoBlog" vendor="Evo-Dev"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-03" name="CVE-2006-1078" published="2006-03-08" seq="2006-1078" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file.  NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE.  However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426823/100/0/threaded">20060305 htpasswd bufferoverflow and command execution in thttpd-2.25b.</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=thttpd&amp;m=114153031201867&amp;w=2">[thttpd] 20060305 htpasswd.c security issues</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=thttpd&amp;m=114154083000296&amp;w=2">[thttpd] 20060305 Re: htpasswd.c security issues</ref><ref source="BID" url="http://www.securityfocus.com/bid/16972">16972</ref><ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2004/Oct/0359.html">20041029 Re: local buffer overflow in htpasswd for apache 1.3.31 not fixed in .33?</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0547.html">20040916 FlowSecurity.org: Local Stack Overflow on htpasswd apache 1.3.31 advsory.</ref><ref source="FULLDISC" url="http://www.security-express.com/archives/fulldisclosure/2004-10/1117.html">20041029 Apache 1.3.33 local buffer overflow in apache 1.3.31 not fixed in .33?</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051562.html">20070102 Apache 1.3.37 htpasswd buffer overflow vulnerability</ref><ref source="" url="http://issues.apache.org/bugzilla/show_bug.cgi?id=31975"></ref><ref source="" url="http://issues.apache.org/bugzilla/show_bug.cgi?id=41279"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31236">apache-htpasswd-strcpy-bo(31236)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25216">
thttpd-command-file-bo(25216)</ref></refs><vuln_soft><prod name="thttpd" vendor="Acme Labs"><vers num="2.25b"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-03" name="CVE-2006-1079" published="2006-03-08" seq="2006-1079" severity="High" type="CVE"><desc><descript source="cve">htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function.  NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE.  However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426823/100/0/threaded">20060305 htpasswd bufferoverflow and command execution in thttpd-2.25b.</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=thttpd&amp;m=114153031201867&amp;w=2">[thttpd] 20060305 htpasswd.c security issues</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=thttpd&amp;m=114154083000296&amp;w=2">[thttpd] 20060305 Re: htpasswd.c security issues</ref><ref source="OSVDB" url="http://www.osvdb.org/23828">23828</ref><ref source="BID" url="http://www.securityfocus.com/bid/16972">16972</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25217">
thttpd-command-line-bo(25217)</ref></refs><vuln_soft><prod name="thttpd" vendor="Acme Labs"><vers num="2.25b"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1080" published="2006-03-08" seq="2006-1080" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in Game-Panel 2.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter, possibly requiring a URL encoded value.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426825/100/0/threaded">20060304 Game-Panel &lt;= 2.1.6 XSS</ref><ref source="" url="http://notlegal.ws/gamepanel.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16979">16979</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0864">ADV-2006-0864</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19143">19143</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25144">
gamepanel-login-xss(25144)</ref></refs><vuln_soft><prod name="Game-Panel" vendor="Game-Panel"><vers num="2.6.1"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1081" published="2006-03-08" seq="2006-1081" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in forgotten_password.php in Jonathan Beckett PluggedOut Nexus 0.1 allows remote attackers to execute arbitrary SQL commands via the email parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426575/100/0/threaded">20060302 PluggedOut Nexus SQL injection</ref><ref adv="1" source="" url="http://hamid.ir/security/nexus.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0809">ADV-2006-0809</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19089">19089</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25017">nexus-forgottenpassword-sql-injection(25017)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015715">1015715</ref><ref source="BID" url="http://www.securityfocus.com/bid/16915">16915</ref><ref source="SREASON" url="http://securityreason.com/securityalert/536">536</ref></refs><vuln_soft><prod name="PluggedOut Nexus" vendor="Jonathan Beckett"><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1082" published="2006-03-08" seq="2006-1082" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpArcadeScript 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the gamename parameter in tellafriend.php, (2) the login_status parameter in loginbox.php, (3) the submissionstatus parameter in index.php, the (4) cell_title_background_color and (5) browse_cat_name parameters in browse.php, the (6) gamefile parameter in displaygame.php, and (7) possibly other parameters in unspecified PHP scripts.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426755/100/0/threaded">20060304 phpArcadeScript XSS Injections</ref><ref source="BID" url="http://www.securityfocus.com/bid/16957">16957</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0821">ADV-2006-0821</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19124">19124</ref><ref source="SREASON" url="http://securityreason.com/securityalert/533">533</ref></refs><vuln_soft><prod name="phpArcadeScript" vendor="phpArcadeScript"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1083" published="2006-03-08" seq="2006-1083" severity="High" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to read and possibly execute arbitrary files via a .. (dot dot) in the (1) option[language] and (2) option[template] parameters, and (3) possibly other parameters, to (a) admin.php and (b) other unspecified scripts.  NOTE: the admin.php/option[language] vector can be used by remote unauthenticated attackers to include arbitrary files in conjunction with CVE-2006-1085.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426762/100/0/threaded">20060304 PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref><ref source="" url="http://retrogod.altervista.org/php_stats_0191_adv.html"></ref><ref source="" url="http://www.phpstats.net/forum/viewtopic.php?t=140"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16963">16963</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0822">ADV-2006-0822</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19116">19116</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428614/100/0/threaded">20060322 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429145/100/0/threaded">20060327 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref></refs><vuln_soft><prod name="PHP-Stats" vendor="PHP-Stats"><vers num="0.1.9.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1084" published="2006-03-08" seq="2006-1084" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the option[prefix] parameter in admin.php and other unspecified PHP scripts, and (2) the PC_REMOTE_ADDR HTTP header to click.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426762/100/0/threaded">20060304 PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref><ref source="" url="http://retrogod.altervista.org/php_stats_0191_adv.html"></ref><ref source="" url="http://www.phpstats.net/forum/viewtopic.php?t=140"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16963">16963</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0822">ADV-2006-0822</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19116">19116</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428614/100/0/threaded">20060322 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429145/100/0/threaded">20060327 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref></refs><vuln_soft><prod name="PHP-Stats" vendor="PHP-Stats"><vers num="0.1.9.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1085" published="2006-03-08" seq="2006-1085" severity="High" type="CVE"><desc><descript source="cve">admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileges, and execute arbitrary PHP code by modifying the option[admin_pass] parameter and setting the pass_cookie to the MD5 hash of the specified password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426762/100/0/threaded">20060304 PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref><ref source="" url="http://retrogod.altervista.org/php_stats_0191_adv.html"></ref><ref source="" url="http://www.phpstats.net/forum/viewtopic.php?t=140"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16963">16963</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0822">ADV-2006-0822</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19116">19116</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428614/100/0/threaded">20060322 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429145/100/0/threaded">20060327 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref></refs><vuln_soft><prod name="PHP-Stats" vendor="PHP-Stats"><vers num="0.1.9.1" prev="1"/></prod></vuln_soft></entry><entry modified="2006-03-09" name="CVE-2006-1086" published="2006-03-08" reject="1" seq="2006-1086" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-1083.  Reason: This candidate is a duplicate of CVE-2006-1083.  Notes: All CVE users should reference CVE-2006-1083 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1087" published="2006-03-08" seq="2006-1087" severity="Medium" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the option_new[compatibility_mode] parameter, which is not filtered before being stored in config.php.  NOTE: this vulnerability can be exploited by remote unauthenticated attackers in conjunction with the option[admin_pass] authentication bypass vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426762/100/0/threaded">20060304 PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref><ref source="" url="http://retrogod.altervista.org/php_stats_0191_adv.html"></ref><ref source="" url="http://www.phpstats.net/forum/viewtopic.php?t=140"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16963">16963</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0822">ADV-2006-0822</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19116">19116</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428614/100/0/threaded">20060322 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429145/100/0/threaded">20060327 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref></refs><vuln_soft><prod name="PHP-Stats" vendor="PHP-Stats"><vers num="0.1.9.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1088" published="2006-03-08" seq="2006-1088" severity="Medium" type="CVE"><desc><descript source="cve">PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request to checktables.php, which lists the database table_prefix.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426762/100/0/threaded">20060304 PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref><ref source="" url="http://retrogod.altervista.org/php_stats_0191_adv.html"></ref><ref source="" url="http://www.phpstats.net/forum/viewtopic.php?t=140"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16963">16963</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0822">ADV-2006-0822</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19116">19116</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428614/100/0/threaded">20060322 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429145/100/0/threaded">20060327 Re: PHP-Stats &lt;= 0.1.9.1 remote commands execution</ref></refs><vuln_soft><prod name="PHP-Stats" vendor="PHP-Stats"><vers num="0.1.9.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1089" published="2006-03-09" seq="2006-1089" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in header.php in PunBB 1.2.10 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly handled when the PHP_SELF variable is used to handle a pun_page tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="punbb.org" url="http://www.punbb.org/changelogs/1.2.10_to_1.2.11.txt">changelog 1.2.10_to_1.2.11.txt</ref><ref patch="1" source="punbb.org" url="http://www.punbb.org/download/patch/punbb-1.2.10_to_1.2.11.patch">patch/punbb-1.2.10_to_1.2.11.patch</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19039">19039</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0773">ADV-2006-0773</ref><ref source="BID" url="http://www.securityfocus.com/bid/16891">16891</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24982">
punbb-header-xss(24982)</ref></refs><vuln_soft><prod name="PunBB" vendor="PunBB"><vers num="1.2.10"/><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1.5"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0 Beta3"/><vers num="1.0 Beta2"/><vers num="1.0 Beta1a"/><vers num="1.0 Beta1"/><vers num="1.0 alpha"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1090" published="2006-03-09" seq="2006-1090" severity="High" type="CVE"><desc><descript source="cve">register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations.</descript></desc><sols><sol source="nvd">This vulnerability affects PunBB version 1.2.10, and may affect all previous versions.</sol></sols><loss_types><avail/></loss_types><range><network/></range><refs><ref source="punbb.org" url="http://www.punbb.org/changelogs/1.2.10_to_1.2.11.txt">changelogs/1.2.10_to_1.2.11.txt</ref><ref patch="1" source="punbb.org" url="http://www.punbb.org/download/patch/punbb-1.2.10_to_1.2.11.patch">punbb-1.2.10_to_1.2.11.patch</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0773">ADV-2006-0773</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24837">
punbb-register-ip-dos(24837)</ref></refs><vuln_soft><prod name="PunBB" vendor="PunBB"><vers num="1.2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1091" published="2006-03-09" seq="2006-1091" severity="High" type="CVE"><desc><descript source="cve">Kaspersky Antivirus 5.0.5 and 5.5.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via unknown attack vectors.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/426699">20060303 Kaspersky Memory/CPU Usage Leak by design</ref><ref source="BID" url="http://www.securityfocus.com/bid/16942">16942</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25221">
kaspersky-unspecified-dos(25221)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/535">535</ref></refs><vuln_soft><prod name="Kaspersky Anti-Virus" vendor="Kaspersky Lab"><vers num="5.5.3"/><vers num="5.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1092" published="2006-03-09" seq="2006-1092" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the pagedata subsystem of the process file system (/proc) in Solaris 8 through 10 allows local users to cause a denial of service (system hang or panic) via unknown attack vectors that cause cause the kmem_oversize arena to allocate a large amount of system memory that does not get freed.</descript></desc><sols><sol source="nvd">This vulnerability affects all versions of Sun, Solaris 8.x through 10.x</sol></sols><loss_types><avail/></loss_types><range><local/></range><refs><ref adv="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102159-1">102159</ref><ref source="BID" url="http://www.securityfocus.com/bid/16966">16966</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0829">ADV-2006-0829</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015723">1015723</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19128">19128</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19716">
19716</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25152">
solaris-proc-pagedata-dos(25152)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1618">oval:org.mitre.oval:def:1618</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="10.0"/><vers edition="SPARC" num="9.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1093" published="2006-03-09" seq="2006-1093" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in IBM WebSphere 5.0.2.10 through 5.0.2.15 and 5.1.1.4 through 5.1.1.9 allows remote attackers to obtain sensitive information via unknown attack vectors, which causes JSP source code to be revealed.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1015716">1015716</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0788">ADV-2006-0788</ref><ref source="BID" url="http://www.securityfocus.com/bid/16908">16908</ref></refs><vuln_soft><prod name="WebSphere Application Server" vendor="IBM"><vers num="5.1.1.9"/><vers num="5.1.1.8"/><vers num="5.1.1.7"/><vers num="5.1.1.6"/><vers num="5.1.1.5"/><vers num="5.1.1.4"/><vers num="5.1.1.3"/><vers num="5.1.1.2"/><vers num="5.1.1.1"/><vers num="5.1.1"/><vers num="5.0.2.9"/><vers num="5.0.2.8"/><vers num="5.0.2.7"/><vers num="5.0.2.6"/><vers num="5.0.2.5"/><vers num="5.0.2.4"/><vers num="5.0.2.3"/><vers num="5.0.2.2"/><vers num="5.0.2.14"/><vers num="5.0.2.13"/><vers num="5.0.2.12"/><vers num="5.0.2.11"/><vers num="5.0.2.10"/><vers num="5.0.2.1"/><vers num="5.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-09" name="CVE-2006-1094" published="2006-03-09" seq="2006-1094" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) database.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/426583">20060301 Woltlab Burning Board 2.x (Datenbank MOD fileid) MultipleVulnerabilities</ref><ref source="" url="http://www.nukedx.com/?viewdoc=17"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16914">16914</ref><ref source="OSVDB" url="http://www.osvdb.org/23808">23808</ref><ref source="OSVDB" url="http://www.osvdb.org/23810">23810</ref></refs><vuln_soft><prod name="Datenbank Module" vendor="Datenbank Module"><vers num="2.7" prev="1"/></prod><prod name="Burning Board" vendor="Woltlab"><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3.3"/><vers num="2.3.1"/><vers num="2.2.2"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta 5"/><vers num="2.0 Beta 4"/><vers num="2.0 Beta 3"/><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-21" name="CVE-2006-1095" published="2006-03-09" seq="2006-1095" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://www.cgisecurity.com/2006/02/07"></ref><ref source="" url="http://www.modpython.org/fs_sec_warn.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16916">16916</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0768">ADV-2006-0768</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24965">modpython-filesession-command-execution(24965)</ref><ref source="" url="http://svn.apache.org/viewcvs.cgi/httpd/mod_python/branches/3.2.x/NEWS?rev=378945"></ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015764">1015764</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19239">19239</ref></refs><vuln_soft><prod name="mod_python" vendor="Apache Software Foundation"><vers num="3.2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1096" published="2006-03-09" seq="2006-1096" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  Cross-site scripting (XSS) vulnerability in index.php in NZ Ecommerce allows remote attackers to inject arbitrary web script or HTML via the action parameter.  NOTE: the vendor has disputed this issue in a comment on the researcher&apos;s blog, but research by CVE suggests that this might be a legitimate problem.</descript></desc><sols><sol source="nvd">This vulnerability most likely affects all versions of Digital Builder, NZ Ecommerce.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="blogspot.com" url="http://pridels.blogspot.com/2006/03/nz-ecommerce-sqlxss-vuln.html">nz-ecommerce-sqlxss-vuln</ref><ref source="BID" url="http://www.securityfocus.com/bid/16931">16931</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0803">ADV-2006-0803</ref><ref source="OSVDB" url="http://www.osvdb.org/23600">23600</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19088">19088</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/nz-ecommerce-sqlxss-vuln.html"></ref></refs><vuln_soft><prod name="NZ Ecommerce" vendor="Digital Builder"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1097" published="2006-03-09" seq="2006-1097" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allow remote attackers to inject arbitrary web script or HTML via the fileid parameter to (1) info_db.php or (2) database.php.</descript></desc><sols><sol source="nvd">This vulnerability may only affect Datenbank MOD 2.7 and earlier versions in a Woltlab Burning Board environment. </sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/426583">20060301 Woltlab Burning Board 2.x (Datenbank MOD fileid) MultipleVulnerabilities</ref><ref adv="1" source="nukedx.com" url="http://www.nukedx.com/?viewdoc=17"></ref><ref source="OSVDB" url="http://www.osvdb.org/23809">23809</ref><ref source="OSVDB" url="http://www.osvdb.org/23811">23811</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/0033.html">
20060301 Woltlab Burning Board 2.x (Datenbank MOD fileid) MultipleVulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25004">
wbb-multiple-xss(25004)</ref></refs><vuln_soft><prod name="datenbank module" vendor="datenbank module"><vers num="MOD 2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1098" published="2006-03-09" seq="2006-1098" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php.  NOTE: the vendor has disputed this issue in a comment on the researcher&apos;s blog, but research by CVE suggests that this might be a legitimate problem.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://pridels.blogspot.com/2006/03/nz-ecommerce-sqlxss-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16931">16931</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0803">ADV-2006-0803</ref><ref source="OSVDB" url="http://www.osvdb.org/23601">23601</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19088">19088</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/nz-ecommerce-sqlxss-vuln.html"></ref></refs><vuln_soft><prod name="NZ Ecommerce" vendor="Digital Builder"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1099" published="2006-03-09" seq="2006-1099" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in logIT 1.3 and 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16932">16932</ref></refs><vuln_soft><prod name="logIT" vendor="logIT"><vers num="1.4"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1100" published="2006-03-09" seq="2006-1100" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the sgetstr function in shared/cube.h in Sauerbraten 2006_02_28 and earlier, as derived from the Cube engine, allows remote attackers to execute arbitrary code via long streams of input data.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426865/100/0/threaded">20060306 Multiple vulnerabilities in Sauerbraten engine 2006_02_28</ref><ref adv="1" source="" url="http://aluigi.altervista.org/adv/evilcube-adv.txt"></ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/sauerbraten/sauerbraten/src/shared/cube.h?r1=1.7&amp;r2=1.8"></ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426867/100/0/threaded">20060306 Multiple vulnerabilities in Cube engine 2005_08_29</ref><ref source="BID" url="http://www.securityfocus.com/bid/16986">16986</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0848">ADV-2006-0848</ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/sauerbraten/sauerbraten/src/shared/cube.h?r1=1.7&amp;r2=1.8"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0847">ADV-2006-0847</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19110">19110</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19111">19111</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25083">sauerbraten-sgetstr-bo(25083)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-10.xml">GLSA-200603-10</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19199">19199</ref></refs><vuln_soft><prod name="Cube" vendor="Sauerbraten"><vers num="2005-08-09"/></prod><prod name="Sauerbraten" vendor="Sauerbraten"><vers num="2006-02-28"/><vers num="2006-02-27"/><vers num="2006-01-31"/><vers num="2005-11-07"/><vers num="2005-08-15"/><vers num="2005-07-04"/><vers num="2005-06-12"/><vers num="2005-06-05"/><vers num="2005-05-29"/><vers num="2005-05-24"/><vers num="2004-11-02"/><vers num="2004-05-23"/><vers num="2004-05-08"/><vers num="initial 2004-02-27"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1101" published="2006-03-09" seq="2006-1101" severity="Medium" type="CVE"><desc><descript source="cve">The (1) sgetstr and (2) getint functions in Sauerbraten 2006_02_28, as derived from the Cube engine, allow remote attackers to cause a denial of service (segmentation fault) via long streams of input data that trigger an out-of-bounds read, as demonstrated using SV_EXT tag data in the Cube engine, which is not properly handled by getint.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426865/100/0/threaded">20060306 Multiple vulnerabilities in Sauerbraten engine 2006_02_28</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426867/100/0/threaded">20060306 Multiple vulnerabilities in Cube engine 2005_08_29</ref><ref adv="1" source="" url="http://aluigi.altervista.org/adv/evilcube-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16986">16986</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0848">ADV-2006-0848</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0847">ADV-2006-0847</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19110">19110</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19111">19111</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25085">sauerbraten-multiple-dos(25085)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-10.xml">GLSA-200603-10</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19199">19199</ref></refs><vuln_soft><prod name="Cube" vendor="Sauerbraten"><vers num="2005-08-09"/></prod><prod name="Sauerbraten" vendor="Sauerbraten"><vers num="2006-02-28"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1102" published="2006-03-09" seq="2006-1102" severity="Medium" type="CVE"><desc><descript source="cve">Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial of service (client exit) by forcing the server to change to a map (ogz) file whose name contains &quot;..&quot; sequences and has a certain length that prevents the addition of the &quot;.ogz&quot; extension.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426865/100/0/threaded">20060306 Multiple vulnerabilities in Sauerbraten engine 2006_02_28</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426867/100/0/threaded">20060306 Multiple vulnerabilities in Cube engine 2005_08_29</ref><ref adv="1" source="" url="http://aluigi.altervista.org/adv/evilcube-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16986">16986</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0848">ADV-2006-0848</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0847">ADV-2006-0847</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19110">19110</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19111">19111</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-10.xml">GLSA-200603-10</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19199">19199</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25086">
sauerbraten-sprintf-dos(25086)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/548">548</ref></refs><vuln_soft><prod name="Cube" vendor="Sauerbraten"><vers num="2005-08-09"/></prod><prod name="Sauerbraten" vendor="Sauerbraten"><vers num="2006-02-28"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1103" published="2006-03-09" seq="2006-1103" severity="Medium" type="CVE"><desc><descript source="cve">engine/server.cpp in Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial of service (segmentation fault) via a client that does not completely join the game and times out, which results in a null pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426865/100/0/threaded">20060306 Multiple vulnerabilities in Sauerbraten engine 2006_02_28</ref><ref source="BID" url="http://www.securityfocus.com/bid/16986">16986</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0848">ADV-2006-0848</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25087">sauerbraten-engineserver-dos(25087)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/550">550</ref></refs><vuln_soft><prod name="Cube" vendor="Sauerbraten"><vers num="2005-08-09"/></prod><prod name="Sauerbraten" vendor="Sauerbraten"><vers num="2006-02-28"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1104" published="2006-03-09" seq="2006-1104" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Pixelpost 1.5 beta 1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the showimage parameter in index.php; and the (2) USER_AGENT, (3) HTTP_REFERER, and (4) HTTP_HOST HTTP header fields as used in the book_vistor function in includes/functions.php.  NOTE: the vendor has disputed some issues from the original disclosure, but due to the vagueness of the dispute, it is not clear whether the vendor is disputing this particular issue.</descript></desc><sols><sol source="nvd">These vulnerabilities may affect all versions of Pixelpost.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426764/100/0/threaded">20060304 Pixel Post Multiple Vulnerabilities</ref><ref adv="1" source="neosecurityteam.net" url="http://www.neosecurityteam.net/index.php?action=advisories&amp;id=19">Pixel Post &lt;=1.4.3 Multiple Vulnerabilities</ref><ref source="pixelpost.org" url="http://forum.pixelpost.org/showthread.php?t=3535">&lt;=1.4.3, 1.5 beta 1 Multiple Vulnerabilities </ref><ref source="BID" url="http://www.securityfocus.com/bid/16964">16964</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0823">ADV-2006-0823</ref><ref source="" url="http://www.neosecurityteam.net/index.php?action=advisories&amp;id=19"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25046">pixelpost-functions-sql-injection(25046)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25044">pixelpost-index-sql-injection(25044)</ref></refs><vuln_soft><prod name="Pixelpost" vendor="Pixelpost"><vers num="1.4.3"/><vers num="1.5 Beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1105" published="2006-03-09" seq="2006-1105" severity="Medium" type="CVE"><desc><descript source="cve">Pixelpost 1.5 beta 1 and earlier allows remote attackers to obtain configuration information via a direct request to includes/phpinfo.php, which calls the phpinfo function.  NOTE: the vendor has disputed some issues from the original disclosure, but due to the vagueness of the dispute, it is not clear whether the vendor is disputing this particular issue.</descript></desc><sols><sol source="nvd">This vulnerability may affect all versions of Pixelpost.</sol></sols><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426764/100/0/threaded">20060304 Pixel Post Multiple Vulnerabilities</ref><ref adv="1" source="neosecurityteam.net" url="http://www.neosecurityteam.net/index.php?action=advisories&amp;id=19">Pixel Post &lt;=1.4.3 Multiple Vulnerabilities</ref><ref source="pixelpost.org" url="http://forum.pixelpost.org/showthread.php?t=3535">&lt;=1.4.3, 1.5 beta 1 Multiple Vulnerabilities </ref><ref source="BID" url="http://www.securityfocus.com/bid/16964">16964</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0823">ADV-2006-0823</ref><ref source="" url="http://www.neosecurityteam.net/index.php?action=advisories&amp;id=19"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25048">pixelpost-phpinfo-obtain-information(25048)</ref></refs><vuln_soft><prod name="Pixelpost" vendor="Pixelpost"><vers num="1.4.3"/><vers num="1.5 Beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1106" published="2006-03-09" seq="2006-1106" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Pixelpost 1.5 beta 1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) message, (2) name, (3) url, and (4) email parameters when commenting on a post.  NOTE: the vendor has disputed some issues from the original disclosure, but due to the vagueness of the dispute, it is not clear whether the vendor is disputing this particular issue.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426764/100/0/threaded">20060304 Pixel Post Multiple Vulnerabilities</ref><ref source="" url="http://www.neosecurityteam.net/index.php?action=advisories&amp;id=19"></ref><ref source="" url="http://forum.pixelpost.org/showthread.php?t=3535"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16964">16964</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0823">ADV-2006-0823</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25047">pixelpost-functions-xss(25047)</ref></refs><vuln_soft><prod name="Pixelpost" vendor="Pixelpost"><vers num="1.5 Beta1"/><vers num="1.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1107" published="2006-03-09" seq="2006-1107" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in news.php in NMDeluxe before 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the nick parameter.</descript></desc><sols><sol source="nvd">This vulnerability affects NMDeluxe versions 1.0 and previous.
</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="evuln.com" url="http://evuln.com/vulns/93/summary.html">NMDeluxe XSS &amp; SQL Injection Vulnerabilities</ref><ref patch="1" source="nmdeluxe.com" url="http://nmdeluxe.com/index.php">N/A</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0860">ADV-2006-0860</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19117">19117</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25069">nmdeluxe-news-xss(25069)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428002/100/0/threaded">20060317 [eVuln] NMDeluxe XSS &amp; SQL Injection Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17017">17017</ref><ref source="SREASON" url="http://securityreason.com/securityalert/595">595</ref></refs><vuln_soft><prod name="NMDeluxe" vendor="NMDeluxe"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1108" published="2006-03-09" seq="2006-1108" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in news.php in NMDeluxe before 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><sols><sol source="nvd">This vulnerability affcts NMDeluxe versions 1.0 and previous.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="evuln.com" url="http://evuln.com/vulns/93/summary.html">NMDeluxe XSS &amp; SQL Injection Vulnerabilities</ref><ref patch="1" source="nmdeluxe.com" url="http://nmdeluxe.com/index.php">N/A</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0860">ADV-2006-0860</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19117">19117</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25070">nmdeluxe-news-sql-injection(25070)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428002/100/0/threaded">20060317 [eVuln] NMDeluxe XSS &amp; SQL Injection Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17017">17017</ref><ref source="SREASON" url="http://securityreason.com/securityalert/595">595</ref></refs><vuln_soft><prod name="NMDeluxe" vendor="NMDeluxe"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1109" published="2006-03-09" seq="2006-1109" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.asp in Total Ecommerce 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.  NOTE: it is not clear whether this report is associated with a specific product.  If not, then it should not be included in CVE.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426765/100/0/threaded">20060304 Advisory: TotalECommerce (index.asp id) Remote SQL InjectionVulnerability.</ref><ref adv="1" source="" url="http://www.nukedx.com/?viewdoc=18"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0840">ADV-2006-0840</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19103">19103</ref><ref source="BID" url="http://www.securityfocus.com/bid/16960">16960</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25045">totalecommerce-index-sql-injection(25045)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/530">530</ref></refs><vuln_soft><prod name="TotalECommerce" vendor="TotalECommerce"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1110" published="2006-03-09" seq="2006-1110" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Aztek Forum 4.0 allows remote attackers to inject arbitrary web script or HTML via the message body in a new message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426650/100/0/threaded">20060302 AZTEK forums 4.0 multiple vulnerabilities (PoC)</ref><ref source="milw0rm.com" url="http://milw0rm.com/id.php?id=1547">AZTEK forums 4.0 multiple vulnerabilities (PoC)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16938">16938</ref><ref source="OSVDB" url="http://www.osvdb.org/23610">23610</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19096">19096</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1547">
1547</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25035">
aztekforum-multiple-xss(25035)</ref></refs><vuln_soft><prod name="Aztek Forum" vendor="Aztek Forum"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1111" published="2006-03-09" seq="2006-1111" severity="High" type="CVE"><desc><descript source="cve">Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a &quot;*/*&quot; in the msg parameter to index.php, which reveals usernames and passwords in a MySQL error message, possibly due to a forced SQL error or SQL injection.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426650/100/0/threaded">20060302 AZTEK forums 4.0 multiple vulnerabilities (PoC)</ref><ref source="milw0rm.com" url="http://milw0rm.com/id.php?id=1547">AZTEK forums 4.0 multiple vulnerabilities (PoC)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16938">16938</ref><ref source="OSVDB" url="http://www.osvdb.org/23611">23611</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1547">
1547</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25036">
aztekforum-info-disclosure(25036)</ref></refs><vuln_soft><prod name="Aztek Forum" vendor="Aztek Forum"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1112" published="2006-03-09" seq="2006-1112" severity="Medium" type="CVE"><desc><descript source="cve">Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a long login value in a register form, which displays the installation path in a MySQL error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426650/100/0/threaded">20060302 AZTEK forums 4.0 multiple vulnerabilities (PoC)</ref><ref source="milw0rm.com" url="http://milw0rm.com/id.php?id=1547">AZTEK forums 4.0 multiple vulnerabilities (PoC)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16938">16938</ref><ref source="OSVDB" url="http://www.osvdb.org/23612">23612</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1547">
1547</ref><ref source="SREASON" url="http://securityreason.com/securityalert/539">539</ref></refs><vuln_soft><prod name="Aztek Forum" vendor="Aztek Forum"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1113" published="2006-03-09" seq="2006-1113" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in podcast.php in Loudblog before 0.42 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><sols><sol source="nvd">This vulnerability affects Loudblog versions 0.41 and previous.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426973/100/0/threaded">20060307 Loudblog 0.41 SQL Injection, Local file read/include</ref><ref source="loudblog" url="http://loudblog.de/forum/viewtopic.php?id=590">Loudblog Forum</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0878">ADV-2006-0878</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19172">19172</ref><ref source="BID" url="http://www.securityfocus.com/bid/17023">17023</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25101">
loudblog-podcast-sql-injection(25101)</ref></refs><vuln_soft><prod name="Loudblog" vendor="Gerrit van Aaken"><vers num="0.41"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1114" published="2006-03-09" seq="2006-1114" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in Loudblog before 0.42 allow remote attackers to read or include arbitrary files via a .. (dot dot) and trailing %00 (NULL) byte in the (1) template and (2) page parameters in (a) index.php, and the (3) language parameter in (b) inc/backend_settings.php.</descript></desc><sols><sol source="nvd">This vulnerability affects Loudblog versions 0.41 and previous.</sol></sols><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426973/100/0/threaded">20060307 Loudblog 0.41 SQL Injection, Local file read/include</ref><ref source="loudblog" url="http://loudblog.de/forum/viewtopic.php?id=590">Loudblog forum</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0878">ADV-2006-0878</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19172">19172</ref><ref source="BID" url="http://www.securityfocus.com/bid/17023">17023</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25103">
loudblog-index-directory-traversal(25103)</ref></refs><vuln_soft><prod name="Loudblog" vendor="Gerrit van Aaken"><vers num="0.41"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1115" published="2006-03-09" seq="2006-1115" severity="Low" type="CVE"><desc><descript source="cve">nCipher HSM before 2.22.6, when generating a Diffie-Hellman public/private key pair without any specified DiscreteLogGroup parameters, chooses random parameters that could allow an attacker to crack the private key in significantly less time than a brute force attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ncipher.com" url="http://www.ncipher.com/resources/95/sa12_insecure_generation_of_diffiehellman_keys">SA#12: Insecure Generation of Diffie-Hellman keys</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17006">17006</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0862">ADV-2006-0862</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015719">1015719</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19137">19137</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25060">ncipher-hsm-weak-key(25060)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427146/100/0/threaded">20060308 nCipher Advisory #12: Insecure Generation of Diffie-Hellman keys</ref></refs><vuln_soft><prod name="nCipher Software CD" vendor="nCipher"><vers num=""/></prod><prod name="CHIL" vendor="nCipher"><vers num=""/></prod><prod name="MSCAPI CSP" vendor="nCipher"><vers num="5.54"/><vers num="5.50"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1116" published="2006-03-09" seq="2006-1116" severity="Medium" type="CVE"><desc><descript source="cve">The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a message when the implementation uses a non-zero IV, which allows remote attackers to bypass integrity checks and modify messages without being detected.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ncipher.com" url="http://www.ncipher.com/resources/96/sa13_cbcmac_iv_misleading_programming_interface">SA#13: CBC-MAC IV misleading programming interface</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17011">17011</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0862">ADV-2006-0862</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015718">1015718</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19137">19137</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25062">ncipher-ncore-bypass-security(25062)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427150/100/0/threaded">20060308 nCipher Advisory #13: CBC-MAC IV misleading programming interface</ref></refs><vuln_soft><prod name="nCore" vendor="nCipher"><vers num="2.17"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1117" published="2006-03-09" seq="2006-1117" severity="Low" type="CVE"><desc><descript source="cve">nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote attackers to obtain information about encryption keys and crack those keys with less effort than brute force.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ncipher.com" url="http://www.ncipher.com/resources/97/sa14_presence_of_flaws_in_firmware_security">SA#14: Presence of flaws in firmware security</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17012">17012</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0862">ADV-2006-0862</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015718">1015718</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19137">19137</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25063">ncipher-firmware-weak-security(25063)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427151/100/0/threaded">20060309 nCipher Advisory #14: Presence of flaws in firmware security</ref></refs><vuln_soft><prod name="nCore" vendor="nCipher"><vers num=""/></prod><prod name="payShield" vendor="nCipher"><vers num=""/></prod><prod name="netHSM" vendor="nCipher"><vers num="2.1.12 cam5"/><vers num="2.1"/><vers num="2.0"/></prod><prod name="nShield" vendor="nCipher"><vers num=""/></prod><prod name="DSE200 Document Sealing Engine" vendor="nCipher"><vers num=""/></prod><prod name="SecureDB" vendor="nCipher"><vers num=""/></prod><prod name="Time Source Master Clock" vendor="nCipher"><vers num=""/></prod><prod name="nForce" vendor="nCipher"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1118" published="2006-03-09" seq="2006-1118" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in bmail before Aardvark PR9.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving GBK character sets.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Sourceforge.net" url="http://sourceforge.net/project/shownotes.php?group_id=144412&amp;release_id=399256">Release Name: PR9.1</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0863">ADV-2006-0863</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19147">19147</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25073">bmail-gbkcharacterset-sql-injection(25073)</ref></refs><vuln_soft><prod name="bMail" vendor="bMail"><vers num="PR9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1119" published="2006-03-09" seq="2006-1119" severity="Medium" type="CVE"><desc><descript source="cve">fantastico in Cpanel does not properly handle when it has insufficient permissions to perform certain file operations, which allows remote authenticated users to obtain the full pathname, which is leaked in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426957/100/0/threaded">20060307 Cpanel Path Disclosure Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25277">
cpanel-fantastico-path-disclosure(25277)</ref></refs><vuln_soft><prod name="fantastico" vendor="cPanel"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1120" published="2006-03-09" seq="2006-1120" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 6.1.1 and earlier, with register_globals enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) its_url parameter in the documents page and (2) url parameter in the send_write page of (a) index.php; (3) subject, and (4) images parameters to (b) calendar.php; (5) bid, (6) replying_msg, (7) subject, (8) body, and (9) mid parameters to (c) forums.php; (10) subject and (11) message parameters to (d) inbox.php; (12) subject_color and (13) email parameters to (e) lostpassword.php; and the (14) c_name, (15) content_inicial, and (16) cid parameters to (f) mycontents.php.  NOTE: the calendar.php/day vector is already subsumed by CVE-2006-0220, and the calendar.php/month, calendar.php/year, and search.php/q parameters for calendar.php are already subsumed by CVE-2004-2511.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427175/100/0/threaded">20060309 DCP Portal: Multiple XSS Vulnerabilities</ref><ref adv="1" source="seclab.tuwien.ac.at" url="http://www.seclab.tuwien.ac.at/advisories/TUVSA-0603-001.txt">DCP Portal: Multiple XSS Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17050">17050</ref><ref source="OSVDB" url="http://www.osvdb.org/23976">23976</ref><ref source="OSVDB" url="http://www.osvdb.org/23977">23977</ref><ref source="OSVDB" url="http://www.osvdb.org/23978">23978</ref><ref source="OSVDB" url="http://www.osvdb.org/23979">23979</ref><ref source="OSVDB" url="http://www.osvdb.org/23980">23980</ref><ref source="OSVDB" url="http://www.osvdb.org/23981">23981</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25279">
dcpportal-multiple-scripts-xss(25279)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/392">392</ref></refs><vuln_soft><prod name="DCP-Portal" vendor="Codeworx Technologies"><vers num="6.1.1"/><vers num="5.3.2"/><vers num="5.3.1"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="4.5.1"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/><vers num="3.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1121" published="2006-03-09" seq="2006-1121" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the query string to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426759/100/0/threaded">BUGTRAQ:20060304 [KAPDA::#30] - CuteNews1.4.1 Cross_Site_Scripting Vulnerability</ref><ref adv="1" source="kapda.ir" url="http://kapda.ir/advisory-277.html">advisory-277</ref><ref source="BID" url="http://www.securityfocus.com/bid/16961">16961</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1015726">1015726</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25052">
cutenews-index-script-xss(25052)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/531">531</ref></refs><vuln_soft><prod name="CuteNews" vendor="CutePHP"><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2006-12-27" name="CVE-2006-1122" published="2006-03-09" seq="2006-1122" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Default.asp in D2KBlog 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427103/100/0/threaded">20060308 [KAPDA::#32] - d2kBlog 1.0.3 Multiple Vulnerabilities</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0896">ADV-2006-0896</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19177">19177</ref><ref source="BID" url="http://www.securityfocus.com/bid/17035">17035</ref><ref source="OSVDB" url="http://www.osvdb.org/23771">23771</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25214">d2kblog-default-msg-xss(25214)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/559">559</ref></refs><vuln_soft><prod name="D2KBlog" vendor="D2KSoft"><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1123" published="2006-03-09" seq="2006-1123" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in D2KBlog 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the memName parameter in a cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427103/100/0/threaded">20060308 [KAPDA::#32] - d2kBlog 1.0.3 Multiple Vulnerabilities</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0896">ADV-2006-0896</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19177">19177</ref><ref source="BID" url="http://www.securityfocus.com/bid/17035">17035</ref><ref source="OSVDB" url="http://www.osvdb.org/23770">23770</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25215">d2kblog-memname-sql-injection(25215)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/559">559</ref></refs><vuln_soft><prod name="D2KBlog" vendor="D2KSoft"><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-04" name="CVE-2006-1124" published="2006-03-09" seq="2006-1124" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in RevilloC MailServer and Proxy 1.21 allows remote attackers to execute arbitrary code via a long USER command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0910.html">20060307 RevilloC mail server USER command heap overflow</ref><ref source="morx.org" url="http://www.morx.org/rev.txt">N/A</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427192/100/0/threaded">20060309 RevilloC MailServer 1.x &apos;USER&apos; Command Handling Remote Buffer Overflow Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/16997">16997</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0867">ADV-2006-0867</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19119">19119</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25072">revilloc-user-bo(25072)</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/23735">23735</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015739">1015739</ref></refs><vuln_soft><prod name="RevilloC MailServer" vendor="RevilloC Solutions"><vers num="1.21"/><vers num="proxy 1.21"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1125" published="2006-03-09" seq="2006-1125" severity="Medium" type="CVE"><desc><descript source="cve">Grisoft AVG Free 7.1, and other versions including 7.0.308, sets Everyone/Full Control permissions for certain update files including (1) upd_vers.cfg, (2) incavi.avm, and (3) unspecified drivers, which might allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="dslreports.com" url="http://www.dslreports.com/forum/remark,15601404">remark,15601404</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16952">16952</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0845">ADV-2006-0845</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1015728">1015728</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/19118">19118</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0631.html">

20060303 AVG 7 granting Everyone Full Control to updated files... even its drivers</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25139">
avg-update-gain-privilieges(25139)</ref></refs><vuln_soft><prod name="AVG Antivirus" vendor="Grisoft"><vers num="7.1.308"/><vers num="7.0.323"/><vers num="7.0.251"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1126" published="2006-03-09" seq="2006-1126" severity="Medium" type="CVE"><desc><descript source="cve">Gallery 2 up to 2.0.2 allows remote attackers to spoof their IP address via a modified X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is checked by Gallery before other more reliable sources of IP address information, such as REMOTE_ADDR.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0621.html">20060303 Gallery 2 Multiple Vulnerabilities</ref><ref patch="1" source="gulftech.org" url="http://www.gulftech.org/?node=research&amp;article_id=00106-03022006">Gallery 2 Multiple Vulnerabilities</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015717">1015717</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19104">19104</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0813">ADV-2006-0813</ref><ref source="" url="http://gallery.menalto.com/gallery_2.0.3_released"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25120">
gallery-header-spoofing(25120)</ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="2.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1127" published="2006-03-09" seq="2006-1127" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is not properly handled when adding a comment to an album.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0621.html">20060303 Gallery 2 Multiple Vulnerabilities</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00106-03022006"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16940">16940</ref><ref source="OSVDB" url="http://www.osvdb.org/23596">23596</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015717">1015717</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19104">19104</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0813">ADV-2006-0813</ref><ref source="" url="http://gallery.menalto.com/gallery_2.0.3_released"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25117">
gallery-getremotehostaddress-xss(25117)</ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0 Beta3"/><vers num="2.0 Beta2"/><vers num="2.0 Beta1"/><vers num="2.0 Alpha4"/><vers num="2.0 Alpha3"/><vers num="2.0 Alpha2"/><vers num="2.0 Alpha1"/><vers num="2.0 Alpha"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-1128" published="2006-03-09" seq="2006-1128" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote attackers to access and delete files by specifying the session in a cookie, which is used in constructing file paths before the session value is sanitized.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0621.html">20060303 Gallery 2 Multiple Vulnerabilities</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00106-03022006"></ref><ref source="OSVDB" url="http://www.osvdb.org/23597">23597</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015717">1015717</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19104">19104</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0813">ADV-2006-0813</ref><ref source="" url="http://gallery.menalto.com/gallery_2.0.3_released"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16948">
16948</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25118">
gallery-sessionid-bypass-security(25118)</ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0 Beta3"/><vers num="2.0 Beta2"/><vers num="2.0 Beta1"/><vers num="2.0 Alpha4"/><vers num="2.0 Alpha3"/><vers num="2.0 Alpha2"/><vers num="2.0 Alpha1"/><vers num="2.0 Alpha"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1129" published="2006-03-09" seq="2006-1129" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in config.php in EKINboard 1.0.3 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://evuln.com/vulns/88/summary.html"></ref><ref source="" url="http://www.ekinboard.com/forums/v1/viewtopic.php?id=469"></ref><ref patch="1" source="" url="http://www.ekinboard.com/patch_for_1.0.3.txt"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16861">16861</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0758">ADV-2006-0758</ref><ref source="OSVDB" url="http://www.osvdb.org/23547">23547</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19045">19045</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24922">ekinboard-config-sql-injection(24922)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427073/100/0/threaded">20060308 [eVuln] EKINboard &apos;img&apos; BBCode XSS &amp; Cookie &apos;username&apos; SQL Injection Vulnerabilities</ref></refs><vuln_soft><prod name="EKINboard" vendor="EKINboard"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1130" published="2006-03-09" seq="2006-1130" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in EKINboard 1.0.3 allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in a BBCode img tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://evuln.com/vulns/88/summary.html"></ref><ref patch="1" source="" url="http://www.ekinboard.com/forums/v1/viewtopic.php?id=469"></ref><ref patch="1" source="" url="http://www.ekinboard.com/patch_for_1.0.3.txt"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16861">16861</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0758">ADV-2006-0758</ref><ref source="OSVDB" url="http://www.osvdb.org/23546">23546</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19045">19045</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24921">ekinboard-bbcode-xss(24921)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427073/100/0/threaded">20060308 [eVuln] EKINboard &apos;img&apos; BBCode XSS &amp; Cookie &apos;username&apos; SQL Injection Vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/558">558</ref></refs><vuln_soft><prod name="EKINboard" vendor="EKINboard"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1131" published="2006-03-09" seq="2006-1131" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in read.php in bitweaver CMS 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the comment_title parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://kiki91.altervista.org/exploit/bitweaver_1.2.1_XSS.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0837">ADV-2006-0837</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19101">19101</ref><ref source="BID" url="http://www.securityfocus.com/bid/16973">16973</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25053">
bitweaver-titlefield-xss(25053)</ref></refs><vuln_soft><prod name="bitweaver" vendor="bitweaver"><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1132" published="2006-03-09" seq="2006-1132" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in show.php in vbzoom 1.11 allow remote attackers to execute arbitrary SQL commands via the MainID parameter. NOTE: the SubjectID vector is already covered by CVE-2005-4729.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426874/100/0/threaded">20060306 SQL injection &amp; XSS IN vbzoom v1.11</ref><ref source="BID" url="http://www.securityfocus.com/bid/16955">16955</ref><ref source="SREASON" url="http://securityreason.com/securityalert/552">552</ref></refs><vuln_soft><prod name="VBZoom" vendor="VBZoom"><vers num="1.11"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1133" published="2006-03-09" seq="2006-1133" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in vbzoom 1.11 allow remote attackers to inject arbitrary web script or HTML via the UserID parameter to (1) comment.php or (2) contact.php.  NOTE: the profile.php/UserName vector is already covered by CVE-2005-2441.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426874/100/0/threaded">20060306 SQL injection &amp; XSS IN vbzoom v1.11</ref><ref source="OSVDB" url="http://www.osvdb.org/23812">23812</ref><ref source="OSVDB" url="http://www.osvdb.org/23813">23813</ref><ref source="BID" url="http://www.securityfocus.com/bid/16956">16956</ref><ref source="BID" url="http://www.securityfocus.com/bid/16969">16969</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25090">
vbzoom-comment-contact-xss(25090)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/552">552</ref></refs><vuln_soft><prod name="VBZoom" vendor="VBZoom"><vers num="1.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1134" published="2006-03-09" seq="2006-1134" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in CyBoards PHP Lite 1.25, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the parent parameter to (1) post.php and possibly (2) process_post.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/91/description.html"></ref><ref source="" url="http://www.gold-sonata.com/forums/read.php?board=1&amp;id=17271"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0820">ADV-2006-0820</ref><ref source="OSVDB" url="http://www.osvdb.org/23692">23692</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19135">19135</ref><ref source="" url="http://www.gold-sonata.com/forums/read.php?board=1&amp;id=17271"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17107">17107</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427623/100/0/threaded">20060314 [eVuln] CyBoards PHP Lite SQL Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16987">16987</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25061">
cyboards-processpost-sql-injection(25061)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/582">582</ref></refs><vuln_soft><prod name="CyBoards PHP Lite" vendor="Jason Smith"><vers num="1.25"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1135" published="2006-03-09" seq="2006-1135" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in sBlog 0.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to search.php or (2) username parameter to comments_do.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://kiki91.altervista.org/exploit/sBlog_0.72_xss.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0883">ADV-2006-0883</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19151">19151</ref><ref source="BID" url="http://www.securityfocus.com/bid/17044">17044</ref><ref source="OSVDB" url="http://www.osvdb.org/23759">23759</ref><ref source="OSVDB" url="http://www.osvdb.org/23760">23760</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25111">sblog-username-xss(25111)</ref></refs><vuln_soft><prod name="sBlog" vendor="sBlog"><vers num="0.7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1136" published="2006-03-09" seq="2006-1136" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the PostScript file interpreter code for Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, allows attackers to cause a denial of service via unknown vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_002.pdf"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0857">ADV-2006-0857</ref><ref source="OSVDB" url="http://www.osvdb.org/23724">23724</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015738">1015738</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19146">19146</ref><ref source="BID" url="http://www.securityfocus.com/bid/17014">17014</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25172">
xerox-postscript-interpreter-dos(25172)</ref></refs><vuln_soft><prod name="WorkCentre Pro" vendor="Xerox"><vers num="65 1.001.02.073" prev="1"/><vers num="75 1.001.02.073" prev="1"/><vers num="90 1.001.02.073" prev="1"/><vers num="65 1.001.02.0715" prev="1"/><vers num="75 1.001.02.0715" prev="1"/><vers num="90 1.001.02.0715" prev="1"/></prod><prod name="CopyCentre" vendor="Xerox"><vers num="C65 1.001.02.073" prev="1"/><vers num="C75 1.001.02.073" prev="1"/><vers num="C90 1.001.02.073" prev="1"/><vers num="C65 1.001.02.0715" prev="1"/><vers num="C75 1.001.02.0715" prev="1"/><vers num="C90 1.001.02.0715" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1137" published="2006-03-09" seq="2006-1137" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, allow remote attackers to cause an unspecified denial of service via a crafted PostScript file that will (1) &quot;navigate through the directory&quot; or (2) a &quot;file sent to expose TCP/IP ports&quot;.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_002.pdf"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0857">ADV-2006-0857</ref><ref source="OSVDB" url="http://www.osvdb.org/23725">23725</ref><ref source="OSVDB" url="http://www.osvdb.org/23726">23726</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015738">1015738</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19146">19146</ref><ref source="BID" url="http://www.securityfocus.com/bid/17014">17014</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25173">
xerox-postscript-navigate-dos(25173)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25174">
xerox-postscript-tcpip-dos(25174)</ref></refs><vuln_soft><prod name="WorkCentre Pro" vendor="Xerox"><vers num="65 1.001.02.073" prev="1"/><vers num="75 1.001.02.073" prev="1"/><vers num="90 1.001.02.073" prev="1"/><vers num="65 1.001.02.0715" prev="1"/><vers num="75 1.001.02.0715" prev="1"/><vers num="90 1.001.02.0715" prev="1"/></prod><prod name="CopyCentre" vendor="Xerox"><vers num="C65 1.001.02.073" prev="1"/><vers num="C75 1.001.02.073" prev="1"/><vers num="C90 1.001.02.073" prev="1"/><vers num="C65 1.001.02.0715" prev="1"/><vers num="C75 1.001.02.0715" prev="1"/><vers num="C90 1.001.02.0715" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1138" published="2006-03-09" seq="2006-1138" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the web server code in Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, allows remote attackers to cause a denial of service (memory corruption) via unknown vectors.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_002.pdf"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0857">ADV-2006-0857</ref><ref source="OSVDB" url="http://www.osvdb.org/23727">23727</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015738">1015738</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19146">19146</ref><ref source="BID" url="http://www.securityfocus.com/bid/17014">17014</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25175">
xerox-web-corruption-dos(25175)</ref></refs><vuln_soft><prod name="WorkCentre Pro" vendor="Xerox"><vers num="65 1.001.02.073" prev="1"/><vers num="75 1.001.02.073" prev="1"/><vers num="90 1.001.02.073" prev="1"/><vers num="65 1.001.02.0715" prev="1"/><vers num="75 1.001.02.0715" prev="1"/><vers num="90 1.001.02.0715" prev="1"/></prod><prod name="CopyCentre" vendor="Xerox"><vers num="C65 1.001.02.073" prev="1"/><vers num="C75 1.001.02.073" prev="1"/><vers num="C90 1.001.02.073" prev="1"/><vers num="C65 1.001.02.0715" prev="1"/><vers num="C75 1.001.02.0715" prev="1"/><vers num="C90 1.001.02.0715" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1139" published="2006-03-09" seq="2006-1139" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the ESS/ Network Controller in Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, causes the Immediate Image Overwrite feature to fail after a power loss, which could leave data exposed to attack.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.xerox.com/downloads/usa/en/c/cert_XRX06_002.pdf"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0857">ADV-2006-0857</ref><ref source="OSVDB" url="http://www.osvdb.org/23728">23728</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015738">1015738</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19146">19146</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25176">
xerox-image-overwrite-dos(25176)</ref></refs><vuln_soft><prod name="WorkCentre Pro" vendor="Xerox"><vers num="65 1.001.02.073" prev="1"/><vers num="75 1.001.02.073" prev="1"/><vers num="90 1.001.02.073" prev="1"/><vers num="65 1.001.02.0715" prev="1"/><vers num="75 1.001.02.0715" prev="1"/><vers num="90 1.001.02.0715" prev="1"/></prod><prod name="CopyCentre" vendor="Xerox"><vers num="C65 1.001.02.073" prev="1"/><vers num="C75 1.001.02.073" prev="1"/><vers num="C90 1.001.02.073" prev="1"/><vers num="C65 1.001.02.0715" prev="1"/><vers num="C75 1.001.02.0715" prev="1"/><vers num="C90 1.001.02.0715" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1140" published="2006-03-10" seq="2006-1140" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in rss.php in RedBLoG 0.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.x128.net/redblog-05-remote-sql-injection.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0894">ADV-2006-0894</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19181">19181</ref><ref source="BID" url="http://www.securityfocus.com/bid/17041">17041</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25122">redblog-catid-sql-injection(25122)</ref></refs><vuln_soft><prod name="RedBLoG" vendor="RedBLoG"><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1141" published="2006-03-10" seq="2006-1141" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in qmailadmin.c in QmailAdmin before 1.2.10 allows remote attackers to execute arbitrary code via a long PATH_INFO environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/qmailadmin/qmailadmin/qmailadmin.c?r1=1.6.2.10&amp;r2=1.6.2.11"></ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=6691&amp;release_id=395211"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16994">16994</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0852">ADV-2006-0852</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25065">qmialadmin-qmailadmin-bo(25065)</ref><ref source="OSVDB" url="http://www.osvdb.org/23705">23705</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19262">19262</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200611-15.xml">GLSA-200611-15</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23019">23019</ref></refs><vuln_soft><prod name="QmailAdmin" vendor="Inter7"><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.3"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1142" published="2006-03-10" seq="2006-1142" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Ravenous Web Server before 0.7.1 allows remote attackers to access arbitrary rvplg files, with unknown impact.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=131871&amp;release_id=399092"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0859">ADV-2006-0859</ref><ref source="BID" url="http://www.securityfocus.com/bid/17013">17013</ref><ref source="OSVDB" url="http://www.osvdb.org/23706">23706</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25191">
ravenous-rvplg-unauth-access(25191)</ref></refs><vuln_soft><prod name="Ravenous Web Server" vendor="Solido Systems"><vers num="0.7.0"/><vers num="0.6.0"/><vers num="0.5.9"/><vers num="0.5.1"/><vers num="0.5.0"/><vers num="0.4.0"/><vers num="0.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1143" published="2006-03-10" seq="2006-1143" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in FTPoed Blog Engine 1.1 allows remote attackers to inject arbitrary web script or HTML via the comment_body parameter, as used by the comment field, when posting a comment.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426828/100/0/threaded">20060305 FTPoed Blog Engine =&gt;v1.1 HTML Injection Vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015725">1015725</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25138">
ftpoed-comment-xss(25138)</ref></refs><vuln_soft><prod name="FTPoed Blog Engine" vendor="FTPoed"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1144" published="2006-03-10" seq="2006-1144" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in HitHost 1.0.0 allows remote attackers to inject arbitrary web script or HTML via (1) the user parameter in deleteuser.php and (2) the hits parameter in viewuser.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426931/100/0/threaded">20060306 histhost v1.0.0 xss and possible rmdir</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0886">ADV-2006-0886</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19155">19155</ref><ref source="OSVDB" url="http://www.osvdb.org/23757">23757</ref><ref source="OSVDB" url="http://www.osvdb.org/23758">23758</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25105">hithost-viewuser-deleteuser-xss(25105)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17025">17025</ref></refs><vuln_soft><prod name="HitHost" vendor="David Ravenscroft"><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-1145" published="2006-03-10" seq="2006-1145" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the safe_cprintf function in acebot_cmds.c in Alien Arena 2006 Gold Edition 5.00 allows remote attackers (possibly authenticated) to execute arbitrary code via unspecified vectors when the server sends crafted messages to the clients.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426984/100/0/threaded">20060307 Multiple vulnerabilities in Alien Arena 2006 GE 5.00</ref><ref adv="1" source="" url="http://aluigi.altervista.org/adv/aa2k6x-adv.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0882">ADV-2006-0882</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19144">19144</ref><ref source="BID" url="http://www.securityfocus.com/bid/17028">17028</ref><ref source="OSVDB" url="http://www.osvdb.org/23747">23747</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/0147.html">
20060307 Multiple vulnerabilities in Alien Arena 2006 GE 5.00</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25199">
alien-safe-cprintf-format-string(25199)</ref></refs><vuln_soft><prod name="Alien Arena 2006" vendor="COR Entertainment"><vers num="Gold 5.00"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1146" published="2006-03-10" seq="2006-1146" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Cmd_Say_f function in g_cmds.c in Alien Arena 2006 Gold Edition 5.00 allows remote attackers (possibly authenticated) to execute arbitrary code by sending a long message to the server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426984/100/0/threaded">20060307 Multiple vulnerabilities in Alien Arena 2006 GE 5.00</ref><ref adv="1" source="" url="http://aluigi.altervista.org/adv/aa2k6x-adv.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0882">ADV-2006-0882</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19144">19144</ref><ref source="BID" url="http://www.securityfocus.com/bid/17028">17028</ref><ref source="OSVDB" url="http://www.osvdb.org/23748">23748</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/0147.html">
20060307 Multiple vulnerabilities in Alien Arena 2006 GE 5.00</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25200">
alien-cmd-sa-f-bo(25200)</ref></refs><vuln_soft><prod name="Alien Arena 2006" vendor="COR Entertainment"><vers num="Gold 5.00"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-20" name="CVE-2006-1147" published="2006-03-10" seq="2006-1147" severity="Medium" type="CVE"><desc><descript source="cve">The Com_sprintf function in q_shared.c in Alien Arena 2006 Gold Edition 5.00 does not properly NULL terminate certain long strings, which allows remote attackers (possibly authenticated) to cause a denial of service (application crash) via a long skin, weapon, or model name.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426984/100/0/threaded">20060307 Multiple vulnerabilities in Alien Arena 2006 GE 5.00</ref><ref adv="1" source="" url="http://aluigi.altervista.org/adv/aa2k6x-adv.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0882">ADV-2006-0882</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19144">19144</ref><ref source="BID" url="http://www.securityfocus.com/bid/17028">17028</ref><ref source="OSVDB" url="http://www.osvdb.org/23749">23749</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/0147.html">
20060307 Multiple vulnerabilities in Alien Arena 2006 GE 5.00</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25201">
alien-com-sprintf-dos(25201)</ref></refs><vuln_soft><prod name="Alien Arena 2006" vendor="COR Entertainment"><vers num="Gold 5.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-22" name="CVE-2006-1148" published="2006-03-10" seq="2006-1148" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the procConnectArgs function in servmgr.cpp in PeerCast before 0.1217 allow remote attackers to execute arbitrary code via an HTTP GET request with a long (1) parameter name or (2) value in a URL, which triggers the overflow in the nextCGIarg function in servhs.cpp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427160/100/0/threaded">20060309 INFIGO-2006-03-01: PeerCast streaming server remote buffer overflow</ref><ref adv="1" patch="1" source="" url="http://www.infigo.hr/in_focus/INFIGO-2006-03-01"></ref><ref source="" url="http://www.peercast.org/forum/viewtopic.php?t=3346"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17040">17040</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200603-17.xml">GLSA-200603-17</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0900">ADV-2006-0900</ref><ref source="OSVDB" url="http://www.osvdb.org/23777">23777</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19169">19169</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25113">peercast-url-bo(25113)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19291">19291</ref></refs><vuln_soft><prod name="PeerCast" vendor="PeerCast"><vers num="0.1212"/><vers num="0.1211"/><vers num="0.1215"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1149" published="2006-03-10" seq="2006-1149" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in lib/OWL_API.php in OWL Intranet Engine 0.82, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the xrms_file_root parameter, which is not initialized before use.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="milw0rm.com" url="http://milw0rm.com/exploits/1561">N/A</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0868">ADV-2006-0868</ref><ref source="OSVDB" url="http://www.osvdb.org/23734">23734</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19142">19142</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25082">owl-intranet-owlapi-file-include(25082)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17021">17021</ref></refs><vuln_soft><prod name="Owl Intranet Engine" vendor="Owl"><vers num="0.82"/><vers num="0.8"/><vers num="0.73"/><vers num="0.72"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1150" published="2006-03-10" seq="2006-1150" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Tenes Empanadas Graciela (TEG) 0.11.1, automatically appends an _ (underscore) to the end of duplicate nicknames, which allows remote attackers to cause a denial of service (application crash) by creating multiple users with long, identical nicknames, which triggers an off-by-one error.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/tegob1-adv.txt">Tenes Empanadas Graciela (TEG)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16982">16982</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0846">ADV-2006-0846</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19134">19134</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25165">
teg-nickname-offbyone-dos(25165)</ref></refs><vuln_soft><prod name="Tenes Empanadas Graciela" vendor="TEG"><vers num="0.11.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1151" published="2006-03-10" seq="2006-1151" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in index.php in M-Phorum 0.2 allows remote attackers to inject arbitrary web script or HTML via the go parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427165/100/0/threaded">20060309 M-Phorum Cross Site Scripting</ref><ref source="" url="http://biyosecurity.be/bugs/mphorum.txt"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19121">19121</ref><ref source="OSVDB" url="http://www.osvdb.org/23951">23951</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25312">
mphorum-index-xss(25312)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/477253/100/0/threaded">20070821 Vulnerabilities digest</ref><ref source="" url="http://securityvulns.com/Ldocument750.html"></ref><ref source="" url="http://securityvulns.com/source13951.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/25394">25394</ref></refs><vuln_soft><prod name="M_Phorum" vendor="M_Phorum"><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1152" published="2006-03-10" seq="2006-1152" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in M-Phorum 0.2 allows remote attackers to include arbitrary files via the go parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16977">16977</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0827">ADV-2006-0827</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19121">19121</ref><ref source="OSVDB" url="http://www.osvdb.org/23740">23740</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25102">
mphorum-index-file-include(25102)</ref></refs><vuln_soft><prod name="M_Phorum" vendor="M_Phorum"><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1153" published="2006-03-10" seq="2006-1153" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in D2-Shoutbox 4.2 allows remote attackers to execute arbitrary SQL commands via the load parameter, when performing a Shoutbox action through Invision Power Board (IPB).</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="milw0rm.com" url="http://milw0rm.com/exploits/1556">D2-Shoutbox 4.2(IPB Mod)&lt;=SQL injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/16984">16984</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0865">ADV-2006-0865</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19132">19132</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25074">d2shoutbox-index-sql-injection(25074)</ref></refs><vuln_soft><prod name="D2-Shoutbox" vendor="D2-Shoutbox"><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-27" name="CVE-2006-1154" published="2006-03-10" seq="2006-1154" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in archive.php in Fantastic News 2.1.2 allows remote attackers to include arbitrary files via the CONFIG[script_path] variable.  NOTE: 2.1.4 was also reported to be vulnerable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16985">16985</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0826">ADV-2006-0826</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25064">fantasticnews-archive-file-include(25064)</ref><ref source="" url="http://sx02.coresec.de/advisories/152.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3513">ADV-2006-3513</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21807">21807</ref><ref source="" url="http://www.milw0rm.com/exploits/3027"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23519">23519</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31121">fantasticnews-configscriptpath-file-include(31121)</ref><ref source="BID" url="http://www.securityfocus.com/bid/21796">21796</ref></refs><vuln_soft><prod name="Fantastic News" vendor="Fscripts"><vers num="2.1.4"/><vers num="2.1.2"/><vers num="2.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1155" published="2006-03-12" seq="2006-1155" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in manas tungare Site Membership Script before 8 March, 2006 allows remote attackers to inject arbitrary web script or HTML via the Error parameter in (1) login.asp and (2) default.asp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="manastungare.com" url="http://www.manastungare.com/projects/site-membership/">N/A</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0884">ADV-2006-0884</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19156">19156</ref><ref source="BID" url="http://www.securityfocus.com/bid/17045">17045</ref><ref source="OSVDB" url="http://www.osvdb.org/23753">23753</ref><ref source="OSVDB" url="http://www.osvdb.org/23754">23754</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25109">manas-tungare-login-default-xss(25109)</ref></refs><vuln_soft><prod name="Site Membership Script" vendor="Manas Tungare"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1156" published="2006-03-12" seq="2006-1156" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in manas tungare Site Membership Script before 8 March, 2006 allows remote attackers to execute arbitrary SQL commands via the Username parameter in login.asp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="manastungare.com" url="http://www.manastungare.com/projects/site-membership/">N/A</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0884">ADV-2006-0884</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19156">19156</ref><ref source="BID" url="http://www.securityfocus.com/bid/17045">17045</ref><ref source="OSVDB" url="http://www.osvdb.org/23755">23755</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25110">manas-tungare-login-sql-injection(25110)</ref></refs><vuln_soft><prod name="Site Membership Script" vendor="Manas Tungare"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1157" published="2006-03-12" seq="2006-1157" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Vz Scripts ADP Forum 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the Subject field (possibly messaggio parameter) when posting a new message in post.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427171/100/0/threaded">20060309 ADP Forum 2.0,* script &amp;#304;njection</ref><ref source="biyosecurity" url="http://biyosecurity.be/bugs/adpforum2.txt">ADP Forum 2.0,*  script  &amp;#xdd;njection</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0901">ADV-2006-0901</ref><ref source="BID" url="http://www.securityfocus.com/bid/17047">17047</ref><ref source="OSVDB" url="http://www.osvdb.org/23961">23961</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25189">
adp-forum-subject-xss(25189)</ref></refs><vuln_soft><prod name="ADP Forum" vendor="ADP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-27" name="CVE-2006-1158" published="2006-03-12" seq="2006-1158" severity="High" type="CVE"><desc><descript source="cve">Kerio MailServer before 6.1.3 Patch 1 allows remote attackers to cause a denial of service (application crash) via a crafted IMAP LOGIN command.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="kerio.com" url="http://www.kerio.com/kms_history.html">N/A</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0898">ADV-2006-0898</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19150">19150</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427471/100/0/threaded">20060313 Kerio MailServer bugfun</ref><ref source="BID" url="http://www.securityfocus.com/bid/17043">17043</ref><ref source="OSVDB" url="http://www.osvdb.org/23772">23772</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015748">1015748</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25150">kerio-mailserver-imap-dos(25150)</ref></refs><vuln_soft><prod name="Kerio MailServer" vendor="Kerio"><vers num="6.1.3 Patch 1"/><vers num="6.0.8"/><vers num="6.0.7"/><vers num="6.0.6"/><vers num="6.0.5"/><vers num="6.0.4"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0.0"/><vers num="6.0"/><vers num="5.7.9"/><vers num="5.7.8"/><vers num="5.7.7"/><vers num="5.7.6"/><vers num="5.7.5"/><vers num="5.7.4"/><vers num="5.7.3"/><vers num="5.7.2"/><vers num="5.7.10"/><vers num="5.7.1"/><vers num="5.7.0"/><vers num="5.6.5"/><vers num="5.6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-11-07" name="CVE-2006-1159" published="2006-03-12" seq="2006-1159" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in the query string argument in an HTTP GET request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427158/100/0/threaded">20060309 Easy File Sharing Web Server Multiple Vulnerablilities</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19178">19178</ref><ref source="BID" url="http://www.securityfocus.com/bid/17046">17046</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0912">ADV-2006-0912</ref><ref source="OSVDB" url="http://www.osvdb.org/23792">23792</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25135">easyfilesharing-logging-dos(25135)</ref></refs><vuln_soft><prod name="EFS Web Server" vendor="EFS Software"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-11-07" name="CVE-2006-1160" published="2006-03-12" seq="2006-1160" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote attackers to inject arbitrary web script or HTML via the Description field in creating a folder or uploading a file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427158/100/0/threaded">20060309 Easy File Sharing Web Server Multiple Vulnerablilities</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19178">19178</ref><ref source="BID" url="http://www.securityfocus.com/bid/17046">17046</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0912">ADV-2006-0912</ref><ref source="OSVDB" url="http://www.osvdb.org/23793">23793</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25136">easyfilesharing-description-xss(25136)</ref></refs><vuln_soft><prod name="EFS Web Server" vendor="EFS Software"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-11-07" name="CVE-2006-1161" published="2006-03-12" seq="2006-1161" severity="Medium" type="CVE"><desc><descript source="cve">Absolute path traversal vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote registered users to execute arbitrary code by uploading a malicious file to the Windows startup folder.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427158/100/0/threaded">20060309 Easy File Sharing Web Server Multiple Vulnerablilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17046">17046</ref><ref source="OSVDB" url="http://www.osvdb.org/23791">23791</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39994">easyfilesharing-startup-file-upload(39994)</ref></refs><vuln_soft><prod name="EFS Web Server" vendor="EFS Software"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1162" published="2006-03-12" seq="2006-1162" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Nodez 4.6.1.1 and earlier allows remote attackers to read or include arbitrary PHP files via a ..  (dot dot) in the op parameter, as demonstrated by inserting malicious Email parameters into list.gtdat, then accessing list.gtdat using the op parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Hamid Ebadi" url="http://hamid.ir/security/nodez.txt">Local File Inclusion</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0899">ADV-2006-0899</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19165">19165</ref><ref source="BID" url="http://www.securityfocus.com/bid/17066">17066</ref><ref source="OSVDB" url="http://www.osvdb.org/23774">23774</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015747">1015747</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25119">nodez-op-file-include(25119)</ref></refs><vuln_soft><prod name="Nodez" vendor="Nodez"><vers num="4.6.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1163" published="2006-03-12" seq="2006-1163" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Nodez 4.6.1.1 allows remote attackers to inject arbitrary web script or HTML via the op parameter.  NOTE: it is possible that this issue is resultant from the directory traversal vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Hamid Ebadi" url="http://hamid.ir/security/nodez.txt">PHP Code Injection </ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0899">ADV-2006-0899</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19165">19165</ref><ref source="BID" url="http://www.securityfocus.com/bid/17066">17066</ref><ref source="OSVDB" url="http://www.osvdb.org/23776">23776</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015747">1015747</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25121">nodez-op-xss(25121)</ref></refs><vuln_soft><prod name="Nodez" vendor="Nodez"><vers num="4.6.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1164" published="2006-03-12" seq="2006-1164" severity="High" type="CVE"><desc><descript source="cve">Nodez 4.6.1.1 and earlier stores sensitive data in the list.gtdat file under the web document root with insufficient access control, which allows remote attackers to obtain usernames and password hashes by directly accessing list.gtdat.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="Hamid Ebadi" url="http://hamid.ir/security/nodez.txt">N/A</ref><ref source="BID" url="http://www.securityfocus.com/bid/17066">17066</ref><ref source="OSVDB" url="http://www.osvdb.org/23775">23775</ref></refs><vuln_soft><prod name="Nodez" vendor="Nodez"><vers num="4.6.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1165" published="2006-03-12" seq="2006-1165" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors relating to &quot;handling EXIF data.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="wiki.splitbrain.org" url="http://wiki.splitbrain.org/wiki%3Achanges">Release 2006-03-05</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0909">ADV-2006-0909</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19186">19186</ref><ref source="BID" url="http://www.securityfocus.com/bid/17065">17065</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25137">dokuwiki-mediamanger-xss(25137)</ref></refs><vuln_soft><prod name="DokuWiki" vendor="Andreas Gohr"><vers num="Release 2006-03-05"/><vers num="Release 2006-03-05"/><vers num="Release 2005-09-22"/><vers num="Release 2005-09-19"/><vers num="Release 2005-07-13"/><vers num="Release 2005-07-01"/><vers num="Release 2005-05-07"/><vers num="Release 2005-02-18"/><vers num="Release 2005-02-06"/><vers num="Release 2005-01-16a"/><vers num="Release 2005-01-15"/><vers num="Release 2005-01-14"/><vers num="Release 2004-11-10"/><vers num="Release 2004-11-02"/><vers num="Release 2004-11-01"/><vers num="Release 2004-10-19"/><vers num="Release 2004-09-30"/><vers num="Release 2004-09-25"/><vers num="Release 2004-09-12"/><vers num="Release 2004-08-22"/><vers num="Release 2004-08-15a"/><vers num="Release 2004-08-08"/><vers num="Release 2004-07-25"/><vers num="Release 2004-07-21"/><vers num="Release 2004-07-12"/><vers num="Release 2004-07-07"/><vers num="Release 2004-07-04"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1166" published="2006-03-12" seq="2006-1166" severity="Low" type="CVE"><desc><descript source="cve">Monotone 0.25 and earlier, when a user creates a file in a directory called &quot;mt&quot;, and when checking out that file on a case-insensitive file system such as Windows or Mac OS X, places the file into the &quot;MT&quot; bookkeeping directory, which could allow context-dependent attackers to execute arbitrary Lua programs as the user running monotone.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref patch="1" source="MLIST" url="http://lists.gnu.org/archive/html/monotone-devel/2006-03/msg00062.html">[Monotone-devel] 20060308 [ANNOUNCE] Monotone 0.25.2 -- security fix release</ref><ref source="BID" url="http://www.securityfocus.com/bid/17139">17139</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0990">ADV-2006-0990</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19260">19260</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25294">
monotone-mt-lua-code-execution(25294)</ref></refs><vuln_soft><prod name="Monotone" vendor="Monotone"><vers num="0.25"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-07" name="CVE-2006-1167" published="2007-02-06" seq="2006-1167" severity="Low" type="CVE"><desc><descript source="cve">SGI ProPack 3 SP6 kernel displays the frame buffer contents of the last session after a reboot, which might allow local users to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U">20060402-01-U</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/24571">24571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19607">
19607</ref></refs><vuln_soft><prod name="ProPack" vendor="SGI"><vers num="3 SP6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-15" name="CVE-2006-1168" published="2006-08-14" seq="2006-1168" severity="High" type="CVE"><desc><descript source="cve">The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=141728"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1149">DSA-1149</ref><ref adv="1" patch="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:140">MDKSA-2006:140</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3234">ADV-2006-3234</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21427">21427</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/21434">21434</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/21437">21437</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_20_sr.html">SUSE-SR:2006:020</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/28315">ncompress-decompress-underflow(28315)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0663.html">RHSA-2006:0663</ref><ref source="BID" url="http://www.securityfocus.com/bid/19455">19455</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016836">1016836</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21880">21880</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc">20060901-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22036">22036</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200610-03.xml">GLSA-200610-03</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22296">22296</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-226.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/22377">22377</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21467">
21467</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:140">MDKSA-2006:140</ref></refs><vuln_soft><prod name="ncompress" vendor="ncompress"><vers num="4.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-05" modified="2006-05-09" name="CVE-2006-1172" published="2006-05-09" seq="2006-1172" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the createPKCS10 function in Cryptomathic Cenroll ActiveX Control 1.1.0.0 allows remote attackers to execute arbitrary code via vectors related to the TDC Digital signature.</descript></desc><loss_types><int/></loss_types><vuln_types><input bound="1" buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433079/100/0/threaded">20060505 Cryptomathic ActiveX Buffer Overflow (TDC Digital signature)</ref><ref adv="1" source="" url="http://cirt.dk/advisories/cirt-43-advisory.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17852">17852</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1675">ADV-2006-1675</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/25282">25282</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016034">1016034</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19968">19968</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26255">
cryptomathic-primeink-createpkcs10-bo(26255)</ref></refs><vuln_soft><prod name="Cryptomathic Cenroll ActiveX Control" vendor="TDC"><vers num="1.1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-06-19" name="CVE-2006-1173" published="2006-06-07" seq="2006-1173" severity="Medium" type="CVE"><desc><descript source="cve">Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk consumption by core dump files.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="HP" url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635">HPSBTU02116</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/146718">VU#146718</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20473">20473</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2189">ADV-2006-2189</ref><ref adv="1" patch="1" source="" url="http://www.sendmail.com/security/advisories/SA-200605-01.txt.asc"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0515.html">RHSA-2006:0515</ref><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102460-1">102460</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18433">18433</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016295">1016295</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15779">15779</ref><ref source="" url="http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-18.html"></ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY85415&amp;apar=only">IY85415</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY85930&amp;apar=only">IY85930</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:17.sendmail.asc">FreeBSD-SA-06:17.sendmail</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200606-19.xml">GLSA-200606-19</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:104">MDKSA-2006:104</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata38.html#sendmail2">[3.8] 008: SECURITY FIX: June 15, 2006</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060601-01-P">20060601-01-P</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.631382">SSA:2006-166-01</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Jun/0006.html">SUSE-SA:2006:032</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2351">ADV-2006-2351</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2388">ADV-2006-2388</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2389">ADV-2006-2389</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2390">ADV-2006-2390</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20641">20641</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20650">20650</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20651">20651</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20654">20654</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20673">20673</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20675">20675</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20679">20679</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20683">20683</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20684">20684</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20694">20694</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/437928/100/0/threaded">20060620 Sendmail MIME DoS vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/438241/100/0/threaded">20060621 Re: Sendmail MIME DoS vulnerability</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc">20060602-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20726">20726</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20782">20782</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/438330/100/0/threaded">20060624 Re: Sendmail MIME DoS vulnerability</ref><ref source="" url="http://www.f-secure.com/security/fsc-2006-5.shtml"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2798">ADV-2006-2798</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21042">21042</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/440744/100/0/threaded">20060721 rPSA-2006-0134-1 sendmail sendmail-cf</ref><ref source="" url="https://issues.rpath.com/browse/RPL-526"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21160">21160</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/442939/100/0/threaded">HPSBUX02124</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3135">ADV-2006-3135</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21327">21327</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1155">DSA-1155</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21612">21612</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-148.htm"></ref><ref source="OSVDB" url="http://www.osvdb.org/26197">26197</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21647">21647</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27128">
sendmail-multipart-mime-dos(27128)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:104">MDKSA-2006:104</ref></refs><vuln_soft><prod name="Sendmail" vendor="Sendmail Consortium"><vers num="8.13.6"/><vers num="8.13.5"/><vers num="8.13.4"/><vers num="8.13.3"/><vers num="8.12.11"/><vers num="8.12.9"/><vers num="8.12.8"/><vers num="8.12.7"/><vers num="8.12.6"/><vers num="8.12.5"/><vers num="8.12.4"/><vers num="8.12.3"/><vers num="8.12.2"/><vers num="8.12.1"/><vers num="8.12 beta7"/><vers num="8.12 Beta5"/><vers num="8.12 Beta16"/><vers num="8.12 Beta12"/><vers num="8.12 Beta10"/><vers num="8.12.10"/><vers num="8.12.0"/><vers num="8.11.7"/><vers num="8.11.6"/><vers num="8.11.5"/><vers num="8.11.4"/><vers num="8.11.3"/><vers num="8.11.2"/><vers num="8.11.1"/><vers num="8.11"/><vers num="8.10.2"/><vers num="8.10.1"/><vers num="8.10"/><vers num="8.9.3"/><vers num="8.9.2"/><vers num="8.9.1"/><vers num="8.9.0"/><vers num="8.8.8"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-24" name="CVE-2006-1174" published="2006-05-28" seq="2006-1174" severity="Low" type="CVE"><desc><descript source="cve">useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref patch="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:090">MDKSA-2006:090</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18111">18111</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2006">ADV-2006-2006</ref><ref source="" url="http://cvs.pld.org.pl/shadow/NEWS?rev=1.109"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20370">20370</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200606-02.xml">GLSA-200606-02</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20506">20506</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26958">
shadow-utils-useradd-file-permission(26958)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0276.html">
RHSA-2007:0276</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25098">
25098</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/468336/100/0/threaded">

20070511 rPSA-2007-0096-1 shadow</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1357"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/25267">
25267</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-249.htm"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:090">MDKSA-2006:090</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0431.html">RHSA-2007:0431</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc">20070602-01-P</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3229">ADV-2007-3229</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018221">1018221</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25629">25629</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25894">25894</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25896">25896</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26909">26909</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27706">27706</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/312692">VU#312692</ref></refs><vuln_soft><prod name="shadow" vendor="Debian"><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5"/><vers num="4.0.4.1"/><vers num="4.0.4"/><vers num="4.0.2"/><vers num="4.0.1"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-31" name="CVE-2006-1175" published="2006-05-31" seq="2006-1175" severity="Medium" type="CVE"><desc><descript source="cve">The WeOnlyDo! SFTP (wodSFTP) ActiveX control is marked as safe for scripting, which allows remote attackers to read and write files in arbitrary locations by accessing the control from a web page.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/><config/></vuln_types><range><network/><user_init/></range><refs><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/378604">VU#378604</ref><ref source="BID" url="http://www.securityfocus.com/bid/18192">18192</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2064">ADV-2006-2064</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20361">20361</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26752">
wodsftp-activex-unauth-access(26752)</ref></refs><vuln_soft><prod name="WeOnlyDo SFTP" vendor="WeOnlyDo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-07-21" name="CVE-2006-1176" published="2006-07-07" seq="2006-1176" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in eBay Enhanced Picture Services (aka EPUImageControl Class) in EUPWALcontrol.dll before 1.0.3.48, as used in Sell Your Item (SYI), Setup &amp; Test eBay Enhanced Picture Services, Picture Manager Enhanced Uploader, and CARad.com Add Vehicle, allows remote attackers to execute arbitrary code via a crafted HTML document.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.kb.cert.org/vuls/id/MIMG-6QKPVH"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/597721">VU#597721</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2698">ADV-2006-2698</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016445">1016445</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20969">20969</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27631">ebay-epuimagecontrol-bo(27631)</ref><ref source="BID" url="http://www.securityfocus.com/bid/18921">18921</ref></refs><vuln_soft><prod name="Enhanced Picture Services" vendor="eBay"><vers num="1.0.3.36" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-01" name="CVE-2006-1178" published="2006-07-28" seq="2006-1178" severity="Medium" type="CVE"><desc><descript source="cve">Tamarack MMSd before 7.992 allows remote attackers to cause a denial of service (crash) via malformed RFC1006 (OSI over TCP/IP) packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.kb.cert.org/vuls/id/JGEI-6RZPUT"></ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/372878">VU#372878</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/28053">tamarack-mmsd-packet-dos(28053)</ref><ref source="BID" url="http://www.securityfocus.com/bid/19202">19202</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3080">ADV-2006-3080</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016734">1016734</ref></refs><vuln_soft><prod name="Tamarack MMSd" vendor="Tamarack Consulting"><vers num="7.991"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="4.9" CVSS_score="2.6" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2006-1182" published="2006-03-15" seq="2006-1182" severity="Low" type="CVE"><desc><descript source="cve">Adobe Graphics Server 2.0 and 2.1 (formerly AlterCast) and Adobe Document Server (ADS) 5.0 and 6.0 allows local users to read files with certain extensions or overwrite arbitrary files and execute code via a crafted SOAP request to the AlterCast web service in which the request uses the (1) saveContent or (2) saveOptimized ADS commands, or the (3) loadContent command.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427730/100/0/threaded">20060315 Secunia Research: Adobe Document/Graphics Server File URI ResourceAccess</ref><ref patch="1" source="adobe.com" url="http://www.adobe.com/support/techdocs/332989.html">Adobe Graphics Server and Adobe Document Server configuration security vulnerability </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17113">17113</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015769">1015769</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19229">19229</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0956">ADV-2006-0956</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015768">1015768</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25247">adobe-unauth-command-access(25247)</ref><ref source="OSVDB" url="http://www.osvdb.org/23924">23924</ref><ref source="SREASON" url="http://securityreason.com/securityalert/588">588</ref></refs><vuln_soft><prod name="Document Server" vendor="Adobe"><vers num="6.0"/><vers num="5.0"/></prod><prod name="Graphics Server" vendor="Adobe"><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-13" name="CVE-2006-1183" published="2006-03-13" seq="2006-1183" severity="High" type="CVE"><desc><descript source="cve">The Ubuntu 5.10 installer does not properly clear passwords from the installer log file (questions.dat), and leaves the log file with world-readable permissions, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-262-1">USN-262-1</ref><ref source="Launchpad.net" url="https://launchpad.net/distros/ubuntu/+source/shadow/+bug/34606">Bug #34606 in shadow (Ubuntu)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17086">17086</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015761">1015761</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0927">ADV-2006-0927</ref><ref source="OSVDB" url="http://www.osvdb.org/23868">23868</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19200">19200</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25170">ubuntu-installer-password-disclosure(25170)</ref></refs><vuln_soft><prod name="Ubuntu Linux" vendor="Ubuntu"><vers num="5.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-10-11" modified="2006-05-10" name="CVE-2006-1184" published="2006-05-09" seq="2006-1184" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability.  NOTE: this is a variant of CVE-2005-2119.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433425/100/0/threaded">20060509 [EEYEB20051011B] - Microsoft Distributed Transaction Coordinator Denial of Service</ref><ref adv="1" patch="1" source="" url="http://www.eeye.com/html/research/advisories/AD20060509b.html"></ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-018.mspx">MS06-018</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17905">17905</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1742">ADV-2006-1742</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20000">20000</ref><ref source="OSVDB" url="http://www.osvdb.org/25336">25336</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016047">1016047</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1295">oval:org.mitre.oval:def:1295</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1779">oval:org.mitre.oval:def:1779</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1912">oval:org.mitre.oval:def:1912</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1990">oval:org.mitre.oval:def:1990</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25558">
msdtc-message-dos(25558)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/864">864</ref></refs><vuln_soft><prod name="distributed transaction coordinator" vendor="Microsoft"><vers num=""/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/><vers num="Terminal Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="4.0 SP6a"/><vers num="4.0 SP6"/><vers num="4.0 SP5"/><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="64-bit"/><vers num="64-bit"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Web"/><vers edition="64-bit" num="Standard"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Enterprise"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-11" modified="2006-04-12" name="CVE-2006-1185" published="2006-04-11" seq="2006-1185" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx">MS06-013</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/503124">VU#503124</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html">TA06-101A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1318">ADV-2006-1318</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18957">18957</ref><ref source="BID" url="http://www.securityfocus.com/bid/17450">17450</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015900">1015900</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1677">oval:org.mitre.oval:def:1677</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1711">oval:org.mitre.oval:def:1711</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:787">oval:org.mitre.oval:def:787</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25542">
ie-html-execute-code(25542)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows 2000 SP4" num="5.01 SP4"/><vers edition="Windows 2000 SP4" num="6 SP1"/><vers edition="Windows XPSP1" num="6 SP1"/><vers edition="Windows XP SP2" num="6"/><vers edition="Windows Server 2003 SP1" num="6"/><vers edition="Windows Server 2003 SP1" num="6 SP1"/><vers edition="Windows Server 2003 SP1" num="6"/><vers edition="Windows Server 2003 SP1 Itanium systems" num="6 SP1"/><vers edition="Windows Server 2003 SP1" num="6"/><vers edition="Windows XP Professional 64bit" num="6"/><vers num="6 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1186" published="2006-04-11" seq="2006-1186" severity="High" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx">MS06-013</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html">TA06-101A</ref><ref source="BID" url="http://www.securityfocus.com/bid/17453">17453</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1318">ADV-2006-1318</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18957">18957</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015900">1015900</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1446">oval:org.mitre.oval:def:1446</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1589">oval:org.mitre.oval:def:1589</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1651">oval:org.mitre.oval:def:1651</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1704">oval:org.mitre.oval:def:1704</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:791">oval:org.mitre.oval:def:791</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/959049">
VU#959049</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25545">
ie-com-activex-execute-code(25545)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows Server 2003 SP1" num="6"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5 preview"/><vers num="5.5"/><vers num="5.1"/><vers edition="Windows 2000 SP4" num="5.01 SP4"/><vers num="5.01 SP4"/><vers num="5.01 SP3"/><vers num="5.01 SP2"/><vers num="5.01 SP1"/><vers num="5.01"/><vers num="5.0.1 SP4"/><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers edition="Windows NT 4.0" num="5.0.1"/><vers edition="Windows 98" num="5.0.1"/><vers edition="Windows 95" num="5.0.1"/><vers edition="Windows 2000" num="5.0.1"/><vers num="5.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-12" name="CVE-2006-1188" published="2006-04-11" seq="2006-1188" severity="High" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx">MS06-013</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/824324">VU#824324</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html">TA06-101A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1318">ADV-2006-1318</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18957">18957</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015900">1015900</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1144">oval:org.mitre.oval:def:1144</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1290">oval:org.mitre.oval:def:1290</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1296">oval:org.mitre.oval:def:1296</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1773">oval:org.mitre.oval:def:1773</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435096/30/4710/threaded">

20060525 [BuHa-Security] MS06-013: HTML Tag Memory Corruption Vulnerability in MS IE 6 SP2</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0.2900.2180"/><vers num="6.0.2800.1106"/><vers num="6.0.2800"/><vers num="6.0.2600"/><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers edition="Windows Server 2003" num="6.0"/><vers num="6.0"/><vers edition="Windows XPSP1" num="6 SP1"/><vers edition="Windows Server 2003 SP1 Itanium systems" num="6 SP1"/><vers edition="Windows Server 2003 SP1" num="6 SP1"/><vers edition="Windows 2000 SP4" num="6 SP1"/><vers num="6 SP1"/><vers edition="Windows XP SP2" num="6"/><vers edition="Windows XP Professional 64bit" num="6"/><vers edition="Windows Server 2003 SP1" num="6"/><vers edition="Windows Server 2003 SP1" num="6"/><vers edition="Windows Server 2003 SP1" num="6"/><vers edition="Windows Server 2003 SP1" num="6"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5 preview"/><vers num="5.5"/><vers edition="Macintosh" num="5.2.3"/><vers edition="Mac OS" num="5.1"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2006-1189" published="2006-04-11" seq="2006-1189" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with an International Domain Name (IDN) using double-byte character sets (DBCS), aka the &quot;Double Byte Character Parsing Memory Corruption Vulnerability.&quot;</descript></desc><sols><sol source="nvd">Customers should apply the update immediately.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx">MS06-013</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html">TA06-101A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/341028">VU#341028</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1318">ADV-2006-1318</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18957">18957</ref><ref source="BID" url="http://www.securityfocus.com/bid/17454">17454</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015900">1015900</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1020">oval:org.mitre.oval:def:1020</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1484">oval:org.mitre.oval:def:1484</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:792">oval:org.mitre.oval:def:792</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0227.html">20060411 Microsoft Internet Explorer DBCS Remote Memory Corruption Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25551">ie-double-byte-execute-code(25551)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.1"/><vers num="5.5"/><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-12" name="CVE-2006-1190" published="2006-04-11" seq="2006-1190" severity="High" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx">MS06-013</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/959649">VU#959649</ref><ref source="BID" url="http://www.securityfocus.com/bid/17455">17455</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1318">ADV-2006-1318</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18957">18957</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015900">1015900</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1541">oval:org.mitre.oval:def:1541</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1735">oval:org.mitre.oval:def:1735</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1783">oval:org.mitre.oval:def:1783</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:965">oval:org.mitre.oval:def:965</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25552">
ie-ioleclientsite-execute-code(25552)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.1"/><vers num="5.5"/><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-12" name="CVE-2006-1191" published="2006-04-11" seq="2006-1191" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has navigated to another site.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/><user_init/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx">MS06-013</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1318">ADV-2006-1318</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18957">18957</ref><ref source="BID" url="http://www.securityfocus.com/bid/17457">17457</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015892">1015892</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1251">oval:org.mitre.oval:def:1251</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1710">oval:org.mitre.oval:def:1710</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25555">
ie-popup-zone-bypass(25555)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.1"/><vers num="5.5"/><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-1192" published="2006-04-11" seq="2006-1192" severity="Low" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow &quot;window content to persist&quot; after the user has navigated to another site, aka the &quot;Address Bar Spoofing Vulnerability.&quot;  NOTE: this is a different vulnerability than CVE-2006-1626.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx">MS06-013</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17460">17460</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1318">ADV-2006-1318</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18957">18957</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015899">1015899</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1336">oval:org.mitre.oval:def:1336</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1498">oval:org.mitre.oval:def:1498</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1645">oval:org.mitre.oval:def:1645</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1725">oval:org.mitre.oval:def:1725</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1740">oval:org.mitre.oval:def:1740</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25557">
ie-browser-window-spoofing(25557)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/670">670</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows 2000 SP4" num="5.01 SP4"/><vers edition="Windows 2000 SP4" num="6 SP1"/><vers edition="Windows XPSP1" num="6 SP1"/><vers edition="Windows XP SP2" num="6"/><vers edition="Windows Server 2003 SP1" num="6"/><vers edition="Windows Server 2003 SP1" num="6 SP1"/><vers edition="Windows Server 2003 SP1" num="6"/><vers edition="Windows Server 2003 SP1 Itanium systems" num="6 SP1"/><vers edition="Windows Server 2003 SP1" num="6"/><vers edition="Windows XP Professional 64bit" num="6"/><vers num="6 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-1193" published="2006-06-13" seq="2006-1193" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to &quot;HTML parsing.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-029.mspx">MS06-029</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18381">18381</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2326">ADV-2006-2326</ref><ref source="" url="http://www.sec-consult.com/fileadmin/Advisories/20060613-0_owa_xss_noexploit.txt"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-164A.html">TA06-164A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/138188">VU#138188</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016280">1016280</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20634">20634</ref><ref source="OSVDB" url="http://www.osvdb.org/26441">26441</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1070">oval:org.mitre.oval:def:1070</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1161">oval:org.mitre.oval:def:1161</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1315">oval:org.mitre.oval:def:1315</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/046892.html">

20060614 SEC Consult SA-20060613-0 :: Outlook Web Access Cross Site Scripting Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25550">
exchange-owa-xss(25550)</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="2000 SP1"/><vers num="2000 SP2"/><vers num="2000 SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1194" published="2006-03-13" seq="2006-1194" severity="Medium" type="CVE"><desc><descript source="cve">Integer signedness error in the enet_protocol_handle_incoming_commands function in protocol.c for ENet library CVS version Jul 2005 and earlier, as used in products including (1) Cube, (2) Sauerbraten, and (3) Duke3d_w32, allows remote attackers to cause a denial of service (application crash) via a packet with a large command length value, which leads to an invalid memory access.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427465/100/0/threaded">20060312 Multiple vulnerabilities in ENet library (Jul 2005)</ref><ref adv="1" source="" url="http://aluigi.altervista.org/adv/enetx-adv.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0940">ADV-2006-0940</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19208">19208</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015767">1015767</ref><ref source="OSVDB" url="http://www.osvdb.org/23844">23844</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/043541.html">20060312 Multiple vulnerabilities in ENet library (Jul 2005)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17087">17087</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25157">enet-signedness-dos(25157)</ref></refs><vuln_soft><prod name="ENet Library" vendor="ENet"><vers num="Jul 2005" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1195" published="2006-03-13" seq="2006-1195" severity="Medium" type="CVE"><desc><descript source="cve">The enet_protocol_handle_send_fragment function in protocol.c for ENet library CVS version Jul 2005 and earlier, as used in products including (1) Cube, (2) Sauerbraten, and (3) Duke3d_w32, allows remote attackers to cause a denial of service (application crash) via a packet fragment with a large total data size, which triggers an application abort when memory allocation fails.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427465/100/0/threaded">20060312 Multiple vulnerabilities in ENet library (Jul 2005)</ref><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/enetx-adv.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0940">ADV-2006-0940</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19208">19208</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015767">1015767</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/043541.html">20060312 Multiple vulnerabilities in ENet library (Jul 2005)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17087">17087</ref><ref source="OSVDB" url="http://www.osvdb.org/23845">23845</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25158">enet-packet-dos(25158)</ref></refs><vuln_soft><prod name="ENet Library" vendor="ENet"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1196" published="2006-03-13" seq="2006-1196" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in QwikiWiki 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) from and (2) help parameters to (a) index.php; (3) action, (4) page, (5) debug, (6) help, (7) username, or (8) password parameters to (b) login.php; the (7) help parameter to (c) pageindex.php; or (8) help parameter to (d) recentchanges.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="altervista.org" url="http://kiki91.altervista.org/exploit/qwikiwiki_1.0.5_xss.txt">QwikiWiki 1.5 &lt;== Multiple Script Insertion Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17064">17064</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19182">19182</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25128">qwikiwiki-multiple-scripts-xss(25128)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0910">ADV-2006-0910</ref><ref source="OSVDB" url="http://www.osvdb.org/23786">23786</ref><ref source="OSVDB" url="http://www.osvdb.org/23787">23787</ref><ref source="OSVDB" url="http://www.osvdb.org/23788">23788</ref><ref source="OSVDB" url="http://www.osvdb.org/23789">23789</ref></refs><vuln_soft><prod name="QwikiWiki" vendor="David Barrett"><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1197" published="2006-03-13" seq="2006-1197" severity="High" type="CVE"><desc><descript source="cve">SafeDisc installs the driver service for the secdrv.sys driver with insecure permissions, which allows local users to gain privileges by changing the configuration to reference a malicious program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427410/100/0/threaded">20060311 Copy protection scheme SafeDisc allows privilege escalation</ref><ref source="BID" url="http://www.securityfocus.com/bid/17070">17070</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25162">safedisk-secdrv-gain-privileges(25162)</ref></refs><vuln_soft><prod name="SafeDisc" vendor="Macrovision"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1198" published="2006-03-13" seq="2006-1198" severity="Low" type="CVE"><desc><descript source="cve">Comvigo IM Lock 2006 uses a simple substitution cipher to encrypt a password stored in the msnvs\prc registry value, for which all users have Read permission, which allows local users to bypass the product&apos;s blocking functionality by decrypting the password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426935/100/0/threaded">20060306 IM Lock 2006 - Insecure Registry Permission Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0866">ADV-2006-0866</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19140">19140</ref><ref source="BID" url="http://www.securityfocus.com/bid/16988">16988</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25219">
imlock-password-weak-encryption(25219)</ref></refs><vuln_soft><prod name="IM Lock" vendor="Comvigo"><vers num="Home 2006"/><vers num="Professional 2006"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1199" published="2006-03-13" seq="2006-1199" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in iframe.php in daverave Link Bank allows remote attackers to inject arbitrary web script or HTML via the site parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426932/100/0/threaded">20060306 link bank code execution and xss</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0885">ADV-2006-0885</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19154">19154</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25107">linkbank-iframe-xss(25107)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17001">17001</ref><ref source="OSVDB" url="http://www.osvdb.org/23751">23751</ref></refs><vuln_soft><prod name="Link Bank" vendor="DaveRave"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1200" published="2006-03-13" seq="2006-1200" severity="High" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in add_link.txt in daverave Link Bank allows remote attackers to execute arbitrary PHP code via the url_name parameter, which is not sanitized before being stored in links.txt, which is later used in an include statement.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426932/100/0/threaded">20060306 link bank code execution and xss</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0885">ADV-2006-0885</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19154">19154</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25108">linkbank-multiple-php-injection(25108)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17004">17004</ref><ref source="OSVDB" url="http://www.osvdb.org/23750">
23750</ref><ref source="SREASON" url="http://securityreason.com/securityalert/553">553</ref></refs><vuln_soft><prod name="Link Bank" vendor="DaveRave"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-06-20" name="CVE-2006-1201" published="2006-03-13" seq="2006-1201" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in resetpw.php in eschew.net phpBannerExchange 2.0 and earlier, and other versions before 2.0 Update 5, allows remote attackers to read arbitrary files via a .. (dot dot) in the email parameter during a &quot;Recover password&quot; operation (recoverpw.php).</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426940/100/0/threaded">20060307 phpBannerExchange 2.0 Directory Traversal Vulnerability</ref><ref adv="1" source="" url="http://www.h4cky0u.org/advisories/HYSA-2006-004-phpbanner.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0869">ADV-2006-0869</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19127">19127</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25071">phpbannerexchange-resetpw-dir-traversal(25071)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25080">phpbannerexchange-recoverpw-dir-traversal(25080)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0879.html">20060307 phpBannerExchange 2.0 Directory Traversal Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/23720">23720</ref><ref source="BID" url="http://www.securityfocus.com/bid/16996">16996</ref><ref source="" url="http://www.eschew.net/scripts/phpbe/2.0/releasenotes.php"></ref></refs><vuln_soft><prod name="phpBannerExchange" vendor="eschew.net"><vers num="2.0 Update 4"/><vers num="2.0 Update 3"/><vers num="2.0 Update 2"/><vers num="2.0 Update 1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1202" published="2006-03-13" seq="2006-1202" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in textfileBB 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mess and (2) user parameters in messanger.php, possibly requiring a URL encoded value.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427081/100/0/threaded">20060308 textfileBB &lt;= 1.0 Multiple XSS</ref><ref source="" url="http://notlegal.ws/textfilebbmessanger.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0897">ADV-2006-0897</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19149">19149</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015744">1015744</ref><ref source="BID" url="http://www.securityfocus.com/bid/17029">17029</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25091">
textbb-messanger-xss(25091)</ref></refs><vuln_soft><prod name="textfileBB" vendor="Jcink.com"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1203" published="2006-03-13" seq="2006-1203" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in common.php in txtForum 1.0.4-dev and earlier allows remote attackers to include and execute arbitrary PHP code via a URL in the skin parameter to login.php, and possibly other parameters to other PHP scripts, related to include statements in common.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427188/100/0/threaded">20060309 txtForum: Script Injection Vulnerability</ref><ref adv="1" source="" url="http://www.seclab.tuwien.ac.at/advisories/TUVSA-0603-004.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17061">17061</ref><ref source="OSVDB" url="http://www.osvdb.org/23952">23952</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25131">txtforum-login-file-include(25131)</ref></refs><vuln_soft><prod name="txtForum" vendor="txtForum"><vers num="1.0.4 DEV" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1204" published="2006-03-13" seq="2006-1204" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in txtForum 1.0.4-dev and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prev, (2) next, and (3) rand5 parameters in (a) index.php; the (4) r_username and (5) r_loc parameters in (b) new_topic.php; the (6) r_num, (7) r_family_name, (8) r_icq, (9) r_yahoo, (10) r_aim, (11) r_homepage, (12) r_interests, (13) r_about, (14) selected1, (15) selected0, (16) signature_selected1, (17) signature_selected0, (18) smile_selected1, (19) smile_selected0, (20) ubb_selected1, and (21) ubb_selected0 parameters in (c) profile.php; the (22) quote and (23) tid parameters in (d) reply.php; and the (24) tid, (25) sticked, and (26) mid parameters in (e) view_topic.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427186/100/0/threaded">20060309 txtForum: Multiple XSS Vulnerabilities</ref><ref adv="1" source="" url="http://www.seclab.tuwien.ac.at/advisories/TUVSA-0603-003.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17054">17054</ref><ref source="OSVDB" url="http://www.osvdb.org/23953">23953</ref><ref source="OSVDB" url="http://www.osvdb.org/23954">23954</ref><ref source="OSVDB" url="http://www.osvdb.org/23955">23955</ref><ref source="OSVDB" url="http://www.osvdb.org/23956">23956</ref><ref source="OSVDB" url="http://www.osvdb.org/23957">23957</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25132">txtforum-multiple-xss(25132)</ref></refs><vuln_soft><prod name="txtForum" vendor="txtForum"><vers num="1.0.4 DEV" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-07" name="CVE-2006-1205" published="2006-03-13" seq="2006-1205" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in myWebland myBloggie 2.1.3 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) confirmredirect and (2) post_id parameters in (a) delcomment.php, as reachable when mode=delcom from index.php; and the (3) del and (4) message parameters in (b) upload.php, the (5) errormsg parameter in (c) addcat.php, (d) edituser.php, (e) adduser.php, and (f) editcat.php, the (6) trackback_url parameter in (g) add.php, (7) id parameter in (h) deluser.php, (8) cat_id parameter in (i) delcat.php, and (9) post_id parameter in (j) del.php, as reachable from admin.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427182/100/0/threaded">20060309 MyBloggie: Multiple XSS Vulnerabilities</ref><ref adv="1" source="" url="http://www.seclab.tuwien.ac.at/advisories/TUVSA-0603-002.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17048">17048</ref><ref source="OSVDB" url="http://www.osvdb.org/23973">23973</ref><ref source="OSVDB" url="http://www.osvdb.org/23974">23974</ref><ref source="OSVDB" url="http://www.osvdb.org/23975">23975</ref><ref source="OSVDB" url="http://www.osvdb.org/23986">23986</ref><ref source="OSVDB" url="http://www.osvdb.org/23987">23987</ref><ref source="OSVDB" url="http://www.osvdb.org/23988">23988</ref><ref source="OSVDB" url="http://www.osvdb.org/23989">23989</ref><ref source="OSVDB" url="http://www.osvdb.org/23990">23990</ref><ref source="OSVDB" url="http://www.osvdb.org/23991">23991</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25134">mybloggie-index-admin-xss(25134)</ref><ref source="OSVDB" url="http://www.osvdb.org/23992">23992</ref></refs><vuln_soft><prod name="myBloggie" vendor="myWebland"><vers num="2.1.3 Beta"/><vers num="2.1.3"/><vers num="2.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-15" name="CVE-2006-1206" published="2006-03-13" seq="2006-1206" severity="Medium" type="CVE"><desc><descript source="cve">Matt Johnston Dropbear SSH server 0.47 and earlier, as used in embedded Linux devices and on general-purpose operating systems, allows remote attackers to cause a denial of service (connection slot exhaustion) via a large number of connection attempts that exceeds the MAX_UNAUTH_CLIENTS defined value of 30.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426999/100/0/threaded">20060307 Dropbear SSH server Denial of Service</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17024">17024</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25075">dropbear-connection-dos(25075)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015742">1015742</ref></refs><vuln_soft><prod name="Dropbear SSH Server" vendor="Matt Johnston"><vers num="0.47"/><vers num="0.46"/><vers num="0.45"/><vers num="0.44"/><vers num="0.43"/><vers num="0.42"/><vers num="0.41"/><vers num="0.40"/><vers num="0.39"/><vers num="0.38"/><vers num="0.37"/><vers num="0.36"/><vers num="0.35"/><vers num="0.34"/><vers num="0.33"/><vers num="0.32"/><vers num="0.31"/><vers num="0.30"/><vers num="0.29"/><vers num="0.28"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-15" name="CVE-2006-1207" published="2006-03-13" seq="2006-1207" severity="Medium" type="CVE"><desc><descript source="cve">PHP Upload Center stores password hashes under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for the upload/users/[USERNAME] file.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427215/100/0/threaded">20060309 PHP Upload Center Download users password hashes And phpshell Upload</ref><ref source="" url="http://biyosecurity.be/bugs/phpuploadcenter2.txt"></ref><ref source="" url="http://www.blogcu.com/Liz0ziM/317250/"></ref><ref source="" url="http://www.scripts-by.net/PHP/File-Manipulation/php-upload-center.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/23627">23627</ref></refs><vuln_soft><prod name="PHP Upload Center" vendor="Sergey Korostel"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1208" published="2006-03-13" seq="2006-1208" severity="High" type="CVE"><desc><descript source="cve">Sergey Korostel PHP Upload Center allows remote attackers to execute arbitrary PHP code by uploading a file whose name ends in a .php.li extension, which can be accessed from the upload directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427215/100/0/threaded">20060309 PHP Upload Center Download users password hashes And phpshell Upload</ref><ref source="" url="http://biyosecurity.be/bugs/phpuploadcenter2.txt"></ref><ref source="" url="http://www.blogcu.com/Liz0ziM/317250/"></ref><ref source="" url="http://www.scripts-by.net/PHP/File-Manipulation/php-upload-center.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0817">ADV-2006-0817</ref><ref source="OSVDB" url="http://www.osvdb.org/23626">23626</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19107">19107</ref><ref source="SREASON" url="http://securityreason.com/securityalert/564">564</ref></refs><vuln_soft><prod name="PHP Upload Center" vendor="Sergey Korostel"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1209" published="2006-03-13" seq="2006-1209" severity="Medium" type="CVE"><desc><descript source="cve">PHP Advanced Transfer Manager 1.00 through 1.30 stores sensitive information, including password hashes, under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for a users/[USERNAME] file.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427216/100/0/threaded">20060309 PHP Advanced Transfer Manager Download users password hashes</ref><ref source="" url="http://biyosecurity.be/bugs/patm.txt"></ref><ref source="" url="http://www.blogcu.com/Liz0ziM/316652/"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25127">phpatm-password-hash-disclosure(25127)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17134">17134</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/437513/100/200/threaded">20060613 Re: PHP Advanced Transfer Manager Download users password hashes</ref><ref source="SREASON" url="http://securityreason.com/securityalert/565">565</ref></refs><vuln_soft><prod name="PHP Advanced Transfer Manager" vendor="Bugada Andrea"><vers num="1.00"/><vers num="1.01"/><vers num="1.02"/><vers num="1.03"/><vers num="1.22"/><vers num="1.21"/><vers num="1.20"/><vers num="1.30"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-1210" published="2006-03-13" seq="2006-1210" severity="High" type="CVE"><desc><descript source="cve">The web interface for IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 includes the MySQL database username and password in cleartext in body.phtml, which allows remote attackers to gain privileges by reading the source.  NOTE: IBM has privately confirmed to CVE that a fix is available for these issues.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427155/100/0/threaded">20060308 Remote access to NeuSecure/Netcool backend database via web interface credentials leakage</ref><ref source="BID" url="http://www.securityfocus.com/bid/17032">17032</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25270">
netcool-neusecure-ns-unauth-access(25270)</ref></refs><vuln_soft><prod name="Netcool_NeuSecure" vendor="Micromuse"><vers num="3.0.236"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-1211" published="2006-03-13" seq="2006-1211" severity="High" type="CVE"><desc><descript source="cve">IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 configures a MySQL database to allow connections from any source IP address with the ns database account, which allows remote attackers to bypass the Netcool/NeuSecure application layer and perform unauthorized database actions.  NOTE: IBM has privately confirmed to CVE that a fix is available for these issues.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427155/100/0/threaded">20060308 Remote access to NeuSecure/Netcool backend database via web interface credentials leakage</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25270">
netcool-neusecure-ns-unauth-access(25270)</ref></refs><vuln_soft><prod name="Netcool_NeuSecure" vendor="Micromuse"><vers num="3.0.236"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-30" name="CVE-2006-1212" published="2006-03-13" seq="2006-1212" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in index.php in Core CoreNews 2.0.1 allows remote attackers to execute arbitrary commands via the page parameter, possibly due to a PHP remote file include vulnerability.  NOTE: this vulnerability could not be confirmed by source code inspection of CoreNews 2.0.1, which does not appear to use a &quot;page&quot; parameter or variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427387/100/0/threaded">20060309 CoreNews 2.0.1 Remote Command Exucetion</ref><ref source="" url="http://web.archive.org/web/20050323212004/www.coreslawn.de/?show=downloads&amp;cat_id=1"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17067">17067</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25180">corenews-index-command-execution(25180)</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2006-March/000602.html">
20060313 Oddness - CoreNews 2.0.1 Remote Command Exucetion</ref><ref source="OSVDB" url="http://www.osvdb.org/24080">
24080</ref><ref source="SREASON" url="http://securityreason.com/securityalert/754">754</ref></refs><vuln_soft><prod name="CoreNews" vendor="CoreNews"><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1213" published="2006-03-13" seq="2006-1213" severity="High" type="CVE"><desc><descript source="cve">JiRo&apos;s Banner System Experience and Professional 1.0 and earlier allows remote attackers to bypass access restrictions and gain privileges via a direct request to certain scripts in the files directory, as demonstrated by using addadmin.asp to create a new administrator account.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427326/100/0/threaded">20060309 Advisory: Jiros Banner Experience Pro Remote Privilege Escalation.</ref><ref adv="1" source="" url="http://www.nukedx.com/?viewdoc=19"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0911">ADV-2006-0911</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19184">19184</ref><ref source="BID" url="http://www.securityfocus.com/bid/17060">17060</ref><ref source="OSVDB" url="http://www.osvdb.org/23780">23780</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/0211.html">
20060309 Advisory: Jiros Banner Experience Pro Remote Privilege Escalation.</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25169">
jbspro-security-bypass(25169)</ref></refs><vuln_soft><prod name="Banner System" vendor="JiRo"><vers num="1.0 Experience"/><vers num="1.0 Professional"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1214" published="2006-03-13" seq="2006-1214" severity="Medium" type="CVE"><desc><descript source="cve">UnrealIRCd 3.2.3 allows remote attackers to cause an unspecified denial of service by causing a linked server to send malformed TKL Q:Line commands, as demonstrated by &quot;TKL - q\x08Q *\x08PoC.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427213/100/0/threaded">20060309 UnrealIRCd3.2.3 Server-Link Denial of Service</ref><ref patch="1" source="unrealircd.com" url="http://forums.unrealircd.com/viewtopic.php?t=2985">Unreal 3.2.4 released</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0908">ADV-2006-0908</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/23778">23778</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19188">19188</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25130">unrealircd-server-link-dos(25130)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17057">17057</ref></refs><vuln_soft><prod name="UnrealIRCd" vendor="Unreal"><vers num="3.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1215" published="2006-03-13" seq="2006-1215" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in misc.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the percent parameter.  NOTE: this issue has been disputed in a followup post, although the original disclosure might be related to reflected XSS.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/426766">20060304 Wbb 2.3. xss</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/426816/30/0/threaded">20060304 Re: Wbb 2.3. xss</ref><ref source="BID" url="http://www.securityfocus.com/bid/16959">16959</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25156">
wbb-misc-xss(25156)</ref></refs><vuln_soft><prod name="Burning Board" vendor="Woltlab"><vers num="2.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1216" published="2006-03-13" seq="2006-1216" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in bigshow.php in Runcms 1.x allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/426829">20060304 [KAPDA::#31] - Runcms 1.x Cross_Site_Scripting vulnerability in bigshow.php</ref><ref adv="1" source="" url="http://www.kapda.ir/advisory-280.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16970">16970</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18997">18997</ref><ref source="OSVDB" url="http://www.osvdb.org/23823">23823</ref><ref source="SREASON" url="http://securityreason.com/securityalert/474">474</ref></refs><vuln_soft><prod name="RunCMS" vendor="RunCMS"><vers num="1.2"/><vers num="1.1a"/><vers num="1.1"/><vers num="1.3a5"/><vers num="1.3a2"/><vers num="1.3a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1217" published="2006-03-13" seq="2006-1217" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in DSPoll 1.1 allows remote attackers to execute arbitrary SQL commands via the pollid parameter to (1) results.php, (2) topolls.php, (3) pollit.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/96/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0932">ADV-2006-0932</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19209">19209</ref><ref source="BID" url="http://www.securityfocus.com/bid/17103">17103</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25192">dspoll-pollid-sql-injection(25192)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015758">1015758</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428663/100/0/threaded">20060324 [eVuln] DSPoll Multiple SQL Injection Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/23879">23879</ref><ref source="OSVDB" url="http://www.osvdb.org/23880">23880</ref><ref source="OSVDB" url="http://www.osvdb.org/23881">23881</ref><ref source="SREASON" url="http://securityreason.com/securityalert/620">620</ref><ref source="SREASON" url="http://securityreason.com/securityalert/622">622</ref></refs><vuln_soft><prod name="DSPoll" vendor="DSPortal"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-1218" published="2006-03-13" seq="2006-1218" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the HTTP proxy in Novell BorderManager 3.8 and earlier allows remote attackers to cause a denial of service (CPU consumption and ABEND) via unknown attack vectors related to &quot;media streaming over HTTP 1.1&quot;.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972993.htm"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17031">17031</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0879">ADV-2006-0879</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19163">19163</ref><ref source="OSVDB" url="http://www.osvdb.org/23752">23752</ref></refs><vuln_soft><prod name="BorderManager" vendor="Novell"><vers num="3.8"/><vers edition="SP4" num="3.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-15" name="CVE-2006-1219" published="2006-03-13" seq="2006-1219" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Gallery 2.0.3 and earlier, and 2.1 before RC-2a, allows remote attackers to include arbitrary PHP files via &quot;..&quot; (dot dot) sequences in the stepOrder parameter to (1) upgrade/index.php or (2) install/index.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/1566"></ref><ref source="" url="http://gallery.menalto.com/2.0.4_and_2.1_rc_2a_update"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0895">ADV-2006-0895</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19175">19175</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25129">gallery-multiple-index-file-include(25129)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17051">17051</ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="2.1 rc2"/><vers num="2.1 rc1"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0 Beta3"/><vers num="2.0 Beta2"/><vers num="2.0 Beta1"/><vers num="2.0 Alpha4"/><vers num="2.0 Alpha3"/><vers num="2.0 Alpha2"/><vers num="2.0 Alpha1"/><vers num="2.0 Alpha"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-1220" published="2006-03-13" seq="2006-1220" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the mach_msg_send function in the kernel for Mac OS X might allow local users to execute arbitrary code via unknown attack vectors related to a large message header size, which leads to a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="" url="http://www.felinemenace.org/~nemo/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17056">17056</ref><ref source="OSVDB" url="http://www.osvdb.org/28453">28453</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/><vers num="10.1.4"/><vers num="10.1.3"/><vers num="10.1.2"/><vers num="10.1.1"/><vers num="10.1"/><vers num="10.0"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/><vers num="10.1.4"/><vers num="10.1.3"/><vers num="10.1.2"/><vers num="10.1.1"/><vers num="10.1"/><vers num="10.0.4"/><vers num="10.0.3"/><vers num="10.0.2"/><vers num="10.0.1"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-15" name="CVE-2006-1221" published="2006-03-14" seq="2006-1221" severity="Medium" type="CVE"><desc><descript source="cve">Untrusted search path vulnerability in the TrueVector service (VSMON.exe) in Zone Labs ZoneAlarm 6.x and Integrity does not search ZoneAlarm&apos;s own folders before other folders that are specified in a user&apos;s PATH, which might allow local users to execute code as SYSTEM by placing malicious DLLs into a folder that has insecure permissions, but is searched before ZoneAlarm&apos;s folder.  NOTE: since this issue is dependent on the existence of a vulnerability in a separate product (weak permissions of executables or libraries, or the execution of malicious code), perhaps it should not be included in CVE.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427122/100/0/threaded">20060308 18 ways to escalate privileges in Zone Labs ZoneAlarm Security Suite build 6.1.744.000</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427145/100/0/threaded">20060309 Re: 18 ways to escalate privileges in Zone Labs ZoneAlarm Security Suite build 6.1.744.000</ref><ref source="" url="http://reedarvin.thearvins.com/20060308-01.html"></ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427309/100/0/threaded">20060309 Statement Regarding Reported Local Escalation of Privileges Vulnerability for ZoneAlarm</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0947">ADV-2006-0947</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015743">1015743</ref><ref source="BID" url="http://www.securityfocus.com/bid/17037">17037</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25097">
zonealarm-path-gain-privileges(25097)</ref></refs><vuln_soft><prod name="ZoneAlarm Security Suite" vendor="Zone Labs"><vers num="6.1.744.000"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-16" name="CVE-2006-1222" published="2006-03-14" seq="2006-1222" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in zeroboard 4.1 pl7 allows allow remote attackers to inject arbitrary web script or HTML via the (1) memo box title, (2) user email, and (3) homepage fields.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427466/100/0/threaded">20060312 [INetCop Security Advisory] zeroboard IP session bypass XSS vulnerability</ref><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042872.html">20060312 [INetCop Security Advisory] zeroboard IP session bypass XSS vulnerability</ref><ref adv="1" source="" url="http://www.inetcop.org/upfiles/33INCSA.2006-0x82-029-zeroboard.pdf"></ref><ref source="" url="http://www.nzeo.com/bbs/zboard.php?id=cgi_bugreport2&amp;no=5406"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17075">17075</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0944">ADV-2006-0944</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19214">19214</ref><ref source="" url="http://www.nzeo.com/bbs/zboard.php?id=cgi_bugreport2&amp;no=5406"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25212">zeroboard-multiple-fields-xss(25212)</ref><ref source="OSVDB" url="http://www.osvdb.org/23847">23847</ref></refs><vuln_soft><prod name="Zeroboard" vendor="Zeroboard"><vers num="4.1 pl7"/><vers num="4.1 pl6"/><vers num="4.1 pl5"/><vers num="4.1 pl4"/><vers num="4.1 pl3"/><vers num="4.1 pl2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-15" name="CVE-2006-1223" published="2006-03-14" seq="2006-1223" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Jupiter Content Manager 1.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in the image BBcode tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427406/100/0/threaded">20060311 Jupiter CMS &lt;= 1.1.5 multiple XSS attack vectors.</ref><ref source="BID" url="http://www.securityfocus.com/bid/17072">17072</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0942">ADV-2006-0942</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19215">19215</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25241">jupitercm-bbcodetag-xss(25241)</ref><ref source="OSVDB" url="http://www.osvdb.org/23839">23839</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430903/100/0/threaded">20060412 Re: Jupiter CMS &lt;= 1.1.5 multiple XSS attack vectors.</ref><ref source="" url="http://www.jupiterportal.com/index.php?n=modules/forum&amp;a=3&amp;d=11&amp;o=5&amp;q=313"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/572">572</ref></refs><vuln_soft><prod name="Jupiter CMS" vendor="Jupiter CMS"><vers num="1.1.5" prev="1"/><vers num="1.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-15" name="CVE-2006-1224" published="2006-03-14" seq="2006-1224" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in dwnld.php in GuppY 4.5.11 allows remote attackers to overwrite arbitrary files via a &quot;%2E.&quot; (mixed encoding) in the pg parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427329/100/0/threaded">20060310 [KAPDA::#33] - GuppY &lt;= 4.5.11 Remote DoS vulnerability</ref><ref adv="1" patch="1" source="kapda.ir" url="http://www.kapda.ir/advisory-291.html">GuppY &lt;= 4.5.11 Remote DoS vulnerability</ref><ref patch="1" source="freeguppy.org" url="http://www.freeguppy.org/?lng=en">The 3 last news (Forum)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17068">17068</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0936">ADV-2006-0936</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015753">1015753</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19222">19222</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25141">guppy-dwnld-file-deletion(25141)</ref><ref source="OSVDB" url="http://www.osvdb.org/23846">23846</ref><ref source="OSVDB" url="http://www.osvdb.org/23993">23993</ref><ref source="SREASON" url="http://securityreason.com/securityalert/569">569</ref><ref source="" url="http://www.kapda.ir/advisory-291.html"></ref></refs><vuln_soft><prod name="GuppY" vendor="GuppY"><vers num="4.5.11"/><vers num="4.5.10"/><vers num="4.5.9"/><vers num="4.5.4"/><vers num="4.5.3a"/><vers num="4.5.3"/><vers num="4.5"/><vers num="2.4 p4"/><vers num="2.4 p3"/><vers num="2.4 p1"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-1225" published="2006-03-14" seq="2006-1225" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427591/100/0/threaded">20060314 [DRUPAL-SA-2006-004] Drupal 4.6.6 / 4.5.8 fixes mail header injection issue</ref><ref adv="1" patch="1" source="drupal.org" url="http://drupal.org/node/53806">Advisory ID: DRUPAL-SA-2006-004 </ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19245">19245</ref><ref source="BID" url="http://www.securityfocus.com/bid/17104">17104</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1007">DSA-1007</ref><ref source="OSVDB" url="http://www.osvdb.org/23912">23912</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19257">19257</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25206">drupal-header-data-manipulation(25206)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/579">579</ref></refs><vuln_soft><prod name="Drupal" vendor="Drupal"><vers num="4.6.1"/><vers num="4.6.0"/><vers num="4.5.3"/><vers num="4.5.2"/><vers num="4.5.1"/><vers num="4.5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-1226" published="2006-03-14" seq="2006-1226" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427588/100/0/threaded">20060314 [DRUPAL-SA-2006-002] Drupal 4.6.6 / 4.5.8 fixes XSS issue</ref><ref adv="1" patch="1" source="drupal.org" url="http://drupal.org/node/53803">Advisory ID: DRUPAL-SA-2006-002 </ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19245">19245</ref><ref source="BID" url="http://www.securityfocus.com/bid/17104">17104</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1007">DSA-1007</ref><ref source="OSVDB" url="http://www.osvdb.org/23910">23910</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19257">19257</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25202">drupal-undisclosed-xss(25202)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/581">581</ref></refs><vuln_soft><prod name="Drupal" vendor="Drupal"><vers num="4.6.1"/><vers num="4.6.0"/><vers num="4.5.3"/><vers num="4.5.2"/><vers num="4.5.1"/><vers num="4.5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-1227" published="2006-03-14" seq="2006-1227" severity="Medium" type="CVE"><desc><descript source="cve">Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8, when menu.module is used to create a menu item, does not implement access control for the page that is referenced, which might allow remote attackers to access administrator pages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427587/100/0/threaded">20060314 [DRUPAL-SA-2006-001] Drupal 4.6.6 / 4.5.8 fixes access control issue</ref><ref adv="1" patch="1" source="drupal.org" url="http://drupal.org/node/53796">Advisory ID: DRUPAL-SA-2006-001</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19245">19245</ref><ref source="BID" url="http://www.securityfocus.com/bid/17104">17104</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1007">DSA-1007</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/23909">23909</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19257">19257</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25197">drupal-menumodule-bypass-security(25197)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/578">578</ref></refs><vuln_soft><prod name="Drupal" vendor="Drupal"><vers num="4.6.5"/><vers num="4.6.4"/><vers num="4.6.3"/><vers num="4.6.2"/><vers num="4.6.1"/><vers num="4.6.0"/><vers num="4.5.7"/><vers num="4.5.6"/><vers num="4.5.5"/><vers num="4.5.4"/><vers num="4.5.3"/><vers num="4.5.2"/><vers num="4.5.2"/><vers num="4.5.1"/><vers num="4.5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-1228" published="2006-03-14" seq="2006-1228" severity="Medium" type="CVE"><desc><descript source="cve">Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.</descript></desc><sols><sol source="nvd">This vulnerability affects Drupal versions 4.6.x before 4.6.6, as well as versions 4.5.x before 4.5.8</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427589/100/0/threaded">20060314 [DRUPAL-SA-2006-003] Drupal 4.6.6 / 4.5.8 fixes session fixation issue</ref><ref adv="1" patch="1" source="drupal.org" url="http://drupal.org/node/53805">Advisory ID: DRUPAL-SA-2006-003</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19245">19245</ref><ref source="BID" url="http://www.securityfocus.com/bid/17104">17104</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1007">DSA-1007</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19257">19257</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25205">drupal-login-session-hijacking(25205)</ref><ref source="OSVDB" url="http://www.osvdb.org/23911">23911</ref><ref source="SREASON" url="http://securityreason.com/securityalert/580">580</ref></refs><vuln_soft><prod name="Drupal" vendor="Drupal"><vers num="4.6.1"/><vers num="4.6.0"/><vers num="4.5.3"/><vers num="4.5.2"/><vers num="4.5.1"/><vers num="4.5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-1229" published="2006-03-14" seq="2006-1229" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands via the search parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><sols><sol source="nvd">This vulnerability may affect all versions of Hosting Controller previous to 6.1 Hotfix 2.9 as well.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0914">ADV-2006-0914</ref><ref source="OSVDB" url="http://www.osvdb.org/23802">23802</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19191">19191</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25140">hosting-controller-search-sql-injection(25140)</ref></refs><vuln_soft><prod name="Hosting Controller" vendor="Hosting Controller"><vers num="6.1 Hotfix 2.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2006-1230" published="2006-03-14" seq="2006-1230" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in create.php in vCard 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) card_id, (2) uploaded, (3) card_fontsize, or (4) card_color parameter.  NOTE: the card_id vector was later reported to affect vCard 2.9, and the uploaded vector for 2.6.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427408/100/0/threaded">20060311 XSS in vCard</ref><ref source="BID" url="http://www.securityfocus.com/bid/17073">17073</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0945">ADV-2006-0945</ref><ref source="OSVDB" url="http://www.osvdb.org/23838">23838</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19216">19216</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25181">vcard-create-xss(25181)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435310/100/0/threaded">20060527 multiple Xss exploits in : vCard 2.9</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016183">1016183</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461922/100/0/threaded">20070304 XSS Remote In vCard 2.6 (c)2002</ref><ref source="BID" url="http://www.securityfocus.com/bid/22819">22819</ref></refs><vuln_soft><prod name="vCard" vendor="Belchior Foundry"><vers num="2.9"/><vers num="2.8"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-1231" published="2006-03-14" seq="2006-1231" severity="Low" type="CVE"><desc><descript source="cve">CAPI4HylaFAX 1.3, when compiled with GENERATE_DEBUGSFFDATAFILE set, allows local users to modify arbitrary files via a symlink attack on the c2faxrecv_dbgdatafile.sff temporary file.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427084/100/0/threaded">20060307 capi4hylafax insecure manipulation with tmp files</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114176689513438&amp;w=2">20060307 capi4hylafax insecure manipulation with tmp files</ref><ref source="BID" url="http://www.securityfocus.com/bid/17034">17034</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114176689513438&amp;w=2">20060307 capi4hylafax insecure manipulation with tmp files</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25262">
capi4hylafax-c2faxrecvdbgdatafile-symlink(25262)</ref></refs><vuln_soft><prod name="CAPI4HylaFAX" vendor="Julian Pawlowski"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-1232" published="2006-03-14" seq="2006-1232" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in DSDownload 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) key and (2) category parameters to (a) search.php and (b) downloads.php.</descript></desc><sols><sol source="nvd">&quot;magic_quotes_gpc&quot; parameter must be disabled in order for this vulnerability to be exploited.  This vulnerability may affect DSPortal, DSDownload versions previous to 1.0 as well.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="evuln.com" url="http://evuln.com/vulns/99/summary.html">DSDownload Multiple SQL Injection Vulnerabilities</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0934">ADV-2006-0934</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19202">19202</ref><ref source="BID" url="http://www.securityfocus.com/bid/17116">17116</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015755">1015755</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25193">dsdownload-multiple-sql-injection(25193)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428808/100/0/threaded">20060325 [eVuln] DSDownload Multiple SQL Injection Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/23886">23886</ref><ref source="OSVDB" url="http://www.osvdb.org/23887">23887</ref><ref source="SREASON" url="http://securityreason.com/securityalert/626">626</ref></refs><vuln_soft><prod name="DSDownload" vendor="DSPortal"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-1233" published="2006-03-14" seq="2006-1233" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WMNews allow remote attackers to inject arbitrary web script or HTML via the (1) ArtCat parameter to wmview.php, (2) ctrrowcol parameter to footer.php, or (3) ArtID parameter to wmcomments.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427479/100/0/threaded">20060312 WMNews Cross Site Scripting</ref><ref source="" url="http://biyosecurity.be/bugs/wmnews.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17076">17076</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0939">ADV-2006-0939</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19204">19204</ref><ref source="OSVDB" url="http://www.osvdb.org/23840">23840</ref><ref source="OSVDB" url="http://www.osvdb.org/23841">23841</ref><ref source="OSVDB" url="http://www.osvdb.org/23842">23842</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25210">wmnews-multiple-scripts-xss(25210)</ref></refs><vuln_soft><prod name="WMNews" vendor="Mikael Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1234" published="2006-03-14" seq="2006-1234" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in DSCounter 1.2, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FOR environment variable) in an HTTP header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/98/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0933">ADV-2006-0933</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015756">1015756</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19206">19206</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25190">dscounter-index-sql-injection(25190)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428807/100/0/threaded">20060325 [eVuln] DSCounter %27X-Forwarded-For%27 SQL Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17112">17112</ref><ref source="OSVDB" url="http://www.osvdb.org/23882">23882</ref><ref source="SREASON" url="http://securityreason.com/securityalert/627">627</ref></refs><vuln_soft><prod name="DSCounter" vendor="DSPortal"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-1235" published="2006-03-14" seq="2006-1235" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in admin/deleteuser.php in HitHost 1.0.0 might allow remote attackers to delete directories (possibly only empty directories) via the $deleteuser variable.  NOTE: the initial disclosure for this issue indicated that the researcher was unable to prove this issue; however, this might have been due to certain behaviors of rmdir.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426931/100/0/threaded">20060306 histhost v1.0.0 xss and possible rmdir</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427631/100/0/threaded">20060314 Re: histhost v1.0.0 xss and possible rmdir</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19155">19155</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25106">hithost-deleteuser-directory-deletion(25106)</ref></refs><vuln_soft><prod name="HitHost" vendor="David Ravenscroft"><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-1236" published="2006-03-14" seq="2006-1236" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrary code via a long setup sound command, a different vulnerability than CVE-2006-1010.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/1582"></ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/crossfire/crossfire/socket/request.c?rev=1.86&amp;view=log"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17093">17093</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19237">19237</ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/crossfire/crossfire/socket/request.c?rev=1.86&amp;view=log"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1009">DSA-1009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19276">19276</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0951">ADV-2006-0951</ref><ref source="OSVDB" url="http://www.osvdb.org/23904">23904</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25252">crossfire-setup-bo(25252)</ref></refs><vuln_soft><prod name="Crossfire" vendor="Crossfire"><vers num="1.9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1237" published="2006-03-15" seq="2006-1237" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in DSNewsletter 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the email parameter to (1) include/sub.php, (2) include/confirm.php, or (3) include/unconfirm.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/97/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0931">ADV-2006-0931</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015757">1015757</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19207">19207</ref><ref source="BID" url="http://www.securityfocus.com/bid/17111">17111</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25188">dsnewsletter-email-sql-injection(25188)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428664/100/0/threaded">20060324 [eVuln] DSNewsletter SQL Injection Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/23883">23883</ref><ref source="OSVDB" url="http://www.osvdb.org/23884">23884</ref><ref source="OSVDB" url="http://www.osvdb.org/23885">23885</ref><ref source="SREASON" url="http://securityreason.com/securityalert/623">623</ref></refs><vuln_soft><prod name="DSNewsletter" vendor="DSPortal"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1238" published="2006-03-15" seq="2006-1238" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in DSLogin 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the $log_userid variable in (1) index.php and (2) admin/index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/100/summary.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015754">1015754</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19201">19201</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0953">ADV-2006-0953</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25194">dslogin-index-bypass-authentication(25194)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428902/100/0/threaded">20060327 [eVuln] DSLogin Authentication Bypass Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17262">17262</ref><ref source="OSVDB" url="http://www.osvdb.org/23896">23896</ref><ref source="SREASON" url="http://securityreason.com/securityalert/637">637</ref></refs><vuln_soft><prod name="DSLogin" vendor="DSPortal"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-1239" published="2006-03-15" seq="2006-1239" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in issue/createissue.aspx in Gemini 2.0 allows remote attackers to inject arbitrary web script or HTML via the rtcDescription$RadEditor1 field.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/23907">23907</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19049">19049</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25195">gemini-createissue-xss(25195)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0954">ADV-2006-0954</ref><ref source="BID" url="http://www.securityfocus.com/bid/17092">17092</ref></refs><vuln_soft><prod name="Gemini" vendor="CounterSoft"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-05" name="CVE-2006-1240" published="2006-03-15" seq="2006-1240" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in inet_server.cpp in (1) fb_inet_server and (2) fbserver in Firebird 1.5.2.4731 allows local users to gain privileges via a long value of the -p argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427480/100/0/threaded">20060312 Buffer Overflow and Installation Script Error in Firebird 1.5.3</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17077">17077</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/043546.html">
20060312 Buffer Overflow and Installation Script Error in Firebird 1.5.3</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25282">
firebird-fbinetserver-fbserver-bo(25282)</ref></refs><vuln_soft><prod name="Firebird" vendor="Firebird"><vers num="1.5.2"/><vers num="1.5.1"/><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-21" name="CVE-2006-1241" published="2006-03-15" seq="2006-1241" severity="Medium" type="CVE"><desc><descript source="cve">Firebird 1.5.2.4731 installs (1) fb_lock_mgr, (2) gds_drop, and (3) fb_inet_server with setuid firebird permissions, which might allow local users to gain privileges via a buffer overflow as identified by CVE-2006-1240, or possibly other vulnerabilities.</descript></desc><sols><sol source="nvd">The problems are fixed in the current 1.5.3 version of the Firebird binary distribution.</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427480/100/0/threaded">20060312 Buffer Overflow and Installation Script Error in Firebird 1.5.3</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17077">17077</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/043546.html">
20060312 Buffer Overflow and Installation Script Error in Firebird 1.5.3</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25282">
firebird-fbinetserver-fbserver-bo(25282)</ref></refs><vuln_soft><prod name="Firebird" vendor="Firebird"><vers num="1.5.2.4731"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1242" published="2006-03-15" seq="2006-1242" severity="Medium" type="CVE"><desc><descript source="cve">The ip_push_pending_frames function in Linux 2.4.x and 2.6.x before 2.6.16 increments the IP ID field when sending a RST after receiving unsolicited TCP SYN-ACK packets, which allows remote attackers to conduct an Idle Scan (nmap -sI) attack, which bypasses intended protections against such attacks.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427622/100/0/threaded">20060314 Linux zero IP ID vulnerability?</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427753/100/0/threaded">20060315 Re: Linux zero IP ID vulnerability?</ref><ref source="BID" url="http://www.securityfocus.com/bid/17109">17109</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427893/100/0/threaded">20060316 Re: Linux zero IP ID vulnerability?</ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.1"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1140">ADV-2006-1140</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19402">19402</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-281-1">USN-281-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19955">19955</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:086">MDKSA-2006:086</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20157">20157</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1097">DSA-1097</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20671">20671</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0437.html">RHSA-2006:0437</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21136">21136</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0575.html">RHSA-2006:0575</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21465">21465</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21983">21983</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/22417">22417</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428605/30/6210/threaded">
20060323 Re: Linux zero IP ID vulnerability?</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:086">MDKSA-2006:086</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.15.5"/><vers num="2.6.15.4"/><vers num="2.6.15.3"/><vers num="2.6.15.2"/><vers num="2.6.15.1"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.15"/><vers num="2.6.14.5"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.14"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13-rc7"/><vers num="2.6.13-rc6"/><vers num="2.6.13-rc4"/><vers num="2.6.13-rc1"/><vers num="2.6.13"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12-rc5"/><vers num="2.6.12-rc4"/><vers num="2.6.12-rc1"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11-rc4"/><vers num="2.6.11-rc3"/><vers num="2.6.11-rc2"/><vers num="2.6.11"/><vers num="2.6.10-rc2"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1-rc2"/><vers num="2.6.1-rc1"/><vers num="2.6.1"/><vers num="2.6 test 9 CVS"/><vers num="2.6-test9"/><vers num="2.6-test8"/><vers num="2.6-test7"/><vers num="2.6-test6"/><vers num="2.6-test5"/><vers num="2.6-test4"/><vers num="2.6-test3"/><vers num="2.6-test2"/><vers num="2.6-test11"/><vers num="2.6-test10"/><vers num="2.6-test1"/><vers num="2.6"/><vers num="2.4.33-pre1"/><vers num="2.4.32-pre2"/><vers num="2.4.32-pre1"/><vers num="2.4.32"/><vers num="2.4.31-pre1"/><vers num="2.4.31"/><vers num="2.4.30-rc3"/><vers num="2.4.30-rc2"/><vers num="2.4.30"/><vers num="2.4.29-rc2"/><vers num="2.4.29-rc1"/><vers num="2.4.29"/><vers num="2.4.28"/><vers num="2.4.27-pre5"/><vers num="2.4.27-pre4"/><vers num="2.4.27-pre3"/><vers num="2.4.27-pre2"/><vers num="2.4.27-pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24-ow1"/><vers num="2.4.24"/><vers num="2.4.23-pre9"/><vers num="2.4.23-ow2"/><vers num="2.4.23"/><vers num="2.4.22"/><vers num="2.4.21-pre7"/><vers num="2.4.21-pre4"/><vers num="2.4.21-pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.19-pre6"/><vers num="2.4.19-pre5"/><vers num="2.4.19-pre4"/><vers num="2.4.19-pre3"/><vers num="2.4.19-pre2"/><vers num="2.4.19-pre1"/><vers num="2.4.19"/><vers num="2.4.18-pre-8"/><vers num="2.4.18-pre-7"/><vers num="2.4.18-pre-6"/><vers num="2.4.18-pre-5"/><vers num="2.4.18-pre-4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3"/><vers num="2.4.2"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-24" name="CVE-2006-1243" published="2006-03-15" seq="2006-1243" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included using install05.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/1581"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17102">17102</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1007">ADV-2006-1007</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19270">19270</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25322">simplephpblog-install05-file-include(25322)</ref><ref source="" url="http://sourceforge.net/forum/forum.php?forum_id=564904"></ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-November/001138.html">[VIM] Vendor ACK for CVE-2006-1243 (older Simple PHP Blog)</ref></refs><vuln_soft><prod name="Simple PHP Blog" vendor="Alexander Palmo"><vers num="0.4.7.1" prev="1"/><vers num="0.4.7"/><vers num="0.4.6"/><vers num="0.4.5"/><vers num="0.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-1244" published="2006-03-15" seq="2006-1244" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc.  NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006-0301 and CVE-2005-3624 through CVE-2005-3628 were fixed.  Some of these newer fixes appear to be security-relevant, although it is not clear if they fix specific issues or are defensive in nature.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-979">DSA-979</ref><ref patch="1" source="" url="http://security.debian.org/pool/updates/main/p/pdfkit.framework/pdfkit.framework_0.8-2sarge3.diff.gz"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-982">DSA-982</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-983">DSA-983</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-984">DSA-984</ref><ref source="BID" url="http://www.securityfocus.com/bid/16748">16748</ref><ref source="OSVDB" url="http://www.osvdb.org/23834">23834</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1019">DSA-1019</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19364">19364</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-270-1">USN-270-1</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19644">19644</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18948">18948</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19021">19021</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19091">19091</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-998">DSA-998</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19065">19065</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19164">19164</ref></refs><vuln_soft><prod name="Xpdf" vendor="Xpdf"><vers num="0.93"/><vers num="0.92"/><vers num="0.91"/><vers num="0.90"/><vers num="3.0 pl3"/><vers num="3.0 pl2"/><vers num="3.0.1 pl1"/><vers num="3.0.1"/><vers num="3.0"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.1"/><vers num="1.0a"/><vers num="1.0"/></prod><prod name="GPdf" vendor="GNOME"><vers num="2.8.2"/></prod><prod name="libextractor" vendor="libextractor"><vers num="0.5"/><vers num="0.4.2"/><vers num="0.4.1"/><vers num="0.4"/><vers num="0.3.11"/><vers num="0.3.9"/><vers num="0.3.8"/><vers num="0.3.7"/><vers num="0.3.6"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.1 sparc"/><vers num="3.1 s_390"/><vers num="3.1 ppc"/><vers num="3.1 mipsel"/><vers num="3.1 mips"/><vers num="3.1 m68k"/><vers num="3.1 ia-64"/><vers num="3.1 ia-32"/><vers num="3.1 hppa"/><vers num="3.1 arm"/><vers num="3.1 amd64"/><vers num="3.1 alpha"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1245" published="2006-03-16" seq="2006-1245" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the &quot;Multiple Event Handler Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0855.html">20060316 Remote overflow in MSIE script action handlers (mshtml.dll)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17131">17131</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19269">19269</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25292">ie-mshtml-bo(25292)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428810/100/0/threaded">20060325 Re: [optimized PoC] Remote overflow in MSIE script action handlers (mshtml.dll)</ref><ref source="OSVDB" url="http://www.osvdb.org/23964">23964</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015794">1015794</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx">MS06-013</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html">TA06-101A</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/984473">VU#984473</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1318">ADV-2006-1318</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18957">18957</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1451">oval:org.mitre.oval:def:1451</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1569">oval:org.mitre.oval:def:1569</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1599">oval:org.mitre.oval:def:1599</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1632">oval:org.mitre.oval:def:1632</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1766">oval:org.mitre.oval:def:1766</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/453436/100/0/threaded">20061203 MS Internet Explorer 6.0 (mshtml.dll) Denial of Service Exploit</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/453554/100/0/threaded">20061205 Re: MS Internet Explorer 6.0 (mshtml.dll) Denial of Service Exploit</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0 SP2" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1246" published="2006-03-17" seq="2006-1246" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in mklvcopy in BOS.RTE.LVM in IBM AIX 5.3 allows local users to execute arbitrary commands when mklvcopy calls external commands, possibly due to an untrusted search path vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY82739">IY82739</ref><ref source="BID" url="http://www.securityfocus.com/bid/17115">17115</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0957">ADV-2006-0957</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19235">19235</ref><ref source="OSVDB" url="http://www.osvdb.org/23921">23921</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015786">1015786</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25299">aix-bosrtelvm-gain-privileges(25299)</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-March/000641.html">[VIM] 20060323 IBM changing significant details?</ref><ref adv="1" patch="1" source="" url="http://www.nsfocus.com/english/homepage/research/0602.htm"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25849">
aix-mklvcopy-code-execution(25849)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1247" published="2006-04-19" seq="2006-1247" severity="Low" type="CVE"><desc><descript source="cve">rm_mlcache_file in bos.rte.install in AIX 5.1.0 through 5.3.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY82357">IY82357</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17576">17576</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1389">ADV-2006-1389</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19656">19656</ref><ref adv="1" patch="1" source="" url="http://www.nsfocus.com/english/homepage/research/0603.htm"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431848/100/0/threaded">20060424 NSFOCUS SA2006-02 : IBM AIX mklvcopy Local Privilege Escalation Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431846/100/0/threaded">20060424 NSFOCUS SA2006-03 : IBM AIX rm_mlcache_file Local Race Condition Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/24706">24706</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015952">1015952</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25848">
aix-rm-mlcache-file-overwrite(25848)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3.0.20"/><vers num="5.3.0.10"/><vers num="5.3.0"/><vers num="5.3 ML03"/><vers num="5.3 L"/><vers num="5.3"/><vers num="5.2.2"/><vers num="5.2.0.54"/><vers num="5.2.0.50"/><vers num="5.2 L"/><vers num="5.2"/><vers num="5.1L"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-1248" published="2006-03-17" seq="2006-1248" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><local/></range><refs><ref patch="1" source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?admit=-682735245+1142620131327+28353475&amp;docId=c00614838">HPSBUX02102</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19305">19305</ref><ref source="BID" url="http://www.securityfocus.com/bid/17143">17143</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0997">ADV-2006-0997</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015782">1015782</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015834">1015834</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00614838">HPSBUX02102</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25311">
hpux-usermod-unauthorized-access(25311)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1098">oval:org.mitre.oval:def:1098</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:772">oval:org.mitre.oval:def:772</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:785">oval:org.mitre.oval:def:785</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="B.11.00"/><vers num="B.11.11"/><vers edition="IA64 64-bit" num="B.11.23"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-03-07" modified="2008-03-21" name="CVE-2006-1249" published="2006-03-18" seq="2006-1249" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in Apple QuickTime Player 7.0.3 and 7.0.4 and iTunes 6.0.1 and 6.0.2 allows remote attackers to execute arbitrary code via a FlashPix (FPX) image that contains a field that specifies a large number of blocks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.eeye.com/html/research/upcoming/20060307b.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17074">17074</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433831/100/0/threaded">20060512 Apple QuickDraw/QuickTime Multiple Vulnerabilities</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html">APPLE-SA-2006-05-11</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016067">1016067</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20069">20069</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433850/100/0/threaded">20060511 [EEYEB-20060307] Apple QuickTime FPX Integer Overflow</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/570689">VU#570689</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1778">ADV-2006-1778</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26398">quicktime-flashpix-overflow(26398)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html">TA06-132B</ref></refs><vuln_soft><prod name="iTunes" vendor="Apple"><vers num="6.0.2"/><vers num="6.0.1"/></prod><prod name="Quicktime" vendor="Apple"><vers num="7.0.4"/><vers num="7.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1250" published="2006-03-18" seq="2006-1250" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Webmail module in Winmail before 4.3 has unknown impact and unknown remote attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://www.magicwinmail.net/changelog.asp"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0858">ADV-2006-0858</ref><ref source="BID" url="http://www.securityfocus.com/bid/17009">17009</ref></refs><vuln_soft><prod name="Winmail" vendor="AMAX Information Technologies"><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2006-1251" published="2006-03-18" seq="2006-1251" severity="Medium" type="CVE"><desc><descript source="cve">Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345071"></ref><ref patch="1" source="" url="http://marc.merlins.org/linux/exim/files/sa-exim-cvs/Changelog.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17110">17110</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0941">ADV-2006-0941</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19225">19225</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25286">saexim-greylistclean-file-deletion(25286)</ref></refs><vuln_soft><prod name="sa-exim" vendor="sa-exim"><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1252" published="2006-03-18" seq="2006-1252" severity="High" type="CVE"><desc><descript source="cve">Eval injection vulnerability in cal.php in Light Weight Calendar (LWC) 1.0 allows remote attackers to execute arbitrary PHP code via the date parameter to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/1570"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17059">17059</ref></refs><vuln_soft><prod name="Light Weight Calendar" vendor="Light Weight Calendar"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1253" published="2006-03-18" seq="2006-1253" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in glFTPd before 2.01 RC5 allows remote attackers to bypass IP checks via a crafted DNS hostname, possibly a hostname that appears to be an IP address.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.glftpd.com/files/docs/changelog"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19221">19221</ref><ref source="BID" url="http://www.securityfocus.com/bid/17118">17118</ref></refs><vuln_soft><prod name="glFTPd" vendor="glFTPd"><vers num="2.01 RC4"/><vers num="2.01 RC3"/><vers num="2.01 RC2"/><vers num="2.01 RC1"/><vers num="2.0"/><vers num="2.0 RC7"/><vers num="2.0 RC6"/><vers num="2.0 RC5"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="1.32"/><vers num="1.31"/><vers num="1.30"/><vers num="1.29.1"/><vers num="1.29"/><vers num="1.28"/><vers num="1.27"/><vers num="1.26"/><vers num="1.25"/><vers num="1.24"/><vers num="1.23"/><vers num="1.22"/><vers num="1.21"/><vers num="1.20"/><vers num="1.19"/><vers num="1.18"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-06-25" name="CVE-2006-1254" published="2006-03-18" seq="2006-1254" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in BorderWare MXtreme 5.0 and 6.0 allows remote attackers to have an unknown impact via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0972">ADV-2006-0972</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19223">19223</ref><ref source="BID" url="http://www.securityfocus.com/bid/17140">17140</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015787">1015787</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25325">borderware-mxtreme-web-admin(25325)</ref><ref source="OSVDB" url="http://www.osvdb.org/23939">23939</ref></refs><vuln_soft><prod name="MXtreme" vendor="BorderWare"><vers num="5.0"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2006-1255" published="2006-03-18" seq="2006-1255" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string to the (1) LOGIN or (2) SELECT command, a different set of attack vectors and possibly a different vulnerability than CVE-2003-1177.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/043972.html">20060316 Mercur IMAPD 5.0 SP3 DoS Exploit or more?</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0977">ADV-2006-0977</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19267">19267</ref><ref source="BID" url="http://www.securityfocus.com/bid/17138">17138</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25290">mercur-imap-bo(25290)</ref><ref source="OSVDB" url="http://www.osvdb.org/23950">23950</ref></refs><vuln_soft><prod name="Mercur Messaging" vendor="Mercur"><vers num="2005 5.0 SP3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1256" published="2006-03-18" seq="2006-1256" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in guestbook.php in Soren Boysen (SkullSplitter) PHP Guestbook 2.6 allows remote attackers to inject arbitrary web script or HTML via the url parameter.</descript></desc><sols><sol source="nvd">This vulnerability can only be exploited if the &quot;magic_quotes_gpc&quot; parameter is set to &apos;off&apos;.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="evuln.com" url="http://evuln.com/vulns/104/summary.html">Skull-Splitter&apos;s PHP Guestbook XSS Vulnerability</ref><ref patch="1" source="boysen.be" url="http://www.boysen.be/en/">Guestbook update - v2.75</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17136">17136</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0974">ADV-2006-0974</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19268">19268</ref><ref source="OSVDB" url="http://www.osvdb.org/23941">23941</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25293">skullsplitter-guestbook-xss(25293)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429254/100/0/threaded">20060329 [eVuln] Skull-Splitter%27s PHP Guestbook XSS Vulnerability</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-March/000613.html">[VIM] 20060318 Vendor ACK for Skull-Splitter Guestbook XSS</ref><ref source="SREASON" url="http://securityreason.com/securityalert/650">650</ref></refs><vuln_soft><prod name="PHP Guestbook" vendor="SkullSplitter"><vers num="2.7"/><vers num="2.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-30" name="CVE-2006-1257" published="2006-03-18" seq="2006-1257" severity="High" type="CVE"><desc><descript source="cve">The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a valid username and any password, then going to the main site twice.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427974/100/0/threaded">20060316 Microsoft Commerce Server 2002: Logon as known user with a false password</ref><ref source="" url="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/csvr2002/htm/cs_se_securityconcepts_cbgw.asp"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17134">17134</ref><ref source="OSVDB" url="http://www.osvdb.org/24121">24121</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25330">mscs-authfiles-authentication-bypass(25330)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/594">594</ref></refs><vuln_soft><prod name="commerce server" vendor="Microsoft"><vers num="2002 SP1"/><vers num="2002"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-1258" published="2006-03-18" seq="2006-1258" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.1 allows remote attackers to inject arbitrary web script or HTML via the set_theme parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17142">17142</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19277">19277</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0991">ADV-2006-0991</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015776">1015776</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25305">phpmyadmin-settheme-xss(25305)</ref><ref source="OSVDB" url="http://www.osvdb.org/23943">23943</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.8.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1259" published="2006-03-18" seq="2006-1259" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Maian Support 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) email or (2) pass parameter to admin/index.php.</descript></desc><sols><sol source="nvd">Successful exploitation requires that the &quot;magic_quotes_gpc&quot; parameter is disabled.  This vulnerability may affect earlier versions of Maian, Support as well.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="evuln.com" url="http://evuln.com/vulns/103/summary.html">Maian Support Authentication Bypass</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19275">19275</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0992">ADV-2006-0992</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25300">maiansupport-adminindex-sql-injection(25300)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429098/100/0/threaded">20060328 [eVuln] Maian Support Authentication Bypass</ref><ref source="OSVDB" url="http://www.osvdb.org/23944">23944</ref><ref source="SREASON" url="http://securityreason.com/securityalert/645">645</ref></refs><vuln_soft><prod name="Support" vendor="Maian"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1260" published="2006-03-18" seq="2006-1260" severity="Medium" type="CVE"><desc><descript source="cve">Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which bypasses a sanity check.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/043657.html">20060315 CodeScan Advisory: Unauthenticated Arbitrary File Read in Horde v3.09 and prior</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17117">17117</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0959">ADV-2006-0959</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/23918">23918</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015771">1015771</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19246">19246</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25239">horde-servicesgo-information-disclosure(25239)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427710/100/0/threaded">20060315 CodeScan Advisory: Unauthenticated Arbitrary File Read in Horde v3.09 and prior</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-02.xml">GLSA-200604-02</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19528">19528</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1033">DSA-1033</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19619">19619</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_28.html">SUSE-SR:2006:009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19897">19897</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1034">DSA-1034</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19692">19692</ref><ref source="SREASON" url="http://securityreason.com/securityalert/590">590</ref></refs><vuln_soft><prod name="Horde" vendor="Horde"><vers num="3.0.9"/><vers num="3.0.8"/><vers num="3.0.7"/><vers num="3.0.6"/><vers num="3.0.4 RC2"/><vers num="3.0.4 RC1"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/><vers num="2.2.9"/><vers num="2.2.8"/><vers num="2.2.7"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4 RC1"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.1"/><vers num="2.2"/><vers num="2.1.3"/><vers num="2.1"/><vers num="2.0"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1261" published="2006-03-18" seq="2006-1261" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ASPPortal 3.00 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=114243660409338&amp;w=2">20060315 CodeScan Advisory: Multiple Vulnerabilities In ASPPortal.net</ref><ref adv="1" patch="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/1517.html">20060314 CodeScan Advisory: Multiple Vulnerabilities In ASPPortal.net</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19247">19247</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25235">aspportal-multiple-xss(25235)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015772">1015772</ref><ref source="" url="http://www.aspportal.net/content/news/News_Item.asp?content_ID=32"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17114">17114</ref><ref source="OSVDB" url="http://www.osvdb.org/23920">23920</ref></refs><vuln_soft><prod name="ASPPortal" vendor="ASPPortal"><vers num="3.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1262" published="2006-03-18" seq="2006-1262" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in ASPPortal 3.00 have unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=114243660409338&amp;w=2">20060315 CodeScan Advisory: Multiple Vulnerabilities In ASPPortal.net</ref><ref adv="1" patch="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/1517.html">20060314 CodeScan Advisory: Multiple Vulnerabilities In ASPPortal.net</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19247">19247</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25234">aspportal-multiple-scripts-sql-injection(25234)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015772">1015772</ref><ref source="" url="http://www.aspportal.net/content/news/News_Item.asp?content_ID=32"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17114">17114</ref><ref source="OSVDB" url="http://www.osvdb.org/23919">23919</ref><ref source="SREASON" url="http://securityreason.com/securityalert/592">592</ref></refs><vuln_soft><prod name="ASPPortal" vendor="ASPPortal"><vers num="3.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1263" published="2006-03-18" seq="2006-1263" severity="Medium" type="CVE"><desc><descript source="cve">Multiple &quot;unannounced&quot; cross-site scripting (XSS) vulnerabilities in WordPress before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="wordpress.org" url="http://wordpress.org/development/2006/03/security-202/">2.0.2 Security Release</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17069">17069</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="(B2) 0.6.2.1"/><vers num="(B2) 0.6.2"/><vers num="2.0.1"/><vers num="2.0"/><vers num="1.5.2"/><vers num="1.5.1.3"/><vers num="1.5.1.2"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/><vers num="0.71"/><vers num="0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1264" published="2006-03-18" seq="2006-1264" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in xhawk.net discussion 2.0 beta2 allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in a BBCode img tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427729/100/0/threaded">20060315 [eVuln] discussion - xhawk.net BBCode &apos;img&apos; XSS &amp; SQL Injection Vulnerabilities</ref><ref source="evuln.com" url="http://evuln.com/vulns/92/summary.html">discussion - xhawk.net BBCode &apos;img&apos; XSS &amp; SQL Injection Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17119">17119</ref><ref source="OSVDB" url="http://www.osvdb.org/23970">23970</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25236">
discussion-bbcode-xss(25236)</ref></refs><vuln_soft><prod name="discussion" vendor="xhawk.net"><vers num="2.0 Beta2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1265" published="2006-03-18" seq="2006-1265" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in discussion.class.php in xhawk.net discussion 2.0 beta2 allows remote attackers to execute arbitrary SQL commands via the view parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427729/100/0/threaded">20060315 [eVuln] discussion - xhawk.net BBCode &apos;img&apos; XSS &amp; SQL Injection Vulnerabilities</ref><ref source="evuln.com" url="http://evuln.com/vulns/92/summary.html">discussion - xhawk.net BBCode &apos;img&apos; XSS &amp; SQL Injection Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/23971">23971</ref><ref source="BID" url="http://www.securityfocus.com/bid/17121">17121</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25237">
discussion-class-sql-injection(25237)</ref></refs><vuln_soft><prod name="discussion" vendor="xhawk.net"><vers num="2.0 Beta2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1266" published="2006-03-18" seq="2006-1266" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Service_Requests.asp in VPMi Enterprise 3.3 allows remote attackers to inject arbitrary web script or HTML via the Request_Name_Display parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-March/000605.html">[VIM] 20060314 vendor dispute: VCS</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/23916">23916</ref><ref source="BID" url="http://www.securityfocus.com/bid/17172">17172</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19297">19297</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25339">vpmi-servicerequests-xss(25339)</ref></refs><vuln_soft><prod name="VPMi Enterprise" vendor="Virtual Communication Services"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1267" published="2006-03-18" seq="2006-1267" severity="Medium" type="CVE"><desc><descript source="cve">Invision Power Board 2.1.4 allows remote attackers to hijack sessions and possibly gain administrative privileges by obtaining the session ID from the s parameter, then replaying it in another request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427751/100/0/threaded">20060314 Invision Power Board v2.1.4 - session hijacking</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/427847/100/0/threaded">20060316 Re: Invision Power Board v2.1.4 - session hijacking</ref></refs><vuln_soft><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1268" published="2006-03-18" seq="2006-1268" severity="High" type="CVE"><desc><descript source="cve">The Internet Key Exchange implementation in Funkwerk X2300 7.2.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite.  NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="funkwerk-ec.com" url="http://www.funkwerk-ec.com/portal/downloadcenter/dateien/x2300/r7201p09/readme_721p9.pdf">Readme for System Software 7.2.1: PATCH 9</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0958">ADV-2006-0958</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19233">19233</ref><ref source="BID" url="http://www.securityfocus.com/bid/17124">17124</ref></refs><vuln_soft><prod name="X2300" vendor="Funkwerk"><vers num="7.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1269" published="2006-03-18" seq="2006-1269" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the parse function in parse.c in zoo 2.10 might allow local users to execute arbitrary code via long filename command line arguments, which are not properly handled during archive creation.  NOTE: since this issue is local and not setuid, the set of attack scenarios is limited, although is reasonable to expect that there are some situations in which the zoo user might automatically list attacker-controlled filenames to add to the zoo archive.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="bugzilla" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=183426">Bugzilla Bug 183426</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-12.xml">GLSA-200603-12</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19250">19250</ref><ref source="BID" url="http://www.securityfocus.com/bid/17126">17126</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0969">ADV-2006-0969</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19254">19254</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25264">zoo-parse-bo(25264)</ref></refs><vuln_soft><prod name="zoo" vendor="Rahul Dhesi"><vers num="2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1270" published="2006-03-18" seq="2006-1270" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in zones.php in Inprotect 0.21 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Description field.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript></desc><sols><sol source="nvd">A remote attacker must have &quot;Manage Zones and Server&quot; permissions on Inprotect to exploit this vulnerability.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17141">17141</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0970">ADV-2006-0970</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19248">19248</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25280">inprotect-zones-xss(25280)</ref><ref source="OSVDB" url="http://www.osvdb.org/23936">23936</ref></refs><vuln_soft><prod name="Inprotect" vendor="Inprotect"><vers num="0.21" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1271" published="2006-03-18" seq="2006-1271" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in OxyNews allows remote attackers to execute arbitrary SQL commands via the oxynews_comment_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://biyosecurity.be/bugs/oxynews.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17132">17132</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0976">ADV-2006-0976</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19255">19255</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25301">oxynews-index-sql-injection(25301)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428057/100/0/threaded">20060316 Oxynews Sql &amp;#304;njection</ref><ref source="OSVDB" url="http://www.osvdb.org/23940">23940</ref></refs><vuln_soft><prod name="Oxynews" vendor="Oxynews"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-05" name="CVE-2006-1272" published="2006-03-18" seq="2006-1272" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in member.php in MyBulletin Board (MyBB) 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) aim, (2) yahoo, (3) msn, or (4) website field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427746/100/0/threaded">20060314 [[KAPDA::#35] MyBB 1.0.3~member.php~XSS Attack in contact details</ref><ref source="" url="http://community.mybboard.net/showthread.php?tid=7368"></ref><ref adv="1" source="" url="http://kapda.ir/advisory-297.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17097">17097</ref><ref source="OSVDB" url="http://www.osvdb.org/23935">23935</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25263">
mybb-member-xss(25263)</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-1273" published="2006-03-19" seq="2006-1273" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Mozilla Firefox 1.0.7 and 1.5.0.1 allows remote attackers to cause a denial of service (crash) via an HTML tag with a large number of script action handlers such as onload and onmouseover, which triggers the crash when the user views the page source.  NOTE: Red Hat has disputed this issue, suggesting that &quot;It is likely the reporter was running the IE Tab extension,&quot; and Mozilla also confirmed that this is not an issue in Firefox itself.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427977/100/0/threaded">20060317 Re: Re: Remote overflow in MSIE script action handlers (mshtml.dll)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428159/100/0/threaded">20060318 Re: Re: Remote overflow in MSIE script action handlers (mshtml.dll)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/593">593</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0.7"/><vers num="1.5.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1274" published="2006-03-19" seq="2006-1274" severity="High" type="CVE"><desc><descript source="cve">Classic Planer in AntiVir PersonalEdition Classic 7 does not drop privileges before executing external programs, which allows local users to gain privileges via notepad.exe, which is used to display scan reports.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427412/100/0/threaded">20060311 AntiVir PersonalEdition Classic: Local Privilige Escalation</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042868.html">20060311 AntiVir PersonalEdition Classic: Local Privilige Escalation</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17071">17071</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0948">ADV-2006-0948</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19217">19217</ref><ref source="OSVDB" url="http://www.osvdb.org/23843">23843</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25244">antivir-notepad-gain-privilege(25244)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/573">573</ref></refs><vuln_soft><prod name="Antivir Personal" vendor="Avira"><vers edition="Premium" num="Any"/><vers edition="Classic" num="7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-12" modified="2006-06-01" name="CVE-2006-1275" published="2006-03-19" seq="2006-1275" severity="Medium" type="CVE"><desc><descript source="cve">GGZ Gaming Zone 0.0.12 allows remote attackers to cause a denial of service (client disconnect) via inputs that produce malformed XML, including (1) trailing &apos; (apostrophe) character on the ID attribute in a PLAYER XML tag, (2) joining with a long ID attribute or non-trailing &apos; characters, which causes a &lt;none&gt; name to be assigned, and then disconnecting, or (3) a long CDATA message attribute, which prevents closing tags from being added to the string.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://aluigi.altervista.org/adv/ggzcdos-adv.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0935">ADV-2006-0935</ref><ref source="OSVDB" url="http://www.osvdb.org/23848">23848</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19212">19212</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25164">ggzgaminzone-xml-dos(25164)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17094">17094</ref></refs><vuln_soft><prod name="GGZ Gaming Zone" vendor="GGZ Gaming Zone"><vers num="0.0.12"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1276" published="2006-03-19" seq="2006-1276" severity="High" type="CVE"><desc><descript source="cve">admin.php in Himpfen Consulting Company PHP SimpleNEWS 1.0.0 allows remote attackers to bypass authentication by setting the admin parameter in a cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="evuln.com" url="http://evuln.com/vulns/94/summary.html">EV0094</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0913">ADV-2006-0913</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19195">19195</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/428427">20060322 [eVuln] PHP SimpleNEWS, PHP SimpleNEWS MySQL - Authentication Bypass Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17186">17186</ref><ref source="OSVDB" url="http://www.osvdb.org/23803">23803</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25177">
simplenews-admin-bypass-security(25177)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/613">613</ref></refs><vuln_soft><prod name="PHP SimpleNEWS" vendor="Himpfen Consulting"><vers num="1.0.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-16" name="CVE-2006-1277" published="2006-03-19" seq="2006-1277" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in signup.php in @1 File Store 2006.03.07 allows remote attackers to inject arbitrary web script or HTML via the (1) real_name, (2) email, and (3) login parameters.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/95/summary.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0943">ADV-2006-0943</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19224">19224</ref><ref source="OSVDB" url="http://www.osvdb.org/23850">23850</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428659/100/0/threaded">20060324 [eVuln] @1 File Store Multiple XSS and SQL Injection Vulnerabilities</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015826">1015826</ref><ref source="BID" url="http://www.securityfocus.com/bid/17090">17090</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25182">
filestore-signup-xss(25182)</ref></refs><vuln_soft><prod name="@1 File Store" vendor="Upoint"><vers num="2006.03.07" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1278" published="2006-03-19" seq="2006-1278" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3) edit.php and (4) delete.php in control/files/, (5) edit.php and (6) delete.php in control/users/, (7) edit.php, (8) access.php, and (9) in control/folders/, (10) access.php and (11) delete.php in control/groups/, (12) confirm.php, and (13) download.php; (14) the email parameter in password.php, and (15) the id parameter in folder.php.</descript></desc><sols><sol source="nvd">Successful exploitation requires that the &quot;magic_quotes_gpc&quot; parameter is disabled.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="evuln.com" url="http://evuln.com/vulns/95/summary.html">EV0095</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0943">ADV-2006-0943</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19224">19224</ref><ref source="OSVDB" url="http://www.osvdb.org/23851">23851</ref><ref source="OSVDB" url="http://www.osvdb.org/23852">23852</ref><ref source="OSVDB" url="http://www.osvdb.org/23853">23853</ref><ref source="OSVDB" url="http://www.osvdb.org/23854">23854</ref><ref source="OSVDB" url="http://www.osvdb.org/23855">23855</ref><ref source="OSVDB" url="http://www.osvdb.org/23856">23856</ref><ref source="OSVDB" url="http://www.osvdb.org/23857">23857</ref><ref source="OSVDB" url="http://www.osvdb.org/23858">23858</ref><ref source="OSVDB" url="http://www.osvdb.org/23859">23859</ref><ref source="OSVDB" url="http://www.osvdb.org/23860">23860</ref><ref source="OSVDB" url="http://www.osvdb.org/23861">23861</ref><ref source="OSVDB" url="http://www.osvdb.org/23862">23862</ref><ref source="OSVDB" url="http://www.osvdb.org/23863">23863</ref><ref source="OSVDB" url="http://www.osvdb.org/23864">23864</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428659/100/0/threaded">20060324 [eVuln] @1 File Store Multiple XSS and SQL Injection Vulnerabilities</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015826">1015826</ref><ref source="BID" url="http://www.securityfocus.com/bid/17090">17090</ref><ref source="OSVDB" url="http://www.osvdb.org/24106">24106</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25183">
filestore-multiple-sql-injection(25183)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/619">619</ref></refs><vuln_soft><prod name="@1 File Store" vendor="Upoint"><vers num="2006.03.07" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-1279" published="2006-03-19" seq="2006-1279" severity="Medium" type="CVE"><desc><descript source="cve">CGI::Session 4.03-1 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by (1) Driver::File, (2) Driver::db_file, and possibly (3) Driver::sqlite.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=356555"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0946">ADV-2006-0946</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19211">19211</ref><ref source="BID" url="http://www.securityfocus.com/bid/17177">17177</ref><ref source="OSVDB" url="http://www.osvdb.org/23865">23865</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25285">
cgisession-cgisess-information-disclosure(25285)</ref></refs><vuln_soft><prod name="CGI::Session" vendor="Sherzod Ruzmetov"><vers num="4.03" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-1280" published="2006-03-19" seq="2006-1280" severity="High" type="CVE"><desc><descript source="cve">CGI::Session 4.03-1 does not set proper permissions on temporary files created in (1) Driver::File and (2) Driver::db_file, which allows local users to obtain privileged information, such as session keys, by viewing the files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="debian.org" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=356555">356555</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0946">ADV-2006-0946</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19211">19211</ref><ref source="OSVDB" url="http://www.osvdb.org/23866">23866</ref><ref source="OSVDB" url="http://www.osvdb.org/23867">23867</ref><ref source="BID" url="http://www.securityfocus.com/bid/17099">17099</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25283">
cgisession-driver-files-insecure-permissions(25283)</ref></refs><vuln_soft><prod name="CGI::Session" vendor="Sherzod Ruzmetov"><vers num="4.03" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2006-1281" published="2006-03-19" seq="2006-1281" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in member.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vulnerability than CVE-2006-1272.  NOTE: 1.10 was later reported to be vulnerable.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427744/100/0/threaded">20060314 [KAPDA::#35] - MyBB1.0.4~member.php~XSS after login</ref><ref adv="1" source="kapda.ir" url="http://kapda.ir/advisory-296.html">MyBB1.0.4</ref><ref source="myimei.com" url="http://myimei.com/security/2006-03-09/mybb104memberphpxss-after-login.html">MyBB1.0.4~member.php~XSS after login</ref><ref patch="1" source="community.mybboard.net" url="http://community.mybboard.net/showthread.php?tid=7368">MyBB 1.1 Released </ref><ref source="BID" url="http://www.securityfocus.com/bid/17097">17097</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0971">ADV-2006-0971</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19213">19213</ref><ref source="BID" url="http://www.securityfocus.com/bid/17492">17492</ref><ref source="OSVDB" url="http://www.osvdb.org/23935">23935</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25266">mybb-member-url-xss(25266)</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 PR2"/><vers num="RC4"/><vers num="RC3"/><vers num="RC2"/><vers num="RC1"/><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1282" published="2006-03-19" seq="2006-1282" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in inc/function.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to conduct cross-site scripting (XSS), poison caches, or hijack pages via CRLF (%0A%0D) sequences in the Referrer HTTP header field, possibly when redirecting to other web pages.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427747/100/0/threaded">20060314 [KAPDA::#34] - MyBB1.0.4~redirectfunction()~HeaderInjection</ref><ref adv="1" patch="1" source="kapda.ir" url="http://kapda.ir/advisory-295.html">[KAPDA::#34]MyBB1.0.4</ref><ref source="myimei.com" url="http://myimei.com/security/2006-03-10/mybb104redirectfunctionheaderinjection.html">MyBB1.0.4~redirectfunction()~HeaderInjection</ref><ref patch="1" source="community.mybboard.net" url="http://community.mybboard.net/showthread.php?tid=7368">MyBB 1.1 Released </ref><ref source="BID" url="http://www.securityfocus.com/bid/17097">17097</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25267">
mybb-crlf-header-injection(25267)</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 PR2"/><vers num="1.0 Final"/><vers num="RC4"/><vers num="RC3"/><vers num="RC2"/><vers num="RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-1283" published="2006-03-23" seq="2006-1283" severity="High" type="CVE"><desc><descript source="cve">opiepasswd in One-Time Passwords in Everything (OPIE) in FreeBSD 4.10-RELEASE-p22 through 6.1-STABLE before 20060322 uses the getlogin function to determine the invoking user account, which might allow local users to configure OPIE access to the root account and possibly gain root privileges if a root shell is permitted by the configuration of the wheel group or sshd.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:12.opie.asc">FreeBSD-SA-06:12</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17194">17194</ref><ref source="OSVDB" url="http://www.osvdb.org/24067">24067</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015817">1015817</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19347">19347</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25397">bsd-opie-unauthorized-privileges(25397)</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1074">ADV-2006-1074</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.0 Stable"/><vers num="6.0 Release"/><vers num="5.4 Releng"/><vers num="5.4 Release"/><vers num="5.4 pre"/><vers num="5.3 Stable"/><vers num="5.3 Releng"/><vers num="5.3 Release"/><vers num="5.3"/><vers num="5.2.1 Release"/><vers num="5.2 Releng"/><vers num="5.2 Release"/><vers num="5.2"/><vers num="5.1 Releng"/><vers num="5.1 Release Alpha"/><vers num="5.1 p5 Release"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.0 Releng"/><vers num="5.0 p14 Release"/><vers num="5.0 alpha"/><vers num="5.0"/><vers num="4.11 Stable"/><vers num="4.11 Releng"/><vers num="4.11 p3 Release"/><vers num="4.10 Releng"/><vers num="4.10 p8 Release"/><vers num="4.10 Release"/><vers num="4.10"/><vers num="4.9 Releng"/><vers num="4.9 pre"/><vers num="4.9"/><vers num="4.8 Releng"/><vers num="4.8 p7 Release"/><vers num="4.8 pre"/><vers num="4.8"/><vers num="4.7 Stable"/><vers num="4.7 Releng"/><vers num="4.7 p17 Release"/><vers num="4.7 Release"/><vers num="4.7"/><vers num="4.6.2"/><vers num="4.6 Stable"/><vers num="4.6 Releng"/><vers num="4.6 p20 Release"/><vers num="4.6 Release"/><vers num="4.6"/><vers num="4.5 Stable pre 2002-03-07"/><vers num="4.5 Stable"/><vers num="4.5 Releng"/><vers num="4.5 p32 Release"/><vers num="4.5 Release"/><vers num="4.5"/><vers num="4.4 Stable"/><vers num="4.4 Releng"/><vers num="4.4 p42 Release"/><vers num="4.4"/><vers num="4.3 Stable"/><vers num="4.3 Releng"/><vers num="4.3 p38 Release"/><vers num="4.3 Release"/><vers num="4.3"/><vers num="4.2 Stable pre 2000-12-23"/><vers num="4.2 Stable pre 2001-05-02"/><vers num="4.2 Stable"/><vers num="4.2 Release"/><vers num="4.2"/><vers num="4.1.1 Stable"/><vers num="4.1.1 Release"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0 Releng"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="3.5.1 Stable pre 2001-07-20"/><vers num="3.5.1 Stable"/><vers num="3.5.1 Release"/><vers num="3.5.1"/><vers num="3.5 Stable pre 2000-12-23"/><vers num="3.5 Stable pre 2001-05-02"/><vers num="3.5 Stable"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0 Releng"/><vers num="3.0"/><vers num="2.2.8"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.1"/><vers num="2.2"/><vers num="2.1.7.1"/><vers num="2.1.6.1"/><vers num="2.1.6"/><vers num="2.1.5"/><vers num="2.1 Stable"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0"/><vers num="1.1.5.1"/><vers num="5.4 Stable"/><vers num="4.10 pre"/><vers num="2.2.7"/><vers num="2.1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1284" published="2006-03-19" seq="2006-1284" severity="Medium" type="CVE"><desc><descript source="cve">The installation of SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, includes a default administrator login account and password, which allows local users to gain privileges or modify tasks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref source="" url="http://securityresponse.symantec.com/avcenter/security/Content/2006.03.07.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19171">19171</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0870">ADV-2006-0870</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015733">1015733</ref></refs><vuln_soft><prod name="Ghost" vendor="Symantec"><vers num="8.0"/><vers num="8.2"/></prod><prod name="Ghost Solutions Suite" vendor="Symantec"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.2" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="4.9" CVSS_score="3.2" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1285" published="2006-03-19" seq="2006-1285" severity="Low" type="CVE"><desc><descript source="cve">SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, gives read and write permissions to all users for database shared memory sections, which allows local users to access and possibly modify certain information.</descript></desc><sols><sol source="nvd">Update to Symantec Ghost 8.3 that is shipped as a part of Symantec Ghost Solutions Suite 1.1.</sol></sols><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://securityresponse.symantec.com/avcenter/security/Content/2006.03.07.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19171">19171</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0870">ADV-2006-0870</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015733">1015733</ref><ref source="BID" url="http://www.securityfocus.com/bid/17019">17019</ref></refs><vuln_soft><prod name="Ghost" vendor="Symantec"><vers num="8.0"/><vers num="8.2"/></prod><prod name="Ghost Solutions Suite" vendor="Symantec"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1286" published="2006-03-19" seq="2006-1286" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in the login dialog in dbisqlc.exe in SQLAnywhere for Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, might allow local users to read certain sensitive information from the database.</descript></desc><sols><sol source="nvd">Update to Symantec Ghost 8.3 that is shipped as a part of Symantec Ghost Solutions Suite 1.1.
</sol></sols><loss_types><conf/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="" url="http://securityresponse.symantec.com/avcenter/security/Content/2006.03.07.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19171">19171</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0870">ADV-2006-0870</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015733">1015733</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25089">
ghost-dbisqlc-bo(25089)</ref></refs><vuln_soft><prod name="Ghost" vendor="Symantec"><vers num="8.0"/><vers num="8.2"/></prod><prod name="Ghost Solutions Suite" vendor="Symantec"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1287" published="2006-03-19" seq="2006-1287" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060130 allows remote attackers to steal cookies and probably conduct other activities when the victim is using Internet Explorer.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://forums.invisionpower.com/index.php?showtopic=206790"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0861">ADV-2006-0861</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19141">19141</ref></refs><vuln_soft><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.0.4"/><vers num="2.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1288" published="2006-03-19" seq="2006-1288" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060105 allow remote attackers to execute arbitrary SQL commands via cookies, related to (1) arrays of id/stamp pairs and (2) the keys in arrays of key/value pairs in ipsclass.php; (3) the topics variable in usercp.php; and the topicsread cookie in (4) topics.php, (5) search.php, and (6) forums.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://forums.invisionpower.com/index.php?showtopic=204627"></ref><ref patch="1" source="" url="http://forums.invisionpower.com/index.php?act=Attach&amp;type=post&amp;id=9642"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0861">ADV-2006-0861</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19141">19141</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25100">
invision-multiple-sql-injection(25100)</ref></refs><vuln_soft><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.0.4"/><vers num="2.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1289" published="2006-03-19" seq="2006-1289" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Milkeyway Captive Portal 0.1 and 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username, (2) password, (3) team, (4) level, (5) status, (6) teamname, and (7) teamlead parameters in (a) auth.php; the (8) username, (9) action, and (10) filter parameters in (b) authuser.php; the (11) username parameter in (c) utils.php; the (12) id and (13) date parameters in (d) traffic.php; the (14) username parameter in (e) userstatistics.php; and the (15) USERNAME and (16) PASSWORD parameters in a cookie to (f) chgpwd.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427890/100/0/threaded">20060316 Milkeyway Multiple Vulnerabilities</ref><ref source="" url="http://www.ush.it/team/ascii/hack-milkeway/milkeyway.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17127">17127</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0968">ADV-2006-0968</ref><ref source="" url="http://www.ush.it/team/ascii/hack-milkeway/advisory.txt"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015778">1015778</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19258">19258</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25287">milkeyway-admin-sql-injection(25287)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25281">milkeyway-multiple-sql-injection(25281)</ref><ref source="OSVDB" url="http://www.osvdb.org/23925">23925</ref><ref source="OSVDB" url="http://www.osvdb.org/23927">23927</ref><ref source="OSVDB" url="http://www.osvdb.org/23928">23928</ref><ref source="OSVDB" url="http://www.osvdb.org/23929">23929</ref><ref source="OSVDB" url="http://www.osvdb.org/23931">23931</ref></refs><vuln_soft><prod name="Milkeyway Captive Portal" vendor="Milkeyway"><vers num="0.1"/><vers num="0.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1290" published="2006-03-19" seq="2006-1290" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Milkeyway Captive Portal 0.1 and 0.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) ipAddress, (2) act, (3) username, and (4) unspecified other parameters in (a) authuser.php; and the (5) username and (6) unspecified other parameters in (b) userstatistics.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427890/100/0/threaded">20060316 Milkeyway Multiple Vulnerabilities</ref><ref source="" url="http://www.ush.it/team/ascii/hack-milkeway/milkeyway.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17127">17127</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0968">ADV-2006-0968</ref><ref source="" url="http://www.ush.it/team/ascii/hack-milkeway/advisory.txt"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015778">1015778</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19258">19258</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25288">milkeyway-multiple-xss(25288)</ref><ref source="OSVDB" url="http://www.osvdb.org/23932">23932</ref><ref source="OSVDB" url="http://www.osvdb.org/23933">23933</ref></refs><vuln_soft><prod name="Milkeyway Captive Portal" vendor="Milkeyway"><vers num="0.1"/><vers num="0.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1291" published="2006-03-19" seq="2006-1291" severity="High" type="CVE"><desc><descript source="cve">publish.ical.php in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier does not require authentication for write access to the calendars directory, which allows remote attackers to upload and execute arbitrary PHP scripts via a WebDAV PUT request with a filename containing a .php extension and a trailing null character.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/php-iCalendar-221.upload.php"></ref><ref source="" url="http://www.milw0rm.com/exploits/1586"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17129">17129</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1019">ADV-2006-1019</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19285">19285</ref></refs><vuln_soft><prod name="PHP iCalendar" vendor="PHP iCalendar"><vers num="2.2.1" prev="1"/><vers num="2.0.1"/><vers num="2.0c"/><vers num="2.0b"/><vers num="2.0a2"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1292" published="2006-03-19" seq="2006-1292" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by day.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/1585"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17125">17125</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1019">ADV-2006-1019</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19285">19285</ref></refs><vuln_soft><prod name="PHP iCalendar" vendor="PHP iCalendar"><vers num="2.2.1" prev="1"/><vers num="2.0.1"/><vers num="2.0c"/><vers num="2.0b"/><vers num="2.0a2"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-1293" published="2006-03-19" seq="2006-1293" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Contrexx CMS 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF).</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428075/100/0/threaded">20060318 Contrexx CMS Xss Vuln</ref><ref source="" url="http://soot.shabgard.org/Contrexx-CMS.txt"></ref><ref source="" url="http://www.contrexx.com/?section=media1&amp;act=download&amp;path=/media/archive1/Opensource/Bugfixes/contrexx_1.0.8/&amp;file=contrexx_v1.0.8_bugfix_27-02-06.zip"></ref><ref source="" url="http://www.contrexx.com/?section=news&amp;cmd=details&amp;newsid=54"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17128">17128</ref><ref source="" url="http://www.contrexx.com/?section=media1&amp;act=download&amp;path=/media/archive1/Opensource/Bugfixes/contrexx_1.0.8/&amp;file=contrexx_v1.0.8_bugfix_27-02-06.zip"></ref><ref source="" url="http://www.contrexx.com/?section=news&amp;cmd=details&amp;newsid=54"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1013">ADV-2006-1013</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19294">19294</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25332">contrexx-index-xss(25332)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/599">599</ref></refs><vuln_soft><prod name="Contrexx" vendor="Astalavista IT Engineering"><vers num="1.0.8" prev="1"/><vers num="1.0.7"/><vers num="1.0.5"/><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1294" published="2006-03-19" seq="2006-1294" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in PageController.php in KnowledgebasePublisher 1.2 allows remote attackers to include and execute arbitrary PHP code via a URL in the dir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/1587"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17120">17120</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1020">ADV-2006-1020</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19298">19298</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25338">knowledgebasepublisher-dir-file-include(25338)</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=402179&amp;group_id=144153"></ref><ref source="OSVDB" url="http://www.osvdb.org/24002">24002</ref></refs><vuln_soft><prod name="KnowledgebasePublisher" vendor="KnowledgebasePublisher"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1295" published="2006-03-19" seq="2006-1295" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in recherche.php3 in SPIP 1.8.2-g allows remote attackers to inject arbitrary web script or HTML via the recherche parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.silitix.com/spip-xss.html"></ref><ref source="" url="http://www.zone-h.fr/advisories/read/id=1105"></ref><ref patch="1" source="" url="http://zone.spip.org/trac/spip-zone/changeset/1672"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17130">17130</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25389">
spip-research-xss(25389)</ref></refs><vuln_soft><prod name="SPIP" vendor="SPIP"><vers num="1.8.2g"/><vers num="1.8.2e"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-21" name="CVE-2006-1296" published="2006-03-19" seq="2006-1296" severity="High" type="CVE"><desc><descript source="cve">Untrusted search path vulnerability in Beagle 0.2.2.1 might allow local users to gain privileges via a malicious beagle-info program in the current working directory, or possibly directories specified in the PATH.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=357392"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19278">19278</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25303">beagle-beagle-status-privilege-escalation(25303)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17195">17195</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00047.html">FEDORA-2006-188</ref><ref source="OSVDB" url="http://www.osvdb.org/23942">23942</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19336">19336</ref></refs><vuln_soft><prod name="Beagle" vendor="Beagle"><vers num="0.2.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-1297" published="2006-03-19" seq="2006-1297" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Veritas Backup Exec for Windows Server Remote Agent 9.1 through 10.1, for Netware Servers and Remote Agent 9.1 and 9.2, and Remote Agent for Linux Servers 10.0 and 10.1 allow attackers to cause a denial of service (application crash or unavailability) due to &quot;memory errors.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428016/100/0/threaded">20060317 Symantec Security Advisory SYM06-004</ref><ref patch="1" source="" url="http://www.symantec.com/avcenter/security/Content/2006.03.17a.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17098">17098</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0995">ADV-2006-0995</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19242">19242</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015784">1015784</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25309">backupexec-app-memory-dos(25309)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/597">597</ref></refs><vuln_soft><prod name="Backup Exec" vendor="Symantec Veritas"><vers num="NetWare Server 9.1"/><vers num="NetWare Server 9.2"/></prod><prod name="Backup Exec Remote Agent" vendor="Symantec Veritas"><vers num="Windows Server 9.1"/><vers num="Windows Server 10.0"/><vers num="Windows Server 10.1"/><vers num="Unix/Linux Server 10.1"/><vers num="Unix/Linux Server 10.0"/><vers num="NetWare Server 9.1"/><vers num="NetWare Server 9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-1298" published="2006-03-19" seq="2006-1298" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the Job Engine service (bengine.exe) in the Media Server in Veritas Backup Exec 10d (10.1) for Windows Servers rev. 5629, Backup Exec 10.0 for Windows Servers rev. 5520, Backup Exec 10.0 for Windows Servers rev. 5484, and Backup Exec 9.1 for Windows Servers rev. 4691, when the job log mode is Full Detailed (aka Full Details), allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a crafted filename on a machine that is backed up by Backup Exec.</descript></desc><sols><sol source="nvd">This vulnerability can only be exploited if the &apos;job log&apos; mode is set to &quot;Full Detailed&quot; (aka Full Details).  Other older versions of Windows Server (those that have been End-Of-Life&apos;d) should be upgraded to the latest patch of one of the current versions listed above.</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Veritas" url="http://support.veritas.com/docs/282254">Document ID: 282254 </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17096">17096</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428223/100/0/threaded">20060320 Symantec Security Advisory, SYM06-005</ref><ref source="" url="http://www.symantec.com/avcenter/security/Content/2006.03.17b.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19242">19242</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0996">ADV-2006-0996</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015785">1015785</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25310">backupexec-bengine-format-string(25310)</ref></refs><vuln_soft><prod name="Backup Exec" vendor="Symantec Veritas"><vers num="for Windows Servers 9.1 rev. 4691 SP2"/><vers num="for Windows Servers 9.1 rev. 4691"/><vers num="for Windows Servers 9.1"/><vers num="for Windows Servers 10.1"/><vers num="for Windows Servers 10d"/><vers edition="Windows Servers" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-07-12" name="CVE-2006-1300" published="2006-07-11" seq="2006-1300" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified &quot;URL paths&quot; that can access Application Folder objects &quot;explicitly by name.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-033.mspx">MS06-033</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18920">18920</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2751">ADV-2006-2751</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016465">1016465</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20999">20999</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26802">ms-aspnet-appcode-information-disclosure(26802)</ref><ref source="OSVDB" url="http://www.osvdb.org/27153">27153</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:419">oval:org.mitre.oval:def:419</ref></refs><vuln_soft><prod name=".NET Framework" vendor="Microsoft"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-1301" published="2006-07-13" seq="2006-1301" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted SELECTION record that triggers memory corruption, a different vulnerability than CVE-2006-1302.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-037.mspx">MS06-037</ref><ref source="BID" url="http://www.securityfocus.com/bid/18853">18853</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2755">ADV-2006-2755</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016472">1016472</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:557">oval:org.mitre.oval:def:557</ref></refs><vuln_soft><prod name="Excel Viewer" vendor="Microsoft"><vers num="2003"/></prod><prod name="Excel" vendor="Microsoft"><vers edition="Mac OS X" num="X"/><vers edition="Mac OS X" num="2004"/><vers edition="SP1" num="2003"/><vers num="2003"/><vers edition="SP3" num="2002"/><vers edition="SP2" num="2002"/><vers edition="SP1" num="2002"/><vers num="2002"/><vers edition="SR1" num="2000"/><vers edition="SP3" num="2000"/><vers edition="SP2" num="2000"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-30" modified="2006-08-28" name="CVE-2006-1302" published="2006-07-13" seq="2006-1302" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka &quot;Malformed SELECTION record Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/439914/100/0/threaded">20060712 NSFOCUS SA2006-05 : Microsoft Excel SELECTION Record Memory Corruption Vulnerability</ref><ref adv="1" source="" url="http://www.nsfocus.com/english/homepage/research/0605.htm"></ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-037.mspx">MS06-037</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18885">18885</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2755">ADV-2006-2755</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016472">1016472</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:379">oval:org.mitre.oval:def:379</ref><ref source="SREASON" url="http://securityreason.com/securityalert/1238">1238</ref></refs><vuln_soft><prod name="Excel Viewer" vendor="Microsoft"><vers num="2003"/></prod><prod name="Excel" vendor="Microsoft"><vers edition="Mac OS X" num="X"/><vers edition="Mac OS X" num="2004"/><vers edition="SP1" num="2003"/><vers num="2003"/><vers edition="SP3" num="2002"/><vers edition="SP2" num="2002"/><vers edition="SP1" num="2002"/><vers num="2002"/><vers edition="SR1" num="2000"/><vers edition="SP3" num="2000"/><vers edition="SP2" num="2000"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-06-20" name="CVE-2006-1303" published="2006-06-13" seq="2006-1303" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code by instantiating certain COM objects from Wmm2fxa.dll as ActiveX controls including (1) DXImageTransform.Microsoft.MMSpecialEffect1Input, (2) DXImageTransform.Microsoft.MMSpecialEffect1Input.1, (3) DXImageTransform.Microsoft.MMSpecialEffect2Inputs, (4) DXImageTransform.Microsoft.MMSpecialEffect2Inputs.1, (5) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input, and (6) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input.1, which causes memory corruption during garbage collection.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-021.mspx">MS06-021</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18328">18328</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2319">ADV-2006-2319</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016291">1016291</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20595">20595</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/437041/100/0/threaded">20060613 ZDI-06-018: Microsoft Internet Explorer DXImageTransform ActiveX Memory Corruption Vulnerability</ref><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-06-018.html"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1135">oval:org.mitre.oval:def:1135</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1767">oval:org.mitre.oval:def:1767</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1830">oval:org.mitre.oval:def:1830</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1928">oval:org.mitre.oval:def:1928</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1973">oval:org.mitre.oval:def:1973</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2017">oval:org.mitre.oval:def:2017</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/959049">
VU#959049</ref><ref source="OSVDB" url="http://www.osvdb.org/26442">
26442</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26774">
ie-wmm2fxadll-execute-code(26774)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0.1 SP4"/><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers edition="Windows NT 4.0" num="5.0.1"/><vers edition="Windows 98" num="5.0.1"/><vers edition="Windows 95" num="5.0.1"/><vers edition="Windows 2000" num="5.0.1"/><vers num="5.0.1"/><vers num="6.0 SP1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-30" modified="2006-08-28" name="CVE-2006-1304" published="2006-07-13" seq="2006-1304" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a &quot;data filling operation.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/439909/100/0/threaded">20060712 NSFOCUS SA2006-06 : Microsoft Excel COLINFO Record Buffer Overflow Vulnerability</ref><ref adv="1" source="" url="http://www.nsfocus.com/english/homepage/research/0606.htm"></ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-037.mspx">MS06-037</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18888">18888</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2755">ADV-2006-2755</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016472">1016472</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:545">oval:org.mitre.oval:def:545</ref></refs><vuln_soft><prod name="Excel Viewer" vendor="Microsoft"><vers num="2003"/></prod><prod name="Excel" vendor="Microsoft"><vers edition="Mac OS X" num="X"/><vers edition="SP1" num="2003"/><vers num="2003"/><vers edition="SP3" num="2002"/><vers edition="SP2" num="2002"/><vers edition="SP1" num="2002"/><vers num="2002"/><vers edition="SR1" num="2000"/><vers edition="SP3" num="2000"/><vers edition="SP2" num="2000"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2006-1305" published="2006-12-31" seq="2006-1305" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers of recipients in To or CC headers.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-003.mspx">MS07-003</ref><ref source="" url="http://blogs.securiteam.com/index.php/archives/347"></ref><ref source="" url="http://osvdb.org/ref/24/24081-outlook1.txt"></ref><ref source="MLIST" url="http://linuxbox.org/pipermail/funsec/2006-March/005208.html">[funsec] 20060308 DOSing Outlook 2003</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/21937">21937</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0104">ADV-2007-0104</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1017488">1017488</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23674">23674</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html">TA07-009A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/617436">VU#617436</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded">HPSBST02184</ref><ref source="OSVDB" url="http://www.osvdb.org/31253">31253</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:122">oval:org.mitre.oval:def:122</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP2"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-30" modified="2006-08-28" name="CVE-2006-1306" published="2006-07-13" seq="2006-1306" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted BIFF record with an attacker-controlled array index that is used for a function pointer, aka &quot;Malformed OBJECT record Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/439884/100/0/threaded">20060712 Microsoft Excel Array Index Error Remote Code Execution</ref><ref adv="1" source="" url="http://secway.org/advisory/AD20060711.txt"></ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-037.mspx">MS06-037</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18886">18886</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2755">ADV-2006-2755</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016472">1016472</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:950">oval:org.mitre.oval:def:950</ref></refs><vuln_soft><prod name="Excel Viewer" vendor="Microsoft"><vers num="2003"/></prod><prod name="Excel" vendor="Microsoft"><vers edition="Mac OS X" num="X"/><vers edition="Mac OS X" num="2004"/><vers edition="SP1" num="2003"/><vers num="2003"/><vers edition="SP3" num="2002"/><vers edition="SP2" num="2002"/><vers edition="SP1" num="2002"/><vers num="2002"/><vers edition="SR1" num="2000"/><vers edition="SP3" num="2000"/><vers edition="SP2" num="2000"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-1308" published="2006-07-13" seq="2006-1308" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted FNGROUPCOUNT value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047837.html">20060712 Microsoft Excel Could Allow Remote Code Execution by Malformed FNGROUPCOUNT value Vulnerability</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-037.mspx">MS06-037</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18890">18890</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27464">excel-fngroupcount-bo(27464)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2755">ADV-2006-2755</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016472">1016472</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:243">oval:org.mitre.oval:def:243</ref></refs><vuln_soft><prod name="Excel Viewer" vendor="Microsoft"><vers num="2003"/></prod><prod name="Excel" vendor="Microsoft"><vers edition="Mac OS X" num="X"/><vers edition="Mac OS X" num="2004"/><vers edition="SP1" num="2003"/><vers num="2003"/><vers edition="SP3" num="2002"/><vers edition="SP2" num="2002"/><vers edition="SP1" num="2002"/><vers num="2002"/><vers edition="SR1" num="2000"/><vers edition="SP3" num="2000"/><vers edition="SP2" num="2000"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-1309" published="2006-07-13" seq="2006-1309" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-037.mspx">MS06-037</ref><ref source="BID" url="http://www.securityfocus.com/bid/18910">18910</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2755">ADV-2006-2755</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016472">1016472</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:752">oval:org.mitre.oval:def:752</ref></refs><vuln_soft><prod name="Excel Viewer" vendor="Microsoft"><vers num="2003"/></prod><prod name="Excel" vendor="Microsoft"><vers edition="Mac OS X" num="X"/><vers edition="Mac OS X" num="2004"/><vers edition="SP1" num="2003"/><vers num="2003"/><vers edition="SP3" num="2002"/><vers edition="SP2" num="2002"/><vers edition="SP1" num="2002"/><vers num="2002"/><vers edition="SR1" num="2000"/><vers edition="SP3" num="2000"/><vers edition="SP2" num="2000"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2006-1311" published="2007-02-13" seq="2006-1311" severity="High" type="CVE"><desc><descript source="cve">The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3, 2003 SP2, and Office 2004 for Mac; and Learning Essentials for Microsoft Office 1.0, 1.1, and 1.5 allows user-assisted remote attackers to execute arbitrary code via a malformed OLE object in an RTF file, which triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-013.mspx">MS07-013</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/368132">
VU#368132</ref><ref source="BID" url="http://www.securityfocus.com/bid/21876">
21876</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0582">
ADV-2007-0582</ref><ref source="OSVDB" url="http://www.osvdb.org/31886">
31886</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017640">
1017640</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017641">
1017641</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24152">
24152</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/30592">
ms-richedit-code-execution(30592)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html">TA07-044A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1090">oval:org.mitre.oval:def:1090</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP2"/></prod><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP2"/><vers num=""/></prod><prod name="Windows 2003" vendor="Microsoft"><vers num="SP1"/></prod><prod name="Learning Essentials" vendor="Microsoft"><vers num="1.0"/><vers num="1.1"/><vers num="1.5"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2006-12-20" name="CVE-2006-1313" published="2006-06-13" seq="2006-1313" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will &quot;release objects early&quot; in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-023.mspx">MS06-023</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/390044">VU#390044</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18359">18359</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2321">ADV-2006-2321</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20620">20620</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-164A.html">TA06-164A</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016283">1016283</ref><ref source="OSVDB" url="http://www.osvdb.org/26434">26434</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26805">ms-jscript-code-execution(26805)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1067">oval:org.mitre.oval:def:1067</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1644">oval:org.mitre.oval:def:1644</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1785">oval:org.mitre.oval:def:1785</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2003">oval:org.mitre.oval:def:2003</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="SP1" num="Web"/><vers num="Web"/><vers num="Standard 64-bit"/><vers edition="SP1" num="Standard"/><vers num="Standard"/><vers num="Enterprise 64-bit"/><vers edition="SP1" num="Enterprise Edition 64-bit"/><vers num="Enterprise Edition 64-bit"/><vers edition="SP1" num="Enterprise Edition"/><vers edition="Enterprise" num="SP1"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1" num="Datacenter Edition 64-bit"/><vers num="Datacenter Edition 64-bit"/><vers edition="SP1" num="Datacenter Edition"/><vers num="Datacenter Edition"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-07-12" name="CVE-2006-1314" published="2006-07-11" seq="2006-1314" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.tippingpoint.com/security/advisories/TSRT-06-02.html"></ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-035.mspx">MS06-035</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/439773/100/0/threaded">20060711 TSRT-06-02: Microsoft SRV.SYS Mailslot Ring0 Memory Corruption Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/189140">VU#189140</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26818">win-mailslot-bo(26818)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-192A.html">TA06-192A</ref><ref source="BID" url="http://www.securityfocus.com/bid/18863">18863</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2753">ADV-2006-2753</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21007">21007</ref><ref source="OSVDB" url="http://www.osvdb.org/27154">27154</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:600">oval:org.mitre.oval:def:600</ref><ref source="SREASON" url="http://securityreason.com/securityalert/1212">1212</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/><vers edition="64-bit" num="Professional"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/><vers num="SP1"/><vers num="Itanium"/><vers edition="Itanium" num="SP1"/><vers num="64-bit"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-07-12" name="CVE-2006-1315" published="2006-07-11" seq="2006-1315" severity="Medium" type="CVE"><desc><descript source="cve">The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not properly initialized, aka &quot;SMB Information Disclosure Vulnerability.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-035.mspx">MS06-035</ref><ref source="BID" url="http://www.securityfocus.com/bid/18891">18891</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26820">win-smb-information-disclosure(26820)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016467">1016467</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/439881/100/0/threaded">20060711 SMB Information Disclosure Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2753">ADV-2006-2753</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21007">21007</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/333636">VU#333636</ref><ref source="OSVDB" url="http://www.osvdb.org/27155">27155</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3">oval:org.mitre.oval:def:3</ref></refs><vuln_soft><prod name="Server Service" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-1316" published="2006-07-11" seq="2006-1316" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with malformed string that triggers memory corruption related to record lengths, aka &quot;Microsoft Office Parsing Vulnerability,&quot; a different vulnerability than CVE-2006-2389.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-038.mspx">MS06-038</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/580036">VU#580036</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2756">ADV-2006-2756</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21012">21012</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27607">office-string-parse-bo(27607)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-192A.html">TA06-192A</ref><ref source="BID" url="http://www.securityfocus.com/bid/18912">18912</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016469">1016469</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:918">oval:org.mitre.oval:def:918</ref><ref source="OSVDB" url="http://www.osvdb.org/27148">
27148</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2003 SP2"/><vers num="2003 SP1"/><vers num="2000 SP3"/><vers num="XP SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1319" published="2006-03-20" seq="2006-1319" severity="Medium" type="CVE"><desc><descript source="cve">chpst in runit 1.3.3-1 for Debian GNU/Linux, when compiled on little endian i386 machines against dietlibc, does not properly handle when multiple groups are specified in the -u option, which causes chpst to assign permissions for the root group due to inconsistent bit sizes for the gid_t type.</descript></desc><sols><sol source="nvd">This vulnerability may be relevant only to Debian GNU/Linux implementations on little endian i386 machines.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="debian.org" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=356016">#356016</ref><ref source="BID" url="http://www.securityfocus.com/bid/17179">17179</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19323">19323</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25419">
runit-chpst-gain-privileges(25419)</ref></refs><vuln_soft><prod name="runit" vendor="runit"><vers num="1.3.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1320" published="2006-03-20" seq="2006-1320" severity="High" type="CVE"><desc><descript source="cve">util.c in rssh 2.3.0 in Debian GNU/Linux does not use braces to make a block, which causes a check for CVS to always succeed and allows rsync and rdist to bypass intended access restrictions in rssh.conf.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=346322"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25424">debian-rssh-rsync-rdist-bypass-security(25424)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1109">DSA-1109</ref><ref source="BID" url="http://www.securityfocus.com/bid/18999">18999</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21087">21087</ref></refs><vuln_soft><prod name="rssh" vendor="rssh"><vers num="2.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1321" published="2006-03-20" seq="2006-1321" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in webcheck before 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the (1) url, (2) title, or (3) author name in a crawled page, which is not properly sanitized in the tooltips of a report.</descript></desc><sols><sol source="nvd">Versions before 1.0 are named &quot;linbot&quot; instead of &quot;webcheck&quot;.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Webcheck News" url="http://ch.tudelft.nl/~arthur/webcheck/news.html#20060130">2006-01-30 release 1.9.6 of webcheck </ref><ref source="BID" url="http://www.securityfocus.com/bid/17212">17212</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19309">19309</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25428">webcheck-content-xss(25428)</ref></refs><vuln_soft><prod name="webcheck" vendor="webcheck"><vers num="1.9.5" prev="1"/><vers num="1.9.4"/><vers num="1.9.3"/><vers num="1.9.2"/><vers num="1.9.1"/><vers num="1.9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1322" published="2006-03-20" seq="2006-1322" severity="Medium" type="CVE"><desc><descript source="cve">Novell Netware NWFTPD 5.06.05 allows remote attackers to cause a denial of service (ABEND) via an MDTM command that uses a long path for the target file, possibly due to a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2973435.htm"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17137">17137</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0975">ADV-2006-0975</ref><ref source="OSVDB" url="http://www.osvdb.org/23949">23949</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015781">1015781</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19265">19265</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25289">netware-nwftpd-mdtm-dos(25289)</ref></refs><vuln_soft><prod name="Netware FTP Server" vendor="Novell"><vers num="5.07"/></prod><prod name="Netware" vendor="Novell"><vers num="6.5 SP4"/></prod><prod name="Netware NWFTPD" vendor="Novell"><vers num="5.06.05" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-1323" published="2006-03-20" seq="2006-1323" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in WinHKI 1.6 and earlier allows user-assisted attackers to overwrite arbitrary files via a (1) RAR, (2) TAR, (3) ZIP, or (4) TAR.GZ archive with a file whose file name contains &quot;..&quot; sequences.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://hamid.ir/security/winhki.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1010">ADV-2006-1010</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19296">19296</ref><ref source="BID" url="http://www.securityfocus.com/bid/17153">17153</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428433/100/0/threaded">20060322 WinHKI 1.6x Archive Extraction Directory traversal</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25335">winhki-extract-directory-traversal(25335)</ref></refs><vuln_soft><prod name="WinHKI" vendor="Webtoolmaster Software"><vers num="1.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1324" published="2006-03-20" seq="2006-1324" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter when a SQL error is generated.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/428080">20060318 Xss in Wbb 2.3.4</ref><ref source="BID" url="http://www.securityfocus.com/bid/17147">17147</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1003">ADV-2006-1003</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19293">19293</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25313">wbb-classdbmysql-xss(25313)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015789">1015789</ref><ref source="SREASON" url="http://securityreason.com/securityalert/529">529</ref><ref source="SREASON" url="http://securityreason.com/securityalert/598">598</ref></refs><vuln_soft><prod name="Burning Board" vendor="Woltlab"><vers num="2.3.4" prev="1"/><vers num="1.0.2pl2e Lite" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-20" name="CVE-2006-1325" published="2006-03-20" seq="2006-1325" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Streber 0.055 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript></desc><sols><sol source="nvd">The vulnerability has been fixed in version 0.055 (development release).</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.streber-pm.org/phpBB2/viewtopic.php?p=491#491"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1005">ADV-2006-1005</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19263">19263</ref><ref source="BID" url="http://www.securityfocus.com/bid/17157">17157</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25317">streber-xss(25317)</ref></refs><vuln_soft><prod name="Streber" vendor="Streber"><vers num="0.055" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-21" name="CVE-2006-1326" published="2006-03-20" seq="2006-1326" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board 2.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) result_type, (2) search_in, (3) nav, (4) forums, and (5) s parameters in the Search action to index.php; (6) st parameter to index.php with showtopics set to 1; (7) m, (8) y, and (9) d parameters in a calendar action; (10) t parameter in a Print action; (11) MID parameter in a Mail action; (12) HID parameter in a Help action; (13) active parameter in a search action; (14) sort_order, (15) max_results, or (16) sort_key parameter in a Members action.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428015/100/0/threaded">20060317 XSS IN Invision Power Board</ref><ref source="BID" url="http://www.securityfocus.com/bid/17144">17144</ref><ref source="OSVDB" url="http://www.osvdb.org/25009">
25009</ref><ref source="OSVDB" url="http://www.osvdb.org/25010">
25010</ref><ref source="OSVDB" url="http://www.osvdb.org/25011">
25011</ref><ref source="OSVDB" url="http://www.osvdb.org/25012">
25012</ref><ref source="OSVDB" url="http://www.osvdb.org/25013">
25013</ref><ref source="OSVDB" url="http://www.osvdb.org/25014">
25014</ref><ref source="OSVDB" url="http://www.osvdb.org/25015">
25015</ref></refs><vuln_soft><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-21" name="CVE-2006-1327" published="2006-03-20" seq="2006-1327" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in reg.php in SoftBB 0.1 allows remote attackers to execute arbitrary SQL commands via the mail parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/1594"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1002">ADV-2006-1002</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19283">19283</ref><ref source="BID" url="http://www.securityfocus.com/bid/17160">17160</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25320">softbb-reg-sql-injection(25320)</ref><ref source="OSVDB" url="http://www.osvdb.org/23999">23999</ref></refs><vuln_soft><prod name="SoftBB" vendor="SoftBB"><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-21" name="CVE-2006-1328" published="2006-03-20" seq="2006-1328" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in count.php in Skull-Splitter PHP Downloadcounter for Wallpapers 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) count_fieldname, (2) url_fieldname, or (3) url parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/105/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1004">ADV-2006-1004</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19314">19314</ref><ref source="BID" url="http://www.securityfocus.com/bid/17156">17156</ref><ref source="OSVDB" url="http://www.osvdb.org/23972">23972</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25316">downloadcounter-count-sql-injection(25316)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429255/100/0/threaded">20060329 [eVuln] Skull-Splitter%27s PHP Downloadcounter for Wallpapers SQL Injection</ref><ref source="SREASON" url="http://securityreason.com/securityalert/649">649</ref></refs><vuln_soft><prod name="Download Counter Wallpaper" vendor="Skull-Splitter"><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-1329" published="2006-03-20" seq="2006-1329" severity="Medium" type="CVE"><desc><descript source="cve">The SASL negotiation in Jabber Studio jabberd before 2.0s11 allows remote attackers to cause a denial of service (&quot;c2s segfault&quot;) by sending a &quot;response stanza before an auth stanza&quot;.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://article.gmane.org/gmane.network.jabber.admin/27372"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1009">ADV-2006-1009</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19281">19281</ref><ref source="BID" url="http://www.securityfocus.com/bid/17155">17155</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25334">jabberd-sasl-dos(25334)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</ref></refs><vuln_soft><prod name="jabberd" vendor="JabberStudio"><vers num="2.0 s10"/><vers num="2.0 s9"/><vers num="2.0 s8"/><vers num="2.0 s7"/><vers num="2.0 s6"/><vers num="2.0 s5"/><vers num="2.0 s4"/><vers num="2.0 s3"/><vers num="2.0 s2"/><vers num="2.0 s1"/><vers num="2.0 rc2"/><vers num="2.0 rc1"/><vers num="2.0 b3"/><vers num="2.0 b2"/><vers num="2.0 b1"/><vers num="2.0 a6"/><vers num="2.0 a5"/><vers num="2.0 a4"/><vers num="2.0 a3"/><vers num="2.0 a2"/><vers num="2.0 a1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1330" published="2006-03-20" seq="2006-1330" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid parameter to (1) friend.php or (2) article.php.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/428156">20060318 phpWebsite &lt;= SQL Injection (friend.php) &amp; (article.php)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17150">17150</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1039">ADV-2006-1039</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19315">19315</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25328">phpwebsite-multiple-sql-injection(25328)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430870/100/0/threaded">20060413 Re: phpWebsite &lt;= SQL Injection (friend.php) &amp; (article.php)</ref></refs><vuln_soft><prod name="phpWebsite" vendor="phpWebsite"><vers num="0.8.3"/><vers num="0.8.2"/><vers num="0.7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-21" name="CVE-2006-1331" published="2006-03-20" seq="2006-1331" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah&apos;s Classifieds 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) method or (2) list parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/428157">20060320 Noah&apos;s Classifieds Multiple Path Disclosure and Cross Site Scripting Vulnerabilities</ref><ref adv="1" source="" url="http://zone14.free.fr/advisories/1"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17151">17151</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25331">noahs-index-path-disclosure(25331)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/0191.html">
20060308 Noah&apos;s Classifieds Multiple Cross-Site Scripting Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25099">
noahs-index-xss(25099)</ref></refs><vuln_soft><prod name="Noah&apos;s Classifieds" vendor="PhpOutsourcing"><vers num="1.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-21" name="CVE-2006-1332" published="2006-03-20" seq="2006-1332" severity="Medium" type="CVE"><desc><descript source="cve">Noah&apos;s Classifieds 1.3 and earlier allows remote attackers to obtain sensitive information via an invalid list parameter in the showdetails method to index.php, which reveals the path in an error message.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/428157">20060320 Noah&apos;s Classifieds Multiple Path Disclosure and Cross Site Scripting Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25331">noahs-index-path-disclosure(25331)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/471">471</ref><ref source="SREASON" url="http://securityreason.com/securityalert/605">605</ref></refs><vuln_soft><prod name="Noah&apos;s Classifieds" vendor="PhpOutsourcing"><vers num="1.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-21" name="CVE-2006-1333" published="2006-03-20" seq="2006-1333" severity="Medium" type="CVE"><desc><descript source="cve">Multpile SQL injection vulnerabilities in BetaParticle Blog 6.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to template_permalink.asp or (2) fldGalleryID parameter to template_gallery_detail.asp.</descript></desc><sols><sol source="nvd">Update to version 6.02.</sol></sols><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/428082">20060318 Advisory: BetaParticle Blog &lt;= 6.0 Multiple Remote SQL InjectionVulnerabilities</ref><ref source="" url="http://www.nukedx.com/?viewdoc=20"></ref><ref source="" url="http://blog.betaparticle.com/UserFiles/File/6fix.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17148">17148</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1000">ADV-2006-1000</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19292">19292</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25327">bpblog-multiple-sql-injection(25327)</ref><ref source="OSVDB" url="http://www.osvdb.org/23965">23965</ref><ref source="OSVDB" url="http://www.osvdb.org/23966">23966</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015788">1015788</ref><ref source="SREASON" url="http://securityreason.com/securityalert/600">600</ref></refs><vuln_soft><prod name="Betaparticle blog" vendor="Betaparticle"><vers num="6.0"/><vers num="5.0"/><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-21" name="CVE-2006-1334" published="2006-03-20" seq="2006-1334" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Maian Weblog 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) entry and (2) email parameters to (a) print.php and (b) mail.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/101/summary.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0994">ADV-2006-0994</ref><ref source="OSVDB" url="http://www.osvdb.org/23946">23946</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19273">19273</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25295">maianweblog-printmail-sql-injection(25295)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17159">17159</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428903/100/0/threaded">20060327 [eVuln] Maian Weblog Multiple SQL Injection Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17247">17247</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015818">1015818</ref><ref source="OSVDB" url="http://www.osvdb.org/23945">23945</ref><ref source="SREASON" url="http://securityreason.com/securityalert/638">638</ref></refs><vuln_soft><prod name="Maian Weblog" vendor="Maian Script World"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-1335" published="2006-03-20" seq="2006-1335" severity="Low" type="CVE"><desc><descript source="cve">gnome screensaver before 2.14, when running on an X server with AllowDeactivateGrabs and AllowClosedownGrabs enabled, allows attackers with physical access to cause the screensaver to crash and access the session via the Ctl+Alt+Keypad-Multiply keyboard sequence, which removes the grab from gnome.</descript></desc><sols><sol source="nvd">The vulnerability has reportedly been fixed in version 2.14.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref source="" url="http://bugzilla.gnome.org/show_bug.cgi?id=326663"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19280">19280</ref><ref source="OSVDB" url="http://www.osvdb.org/24015">24015</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25340">gnomescreensaver-security-bypass(25340)</ref></refs><vuln_soft><prod name="Screensaver" vendor="GNOME"><vers num="2.13" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1336" published="2006-03-20" seq="2006-1336" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in calendar.php in ExtCalendar 1.0 and possibly other versions before 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) year, (2) month, (3) next, and (4) prev parameters.</descript></desc><sols><sol source="nvd">This issue is reportedly addressed in ExtCalendar 2.0. Symantec has not confirmed this fix. Affected users are advised to contact the vendor for further information.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428131/100/0/threaded">20060319 ExtCalendar v1.0 Multiple Xss Vuln</ref><ref source="BID" url="http://www.securityfocus.com/bid/17146">17146</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1012">ADV-2006-1012</ref><ref source="OSVDB" url="http://www.osvdb.org/23969">23969</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19321">19321</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25350">extcalendar-calendar-xss(25350)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/601">601</ref></refs><vuln_soft><prod name="ExtCalendar" vendor="ExtCalendar"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-24" name="CVE-2006-1337" published="2006-03-20" seq="2006-1337" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the POP 3 (POP3) service in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edition before 1.21 allows remote attackers to execute arbitrary code via unknown vectors before authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.mailenable.com/enterprisehistory.asp"></ref><ref source="" url="http://www.mailenable.com/professionalhistory.asp"></ref><ref source="" url="http://www.mailenable.com/standardhistory.asp"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1006">ADV-2006-1006</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19288">19288</ref><ref source="BID" url="http://www.securityfocus.com/bid/17162">17162</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25314">mailenable-pop-authentication(25314)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015797">1015797</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1359.html">20060320 [MU-200603-01] MailEnable POP3 Pre-Authentication Buffer Overflow</ref><ref source="OSVDB" url="http://www.osvdb.org/24012">24012</ref></refs><vuln_soft><prod name="MailEnable Professional" vendor="MailEnable"><vers num="1.73" prev="1"/></prod><prod name="MailEnable Standard" vendor="MailEnable"><vers num="1.93" prev="1"/></prod><prod name="MailEnable Enterprise" vendor="MailEnable"><vers num="1.21" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-07-24" name="CVE-2006-1338" published="2006-03-20" seq="2006-1338" severity="Medium" type="CVE"><desc><descript source="cve">Webmail in MailEnable Professional Edition before 1.73 and Enterprise Edition before 1.21 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors involving &quot;incorrectly encoded quoted-printable emails&quot;.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://www.mailenable.com/enterprisehistory.asp"></ref><ref source="" url="http://www.mailenable.com/professionalhistory.asp"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1006">ADV-2006-1006</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19288">19288</ref><ref source="BID" url="http://www.securityfocus.com/bid/17161">17161</ref><ref source="OSVDB" url="http://www.osvdb.org/24014">24014</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25315">mailenable-webmail-component-dos(25315)</ref></refs><vuln_soft><prod name="MailEnable Professional" vendor="MailEnable"><vers num="1.72"/><vers num="1.71"/><vers num="1.7"/><vers num="1.6"/><vers num="1.54"/><vers num="1.53"/><vers num="1.52"/><vers num="1.51"/><vers num="1.5"/><vers num="1.2a"/><vers num="1.2"/><vers num="1.19"/><vers num="1.18"/><vers num="1.17"/></prod><prod name="MailEnable Enterprise" vendor="MailEnable"><vers num="1.2"/><vers num="1.1"/><vers num="1.04"/><vers num="1.03"/><vers num="1.02"/><vers num="1.01"/><vers num="1.00"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1339" published="2006-03-20" seq="2006-1339" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in inc/functions.inc.php in CuteNews 1.4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the archive parameter in an HTTP POST or COOKIE request, which bypasses a sanity check that is only applied to a GET request.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://hamid.ir/security/cutenews.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17152">17152</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19289">19289</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25324">cutenews-incfunction-directory-traversal(25324)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428434/100/0/threaded">20060322 cutenews 1.4.1 Arbitrary File Access</ref></refs><vuln_soft><prod name="CuteNews" vendor="CutePHP"><vers num="1.4.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1340" published="2006-03-20" seq="2006-1340" severity="Medium" type="CVE"><desc><descript source="cve">CuteNews 1.4.1 and possibly other versions allows remote attackers to obtain the installation path via unspecified vectors involving an invalid file path.</descript></desc><sols><sol source="nvd">Successful exploitation requires that the &quot;register_globals&quot; parameter is enabled.</sol></sols><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Hamid Ebadi" url="http://hamid.ir/security/cutenews.txt">cutenews 1.4.1 Arbitrary File Access</ref><ref source="BID" url="http://www.securityfocus.com/bid/17152">17152</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19289">19289</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428434/100/0/threaded">20060322 cutenews 1.4.1 Arbitrary File Access</ref></refs><vuln_soft><prod name="CuteNews" vendor="CutePHP"><vers num="1.4.1" prev="1"/><vers num="1.4.0"/><vers num="1.3.6"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3"/><vers num="0.88"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1341" published="2006-03-20" seq="2006-1341" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in events.php in Maian Events 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/102/description.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0993">ADV-2006-0993</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19274">19274</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25298">maianevents-events-sql-injection(25298)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429093/100/0/threaded">20060328 [eVuln] Maian Events SQL Injection Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/23947">23947</ref><ref source="SREASON" url="http://securityreason.com/securityalert/646">646</ref></refs><vuln_soft><prod name="Maian Events" vendor="Maian Events"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1342" published="2006-03-21" seq="2006-1342" severity="Low" type="CVE"><desc><descript source="cve">net/ipv4/af_inet.c in Linux kernel 2.4 does not clear sockaddr_in.sin_zero before returning IPv4 socket names from the (1) getsockname, (2) getpeername, and (3) accept functions, which allows local users to obtain portions of potentially sensitive memory.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-netdev&amp;m=114148078223594&amp;w=2">[linux-netdev] 20060304 BUG: Small information leak in SO_ORIGINAL_DST (2.4 and 2.6) and</ref><ref patch="1" source="kernel.org" url="http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git;a=commit;h=09d3b3dcfa80c9094f1748c1be064b9326c9ef2b">[PATCH] Fix small information leak in SO_ORIGINAL_DST and getname()</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19357">19357</ref><ref source="BID" url="http://www.securityfocus.com/bid/17203">17203</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0579.html">RHSA-2006:0579</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0580.html">RHSA-2006:0580</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21035">21035</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451404/100/0/threaded">20061113 VMSA-2006-0006 - VMware ESX Server 2.5.3 Upgrade Patch 4</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451419/100/200/threaded">20061113 VMSA-2006-0005 - VMware ESX Server 2.5.4 Upgrade Patch 1</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451417/100/200/threaded">20061113 VMSA-2006-0007 - VMware ESX Server 2.1.3 Upgrade Patch 2</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451426/100/200/threaded">20061113 VMSA-2006-0008 - VMware ESX Server 2.0.2 Upgrade Patch 2</ref><ref source="" url="http://www.vmware.com/download/esx/esx-202-200610-patch.html"></ref><ref source="" url="http://www.vmware.com/download/esx/esx-213-200610-patch.html"></ref><ref source="" url="http://www.vmware.com/download/esx/esx-254-200610-patch.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4502">ADV-2006-4502</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22875">22875</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1343" published="2006-03-21" seq="2006-1343" severity="Low" type="CVE"><desc><descript source="cve">net/ipv4/netfilter/ip_conntrack_core.c in Linux kernel 2.4 and 2.6, and possibly net/ipv4/netfilter/nf_conntrack_l3proto_ipv4.c in 2.6, does not clear sockaddr_in.sin_zero before returning IPv4 socket names from the getsockopt function with SO_ORIGINAL_DST, which allows local users to obtain portions of potentially sensitive memory.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-netdev&amp;m=114148078223594&amp;w=2">[linux-netdev] 20060304 BUG: Small information leak in SO_ORIGINAL_DST (2.4 and 2.6) and</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19357">19357</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25425">linux-sockaddr-memory-leak(25425)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17203">17203</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-281-1">USN-281-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19955">19955</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435490/100/0/threaded">20060531 rPSA-2006-0087-1 kernel</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2071">ADV-2006-2071</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0032/">2006-0032</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1097">DSA-1097</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20671">20671</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0579.html">RHSA-2006:0579</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0580.html">RHSA-2006:0580</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:123">MDKSA-2006:123</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21045">21045</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0437.html">RHSA-2006:0437</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21136">21136</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0575.html">RHSA-2006:0575</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21465">21465</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:150">MDKSA-2006:150</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21983">21983</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1184">DSA-1184</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22093">22093</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/22417">22417</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451404/100/0/threaded">20061113 VMSA-2006-0006 - VMware ESX Server 2.5.3 Upgrade Patch 4</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451419/100/200/threaded">20061113 VMSA-2006-0005 - VMware ESX Server 2.5.4 Upgrade Patch 1</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451417/100/200/threaded">20061113 VMSA-2006-0007 - VMware ESX Server 2.1.3 Upgrade Patch 2</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451426/100/200/threaded">20061113 VMSA-2006-0008 - VMware ESX Server 2.0.2 Upgrade Patch 2</ref><ref source="" url="http://www.vmware.com/download/esx/esx-202-200610-patch.html"></ref><ref source="" url="http://www.vmware.com/download/esx/esx-213-200610-patch.html"></ref><ref source="" url="http://www.vmware.com/download/esx/esx-254-200610-patch.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4502">ADV-2006-4502</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22875">22875</ref><ref source="OSVDB" url="http://www.osvdb.org/29841">
29841</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:123">MDKSA-2006:123</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:150">MDKSA-2006:150</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1344" published="2006-03-21" seq="2006-1344" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in VeriSign haydn.exe, as used in Managed PKI (MPKI) 6.0, allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the VHTML_FILE parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428267/100/0/threaded">20060320 CORE-2006-0124: Cross-Site Scripting in Verisign?s haydn.exe CGI script</ref><ref adv="1" source="" url="http://www.coresecurity.com/common/showdoc.php?idx=522&amp;idxseccion=10"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17170">17170</ref><ref source="" url="http://www.coresecurity.com/common/showdoc.php?idx=522&amp;idxseccion=10"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1084">ADV-2006-1084</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015813">1015813</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25349">verisign-haydn-xss(25349)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/614">614</ref></refs><vuln_soft><prod name="MPKI" vendor="VeriSign"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-05" name="CVE-2006-1345" published="2006-03-21" seq="2006-1345" severity="Medium" type="CVE"><desc><descript source="cve">polls.php in MyBB (aka MyBulletinBoard) 1.10 allows remote attackers to obtain sensitive information via a vote action with an &quot;option[]=null&quot; parameter value, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428056/100/0/threaded">20060317 MyBB 1.10 Full Path Disclosure</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25337">mybb-polls-path-disclosure(25337)</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1346" published="2006-03-21" seq="2006-1346" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a lang[*][file] parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by index.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/1595"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17165">17165</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1015">ADV-2006-1015</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19322">19322</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-April/000698.html">[VIM] 20060414 Provable vendor ACK for gcards issues</ref><ref source="OSVDB" url="http://www.osvdb.org/24016">24016</ref></refs><vuln_soft><prod name="gCards" vendor="Greg Neustaetter"><vers num="1.43"/><vers num="1.44"/><vers num="1.45" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1347" published="2006-03-21" seq="2006-1347" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in loginfunction.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript></desc><sols><sol source="nvd">Vulnerability can only be exploited if the &quot;magic_quotes_gpc&quot; parameter is set to Off.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/1595">ii) also we have SQL injection...</ref><ref source="BID" url="http://www.securityfocus.com/bid/17165">17165</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1015">ADV-2006-1015</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19322">19322</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25344">gcards-loginfunction-sql-injection(25344)</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-April/000698.html">[VIM] 20060414 Provable vendor ACK for gcards issues</ref><ref source="OSVDB" url="http://www.osvdb.org/24017">24017</ref></refs><vuln_soft><prod name="gCards" vendor="Greg Neustaetter"><vers num="1.45" prev="1"/><vers num="1.44"/><vers num="1.43"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1348" published="2006-03-21" seq="2006-1348" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang[*][file] parameter, which is injected into an error message.  NOTE: this issue might be resultant from CVE-2006-1346.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/1595">iii)xss:</ref><ref source="BID" url="http://www.securityfocus.com/bid/17165">17165</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1015">ADV-2006-1015</ref><ref source="OSVDB" url="http://www.osvdb.org/24018">24018</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19322">19322</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25343">gcards-incsetlang-xss(25343)</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-April/000698.html">[VIM] 20060414 Provable vendor ACK for gcards issues</ref></refs><vuln_soft><prod name="gCards" vendor="Greg Neustaetter"><vers num="1.45" prev="1"/><vers num="1.44"/><vers num="1.43"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-07-28" name="CVE-2006-1349" published="2006-03-21" seq="2006-1349" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Musicbox 2.3 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) id and (2) type and (3) show parameters in a top action in (a) index.php; and the (4) message1 parameter in (b) cart.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17149">17149</ref><ref source="OSVDB" url="http://www.osvdb.org/23967">23967</ref><ref source="OSVDB" url="http://www.osvdb.org/23968">23968</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25525">musicbox-index-cart-xss(25525)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428972/100/0/threaded">20060324 XSS &amp; SQL Injection in Music Box v2.3</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/441000/100/0/threaded">20060724 MusicBox &lt;= 2.3.4 XSS SQL injection Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27925">musicbox-multiple-xss(27925)</ref></refs><vuln_soft><prod name="MusicBox" vendor="MusicBox"><vers num="2.3 Beta 2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1350" published="2006-03-21" seq="2006-1350" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in index.php in 99Articles.com (aka ArticlesOne.com) Free articles directory allows remote attackers to include and execute arbitrary PHP code via a URL in the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428354/100/0/threaded">20060321 Free Articles Directory Remote Command Exucetion</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1037">ADV-2006-1037</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19320">19320</ref><ref source="BID" url="http://www.securityfocus.com/bid/17183">17183</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25378">freearticlesdirectory-index-file-include(25378)</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-March/000626.html">[VIM] 20060322 Free Articles Directory - file inclusion, code execution?</ref><ref source="OSVDB" url="http://www.osvdb.org/24024">24024</ref><ref source="SREASON" url="http://securityreason.com/securityalert/616">616</ref></refs><vuln_soft><prod name="99Articles Directory" vendor="ArticlesOne"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1351" published="2006-03-21" seq="2006-1351" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Server 6.1 SP7 and earlier allows remote attackers to read arbitrary files via unknown attack vectors related to a &quot;default internal servlet&quot; accessed through HTTP.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="dev2dev" url="http://dev2dev.bea.com/pub/advisory/180">(BEA06-120.00)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17166">17166</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1021">ADV-2006-1021</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19310">19310</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015792">1015792</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25347">weblogic-server-default-servlet(25347)</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="6.1 SP7"/><vers num="6.1 SP6"/><vers num="6.1 SP5"/><vers num="6.1 SP4"/><vers num="6.1 SP3"/><vers num="6.1 SP2"/><vers num="6.1 SP1"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1352" published="2006-03-21" seq="2006-1352" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and WebLogic Server 6.1 SP7 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via crafted non-canonicalized XML documents.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://dev2dev.bea.com/pub/advisory/183"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17167">17167</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1021">ADV-2006-1021</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19310">19310</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015790">1015790</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25348">weblogic-xml-parser-dos(25348)</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers edition="Win32" num="8.1 SP4"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/><vers edition="Win32" num="7.0 SP6"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="6.1 SP7"/><vers edition="Win32" num="6.1 SP6"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="8.1 SP4"/><vers num="8.1 SP3"/><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers num="7.0 SP6"/><vers num="7.0 SP5"/><vers num="7.0 SP4"/><vers num="7.0 SP3"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/><vers num="6.1 SP7"/><vers num="6.1 SP6"/><vers num="6.1 SP5"/><vers num="6.1 SP4"/><vers num="6.1 SP3"/><vers num="6.1 SP2"/><vers num="6.1 SP1"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1353" published="2006-03-21" seq="2006-1353" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in ASPPortal 3.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the downloadid parameter in download_click.asp and (2) content_ID parameter in news/News_Item.asp; authenticated administrators can also conduct attacks via (3) user_id parameter to users/add_edit_user.asp, (4) bannerid parameter to banner_adds/banner_add_edit.asp, (5) cat_id parameter to categories/add_edit_cat.asp, (6) Content_ID parameter to News/add_edit_news.asp, (7) download_id parameter to downloads/add_edit_download.asp, (8) Poll_ID parameter to poll/add_edit_poll.asp, (9) contactid parameter to contactus/contactus_add_edit.asp, (10) sortby parameter to poll/poll_list.asp, and (11) unspecified inputs to downloads/add_edit_download.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.nukedx.com/?viewdoc=21"></ref><ref source="" url="http://www.milw0rm.com/exploits/1597"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1014">ADV-2006-1014</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19286">19286</ref><ref source="BID" url="http://www.securityfocus.com/bid/17174">17174</ref><ref source="OSVDB" url="http://www.osvdb.org/24020">24020</ref><ref source="OSVDB" url="http://www.osvdb.org/24084">24084</ref><ref source="OSVDB" url="http://www.osvdb.org/24085">24085</ref><ref source="OSVDB" url="http://www.osvdb.org/24086">24086</ref><ref source="OSVDB" url="http://www.osvdb.org/24087">24087</ref><ref source="OSVDB" url="http://www.osvdb.org/24088">24088</ref><ref source="OSVDB" url="http://www.osvdb.org/24089">24089</ref><ref source="OSVDB" url="http://www.osvdb.org/24090">24090</ref><ref source="OSVDB" url="http://www.osvdb.org/24091">24091</ref><ref source="OSVDB" url="http://www.osvdb.org/24092">24092</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25346">aspportal-downloadclick-sql-injection(25346)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428355/100/0/threaded">20060321 ASPPortal &lt;= 3.1.1 Multiple Remote SQL Injection Vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428615/100/0/threaded">20060322 Re: [SPAM:] - ASPPortal &lt;= 3.1.1 Multiple Remote SQL Injection Vulnerabilities - Email has different SMTP TO: and MIME TO: fields in the email addresses</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1402.html">20060321 ASPPortal &lt;= 3.1.1 Multiple Remote SQL Injection Vulnerabilities</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1431.html">20060322 Re: [SPAM:] - ASPPortal &lt;= 3.1.1 Multiple Remote SQL Injection Vulnerabilities - Email has different SMTP TO: and MIME TO: fields in the email addresses</ref><ref source="SREASON" url="http://securityreason.com/securityalert/608">608</ref></refs><vuln_soft><prod name="ASPPortal" vendor="ASPPortal"><vers num="3.1.1"/><vers num="3.1.0"/><vers num="3.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1354" published="2006-03-21" seq="2006-1354" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash) via &quot;Insufficient input validation&quot; in the EAP-MSCHAPv2 state machine module.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.freeradius.org/security.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1016">ADV-2006-1016</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19300">19300</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:060">MDKSA-2006:060</ref><ref source="SUSE" url="http://lists.suse.de/archive/suse-security-announce/2006-Mar/0009.html">SUSE-SA:2006:019</ref><ref source="BID" url="http://www.securityfocus.com/bid/17171">17171</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015795">1015795</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19405">19405</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0020">2006-0020</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25352">freeradius-eap-mschapv2-auth-bypass(25352)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-03.xml">GLSA-200604-03</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0271.html">RHSA-2006:0271</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19518">19518</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19527">19527</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1089">DSA-1089</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20461">20461</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:060">MDKSA-2006:060</ref></refs><vuln_soft><prod name="FreeRADIUS" vendor="FreeRADIUS"><vers num="1.1.0"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1355" published="2006-03-21" seq="2006-1355" severity="High" type="CVE"><desc><descript source="cve">avast! Antivirus 4.6.763 and earlier sets &quot;BUILTIN\Everyone&quot; permissions to critical system files in the installation folder, which allows local users to gain privileges or disable protection by modifying those files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://www.dslreports.com/forum/remark,15601404~days=9999~start=20"></ref><ref source="" url="http://forum.avast.com/index.php?topic=19862.0"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1011">ADV-2006-1011</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19284">19284</ref><ref source="BID" url="http://www.securityfocus.com/bid/17158">17158</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25336">avast-files-bypass-authorization(25336)</ref></refs><vuln_soft><prod name="Avast Antivirus" vendor="ALWIL"><vers num="4.6.763" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-1356" published="2006-03-21" seq="2006-1356" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the count_vcards function in LibVC 3, as used in Rolo, allows user-assisted attackers to execute arbitrary code via a vCard file (e.g. contacts.vcf) containing a long line.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://osvdb.org/ref/23/23985-libvc.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/23985">23985</ref><ref source="BID" url="http://www.securityfocus.com/bid/17237">17237</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19295">19295</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25430">libvc-vc-bo(25430)</ref></refs><vuln_soft><prod name="Rolo" vendor="Andrew Hsu"><vers num="11"/></prod><prod name="LibVC" vendor="Andrew Hsu"><vers num="3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1357" published="2006-03-21" seq="2006-1357" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in my.support.php3 in F5 Firepass 4100 SSL VPN 5.4.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428318/100/0/threaded">20060321 XSS in Firepass 4100 SSL VPN v.5.4.2 (and probably others)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17175">17175</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1036">ADV-2006-1036</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015798">1015798</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19337">19337</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25393">firepass-mysupport-xss(25393)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/611">611</ref></refs><vuln_soft><prod name="Firepass 4100" vendor="F5"><vers num="5.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1358" published="2006-03-21" seq="2006-1358" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in BEA WebLogic Portal 8.1 up to SP5 causes a JSR-168 Portlet to be retrieved from the cache for the wrong session, which might allow one user to see a Portlet of another user.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref patch="1" source="" url="ftp://ftpna.beasys.com/pub/releases/security/patch_CR259534_81SP5.zip"></ref><ref adv="1" patch="1" source="" url="http://dev2dev.bea.com/pub/advisory/182"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1022">ADV-2006-1022</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19308">19308</ref><ref source="BID" url="http://www.securityfocus.com/bid/17164">17164</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015791">1015791</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25345">weblogic-portal-portlet-disclosure(25345)</ref></refs><vuln_soft><prod name="WebLogic Portal" vendor="BEA Systems"><vers num="8.1 SP5"/><vers num="8.1 SP4"/><vers num="8.1 SP3"/><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1359" published="2006-03-22" seq="2006-1359" severity="High" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/428441">20060322 IE crash</ref><ref adv="1" source="" url="http://www.computerterrorism.com/research/ct22-03-2006"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17196">17196</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1050">ADV-2006-1050</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18680">18680</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/876678">VU#876678</ref><ref source="" url="http://secunia.com/secunia_research/2006-7/advisory/"></ref><ref source="" url="http://www.microsoft.com/technet/security/advisory/917077.mspx"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428583/100/0/threaded">20060322 Microsoft Internet Explorer (mshtml.dll) - Remote Code Execution</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429088/100/0/threaded">20060328 EEYE: Temporary workaround for IE createTextRange vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/24050">24050</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015812">1015812</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25379">ie-createtextrange-command-execution(25379)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428600/100/0/threaded">20060323 Secunia Research: Microsoft Internet Explorer &quot;createTextRange()&quot;Code Execution</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx">MS06-013</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html">TA06-101A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1318">ADV-2006-1318</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1434.html">20060322 FW: [Full-disclosure] IE crash</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1427.html">20060322 IE crash</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1430.html">20060322 Microsoft Internet Explorer (mshtml.dll) - Remote Code Execution</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1662.html">20060327 Determina Fix for the IE createTextRange() bug</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/q-154.shtml">Q-154</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1178">oval:org.mitre.oval:def:1178</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1657">oval:org.mitre.oval:def:1657</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1678">oval:org.mitre.oval:def:1678</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1702">oval:org.mitre.oval:def:1702</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:985">oval:org.mitre.oval:def:985</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429124/30/6120/threaded">20060328 Determina Fix for CVE-2006-1359 (Zero Day MS Internet Explorer Remote &quot;CreateTextRange()&quot; Code Execution)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0 SP2" num="6"/><vers edition="for Microsoft Windows Server 2003 SP1.0 SP1" num="6"/><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/><vers edition="Beta 2" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-07-28" name="CVE-2006-1360" published="2006-03-23" seq="2006-1360" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in MusicBox 2.3 Beta 2 allow remote attckers to execute arbitrary SQL commands via the (1) id, (2) type, or (3) show parameter to (a) index.php; or the (4) message1 or (5) message parameter to (b) cart.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17149">17149</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428972/100/0/threaded">20060324 XSS &amp; SQL Injection in Music Box v2.3</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/441000/100/0/threaded">20060724 MusicBox &lt;= 2.3.4 XSS SQL injection Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27926">musicbox-multiple-sql-injection(27926)</ref></refs><vuln_soft><prod name="MusicBox" vendor="MusicBox"><vers num="2.3 Beta 2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-11-27" name="CVE-2006-1361" published="2006-03-23" seq="2006-1361" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in OSWiki before 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the username field to (1) list.rhtml or (2) show.rhtml.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
OSWiki, OSWiki, 0.3.1</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://svn.sourceforge.net/viewcvs.cgi/opensourcewiki/branches/0.3/oswiki/app/views/user/list.rhtml?view=log"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1035">ADV-2006-1035</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19290">19290</ref><ref source="BID" url="http://www.securityfocus.com/bid/17189">17189</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25410">oswiki-username-xss(25410)</ref></refs><vuln_soft><prod name="OSWiki" vendor="OSWiki"><vers num="0.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1362" published="2006-03-23" seq="2006-1362" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Mini-Nuke CMS System 1.8.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter in (a) members.asp, the (2) catid parameter in (b) articles.asp and (c) programs.asp, and the (3) id parameter in (d) hpages.asp and (e) forum.asp.  NOTE: The pages.asp/id vector is already covered by CVE-2006-0870.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428361/100/0/threaded">20060321 Mini-Nuke&lt;=1.8.2 SQL injection</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18439">18439</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25372">mininuke-multiple-sql-injection(25372)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/617">617</ref></refs><vuln_soft><prod name="Mini-Nuke CMS" vendor="Mini-Nuke"><vers num="1.8.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-1363" published="2006-03-23" seq="2006-1363" severity="High" type="CVE"><desc><descript source="cve">images.php in Justin White (aka YTZ) Free Web Publishing System (FreeWPS) 2.11 allows remote attackers to execute arbitrary PHP code by uploading a .php file into the /upload directory as specified in the dirPath parameter, then performing a direct request to that file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/1600">freewps 2.11 exploit</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1038">ADV-2006-1038</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19343">19343</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25377">freewps-images-file-include(25377)</ref></refs><vuln_soft><prod name="FreeWPS" vendor="Justin White"><vers num="2.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-1364" published="2006-03-23" seq="2006-1364" severity="High" type="CVE"><desc><descript source="cve">Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each of several documents that refer to COM components, or are restricted documents located under the ASP.NET application path.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/1601">w3wp-dos.c</ref><ref source="" url="http://hackingspirits.com/vuln-rnd/w3wp-remote-dos.zip"></ref><ref source="" url="http://www.securiteam.com/windowsntfocus/5KP0O0KI0Y.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17188">17188</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428622/100/0/threaded">20060322 w3wp remote DoS</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044292.html">20060322 w3wp remote DoS</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044291.html">20060322 w3wp remote DoS due to improper reference of STA COM components in ASP.NET</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015825">1015825</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25392">ms-aspnet-w3wp-dos(25392)</ref></refs><vuln_soft><prod name="ASP.NET" vendor="Microsoft"><vers num="1.1 SP1"/><vers num="1.1"/><vers num="1.0 SP2"/><vers num="1.0 SP1"/><vers num="1.0"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-1365" published="2006-03-23" seq="2006-1365" severity="Medium" type="CVE"><desc><descript source="cve">The Motorola PEBL U6, the Motorola V600, and possibly the Motorola E398 and other Motorola phones allow remote attackers to add an entry for their own Bluetooth device to a target device&apos;s list of trusted devices (aka Device History), and possibly obtain AT level access to the target device, by initiating and interrupting an OBEX Push Profile that pretends to send a vCard, aka a &quot;HeloMoto&quot; attack.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://trifinite.org/trifinite_stuff_helomoto.html"></ref><ref source="" url="http://www.digitalmunition.com/DMA%5B2006-0321a%5D.txt"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428431/100/0/threaded">20060321 DMA[2006-0321a] - &apos;Motorola P2K Platform setpath() overflow and Blueline attack&apos;</ref></refs><vuln_soft><prod name="PEBL U6" vendor="Motorola"><vers num="08.83.76R"/></prod><prod name="E398" vendor="Motorola"><vers num=""/></prod><prod name="V600" vendor="Motorola"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-1366" published="2006-03-23" seq="2006-1366" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Motorola PEBL U6 08.83.76R, and possibly other Motorola P2K-based phones, allows remote attackers to cause a denial of service (device shutdown), and possibly execute arbitrary code, via a long OBEX setpath to the OBEX File Transfer (aka FTP) service on Bluetooth channel 9.</descript></desc><sols><sol source="nvd">Arbitrary code execution may also be possible, but has not been confirmed.  This vulnerability may affect other versions of Motorola P2K-based phones.</sol></sols><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428431/100/0/threaded">20060321 DMA[2006-0321a] - &apos;Motorola P2K Platform setpath() overflow and Blueline attack&apos;</ref><ref source="Digital Munition" url="http://www.digitalmunition.com/DMA%5B2006-0321a%5D.txt">DMA[2006-0321a]</ref><ref source="BID" url="http://www.securityfocus.com/bid/17185">17185</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1045">ADV-2006-1045</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19319">19319</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25401">motorola-peblu6-v600-obex-bo(25401)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044287.html">20060321 DMA[2006-0321a] - &apos;Motorola P2K Platform setpath() overflow and Blueline attack&apos;</ref></refs><vuln_soft><prod name="PEBL U6" vendor="Motorola"><vers num="U6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-1367" published="2006-03-23" seq="2006-1367" severity="High" type="CVE"><desc><descript source="cve">The Motorola PEBL U6 08.83.76R, the Motorola V600, and possibly the Motorola E398 and other Motorola P2K-based phones does not require pairing for a connection related to the Headset Audio Gateway service, which allows user-assisted remote attackers to obtain AT level access and view phonebook entries and saved SMS messages by connecting on Bluetooth channel 3 and tricking the user into pressing Grant, aka a &quot;Blueline&quot; attack.  NOTE: while user-assisted, the attack is made more feasible because of a GUI misrepresentation issue that allows a default message to be replaced by an attacker-specified one.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428431/100/0/threaded">20060321 DMA[2006-0321a] - &apos;Motorola P2K Platform setpath() overflow and Blueline attack&apos;</ref><ref source="" url="http://www.digitalmunition.com/DMA%5B2006-0321a%5D.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17190">17190</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1045">ADV-2006-1045</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19319">19319</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044287.html">20060321 DMA[2006-0321a] - &apos;Motorola P2K Platform setpath() overflow and Blueline attack&apos;</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25402">motorola-peblu6-v600-name-spoofing(25402)</ref></refs><vuln_soft><prod name="PEBL U6" vendor="Motorola"><vers num="U6 08.83.76R"/></prod><prod name="V600" vendor="Motorola"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-06-05" name="CVE-2006-1368" published="2006-03-23" seq="2006-1368" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the USB Gadget RNDIS implementation in the Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (kmalloc&apos;d memory corruption) via a remote NDIS response to OID_GEN_SUPPORTED_LIST, which causes memory to be allocated for the reply data but not the reply structure.</descript></desc><sols><sol source="nvd">Update to version 2.6.16.</sol></sols><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=8763716bfe4d8a16bef28c9947cf9d799b1796a5"></ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19330">19330</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1046">ADV-2006-1046</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-281-1">USN-281-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/17831">17831</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19955">19955</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1097">DSA-1097</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20671">20671</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:123">MDKSA-2006:123</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21045">21045</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:123">MDKSA-2006:123</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.15" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-1369" published="2006-03-23" seq="2006-1369" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.5 and earlier before 20060308 allows remote attackers to inject arbitrary web script or HTML via a Private Message (PM) in certain circumstances.</descript></desc><sols><sol source="nvd">Update to version 2.1.5 (2006-03-08 or later).</sol></sols><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://forums.invisionpower.com/index.php?showtopic=209178"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17187">17187</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1044">ADV-2006-1044</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19299">19299</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25384">invision-privatemessage-xss(25384)</ref></refs><vuln_soft><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.1.5"/><vers num="2.1 Alpha2"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-11" name="CVE-2006-1370" published="2006-03-23" seq="2006-1370" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne Player v1, RealPlayer 8, and RealPlayer Enterprise before 20060322 allows remote attackers to have an unknown impact via a malicious Mimio boardCast (mbc) file.</descript></desc><sols><sol source="nvd">This vulnerability affects all versions of RealNetworks, RealPlayer from 10.5 v6.0.12.1040 through 10.5 v6.0.12.1348.  </sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="RealNetworks" url="http://www.service.real.com/realplayer/security/03162006_player/en/">RealNetworks Releases Product Updates.</ref><ref source="BID" url="http://www.securityfocus.com/bid/17202">17202</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1057">ADV-2006-1057</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19358">19358</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015810">1015810</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/451556">VU#451556</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25411">realnetworks-mbc-bo(25411)</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers num="10.5_6.0.12.1348"/><vers num="10.5_6.0.12.1235"/><vers num="10.5_6.0.12.1069"/><vers num="10.5_6.0.12.1059"/><vers num="10.5_6.0.12.1056"/><vers num="10.5_6.0.12.1053"/><vers num="10.5_6.0.12.1040"/><vers num="10.0"/><vers num="8.0"/><vers edition="Enterprise" num="Any"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1371" published="2006-03-23" seq="2006-1371" severity="High" type="CVE"><desc><descript source="cve">Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea FileManager plugin to upload and execute arbitrary PHP files using (1) manager.php, (2) standalonemanager.php, and (3) images.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/1605">Exploit 605</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1052">ADV-2006-1052</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19353">19353</ref><ref source="" url="http://xhp.targetit.ro/index.php?page=3&amp;box_id=34&amp;action=show_single_entry&amp;post_id=10"></ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-March/000649.html">[VIM] 20060324 XHP vendor ack/fix</ref><ref source="BID" url="http://www.securityfocus.com/bid/17209">17209</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25399">xhpcms-filemanager-file-include(25399)</ref><ref source="OSVDB" url="http://www.osvdb.org/24058">24058</ref><ref source="OSVDB" url="http://www.osvdb.org/24059">24059</ref></refs><vuln_soft><prod name="CMS" vendor="XHP"><vers num="0.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-1372" published="2006-03-23" seq="2006-1372" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) EventID parameter in viewEvent.cfm, (2) NewsID parameter in newsView.cfm, or (3) ThisDate parameter in mainCal.cfm.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Blogspot" url="http://pridels.blogspot.com/2006/03/1webcalendar-v-4x-vuln.html">1WebCalendar v 4.x vuln. </ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1040">ADV-2006-1040</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19329">19329</ref><ref source="BID" url="http://www.securityfocus.com/bid/17193">17193</ref><ref source="OSVDB" url="http://www.osvdb.org/24021">24021</ref><ref source="OSVDB" url="http://www.osvdb.org/24022">24022</ref><ref source="OSVDB" url="http://www.osvdb.org/24023">24023</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25373">1webcalendar-multiple-sql-injection(25373)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/1webcalendar-v-4x-vuln.html"></ref></refs><vuln_soft><prod name="1WebCalendar" vendor="Benson IT Solutions"><vers num="4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-1373" published="2006-03-23" seq="2006-1373" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in status_image.php in PHP Live! 3.0 allows remote attackers to inject arbitrary web script or HTML via the base_url parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428452/100/0/threaded">20060322 PHP Live! XSS status_image.php</ref><ref source="BID" url="http://www.securityfocus.com/bid/17184">17184</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1054">ADV-2006-1054</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19340">19340</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25386">phplive-statusimage-xss(25386)</ref></refs><vuln_soft><prod name="PHP Live" vendor="PHP Live"><vers num="3.0" prev="1"/><vers num="2.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-1374" published="2006-03-23" seq="2006-1374" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in viewStatement.php in AdMan 1.0.20051221 and earlier allows remote attackers to execute arbitrary SQL commands via the transactions_offset parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Blogspot" url="http://pridels.blogspot.com/2006/03/adman-v10x-sql-vuln.html">AdMan v1.0.x SQL vuln </ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1071">ADV-2006-1071</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19351">19351</ref><ref source="BID" url="http://www.securityfocus.com/bid/17208">17208</ref><ref source="OSVDB" url="http://www.osvdb.org/24064">24064</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25403">adman-viewstatement-sql-injection(25403)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/adman-v10x-sql-vuln.html"></ref></refs><vuln_soft><prod name="AdMan" vendor="Brain Book Software"><vers num="1.0.20051221" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-1375" published="2006-03-23" seq="2006-1375" severity="Medium" type="CVE"><desc><descript source="cve">AdMan 1.0.20051221 and earlier allows remote attackers to obtain the full path via (1) a blank campaignId parameter to editCampaign.php and (2) a blank schemeId parameter to viewPricingScheme.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://pridels.blogspot.com/2006/03/adman-v10x-sql-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1071">ADV-2006-1071</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19351">19351</ref><ref source="OSVDB" url="http://www.osvdb.org/24065">24065</ref><ref source="OSVDB" url="http://www.osvdb.org/24066">24066</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25404">adman-multiple-path-disclosure(25404)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/adman-v10x-sql-vuln.html"></ref></refs><vuln_soft><prod name="AdMan" vendor="Brain Book Software"><vers num="1.0.20051221" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-1376" published="2006-03-23" seq="2006-1376" severity="Low" type="CVE"><desc><descript source="cve">The installation of Debian GNU/Linux 3.1r1 from the network install CD creates /var/log/debian-installer/cdebconf with world writable permissions, which allows local users to cause a denial of service (disk consumption).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=358210"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19331">19331</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25526">debian-cdebconf-world-writable(25526)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="3.1 r1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-1377" published="2006-03-23" seq="2006-1377" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in img.php in (1) EasyMoblog 0.5.1 and (2) CoMoblog 1.1 allows remote attackers to inject arbitrary web script or HTML via the i parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428553/100/0/threaded">20060323 [KAPDA::#37] - CoMoblog XSS</ref><ref adv="1" source="Kapda" url="http://www.kapda.ir/advisory-301.html">CoMoblog &amp; EasyMoblog XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/17201">17201</ref><ref source="BID" url="http://www.securityfocus.com/bid/17199">17199</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1086">ADV-2006-1086</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1087">ADV-2006-1087</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015824">1015824</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19370">19370</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19379">19379</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25416">comoblog-img-xss(25416)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25420">easymoblog-img-xss(25420)</ref><ref source="OSVDB" url="http://www.osvdb.org/24093">24093</ref><ref source="OSVDB" url="http://www.osvdb.org/24094">24094</ref></refs><vuln_soft><prod name="CoMoblog" vendor="PHP"><vers num="1.1"/></prod><prod name="EasyMoblog" vendor="PHP"><vers num="0.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2006-1378" published="2006-03-23" seq="2006-1378" severity="Medium" type="CVE"><desc><descript source="cve">PasswordSafe 3.0 beta, when running on Windows before XP, uses a weak random number generator (C++ rand function) during generation of the database encryption key, which makes it easier for attackers to decrypt the database and steal passwords by generating keys for all possible rand() seed values and conducting a known plaintext attack.</descript></desc><sols><sol source="nvd">This vulnerability exists only in Windows OS environments before XP.  For some reason it would not let me notate that in the &quot;vulnerable software&quot; section.</sol></sols><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428552/100/0/threaded">20060323 PasswordSafe 3.0 weak random number generator allows key recovery attack</ref><ref source="BID" url="http://www.securityfocus.com/bid/17200">17200</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25429">passwordsafe-key-brute-force(25429)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/445509/100/0/threaded">20060907 Re: PasswordSafe 3.0 weak random number generator allows key recovery attack</ref><ref source="SREASON" url="http://securityreason.com/securityalert/618">618</ref></refs><vuln_soft><prod name="Password Safe" vendor="Counterpane"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-1379" published="2006-03-24" seq="2006-1379" severity="High" type="CVE"><desc><descript source="cve">Trend Micro PC-cillin Internet Security 2006 14.00.1485 and 14.10.0.1023, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying executable programs such as (1) tmntsrv.exe and (2) tmproxy.exe.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Secumind" url="http://www.secumind.net/content/french/modules/news/article.php?storyid=9&amp;sel_lang=english">vulnerability (privilege escalation) in Trend Micro Officescan/PCCillin and IMSS</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1042">ADV-2006-1042</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19282">19282</ref></refs><vuln_soft><prod name="PC-Cillin 2006" vendor="Trend Micro"><vers num="14.10.0.1023" prev="1"/><vers num="14.00.1485"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-1380" published="2006-03-24" seq="2006-1380" severity="High" type="CVE"><desc><descript source="cve">ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possibly other versions before 5.7.0.1121, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying ISNTSysMonitor.exe.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.secumind.net/content/french/modules/news/article.php?storyid=9&amp;sel_lang=english"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1041">ADV-2006-1041</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19022">19022</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25415">
imss-isntsmtp-directory-permissions(25415)</ref></refs><vuln_soft><prod name="InterScan Messaging Security Suite" vendor="Trend Micro"><vers num="5.5 build 1183" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-1381" published="2006-03-24" seq="2006-1381" severity="High" type="CVE"><desc><descript source="cve">Trend Micro OfficeScan 5.5, and probably other versions before 6.5, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying tmlisten.exe.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.secumind.net/content/french/modules/news/article.php?storyid=9&amp;sel_lang=english"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1041">ADV-2006-1041</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/11576">11576</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25415">
imss-isntsmtp-directory-permissions(25415)</ref></refs><vuln_soft><prod name="OfficeScan" vendor="Trend Micro"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-1382" published="2006-03-24" seq="2006-1382" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in impex/ImpExData.php in vBulletin ImpEx module 1.74, when register_globals is disabled, allows remote attackers to include arbitrary files via the systempath parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044318.html">20060323 XOR Crew :: vBulletin ImpEx &lt;= 1.74 - Remote Command Execution Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1056">ADV-2006-1056</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19352">19352</ref><ref source="BID" url="http://www.securityfocus.com/bid/17206">17206</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25391">impex-impexdata-file-include(25391)</ref><ref source="OSVDB" url="http://www.osvdb.org/24070">24070</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467666/100/0/threaded">

20070504 Remote File Include In Script impex</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34095">
impex-systempath-file-include(34095)</ref></refs><vuln_soft><prod name="ImpEx" vendor="Jelsoft"><vers num="1.74" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1383" published="2006-03-24" seq="2006-1383" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Baby FTP Server (BabyFTP) 1.24 allows remote authenticated users to determine existence of files outside the intended document root via unspecified manipulations, which generate different error messages depending on whether a file exists or not.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1069">ADV-2006-1069</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19338">19338</ref><ref source="BID" url="http://www.securityfocus.com/bid/17205">17205</ref><ref source="" url="http://packetstormsecurity.org/0305-exploits/baby.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/24057">24057</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25413">
baby-ftp-information-disclosure(25413)</ref></refs><vuln_soft><prod name="Baby FTP Server" vendor="Pablo Software Solutions"><vers num="1.24"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-1384" published="2006-03-24" seq="2006-1384" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in apwc_win_main.jsp in the web console in IBM Tivoli Business Systems Manager (TBSM) before 3.1.0.1 allows remote attackers to inject arbitrary web script or HTML via the skin parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1OA14904">OA14904</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1073">ADV-2006-1073</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19332">19332</ref><ref source="BID" url="http://www.securityfocus.com/bid/17210">17210</ref><ref source="OSVDB" url="http://www.osvdb.org/24069">24069</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015822">1015822</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25412">tivoli-bsm-skin-xss(25412)</ref></refs><vuln_soft><prod name="Tivoli Business Systems Manager" vendor="IBM"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-1385" published="2006-03-24" seq="2006-1385" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the parseTaggedData function in WavePacket.mm in KisMAC R54 through R73p allows remote attackers to execute arbitrary code via multiple SSIDs in a Cisco vendor tag in a 802.11 management frame.</descript></desc><sols><sol source="nvd">Update to version R73p.</sol></sols><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428537/100/0/threaded">20060323 Advisory 03/2006: KisMAC Cisco Vendor Tag Encapsulated SSID Overflow</ref><ref source="" url="http://www.hardened-php.net/advisory_032006.115.html"></ref><ref source="" url="http://kismac.de/_trac/changeset/113"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17198">17198</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1070">ADV-2006-1070</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19354">19354</ref><ref source="OSVDB" url="http://www.osvdb.org/24072">24072</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25422">kismac-80211-gain-access(25422)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044323.html">
20060323 Advisory 03/2006: KisMAC Cisco Vendor Tag Encapsulated SSID Overflow</ref><ref source="SREASON" url="http://securityreason.com/securityalert/609">609</ref></refs><vuln_soft><prod name="KisMAC" vendor="KisMAC"><vers num="0.5d4"/><vers num="0.5d"/><vers num="0.2a"/><vers num="0.1c"/><vers num="0.1b"/><vers num="0.1a"/><vers num="0.12a"/><vers num="0.11a"/><vers num="0.10a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-1386" published="2006-03-26" seq="2006-1386" severity="High" type="CVE"><desc><descript source="cve">The (1) rdiff and (2) preview scripts in TWiki 4.0 and 4.0.1 ignore access control settings, which allows remote attackers to read restricted areas and access restricted content in TWiki topics.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="" url="http://twiki.org/cgi-bin/view/Codev/SecurityAlertTWiki4RdiffPreviewAccess"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17268">17268</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1116">ADV-2006-1116</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015843">1015843</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19410">19410</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25444">twiki-restricted-content-access(25444)</ref></refs><vuln_soft><prod name="TWiki" vendor="TWiki"><vers num="4.0.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-1387" published="2006-03-26" seq="2006-1387" severity="Medium" type="CVE"><desc><descript source="cve">TWiki 4.0, 4.0.1, and 20010901 through 20040904 allows remote authenticated users with edit rights to cause a denial of service (infinite recursion leading to CPU and memory consumption) via INCLUDE by URL statements that form a loop, such as a page that includes itself.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://twiki.org/cgi-bin/view/Codev/SecurityAdvisoryDosAttackWithInclude"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17267">17267</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1116">ADV-2006-1116</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19410">19410</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25445">twiki-include-edit-dos(25445)</ref></refs><vuln_soft><prod name="TWiki" vendor="TWiki"><vers num="4.0.1"/><vers num="4.0"/><vers num="2004-09-04"/><vers num="2004-09-03"/><vers num="2004-09-02"/><vers num="2004-09-01"/><vers num="2003-02-01"/><vers num="2001-12-01"/><vers num="2001-09-01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-24" name="CVE-2006-1388" published="2006-03-24" seq="2006-1388" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="" url="http://jeffrey.vanderstad.net/grasshopper/"></ref><ref source="" url="http://news.zdnet.com/2100-1009_22-6052396.html?tag=zdfd.newsfeed"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17181">17181</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015800">1015800</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25394">ie-hta-file-execution(25394)</ref><ref source="OSVDB" url="http://www.osvdb.org/24095">24095</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19378">19378</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-013.mspx">MS06-013</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html">TA06-101A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/434641">VU#434641</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1318">ADV-2006-1318</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1415.html">20060321 IE .hta vulnerability reported</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1591">oval:org.mitre.oval:def:1591</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1642">oval:org.mitre.oval:def:1642</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1676">oval:org.mitre.oval:def:1676</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1724">oval:org.mitre.oval:def:1724</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1774">oval:org.mitre.oval:def:1774</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0 SP2" num="6"/><vers edition="for Microsoft Windows Server 2003 SP1.0 SP1" num="6"/><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-1389" published="2006-03-24" seq="2006-1389" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in swagentd in HP-UX B.11.00, B.11.04, and B.11.11 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="HP" url="http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00622788">HPSBUX02105</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17215">17215</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1089">ADV-2006-1089</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015819">1015819</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19373">19373</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-076.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19395">19395</ref><ref source="OSVDB" url="http://www.osvdb.org/24097">24097</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25421">hpux-swagentd-dos(25421)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1031">oval:org.mitre.oval:def:1031</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:312">oval:org.mitre.oval:def:312</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:616">oval:org.mitre.oval:def:616</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="B.11.11"/><vers num="B.11.04"/><vers num="B.11.00"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-1390" published="2006-03-24" seq="2006-1390" severity="Medium" type="CVE"><desc><descript source="cve">The configuration of NetHack 3.4.3-r1 and earlier, Falcon&apos;s Eye 1.9.4a and earlier, and Slash&apos;EM 0.0.760 and earlier on Gentoo Linux allows local users in the games group to modify saved games files to execute arbitrary code via buffer overflows and overwrite arbitrary files via symlink attacks.</descript></desc><sols><sol source="nvd">This vulnerability applies only to the following games/versions: 
1) NetHack 3.4.3-r1 and previous 
2) Falcon&apos;s Eye 1.9.4a and previous 
3) Slash&apos;EM 0.0.760 and previous</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="Gentoo.org" url="http://bugs.gentoo.org/show_bug.cgi?id=122376">Bug#: 122376  </ref><ref source="Gentoo.org" url="http://bugs.gentoo.org/show_bug.cgi?id=125902">Bug#: 125902  </ref><ref source="Gentoo.org" url="http://bugs.gentoo.org/show_bug.cgi?id=127167">Bug#: 127167 </ref><ref source="Gentoo.org" url="http://bugs.gentoo.org/show_bug.cgi?id=127319">Bug#: 127319 </ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-23.xml">GLSA-200603-23</ref><ref source="BID" url="http://www.securityfocus.com/bid/17217">17217</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19376">19376</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428743/100/0/threaded">20060324 Re: [ GLSA 200603-23 ] NetHack, Slash%27EM, Falcon%27s Eye: Local privilege escalation</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428739/100/0/threaded">20060324 Re: [ GLSA 200603-23 ] NetHack, Slash%27EM, Falcon%27s Eye: Localprivilege escalation</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25528">gentoo-multiple-games-privilege-escalation(25528)</ref><ref source="OSVDB" url="http://www.osvdb.org/24104">24104</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/><vers num="1.2"/><vers num="1.1a"/><vers num="0.7"/><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-1391" published="2006-03-24" seq="2006-1391" severity="Medium" type="CVE"><desc><descript source="cve">The (a) Quick &apos;n Easy Web Server before 3.1.1 and (b) Baby ASP Web Server 2.7.2 allows remote attackers to obtain the source code of ASP files via (1) . (dot) and (2) space characters in the extension of a URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428667/100/0/threaded">20060324 Secunia Research: Quick &apos;n Easy/Baby Web Server ASP CodeDisclosure Vulnerability</ref><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2006-19/advisory/"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17222">17222</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1085">ADV-2006-1085</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1088">ADV-2006-1088</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/24100">24100</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19306">19306</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19312">19312</ref><ref source="OSVDB" url="http://www.osvdb.org/24099">24099</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25417">baby-web-asp-disclosure(25417)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25418">quickneasy-web-asp-disclosure(25418)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/624">624</ref></refs><vuln_soft><prod name="Quick and Easy Web Server" vendor="Pablo Software Solutions"><vers num="3.0.6"/><vers num="3.1.0"/></prod><prod name="Baby ASP Web Server" vendor="Pablo Software Solutions"><vers num="2.7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-06-01" name="CVE-2006-1392" published="2006-03-26" seq="2006-1392" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in the login server in University of Washington Pubcookie 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified inputs.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://pubcookie.org/news/20060306-login-secadv.html"></ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/337585">VU#337585</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19348">19348</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25427">pubcookie-login-server-xss(25427)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17221">17221</ref><ref source="OSVDB" url="http://www.osvdb.org/24521">24521</ref></refs><vuln_soft><prod name="Pubcookie" vendor="University of Washington"><vers num="3.0.0"/><vers num="3.1.0"/><vers num="3.1.1"/><vers num="3.2.0"/><vers num="3.2.1"/><vers num="3.2.1a"/><vers num="3.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-1393" published="2006-03-26" seq="2006-1393" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the mod_pubcookie Apache application server module in University of Washington Pubcookie 1.x, 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://pubcookie.org/news/20060306-apps-secadv.html"></ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/314540">VU#314540</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19348">19348</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25426">pubcookie-appserver-module-xss(25426)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17221">17221</ref><ref source="OSVDB" url="http://www.osvdb.org/24103">24103</ref></refs><vuln_soft><prod name="Pubcookie" vendor="University of Washington"><vers num="3.0.0"/><vers num="3.1.0"/><vers num="3.1.1"/><vers num="3.2.0"/><vers num="3.2.1"/><vers num="3.2.1a"/><vers num="3.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-1394" published="2006-03-26" seq="2006-1394" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Microsoft IIS ISAPI filter (aka application server module) in University of Washington Pubcookie 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://pubcookie.org/news/20060306-apps-secadv.html"></ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/314540">VU#314540</ref><ref source="BID" url="http://www.securityfocus.com/bid/17221">17221</ref><ref source="OSVDB" url="http://www.osvdb.org/24520">24520</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19348">19348</ref></refs><vuln_soft><prod name="Pubcookie" vendor="University of Washington"><vers num="3.0.0"/><vers num="3.1.0"/><vers num="3.1.1"/><vers num="3.2.0"/><vers num="3.2.1"/><vers num="3.2.1a"/><vers num="3.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-1395" published="2006-03-26" seq="2006-1395" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in mb.cgi in Cholod MySQL Based Message Board allows remote attackers to execute arbitrary SQL commands via unspecified vectors in a showmessage action, possibly the username parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17224">17224</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1153">ADV-2006-1153</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19439">19439</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25520">cholod-mb-sql-injection(25520)</ref></refs><vuln_soft><prod name="MySQL Based Message Board" vendor="Cholod"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-1396" published="2006-03-26" seq="2006-1396" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Cholod MySQL Based Message Board allow remote attackers to inject arbitrary web script or HTML via unknown vectors.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17223">17223</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1153">ADV-2006-1153</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19439">19439</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25518">cholod-mb-xss(25518)</ref></refs><vuln_soft><prod name="MySQL Based Message Board" vendor="Cholod"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1397" published="2006-03-28" seq="2006-1397" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (a) phpAdsNew and (b) phpPgAds before 2.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) certain parameters to the banner delivery module, which is not properly handled in the administrator interface, or (2) certain parameters to the login form.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428898/100/0/threaded">20060327 [PHPADSNEW-SA-2006-001] phpAdsNew and phpPgAds 2.0.8 fix multiple vulnerabilities</ref><ref source="" url="http://phpadsnew.com/two/nucleus/index.php?itemid=46"></ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=404963"></ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=404964"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17251">17251</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1107">ADV-2006-1107</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015829">1015829</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015828">1015828</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19384">19384</ref><ref source="OSVDB" url="http://www.osvdb.org/24205">24205</ref><ref source="OSVDB" url="http://www.osvdb.org/24206">24206</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25458">phpadsnew-login-banner-xss(25458)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/633">633</ref></refs><vuln_soft><prod name="phpAdsNew" vendor="phpAdsNew"><vers num="2.0.7"/><vers num="2.0.5"/><vers num="2 dev 2001-10-09"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0"/></prod><prod name="phpPgAds" vendor="phpPgAds"><vers num="2.0.7"/><vers num="2.0.5"/><vers num="2.0.4 pr2"/><vers num="2.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1398" published="2006-03-28" seq="2006-1398" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in guestbook.php in G-Book 1.0 allows remote attackers to inject arbitrary web script or HTML via the g_message parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428900/100/0/threaded">20060327 HYSA-2006-006 G-Book 1.0 XSS And Other Vulnerabilities</ref><ref adv="1" source="" url="http://www.h4cky0u.org/advisories/HYSA-2006-006-g-book.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17253">17253</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1100">ADV-2006-1100</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19414">19414</ref><ref source="OSVDB" url="http://www.osvdb.org/24141">24141</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015830">1015830</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25475">gbook-guestbook-xss(25475)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/634">634</ref></refs><vuln_soft><prod name="G-Book" vendor="Sixal"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1399" published="2006-03-28" seq="2006-1399" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in searchresult.php in Meeting Reserve 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the search_term parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17256">17256</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1110">ADV-2006-1110</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19372">19372</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25432">meeting-reserve-searchresult-xss(25432)</ref><ref source="OSVDB" url="http://www.osvdb.org/24162">24162</ref></refs><vuln_soft><prod name="Meeting Reserve" vendor="PHP Lite"><vers num="1.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1400" published="2006-03-28" seq="2006-1400" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in MyTasks/PersonalTaskEdit.asp in Metisware Instructor 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the Task parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://pridels.blogspot.com/2006/03/metisware-instructor-xss-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17234">17234</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1112">ADV-2006-1112</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19385">19385</ref><ref source="OSVDB" url="http://www.osvdb.org/24139">24139</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25490">metisware-instructor-personaltaskcreate-xss(25490)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/metisware-instructor-xss-vuln.html"></ref></refs><vuln_soft><prod name="Instructor" vendor="Metisware"><vers num="1.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1401" published="2006-03-28" seq="2006-1401" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in search.php in Calendar Express 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) allwords or (2) oneword parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17240">17240</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1109">ADV-2006-1109</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19393">19393</ref><ref source="OSVDB" url="http://www.osvdb.org/24161">24161</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25467">calendarexpress-search-xss(25467)</ref></refs><vuln_soft><prod name="Calendar Express" vendor="PHP Lite"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1402" published="2006-03-28" seq="2006-1402" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in client/server Doom (csDoom) 0.7 and earlier allows remote attackers to (1) cause a denial of service via a long nickname or teamname to the SV_SetupUserInfo function or (2) execute arbitrary code via a long string sent when joining a match or a long chat message to the SV_BroadcastPrintf function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://aluigi.altervista.org/adv/csdoombof-adv.txt"></ref><ref source="" url="http://voxelsoft.com/csdoom/"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17248">17248</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1105">ADV-2006-1105</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19389">19389</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25448">csdoom-sv-broadcastprintf-bo(25448)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25449">csdoom-sv-setupuserinfo-bo(25449)</ref></refs><vuln_soft><prod name="csDoom" vendor="csDoom"><vers num="2005 0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1403" published="2006-03-28" seq="2006-1403" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the PrintString function in c_console.cpp in client/server Doom (csDoom) 0.7 and earlier allows remote attackers cause a denial of service and possibly execute arbitrary commands via format string specifiers in strings passed to the console.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/csdoombof-adv.txt">csdoombof-adv</ref><ref patch="1" source="Voxelsoft" url="http://voxelsoft.com/csdoom/">n/a</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17248">17248</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1105">ADV-2006-1105</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19389">19389</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25450">csdoom-printf-format-string(25450)</ref></refs><vuln_soft><prod name="csDoom 2005" vendor="csDoom"><vers num="0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1404" published="2006-03-28" seq="2006-1404" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in bol.cgi in BlankOL 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) file or (2) function parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/03/blankol-xss-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1111">ADV-2006-1111</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19387">19387</ref><ref source="BID" url="http://www.securityfocus.com/bid/17265">17265</ref><ref source="OSVDB" url="http://www.osvdb.org/24124">24124</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25488">blankol-bol-xss(25488)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/blankol-xss-vuln.html"></ref></refs><vuln_soft><prod name="BlankOL" vendor="Industrial Imagination"><vers num="1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1405" published="2006-03-28" seq="2006-1405" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.aspx in SweetSuite.NET Content Management System (ssCMS) 2.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/03/sweetsuitenet-sscms-21x-xss-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1097">ADV-2006-1097</ref><ref source="OSVDB" url="http://www.osvdb.org/24120">24120</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19399">19399</ref><ref source="BID" url="http://www.securityfocus.com/bid/17254">17254</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25452">sscms-search-xss(25452)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/sweetsuitenet-sscms-21x-xss-vuln.html"></ref></refs><vuln_soft><prod name="ssCMS" vendor="Sheer Vision Technologies"><vers num="2.1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1406" published="2006-03-28" seq="2006-1406" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in wbadmlog.aspx in uniForum 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtuser or (2) txtpassword parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/03/uniforum-xss-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17245">17245</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1101">ADV-2006-1101</ref><ref source="OSVDB" url="http://www.osvdb.org/24123">24123</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19397">19397</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25433">uniforum-wbadmlog-xss(25433)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/uniforum-xss-vuln.html"></ref></refs><vuln_soft><prod name="uniForum" vendor="uniForum"><vers num="4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1407" published="2006-03-28" seq="2006-1407" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp.</descript></desc><sols><sol source="nvd">These issues are reportedly fixed by the vendor. Version 3.2.10-stable will contain these fixes when it is released. Contact the vendor for further information on obtaining fixes.</sol></sols><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/03/helm-web-hosting-control-panel-xss.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17263">17263</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1093">ADV-2006-1093</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19375">19375</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-March/000654.html">[VIM] 20060327 Helm Control Panel followup</ref><ref source="OSVDB" url="http://www.osvdb.org/24125">24125</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25470">helm-domainsdefault-xss(25470)</ref><ref source="OSVDB" url="http://www.osvdb.org/24126">24126</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/30309">
helm-domainsusersdefaault-xss(30309)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/helm-web-hosting-control-panel-xss.html"></ref></refs><vuln_soft><prod name="Helm Web Hosting Control Panel" vendor="WebHost Automation"><vers num="3.2.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1408" published="2006-03-28" seq="2006-1408" severity="Medium" type="CVE"><desc><descript source="cve">Vavoom 1.19.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via (1) a packet with no data or (2) a large packet, which prevents Vavoom from discarding the packet from the socket.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://aluigi.altervista.org/adv/vaboom-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17261">17261</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1104">ADV-2006-1104</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19388">19388</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25454">vavoom-fionread-dos(25454)</ref></refs><vuln_soft><prod name="Vavoom" vendor="Vavoom"><vers num="1.19.1"/><vers num="1.19"/><vers num="1.18"/><vers num="1.17"/><vers num="1.16.1"/><vers num="1.16"/><vers num="1.15.3"/><vers num="1.15.2"/><vers num="1.15.1"/><vers num="1.15"/><vers num="1.15 BETA 1"/><vers num="1.14"/><vers num="1.12"/><vers num="1.11.2"/><vers num="1.11.1"/><vers num="1.11"/><vers num="1.10"/><vers num="1.9"/><vers num="1.8"/><vers num="1.7"/><vers num="1.7 BETA 5"/><vers num="1.7 BETA 4"/><vers num="1.7 BETA 3"/><vers num="1.7 BETA 2"/><vers num="1.7 BETA 1"/><vers num="1.666"/><vers num="1.666 BETA 2"/><vers num="1.666 BETA 1"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.5 BETA"/><vers num="1.4"/><vers num="1.4 BETA"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1409" published="2006-03-28" seq="2006-1409" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Vavoom 1.19.1 and earlier allows remote attackers to cause a denial of service (application crash) via an invalid comprLength value in a compressed packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://aluigi.altervista.org/adv/vaboom-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17261">17261</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1104">ADV-2006-1104</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19388">19388</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25455">vavoom-comprlength-bo(25455)</ref></refs><vuln_soft><prod name="Vavoom" vendor="Vavoom"><vers num="1.19.1"/><vers num="1.19"/><vers num="1.18"/><vers num="1.17"/><vers num="1.16.1"/><vers num="1.16"/><vers num="1.15.3"/><vers num="1.15.2"/><vers num="1.15.1"/><vers num="1.15"/><vers num="1.15 BETA 1"/><vers num="1.14"/><vers num="1.12"/><vers num="1.11.2"/><vers num="1.11.1"/><vers num="1.11"/><vers num="1.10"/><vers num="1.9"/><vers num="1.8"/><vers num="1.7"/><vers num="1.7 BETA 5"/><vers num="1.7 BETA 4"/><vers num="1.7 BETA 3"/><vers num="1.7 BETA 2"/><vers num="1.7 BETA 1"/><vers num="1.666"/><vers num="1.666 BETA 2"/><vers num="1.666 BETA 1"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.5 BETA"/><vers num="1.4"/><vers num="1.4 BETA"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1410" published="2006-03-28" seq="2006-1410" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XIGLA Absolute Live Support XE 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Screen name or (2) Session Topic field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://pridels.blogspot.com/2006/03/absolute-live-support-xe-v20-xss-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17258">17258</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1099">ADV-2006-1099</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19415">19415</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25434">absolutelivesupport-register-xss(25434)</ref><ref source="OSVDB" url="http://www.osvdb.org/24131">
24131</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/absolute-live-support-xe-v20-xss-vuln.html"></ref></refs><vuln_soft><prod name="Absolute Live Support XE" vendor="XIGLA"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1411" published="2006-03-28" seq="2006-1411" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the shownew parameter in gallery.asp and (2) unspecified search module parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://pridels.blogspot.com/2006/03/absolute-image-gallery-xe-20-xss-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1103">ADV-2006-1103</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25466">absolute-gallery-xss(25466)</ref><ref source="BID" url="http://www.securityfocus.com/bid/18712">18712</ref><ref source="OSVDB" url="http://www.osvdb.org/24214">
24214</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/absolute-image-gallery-xe-20-xss-vuln.html"></ref></refs><vuln_soft><prod name="Absolute Image Gallery XE" vendor="XIGLA"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1412" published="2006-03-28" seq="2006-1412" severity="Medium" type="CVE"><desc><descript source="cve">TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin password file and obtain password hashes via a direct request to admin/passwd.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/1611"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1115">ADV-2006-1115</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19411">19411</ref><ref source="BID" url="http://www.securityfocus.com/bid/17250">17250</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25465">tftgallery-passwd-disclosure(25465)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/453471/100/0/threaded">20061204 Multiple bugs in TFT-Gallery</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/453485/100/0/threaded">20061204 Re: Multiple bugs in TFT-Gallery</ref></refs><vuln_soft><prod name="TFT Gallery" vendor="TFT Gallery"><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1413" published="2006-03-28" seq="2006-1413" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in EZHomepagePro 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) adid or (2) aname parameter in (a) common/email.asp, (b) users/users_search.asp, or (c) users/users_profiles.asp; (3) page parameter in (d) users/users_calendar.asp; (4) usid parameter in (e) users/users_mgallery.asp; or (5) m parameter in (f) users/users_search.asp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://pridels.blogspot.com/2006/03/ezhomepagepro-multiple-xss-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17236">17236</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1094">ADV-2006-1094</ref><ref source="OSVDB" url="http://www.osvdb.org/24132">24132</ref><ref source="OSVDB" url="http://www.osvdb.org/24133">24133</ref><ref source="OSVDB" url="http://www.osvdb.org/24136">24136</ref><ref source="OSVDB" url="http://www.osvdb.org/24135">24135</ref><ref source="OSVDB" url="http://www.osvdb.org/24134">24134</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19386">19386</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25468">ezhomepagepro-multiple-xss(25468)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/ezhomepagepro-multiple-xss-vuln.html"></ref></refs><vuln_soft><prod name="EZHomePagePro" vendor="HTMLJunction"><vers num="1.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1414" published="2006-03-28" seq="2006-1414" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in toast.asp in Toast Forums 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) author, (2) subject, (3) message, or (4) dayprune parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://pridels.blogspot.com/2006/03/xss-in-toast-forums-16.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17249">17249</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1092">ADV-2006-1092</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/24119">24119</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19401">19401</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25440">toastforums-toast-xss(25440)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/xss-in-toast-forums-16.html"></ref></refs><vuln_soft><prod name="Toast Forums" vendor="Toast Forums"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1415" published="2006-03-28" seq="2006-1415" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in iforget.aspx in dotNetBB 2.42EC SP 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the em parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/03/xss-vuln-in-dotnetbb-v24.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17246">17246</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1098">ADV-2006-1098</ref><ref source="OSVDB" url="http://www.osvdb.org/24122">24122</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19398">19398</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25462">dotnetbb-iforget-xss(25462)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/xss-vuln-in-dotnetbb-v24.html"></ref></refs><vuln_soft><prod name="dotNetBB Forums" vendor="dotNetBB"><vers num="2.42EC SP 3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1416" published="2006-03-28" seq="2006-1416" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in afmsearch.aspx in Absolute FAQ Manager .NET 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the question parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://pridels.blogspot.com/2006/03/absolute-faq-manager-net-xss-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1096">ADV-2006-1096</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19396">19396</ref><ref source="BID" url="http://www.securityfocus.com/bid/17242">17242</ref><ref source="OSVDB" url="http://www.osvdb.org/24127">24127</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25463">absolutefaqmanager-search-xss(25463)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/absolute-faq-manager-net-xss-vuln.html"></ref></refs><vuln_soft><prod name="Absolute FAQ Manager .NET" vendor="XIGLA"><vers num="4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-04" name="CVE-2006-1417" published="2006-03-28" seq="2006-1417" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Caloris Planitia Online Quiz System (aka Web Quiz pro), possibly 1.0, allow remote attackers to inject arbitrary web script or HTML via the (1) exam parameter in prequiz.asp or (2) msg parameter in student.asp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Blogspot" url="http://pridels.blogspot.com/2006/03/web-quiz-pro-xss-vuln.html">Web Quiz pro XSS vuln.</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1091">ADV-2006-1091</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19416">19416</ref><ref source="BID" url="http://www.securityfocus.com/bid/17255">17255</ref><ref source="OSVDB" url="http://www.osvdb.org/24129">24129</ref><ref source="OSVDB" url="http://www.osvdb.org/24130">24130</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25431">webquiz-multiple-xss(25431)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/web-quiz-pro-xss-vuln.html"></ref></refs><vuln_soft><prod name="Web Quiz Pro" vendor="Caloris Planitia Technologies"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-07-12" name="CVE-2006-1418" published="2006-03-28" seq="2006-1418" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in default.asp in Caloris Planitia E-School Management System 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.</descript></desc><sols><sol source="nvd">A new version of School Management System was released on May 28, 2006.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="Blogspot" url="http://pridels.blogspot.com/2006/03/e-school-management-system-xss-vuln.html">E-School Management System XSS vuln.</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1095">ADV-2006-1095</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19381">19381</ref><ref source="BID" url="http://www.securityfocus.com/bid/17257">17257</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25469">eschoolmanagementsystem-default-xss(25469)</ref><ref source="OSVDB" url="http://www.osvdb.org/24128">24128</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/e-school-management-system-xss-vuln.html"></ref></refs><vuln_soft><prod name="E-School Management System" vendor="Caloris Planitia Technologies"><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1419" published="2006-03-28" seq="2006-1419" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the Calendar module in nuked-klan 1.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter to index.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428895/100/0/threaded">20060326 nuked-klan&lt;=1.7.5 SQL Injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/17233">17233</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1134">ADV-2006-1134</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19382">19382</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25446">nuked-klan-calendar-sql-injection(25446)</ref><ref source="OSVDB" url="http://www.osvdb.org/24204">24204</ref><ref source="SREASON" url="http://securityreason.com/securityalert/632">632</ref></refs><vuln_soft><prod name="Nuked-Klan" vendor="Nuked-Klan"><vers num="1.7.5" prev="1"/><vers num="1.7"/><vers num="1.5 SP2"/><vers num="1.5"/><vers num="1.4"/><vers num="1.3 Beta"/><vers num="1.3"/><vers num="1.2 Beta"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1420" published="2006-03-28" seq="2006-1420" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in print.php in SaphpLesson 2.0 allows remote attackers to execute arbitrary SQL commands via the lessid parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428891/100/0/threaded">20060325 SQL Injection in SaphpLesson2.0</ref><ref source="BID" url="http://www.securityfocus.com/bid/17239">17239</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25453">saphplesson-print-sql-injection(25453)</ref><ref source="OSVDB" url="http://www.osvdb.org/24254">24254</ref><ref source="SREASON" url="http://securityreason.com/securityalert/629">629</ref></refs><vuln_soft><prod name="SaphpLesson" vendor="Arabless"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1421" published="2006-03-28" seq="2006-1421" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in akocomment.php in AkoComment 2.0 module for Mambo, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) acname or (2) contentid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428893/100/0/threaded">20060326 AkoComment SQL injection vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17241">17241</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1136">ADV-2006-1136</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19392">19392</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25451">akocomment-akocomment-sql-injection(25451)</ref><ref source="OSVDB" url="http://www.osvdb.org/24209">24209</ref><ref source="SREASON" url="http://securityreason.com/securityalert/631">631</ref></refs><vuln_soft><prod name="AkoComment" vendor="Arthur Konze WebDesign"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1422" published="2006-03-28" seq="2006-1422" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in details_view.php in PHP Booking Calendar 1.0c and earlier allows remote attackers to execute arbitrary SQL commands via the event_id parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/1610">exploit 1610</ref><ref source="BID" url="http://www.securityfocus.com/bid/17230">17230</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25580">phpbookingcal-detailsview-sql-injection(25580)</ref></refs><vuln_soft><prod name="phpBookingCalendar" vendor="PHP"><vers num="1.0c" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1423" published="2006-03-28" seq="2006-1423" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in showflat.php in UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2, and earlier, allows remote attackers to execute arbitrary SQL commands via the Number parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428833/100/0/threaded">20060325 UBBThreads&lt;=5.5.1+6.0.2+6.0 br5+6.0.1 SQL injection</ref><ref source="SREASON" url="http://securityreason.com/securityalert/628">628</ref></refs><vuln_soft><prod name="UBB.threads" vendor="UBBCentral"><vers num="6.0.2" prev="1"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.5.1"/><vers num="3.5"/><vers num="3.4"/></prod></vuln_soft></entry><entry modified="2006-04-19" name="CVE-2006-1424" published="2006-03-28" reject="1" seq="2006-1424" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-1482.  Reason: This candidate is a duplicate of CVE-2006-1482.  Notes: All CVE users should reference CVE-2006-1482 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><refs/></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-1425" published="2006-03-28" seq="2006-1425" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in track.php in phpmyfamily 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428901/100/0/threaded">20060327 HYSA-2006-007 phpmyfamily 1.4.1 CRLF injection &amp; XSS</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114344921211241&amp;w=2">20060327 HYSA-2006-007 phpmyfamily 1.4.1 CRLF injection &amp;</ref><ref source="BID" url="http://www.securityfocus.com/bid/17278">17278</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1130">ADV-2006-1130</ref><ref source="OSVDB" url="http://www.osvdb.org/24166">24166</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19409">19409</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25476">phpmyfamily-track-xss(25476)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/636">636</ref></refs><vuln_soft><prod name="phpmyfamily" vendor="phpmyfamily"><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1426" published="2006-03-28" seq="2006-1426" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Pixel Motion Blog allow remote attackers to execute arbitrary SQL commands via the (1) date parameter in index.php or bypass authentication via the (2) password parameter in admin/index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428964/100/0/threaded">20060327 Blog Pixel Motion&lt;=1.xx Authentication Bypass Vulnerability &amp; SQL injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/17260">17260</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1135">ADV-2006-1135</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19421">19421</ref><ref source="OSVDB" url="http://www.osvdb.org/24168">24168</ref><ref source="OSVDB" url="http://www.osvdb.org/24169">24169</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25478">pixelmotionblog-adminindex-security-bypass(25478)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25481">pixelmotionblog-index-sql-injection(25481)</ref></refs><vuln_soft><prod name="Pixel Motion Blog" vendor="Pixel Motion"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-29" name="CVE-2006-1427" published="2006-03-28" seq="2006-1427" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WebAPP 0.9.9.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) id, (3) num, (4) board, (5) cat, (6) real, (7) viewcat, (8) img, or (9) curcatname parameter in cgi-bin/index.cgi, or (10) vsSD parameter in /mods/calendar/index.cgi.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/03/webapp-multiple-xss-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1102">ADV-2006-1102</ref><ref source="OSVDB" url="http://www.osvdb.org/24278">24278</ref><ref source="OSVDB" url="http://www.osvdb.org/24279">24279</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25435">webapp-index-xss(25435)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17359">17359</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19506">19506</ref><ref source="" url="http://www.web-app.net/cgi-bin/index.cgi?action=downloadinfo&amp;cat=pastversions&amp;id=1"></ref><ref source="" url="http://www.web-app.net/cgi-bin/index.cgi?action=redirectd&amp;cat=pastversions&amp;id=1"></ref><ref source="" url="http://pridels0.blogspot.com/2006/03/webapp-multiple-xss-vuln.html"></ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9.3.2"/><vers num="0.9.9.3.1"/><vers num="0.9.9.3"/><vers num="0.9.9.2.1"/><vers num="0.9.9.2"/><vers num="0.9.9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-29" name="CVE-2006-1428" published="2006-03-28" seq="2006-1428" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the fs parameter to (1) mod.php or (2) mod_print.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/03/phpcoin-v122-xss-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1129">ADV-2006-1129</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19419">19419</ref><ref source="BID" url="http://www.securityfocus.com/bid/17279">17279</ref><ref source="OSVDB" url="http://www.osvdb.org/24188">24188</ref><ref source="OSVDB" url="http://www.osvdb.org/24189">24189</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25492">phpcoin-multiple-xss(25492)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/phpcoin-v122-xss-vuln.html"></ref></refs><vuln_soft><prod name="phpCOIN" vendor="COINSoft Technologies"><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.1.1"/><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-29" name="CVE-2006-1429" published="2006-03-28" seq="2006-1429" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in accountlogon.cfm in classifiedZONE 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the rtn parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/03/classifiedzone-v12-xss-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17273">17273</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1132">ADV-2006-1132</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19427">19427</ref><ref source="OSVDB" url="http://www.osvdb.org/24187">24187</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25494">classifiedzone-accountlogon-xss(25494)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/classifiedzone-v12-xss-vuln.html"></ref></refs><vuln_soft><prod name="classifiedZONE" vendor="fusionZONE"><vers num="1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-29" name="CVE-2006-1430" published="2006-03-28" seq="2006-1430" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in CONTROLzx HMS (formerly DRZES) 3.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dedicatedPlanID parameter to dedicated_order.php, (2) sharedPlanID parameter to shared_order.php, (3) plan_id parameter to customers/server_management.php, and (4) email field to customers/forgotpass.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/03/controlzx-hms-hosting-management.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17282">17282</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1131">ADV-2006-1131</ref><ref source="OSVDB" url="http://www.osvdb.org/24175">24175</ref><ref source="OSVDB" url="http://www.osvdb.org/24174">24174</ref><ref source="OSVDB" url="http://www.osvdb.org/24176">24176</ref><ref source="OSVDB" url="http://www.osvdb.org/24173">24173</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19432">19432</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25491">controlzshms-multiple-scripts-xss(25491)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/controlzx-hms-hosting-management.html"></ref></refs><vuln_soft><prod name="HMS" vendor="CONTROLzx"><vers num="3.3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-29" name="CVE-2006-1431" published="2006-03-28" seq="2006-1431" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in local.cfm in fusionZONE couponZONE 4.2 allows remote attackers to inject arbitrary web script or HTML via URL-encoded (1) srchfor and (2) srchby parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/03/couponzone-v42-multiple-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17272">17272</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1127">ADV-2006-1127</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19430">19430</ref><ref source="OSVDB" url="http://www.osvdb.org/24180">24180</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25484">couponzone-local-xss(25484)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/couponzone-v42-multiple-vuln.html"></ref></refs><vuln_soft><prod name="couponZONE" vendor="fusionZONE"><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-29" name="CVE-2006-1432" published="2006-03-28" seq="2006-1432" severity="Medium" type="CVE"><desc><descript source="cve">fusionZONE couponZONE 4.2 allows remote attackers to obtain the full path of the web server, and other sensitive information, via invalid values, as demonstrated using manipulations associated with SQL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/03/couponzone-v42-multiple-vuln.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25486">couponzone-local-path-disclosure(25486)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/couponzone-v42-multiple-vuln.html"></ref></refs><vuln_soft><prod name="couponZONE" vendor="fusionZONE"><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-03" name="CVE-2006-1433" published="2006-04-03" seq="2006-1433" severity="Medium" type="CVE"><desc><descript source="cve">Annuaire (Directory) 1.0 allows remote attackers to obtain sensitive information via a direct request to include/lang-en.php, which reveals the full installation path.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://osvdb.org/ref/24/24302-annuaire_directory.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/24302">24302</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19548">19548</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25668">annuaire-includelangen-path-disclosure(25668)</ref></refs><vuln_soft><prod name="Directory" vendor="Annuaire"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-04" name="CVE-2006-1434" published="2006-04-03" seq="2006-1434" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in inscription.php in Annuaire (Directory) 1.0 allows remote attackers to inject arbitrary web script or HTML via the Comment Field (COMMENTAIRE parameter).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://osvdb.org/ref/24/24302-annuaire_directory.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/24303">24303</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19548">19548</ref><ref source="BID" url="http://www.securityfocus.com/bid/17393">17393</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25669">annuaire-inscription-xss(25669)</ref></refs><vuln_soft><prod name="Directory" vendor="Annuaire"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-28" modified="2006-04-04" name="CVE-2006-1435" published="2006-04-03" seq="2006-1435" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in genmessage.php in Accounting Receiving and Inventory Administration (ARIA) 0.99-6 allows remote attackers to inject arbitrary web script or HTML via the Message Field (message parameter).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://osvdb.org/ref/24/24255-aria.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/24255">24255</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19551">19551</ref><ref source="BID" url="http://www.securityfocus.com/bid/17411">17411</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25688">aria-genmessage-xss(25688)</ref></refs><vuln_soft><prod name="ARIA" vendor="Accounting Receiving and Inventory Administration"><vers num="0.99-6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-17" name="CVE-2006-1436" published="2006-04-15" seq="2006-1436" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in UPOINT @1 Event Publisher allow remote attackers to inject arbitrary web script or HTML via the (1) Event, (2) Description, (3) Time, (4) Website, and (5) Public Remarks fields to (a) eventpublisher_admin.htm and (b) eventpublisher_usersubmit.htm.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://osvdb.org/ref/24/24236-upoint.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/24235">24235</ref><ref source="OSVDB" url="http://www.osvdb.org/24236">24236</ref><ref source="BID" url="http://www.securityfocus.com/bid/17646">17646</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19727">19727</ref></refs><vuln_soft><prod name="@1 Event Publisher" vendor="UPoint"><vers num="2003-12-18"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-17" name="CVE-2006-1437" published="2006-04-15" seq="2006-1437" severity="Medium" type="CVE"><desc><descript source="cve">UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attackers to read private comments via a direct request to eventpublisher.txt.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://osvdb.org/ref/24/24236-upoint.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/24237">24237</ref><ref source="BID" url="http://www.securityfocus.com/bid/17647">17647</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19727">19727</ref></refs><vuln_soft><prod name="@1 Event Publisher" vendor="UPoint"><vers num="2003-12-18"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-27" modified="2006-04-04" name="CVE-2006-1438" published="2006-04-03" seq="2006-1438" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Andy&apos;s PHP Knowledgebase (aphpkb) 0.57 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword_list parameter to (a) index.php; (2) title, (3) article, (4) author, and (5) keywords parameters to (b) submit_article.php; and (6) Question, (7) Name, and (8) Email parameters to (c) submit_question.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://osvdb.org/ref/24/24310-aphpkb.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/24310">24310</ref><ref source="OSVDB" url="http://www.osvdb.org/24311">24311</ref><ref source="OSVDB" url="http://www.osvdb.org/24312">24312</ref><ref source="BID" url="http://www.securityfocus.com/bid/17377">17377</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19554">19554</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25666">aphpkb-multiple-scripts-xss(25666)</ref></refs><vuln_soft><prod name="Andy&apos;s PHP Knowledgebase" vendor="Andy Grayndler"><vers num="0.57"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-08-13" name="CVE-2006-1439" published="2006-05-12" seq="2006-1439" severity="Low" type="CVE"><desc><descript source="cve">NSSecureTextField in AppKit in Apple Mac OS X 10.4.6 does not re-enable secure event input under certain circumstances, which could allow other applications in the window session to monitor input characters and keyboard events.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol></sols><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="OSVDB" url="http://www.osvdb.org/25583">25583</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26404">macos-appkit-nssecuretext-weak-security(26404)</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-15" name="CVE-2006-1440" published="2006-05-12" seq="2006-1440" severity="Low" type="CVE"><desc><descript source="cve">BOM in Apple Mac OS X 10.3.9 and 10.4.6 allows attackers to overwrite arbitrary files via an archive that contains symbolic links.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol></sols><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016082">1016082</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="OSVDB" url="http://www.osvdb.org/25584">25584</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26405">
macos-bom-archive-file-overwrite(26405)</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-15" name="CVE-2006-1441" published="2006-05-12" seq="2006-1441" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in CFNetwork in Apple Mac OS X 10.4.6 allows remote attackers to execute arbitrary code via crafted chunked transfer encoding.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016082">1016082</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="OSVDB" url="http://www.osvdb.org/25585">25585</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26406">
macos-cfnetwork-chunked-overlow(26406)</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-15" name="CVE-2006-1442" published="2006-05-12" seq="2006-1442" severity="High" type="CVE"><desc><descript source="cve">The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if the client application has not directly requested it, which allows attackers to execute arbitrary code from an untrusted bundle.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016080">1016080</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="OSVDB" url="http://www.osvdb.org/25586">25586</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26407">
macos-corefoundation-bundle-code-execution(26407)</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-15" name="CVE-2006-1443" published="2006-05-12" seq="2006-1443" severity="Medium" type="CVE"><desc><descript source="cve">Integer underflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 allows context-dependent attackers to execute arbitrary code via unspecified vectors involving conversions from string to file system representation within (1) CFStringGetFileSystemRepresentation or (2) getFileSystemRepresentation:maxLength:withPath in NSFileManager, and possibly other similar API functions.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016080">1016080</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="OSVDB" url="http://www.osvdb.org/25587">25587</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26408">
macos-corefoundation-integer-underflow(26408)</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-15" name="CVE-2006-1444" published="2006-05-12" seq="2006-1444" severity="Low" type="CVE"><desc><descript source="cve">CoreGraphics in Apple Mac OS X 10.4.6, when &quot;Enable access for assistive devices&quot; is on, allows an application to bypass restrictions for secure event input and read certain events from other applications in the same window session by using Quartz Event Services.</descript></desc><sols><sol source="nvd">Successful exploitation requires that &quot;Enable access for assistive devices&quot; is on.
This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol></sols><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016079">1016079</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="OSVDB" url="http://www.osvdb.org/25588">25588</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26409">
macos-coregraphics-quartz-security-bypass(26409)</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-15" name="CVE-2006-1445" published="2006-05-12" seq="2006-1445" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the FTP server (FTPServer) in Apple Mac OS X 10.3.9 and 10.4.6 allows remote authenticated users to execute arbitrary code via vectors related to &quot;FTP server path name handling.&quot;</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016084">1016084</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26411">macos-ftpserver-code-execution(26411)</ref><ref source="OSVDB" url="http://www.osvdb.org/25589">25589</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-15" name="CVE-2006-1446" published="2006-05-12" seq="2006-1446" severity="Medium" type="CVE"><desc><descript source="cve">Keychain in Apple Mac OS X 10.3.9 and 10.4.6 might allow an application to bypass a locked Keychain by first obtaining a reference to the Keychain when it is unlocked, then reusing that reference after the Keychain has been locked.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol></sols><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016072">1016072</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26413">macos-keychain-security-bypass(26413)</ref><ref source="OSVDB" url="http://www.osvdb.org/25590">25590</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-15" name="CVE-2006-1447" published="2006-05-12" seq="2006-1447" severity="Medium" type="CVE"><desc><descript source="cve">LaunchServices in Apple Mac OS X 10.4.6 allows remote attackers to cause Safari to launch unsafe content via long file name extensions, which prevents Download Validation from determining which application will be used to open the file.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol></sols><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016081">1016081</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26416">macos-launchservices-security-bypass(26416)</ref><ref source="OSVDB" url="http://www.osvdb.org/25591">25591</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-1448" published="2006-05-12" seq="2006-1448" severity="Medium" type="CVE"><desc><descript source="cve">Finder in Apple Mac OS X 10.3.9 and 10.4.6 allows user-assisted attackers to execute arbitrary code by tricking a user into launching an Internet Location item that appears to use a safe URL scheme, but which actually has a different and more risky scheme.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016082">1016082</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="OSVDB" url="http://www.osvdb.org/25592">25592</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26410">
macos-finder-url-type-spoofing(26410)</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-15" name="CVE-2006-1449" published="2006-05-12" seq="2006-1449" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted MacMIME encapsulated attachment.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016078">1016078</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26417">macos-mail-macmime-bo(26417)</ref><ref source="OSVDB" url="http://www.osvdb.org/25593">25593</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-15" name="CVE-2006-1450" published="2006-05-12" seq="2006-1450" severity="High" type="CVE"><desc><descript source="cve">Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via an enriched text e-mail message with &quot;invalid color information&quot; that causes Mail to allocate and initialize arbitrary classes.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016078">1016078</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26419">macos-mail-color-code-execution(26419)</ref><ref source="OSVDB" url="http://www.osvdb.org/25594">25594</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-15" name="CVE-2006-1451" published="2006-05-12" seq="2006-1451" severity="High" type="CVE"><desc><descript source="cve">MySQL Manager in Apple Mac OS X 10.3.9 and 10.4.6, when setting up a new MySQL database server, does not use the &quot;New MySQL root password&quot; that is provided, which causes the MySQL root password to be blank and allows local users to gain full privileges to that database.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016077">1016077</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26420">macos-mysql-manager-blank-password(26420)</ref><ref source="OSVDB" url="http://www.osvdb.org/25595">25595</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-15" name="CVE-2006-1452" published="2006-05-12" seq="2006-1452" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Preview in Apple Mac OS 10.4 up to 10.4.6 allows local users to execute arbitrary code via a deep directory hierarchy.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.6 (2006-003)</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016076">1016076</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26422">macos-preview-directory-bo(26422)</ref><ref source="OSVDB" url="http://www.osvdb.org/25596">25596</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.6"/><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-24" name="CVE-2006-1453" published="2006-05-12" seq="2006-1453" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickDraw PICT image format file containing malformed font information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433831/100/0/threaded">20060512 Apple QuickDraw/QuickTime Multiple Vulnerabilities</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html">APPLE-SA-2006-05-11</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17953">17953</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016067">1016067</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20069">20069</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1778">ADV-2006-1778</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016075">1016075</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26400">
quicktime-pict-font-bo(26400)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html">TA06-132B</ref><ref source="SREASON" url="http://securityreason.com/securityalert/887">887</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0.4"/><vers num="7.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-24" name="CVE-2006-1454" published="2006-05-12" seq="2006-1454" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickDraw PICT image format file with malformed image data.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433831/100/0/threaded">20060512 Apple QuickDraw/QuickTime Multiple Vulnerabilities</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html">APPLE-SA-2006-05-11</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17953">17953</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016067">1016067</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20069">20069</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1778">ADV-2006-1778</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016075">1016075</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26401">
quicktime-pict-image-bo(26401)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html">TA06-132B</ref><ref source="SREASON" url="http://securityreason.com/securityalert/887">887</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0.4"/><vers num="7.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-15" name="CVE-2006-1455" published="2006-05-12" seq="2006-1455" severity="High" type="CVE"><desc><descript source="cve">QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to cause a denial of service (crash and connection interruption) via a QuickTime movie with a missing track, which triggers a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016070">1016070</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26423">quicktime-missing-track-dos(26423)</ref><ref source="OSVDB" url="http://www.osvdb.org/25599">25599</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.6"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-15" name="CVE-2006-1456" published="2006-05-12" seq="2006-1456" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted RTSP request, which is not properly handled during message logging.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016070">1016070</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26424">quicktime-rtsp-bo(26424)</ref><ref source="OSVDB" url="http://www.osvdb.org/25600">25600</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.6"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-15" name="CVE-2006-1457" published="2006-05-12" seq="2006-1457" severity="Low" type="CVE"><desc><descript source="cve">Safari on Apple Mac OS X 10.4.6, when &quot;Open `safe&apos; files after downloading&quot; is enabled, will automatically expand archives, which could allow remote attackers to overwrite arbitrary files via an archive that contains a symlink.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/519473">VU#519473</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016069">1016069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26427">safari-archive-code-execution(26427)</ref><ref source="OSVDB" url="http://www.osvdb.org/25598">25598</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.6"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-24" name="CVE-2006-1458" published="2006-05-12" seq="2006-1458" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in Apple QuickTime Player before 7.1 allows remote attackers to execute arbitrary code via a crafted JPEG image.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html">APPLE-SA-2006-05-11</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/289705">VU#289705</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17953">17953</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016067">1016067</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20069">20069</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1778">ADV-2006-1778</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26391">
quicktime-jpeg-overflow(26391)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html">TA06-132B</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0.4"/><vers num="7.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-11" modified="2006-05-25" name="CVE-2006-1459" published="2006-05-12" seq="2006-1459" severity="Medium" type="CVE"><desc><descript source="cve">Multiple integer overflows in Apple QuickTime before 7.1 allow remote attackers to cause a denial of service or execute arbitrary code via a crafted QuickTime movie (.MOV).</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433831/100/0/threaded">20060512 Apple QuickDraw/QuickTime Multiple Vulnerabilities</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html">APPLE-SA-2006-05-11</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17953">17953</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016067">1016067</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20069">20069</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1778">ADV-2006-1778</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26392">
quicktime-mov-overflow(26392)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html">TA06-132B</ref><ref source="SREASON" url="http://securityreason.com/securityalert/887">887</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0.4"/><vers num="7.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-06" modified="2006-05-25" name="CVE-2006-1460" published="2006-05-12" seq="2006-1460" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime movie (.MOV), as demonstrated via a large size for a udta Atom.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433831/100/0/threaded">20060512 Apple QuickDraw/QuickTime Multiple Vulnerabilities</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html">APPLE-SA-2006-05-11</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17953">17953</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016067">1016067</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20069">20069</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433810/100/0/threaded">20060512 Apple QuickTime udta ATOM Heap Overflow</ref><ref adv="1" source="" url="http://secway.org/advisory/AD20060512.txt"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1778">ADV-2006-1778</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-May/045987.html">
20060512 Apple QuickTime udta ATOM Heap Overflow</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26393">
quicktime-mov-bo(26393)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html">TA06-132B</ref><ref source="SREASON" url="http://securityreason.com/securityalert/887">887</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0.4"/><vers num="7.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-25" name="CVE-2006-1461" published="2006-05-12" seq="2006-1461" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime Flash (SWF) file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433831/100/0/threaded">20060512 Apple QuickDraw/QuickTime Multiple Vulnerabilities</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html">APPLE-SA-2006-05-11</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17953">17953</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016067">1016067</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20069">20069</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1778">ADV-2006-1778</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26394">
quicktime-flash-bo(26394)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html">TA06-132B</ref><ref source="SREASON" url="http://securityreason.com/securityalert/887">887</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0.4"/><vers num="7.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-25" name="CVE-2006-1462" published="2006-05-12" seq="2006-1462" severity="Medium" type="CVE"><desc><descript source="cve">Multiple integer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime H.264 (M4V) video format file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433831/100/0/threaded">20060512 Apple QuickDraw/QuickTime Multiple Vulnerabilities</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html">APPLE-SA-2006-05-11</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17953">17953</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016067">1016067</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20069">20069</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1778">ADV-2006-1778</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26395">
quicktime-h264-overflow(26395)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html">TA06-132B</ref><ref source="SREASON" url="http://securityreason.com/securityalert/887">887</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0.4"/><vers num="7.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-25" name="CVE-2006-1463" published="2006-05-12" seq="2006-1463" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a H.264 (M4V) video format file with a certain modified size value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433828/100/0/threaded">20060511 ZDI-06-015: Apple QuickTime H.264 Parsing Heap Overflow Vulnerability</ref><ref patch="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-06-015.html"></ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html">APPLE-SA-2006-05-11</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17953">17953</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016067">1016067</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20069">20069</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1778">ADV-2006-1778</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26396">
quicktime-h264-bo(26396)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html">TA06-132B</ref><ref source="SREASON" url="http://securityreason.com/securityalert/888">888</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0.4"/><vers num="7.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-25" name="CVE-2006-1464" published="2006-05-12" seq="2006-1464" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickTime MPEG4 (M4P) video format file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433831/100/0/threaded">20060512 Apple QuickDraw/QuickTime Multiple Vulnerabilities</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html">APPLE-SA-2006-05-11</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17953">17953</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016067">1016067</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20069">20069</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1778">ADV-2006-1778</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/587937">VU#587937</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26397">
quicktime-mpeg4-bo(26397)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html">TA06-132B</ref><ref source="SREASON" url="http://securityreason.com/securityalert/887">887</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0.4"/><vers num="7.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-25" name="CVE-2006-1465" published="2006-05-12" seq="2006-1465" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickTime AVI video format file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433831/100/0/threaded">20060512 Apple QuickDraw/QuickTime Multiple Vulnerabilities</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00002.html">APPLE-SA-2006-05-11</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17953">17953</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016067">1016067</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20069">20069</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1778">ADV-2006-1778</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26399">
quicktime-avi-bo(26399)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132B.html">TA06-132B</ref><ref source="SREASON" url="http://securityreason.com/securityalert/887">887</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0.4"/><vers num="7.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-24" name="CVE-2006-1466" published="2006-05-23" seq="2006-1466" severity="Medium" type="CVE"><desc><descript source="cve">Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00004.html">APPLE-SA-2006-05-23</ref><ref source="BID" url="http://www.securityfocus.com/bid/18091">18091</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1950">ADV-2006-1950</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016143">1016143</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20267">20267</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26634">xcode-webobjects-unauth-access(26634)</ref><ref source="OSVDB" url="http://www.osvdb.org/25889">25889</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4"/></prod><prod name="Xcode Tools" vendor="Apple"><vers num="2.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-07" modified="2006-08-28" name="CVE-2006-1467" published="2006-06-29" seq="2006-1467" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the AAC file parsing code in Apple iTunes before 6.0.5 on Mac OS X 10.2.8 or later, and Windows XP and 2000, allows remote user-assisted attackers to execute arbitrary code via an AAC (M4P, M4A, or M4B) file with a sample table size (STSZ) atom with a &quot;malformed&quot; sample_size_table value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="APPLE" url="http://docs.info.apple.com/article.html?artnum=303952">APPLE-SA-2006-06-29</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/438812/100/0/threaded">20060630 ZDI-06-020: Apple iTunes AAC File Parsing Integer Overflow Vulnerability</ref><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-06-020.html"></ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/907836">VU#907836</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20891">20891</ref><ref source="BID" url="http://www.securityfocus.com/bid/18730">18730</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2601">ADV-2006-2601</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016413">1016413</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27481">itunes-aac-file-overflow(27481)</ref></refs><vuln_soft><prod name="iTunes" vendor="Apple"><vers num="6.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-07-03" name="CVE-2006-1468" published="2006-06-27" seq="2006-1468" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Apple File Protocol (AFP) server in Apple Mac OS X 10.4 up to 10.4.6 includes the names of restricted files and folders within search results, which might allow remote attackers to obtain sensitive information.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.7</sol></sols><loss_types><conf/></loss_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Jun/msg00000.html">APPLE-SA-2006-06-27</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2566">ADV-2006-2566</ref><ref source="BID" url="http://www.securityfocus.com/bid/18686">18686</ref><ref source="BID" url="http://www.securityfocus.com/bid/18733">18733</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016395">1016395</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20877">20877</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27477">macosx-afp-information-disclosure(27477)</ref><ref source="OSVDB" url="http://www.osvdb.org/26930">26930</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.6"/><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-07-06" name="CVE-2006-1469" published="2006-06-27" seq="2006-1469" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.6 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Jun/msg00000.html">APPLE-SA-2006-06-27</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2566">ADV-2006-2566</ref><ref source="BID" url="http://www.securityfocus.com/bid/18686">18686</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016394">1016394</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/988356">VU#988356</ref><ref source="BID" url="http://www.securityfocus.com/bid/18731">18731</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20877">20877</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27478">macosx-imageio-tiff-bo(27478)</ref><ref source="OSVDB" url="http://www.osvdb.org/26931">26931</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.6"/><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.6"/><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-07-06" name="CVE-2006-1470" published="2006-06-27" seq="2006-1470" severity="Medium" type="CVE"><desc><descript source="cve">OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an assert error.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Jun/msg00000.html">APPLE-SA-2006-06-27</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2566">ADV-2006-2566</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/652196">VU#652196</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18686">18686</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18728">18728</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016396">1016396</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20877">20877</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27480">macosx-openldap-directory-dos(27480)</ref><ref source="OSVDB" url="http://www.osvdb.org/26932">26932</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.6"/><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.6"/><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-07-03" name="CVE-2006-1471" published="2006-06-27" seq="2006-1471" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a syslog call in the logging facility, as demonstrated by using a crafted plist file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Jun/msg00000.html">APPLE-SA-2006-06-27</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2566">ADV-2006-2566</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/438699/100/0/threaded">20060629 DMA[2006-0628a] - &apos;Apple OSX launchd unformatted syslog() vulnerability&apos;</ref><ref source="BID" url="http://www.securityfocus.com/bid/18686">18686</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016397">1016397</ref><ref source="BID" url="http://www.securityfocus.com/bid/18724">18724</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20877">20877</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27479">macosx-launchd-format-string(27479)</ref><ref source="OSVDB" url="http://www.osvdb.org/26933">26933</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.6"/><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.6"/><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-26" name="CVE-2006-1472" published="2006-08-02" seq="2006-1472" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in AFP Server in Apple Mac OS X 10.3.9 allows remote attackers to determing names of unauthorized files and folders via unknown vectors related to the search results.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html">APPLE-SA-2006-08-01</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21253">21253</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016620">1016620</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3101">ADV-2006-3101</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/28134">macosx-afp-file-disclosure(28134)</ref><ref source="BID" url="http://www.securityfocus.com/bid/19289">19289</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html">
TA06-214A</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-26" name="CVE-2006-1473" published="2006-08-02" seq="2006-1473" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in AFP Server for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html">APPLE-SA-2006-08-01</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21253">21253</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/575372">VU#575372</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016620">1016620</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3101">ADV-2006-3101</ref><ref source="OSVDB" url="http://www.osvdb.org/27731">27731</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/28135">macosx-afp-overflow(28135)</ref><ref source="BID" url="http://www.securityfocus.com/bid/19289">19289</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html">
TA06-214A</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.7"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-29" name="CVE-2006-1474" published="2006-03-28" seq="2006-1474" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the &quot;failed&quot; functionality in Raindance Web Conferencing Pro allows remote attackers to inject arbitrary web script or HTML via the browser parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428971/100/0/threaded">20060324 [DDSi-SA] XSS in Raindance Communications Web Conferencing Pro</ref></refs><vuln_soft><prod name="Web Conferencing Pro" vendor="Raindance"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-29" name="CVE-2006-1475" published="2006-03-28" seq="2006-1475" severity="Low" type="CVE"><desc><descript source="cve">Windows Firewall in Microsoft Windows XP SP2 does not produce application alerts when an application is executed using the NTFS Alternate Data Streams (ADS) filename:stream syntax, which might allow local users to launch a Trojan horse attack in which the victim does not obtain the alert that Windows Firewall would have produced for a non-ADS file.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428970/100/0/threaded">20060324 Microsoft Windows XP SP2 Firewall issue</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429111/100/0/threaded">20060327 Re: Microsoft Windows XP SP2 Firewall issue</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25597">
winxp-firewall-ads-bypass(25597)</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-31" name="CVE-2006-1476" published="2006-03-28" seq="2006-1476" severity="Low" type="CVE"><desc><descript source="cve">Windows Firewall in Microsoft Windows XP SP2 produces incorrect application block alerts when the application filename is &quot;.exe&quot; (with no characters before the &quot;.&quot;), which might allow local user-assisted users to trick a user into unblocking a Trojan horse program, as demonstrated by a malicious &quot;.exe&quot; program in a folder named &quot;Internet Explorer,&quot; which triggers a question about whether to unblock the &quot;Internet Explorer&quot; program.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428970/100/0/threaded">20060324 Microsoft Windows XP SP2 Firewall issue</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429111/100/0/threaded">20060327 Re: Microsoft Windows XP SP2 Firewall issue</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25598">
winxp-firewall-exe-bypass(25598)</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-29" name="CVE-2006-1477" published="2006-03-28" seq="2006-1477" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Live Helper 1.8 allow remote attackers to include and execute arbitrary PHP code via the abs_path parameter in (1) initiate.php, (2) waiting.php, (3) welcome.php, (4) admin/index.php, (5) javascript.php, (6) checkchat.php, and (7) blank.php.</descript></desc><sols><sol source="nvd">This vulnerability may affect all versions prior to 1.8  as well.</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428976/100/0/threaded">20060327 PHPLiveHelper 1.8 remote command execution (include) Xploit (perl)</ref><ref patch="1" source="Turnkey" url="http://www.turnkeywebtools.com/forum/showthread.php?p=10415">initiate.php is exploitable? </ref><ref source="World Defacers" url="http://www.worlddefacers.de/Public/WD-TMPLH.txt">PHPLiveHelper 1.8 remote command execution Xploit</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1137">ADV-2006-1137</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19428">19428</ref><ref source="OSVDB" url="http://www.osvdb.org/24193">24193</ref><ref source="OSVDB" url="http://www.osvdb.org/24194">24194</ref><ref source="OSVDB" url="http://www.osvdb.org/24195">24195</ref><ref source="OSVDB" url="http://www.osvdb.org/24196">24196</ref><ref source="OSVDB" url="http://www.osvdb.org/24197">24197</ref><ref source="OSVDB" url="http://www.osvdb.org/24198">24198</ref><ref source="OSVDB" url="http://www.osvdb.org/24199">24199</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25489">phplivehelper-abspath-file-include(25489)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/437648/100/0/threaded">20060619 PHP Live Helper &lt;=([abs_path]) Remote File Include Vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/437741/100/0/threaded">20060619 Re: PHP Live Helper &lt;=([abs_path]) Remote File Include Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/18509">
18509</ref></refs><vuln_soft><prod name="PHP Live Helper" vendor="Turnkey Web Tools"><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-29" name="CVE-2006-1478" published="2006-03-28" seq="2006-1478" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in (1) initiate.php and (2) possibly other PHP scripts in Turnkey Web Tools PHP Live Helper 1.8, and possibly later versions, allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the language cookie, as demonstrated by uploading PHP code in a gl_session cookie to users.php, which causes the code to be stored in error.log, which is then included by initiate.php.</descript></desc><sols><sol source="nvd">This vulnerability may affect all other versions of Turnkey Web Tools, PHP Live Helper.</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428976/100/0/threaded">20060327 PHPLiveHelper 1.8 remote command execution (include) Xploit (perl)</ref><ref patch="1" source="Turnkey Web Tools" url="http://www.turnkeywebtools.com/forum/showthread.php?p=10415">initiate.php is exploitable? </ref><ref source="World Defacers" url="http://www.worlddefacers.de/Public/WD-TMPLH.txt">PHPLiveHelper 1.8 remote command execution Xploit</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19428">19428</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25489">phplivehelper-abspath-file-include(25489)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/641">641</ref></refs><vuln_soft><prod name="PHP Live Helper" vendor="Turnkey Web Tools"><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-29" name="CVE-2006-1479" published="2006-03-28" seq="2006-1479" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Serge Rey gtd-php (aka Getting Things Done) 0.5 allow remote attackers to inject arbitrary web script or HTML via the Description field in (1) newProject.php, (2) newList.php, and (3) newWaitingOn.php; the Title field in (4) newProject.php, (5) newList.php, (6) newWaitingOn.php, (7) newChecklist.php, (8) newContext.php, and (9) newGoal.php; the (10) Category Name field in newCategory.php; the (11) listTitle field in listReport.php; the (12) projectName field in projectReport.php; and the (13) checklistTitle field in checklistReport.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://osvdb.org/ref/24/24149-gtd-php.txt">Subject: gtd input sanitization (XSS) vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/24149">24149</ref><ref source="OSVDB" url="http://www.osvdb.org/24150">24150</ref><ref source="OSVDB" url="http://www.osvdb.org/24151">24151</ref><ref source="OSVDB" url="http://www.osvdb.org/24152">24152</ref><ref source="OSVDB" url="http://www.osvdb.org/24153">24153</ref><ref source="OSVDB" url="http://www.osvdb.org/24154">24154</ref><ref source="OSVDB" url="http://www.osvdb.org/24155">24155</ref><ref source="OSVDB" url="http://www.osvdb.org/24156">24156</ref><ref source="OSVDB" url="http://www.osvdb.org/24157">24157</ref><ref source="OSVDB" url="http://www.osvdb.org/24158">24158</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25553">gtdphp-multiple-scripts-xss(25553)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17366">17366</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1203">ADV-2006-1203</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19512">19512</ref></refs><vuln_soft><prod name="gtd-php" vendor="Serge Rey"><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-25" modified="2006-03-30" name="CVE-2006-1480" published="2006-03-28" seq="2006-1480" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and execute commands by (1) injecting code into local log files via GET commands, then (2) accessing that log via a .. (dot dot) sequence and a trailing null (%00) byte in the skin2 COOKIE parameter.</descript></desc><sols><sol source="nvd">Successful exploitation requires that the &quot;magic_quotes_gpc&quot; parameter is disabled.
</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://milw0rm.com/exploits/1608">exploit 1608</ref><ref source="BID" url="http://www.securityfocus.com/bid/17228">17228</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1108">ADV-2006-1108</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19400">19400</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25443">webalbum-skin2-parameter-file-include(25443)</ref><ref source="OSVDB" url="http://www.osvdb.org/24160">24160</ref></refs><vuln_soft><prod name="WebAlbum" vendor="duda"><vers num="2.02" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-25" modified="2006-03-30" name="CVE-2006-1481" published="2006-03-28" seq="2006-1481" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL commands and obtain usernames and passwords via the frm_search_in parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://milw0rm.com/exploits/1609">exploit 1609</ref><ref source="BID" url="http://www.securityfocus.com/bid/17229">17229</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1106">ADV-2006-1106</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19412">19412</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25436">phpticket-search-sql-injection(25436)</ref></refs><vuln_soft><prod name="PHP Ticket" vendor="PHP Ticket"><vers num="0.71" prev="1"/><vers num="0.6"/><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1482" published="2006-03-28" seq="2006-1482" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in ConfTool 1.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428899/100/0/threaded">20060327 CanfTool v1.1 Cross Site Scripting Attack</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-March/000664.html">[VIM] 20060328 Conftool, not Canftool; appears to be distributable</ref><ref source="OSVDB" url="http://www.osvdb.org/24264">24264</ref><ref source="BID" url="http://www.securityfocus.com/bid/17231">17231</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25437">canftool-index-xss(25437)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/635">635</ref></refs><vuln_soft><prod name="ConfTool" vendor="ConfTool"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-22" modified="2006-03-30" name="CVE-2006-1483" published="2006-03-28" seq="2006-1483" severity="Medium" type="CVE"><desc><descript source="cve">Blazix Web Server before 1.2.6, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot), (2) space, and (3) slash characters in the extension of a URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429108/100/0/threaded">20060328 Secunia Research: Blazix Web Server JSP Source Code DisclosureVulnerability</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/secunia_research/2006-22/advisory/">Blazix Web Server JSP Source Code Disclosure Vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17270">17270</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1133">ADV-2006-1133</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19341">19341</ref><ref source="OSVDB" url="http://www.osvdb.org/24178">24178</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015837">1015837</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25485">blazix-jsp-source-disclosure(25485)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/643">643</ref></refs><vuln_soft><prod name="Blazix Web Server" vendor="Desiderata Software"><vers edition="Windows" num="1.2.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1484" published="2006-03-28" seq="2006-1484" severity="High" type="CVE"><desc><descript source="cve">Genius VideoCAM NB Driver does not drop privileges when saving files, which allows local users to gain privileges by opening arbitrary files via the &quot;save as&quot; dialog.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429107/100/0/threaded">20060328 Genius VideoCAM NB Local Privilege Escalation</ref><ref source="BID" url="http://www.securityfocus.com/bid/17284">17284</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015839">1015839</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19437">19437</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25501">genius-videocam-saveas-gain-privileges(25501)</ref></refs><vuln_soft><prod name="Genius VideoCAM NB" vendor="KYE"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1485" published="2006-03-28" seq="2006-1485" severity="Medium" type="CVE"><desc><descript source="cve">gm-upload.cgi in Greymatter 1.3.1 allows remote authenticated users with upload privileges to execute arbitrary programs by uploading files to locations within the web root.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17271">17271</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1138">ADV-2006-1138</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19423">19423</ref><ref source="OSVDB" url="http://www.osvdb.org/24210">24210</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25496">greymatter-gmupload-file-upload(25496)</ref></refs><vuln_soft><prod name="Greymatter" vendor="Greymatter"><vers num="1.3.1" prev="1"/><vers num="1.3"/><vers num="1.21d"/><vers num="1.21c"/><vers num="1.21b"/><vers num="1.21a"/><vers num="1.21"/><vers num="1.2"/><vers num="1.1b"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1486" published="2006-03-28" seq="2006-1486" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in realestateZONE 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) bamin, (2) bemin, (3) pmin, and (4) state parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Blogspot" url="http://pridels.blogspot.com/2006/03/realestatezone-42-multiple-xss-vuln.html">realestateZONE 4.2 Multiple XSS vuln. </ref><ref source="BID" url="http://www.securityfocus.com/bid/17277">17277</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1128">ADV-2006-1128</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19429">19429</ref><ref source="OSVDB" url="http://www.osvdb.org/24186">24186</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25487">realestatezone-index-xss(25487)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/realestatezone-42-multiple-xss-vuln.html"></ref></refs><vuln_soft><prod name="RealestateZONE" vendor="FusionZONE"><vers num="4.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2006-1487" published="2006-03-28" seq="2006-1487" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in ActiveCampaign SupportTrio 2.50.2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the KnowledgeBase search module.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/03/activecampaign-supporttrio-25-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17276">17276</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1126">ADV-2006-1126</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19431">19431</ref><ref source="OSVDB" url="http://www.osvdb.org/24192">24192</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25495">supporttrio-search-xss(25495)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/activecampaign-supporttrio-25-vuln.html"></ref></refs><vuln_soft><prod name="SupportTrio" vendor="ActiveCampaign"><vers num="2.50.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1488" published="2006-03-28" seq="2006-1488" severity="Medium" type="CVE"><desc><descript source="cve">ActiveCampaign SupportTrio 2.5 allows remote attackers to obtain the full path of the server via invalid (1) article or (2) print parameters in a kb action to index.php, or (3) an invalid category parameter to modules/KB/pdf.php, which leaks the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/03/activecampaign-supporttrio-25-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1126">ADV-2006-1126</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19431">19431</ref><ref source="OSVDB" url="http://www.osvdb.org/24190">24190</ref><ref source="OSVDB" url="http://www.osvdb.org/24191">24191</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25517">supporttrio-index-pdf-path-disclosure(25517)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/activecampaign-supporttrio-25-vuln.html"></ref></refs><vuln_soft><prod name="SupportTrio" vendor="ActiveCampaign"><vers num="2.50.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1489" published="2006-03-29" seq="2006-1489" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in FusionZONE CouponZONE local.cfm in 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) companyid, (2) scat, and (3) coid parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/03/couponzone-v42-multiple-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17274">17274</ref><ref source="OSVDB" url="http://www.osvdb.org/24179">24179</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25576">couponzone-local-sql-injection(25576)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/couponzone-v42-multiple-vuln.html"></ref></refs><vuln_soft><prod name="couponZONE" vendor="fusionZONE"><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1490" published="2006-03-29" seq="2006-1490" severity="Medium" type="CVE"><desc><descript source="cve">PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a &quot;binary safety&quot; issue.  NOTE: this issue has been referred to as a &quot;memory leak,&quot; but it is an information leak that discloses memory contents.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429164/100/0/threaded">20060328 Critical PHP bug - act ASAP if you are running web with sensitive data</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429162/100/0/threaded">20060328 Re: [Full-disclosure] Critical PHP bug - act ASAP if you are running web with sensitive data</ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=127939"></ref><ref patch="1" source="" url="http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/html.c?r1=1.112&amp;r2=1.113"></ref><ref source="" url="http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/html.c?view=log"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17296">17296</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1149">ADV-2006-1149</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19383">19383</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25508">php-htmlentitydecode-information-disclosure(25508)</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:063">MDKSA-2006:063</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19499">19499</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0020">2006-0020</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19570">19570</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0276.html">RHSA-2006:0276</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19832">19832</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/05-05-2006.html">SUSE-SA:2006:024</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200605-08.xml">GLSA-200605-08</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2685">ADV-2006-2685</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20951">20951</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-320-1">USN-320-1</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=304829"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html">APPLE-SA-2006-11-28</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-333A.html">TA06-333A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4750">ADV-2006-4750</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23155">23155</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19979">
19979</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20052">
20052</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21125">
21125</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:063">MDKSA-2006:063</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.1.2"/><vers num="5.1.1"/><vers num="5.1.0"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0.0 RC3"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC1"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta1"/><vers num="5.0.0"/><vers num="5.0 candidate 3"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 1"/><vers num="4.4.2"/><vers num="4.4.1"/><vers num="4.4.0"/><vers num="4.3.11"/><vers num="4.3.10"/><vers num="4.3.9"/><vers num="4.3.8"/><vers num="4.3.7"/><vers num="4.3.6"/><vers num="4.3.5"/><vers num="4.3.4"/><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.3"/><vers num="4.2.2"/><vers num="4.2.1"/><vers num="4.2.0"/><vers edition="Dev" num="4.2"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1.0"/><vers num="4.0.7 RC3"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC1"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3 pl1"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1 pl2"/><vers num="4.0.1 pl1"/><vers num="4.0.1"/><vers num="4.0.0"/><vers num="3.0.18"/><vers num="3.0.17"/><vers num="3.0.16"/><vers num="3.0.15"/><vers num="3.0.14"/><vers num="3.0.13"/><vers num="3.0.12"/><vers num="3.0.11"/><vers num="3.0.10"/><vers num="3.0.9"/><vers num="3.0.8"/><vers num="3.0.7"/><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-05" name="CVE-2006-1491" published="2006-03-29" seq="2006-1491" severity="High" type="CVE"><desc><descript source="cve">Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://lists.horde.org/archives/announce/2006/000271.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17292">17292</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1154">ADV-2006-1154</ref><ref source="" url="http://cvs.horde.org/diff.php?f=horde%2Fservices%2Fhelp%2Findex.php&amp;r1=2.85&amp;r2=2.86"></ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015841">1015841</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25516">horde-help-viewer-command-execution(25516)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-02.xml">GLSA-200604-02</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_07_sr.html">SUSE-SR:2006:007</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19528">19528</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19504">19504</ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-March/000671.html">[VIM] 20060330 Recent unspecified Horde vuln is eval injection</ref><ref source="" url="http://lists.horde.org/archives/announce/2006/000272.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19485">19485</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1033">DSA-1033</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19619">19619</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1034">DSA-1034</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19692">19692</ref></refs><vuln_soft><prod name="Application Framework" vendor="Horde"><vers num="3.0.9"/><vers num="3.0.8"/><vers num="3.0.7"/><vers num="3.0.6"/><vers num="3.0.4 RC2"/><vers num="3.0.4 RC1"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1492" published="2006-03-29" seq="2006-1492" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in dir.php in Explorer XP allows remote attackers to read arbitrary files via the chemin parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.silitix.com/explorerxp.php"></ref><ref source="" url="http://www.zataz.com/news/10871/Probleme-de-securite-decouvert-dans-le-logiciel-ExploreXP.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17303">17303</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1165">ADV-2006-1165</ref><ref source="OSVDB" url="http://www.osvdb.org/24259">24259</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015840">1015840</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19460">19460</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25523">explorerxp-dir-directory-traversal(25523)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1806.html">20060329 ExplorerXP : Directory Traversal and Cross Site Scripting</ref></refs><vuln_soft><prod name="Explorer XP" vendor="Nikolay Avrionov"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1493" published="2006-03-29" seq="2006-1493" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in dir.php in Explorer XP allows remote attackers to inject arbitrary web script or HTML via the chemin parameter.  NOTE: it is possible that this issue is resultant from CVE-2006-1492.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.silitix.com/explorerxp.php"></ref><ref source="" url="http://www.zataz.com/news/10871/Probleme-de-securite-decouvert-dans-le-logiciel-ExploreXP.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17303">17303</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1165">ADV-2006-1165</ref><ref source="OSVDB" url="http://www.osvdb.org/24260">24260</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015840">1015840</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19460">19460</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25524">explorerxp-dir-xss(25524)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1806.html">20060329 ExplorerXP : Directory Traversal and Cross Site Scripting</ref></refs><vuln_soft><prod name="Explorer XP" vendor="Nikolay Avrionov"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-10" name="CVE-2006-1494" published="2006-04-10" seq="2006-1494" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="Security Reason" url="http://securityreason.com/achievement_securityalert/36">SecurityAlert Id : 36</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19599">19599</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430456/100/0/threaded">20060409 tempnam() open_basedir bypass PHP 4.4.2 and 5.1.2</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1290">ADV-2006-1290</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015881">1015881</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:074">MDKSA-2006:074</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/05-05-2006.html">SUSE-SA:2006:024</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0568.html">RHSA-2006:0568</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-320-1">USN-320-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21031">21031</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0567.html">RHSA-2006:0567</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U">20060701-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21135">21135</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21202">21202</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21252">21252</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0549.html">RHSA-2006:0549</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-175.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21723">21723</ref><ref source="" url="https://issues.rpath.com/browse/RPL-683"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/22225">22225</ref><ref source="BID" url="http://www.securityfocus.com/bid/17439">17439</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/447866/100/0/threaded">
20061005 rPSA-2006-0182-1 php php-mysql php-pgsql</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/044983.html">
20060408 tempnam() open_basedir bypass PHP 4.4.2 and 5.1.2</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19775">
19775</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19979">
19979</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21125">
21125</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25705">
php-tempnam-directory-traversal(25705)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:074">MDKSA-2006:074</ref><ref source="SREASON" url="http://securityreason.com/securityalert/677">677</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.1.2"/><vers num="5.1.1"/><vers num="5.1.0"/><vers num="5.1"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0.0 RC3"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC1"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta1"/><vers num="5.0.0"/><vers num="5.0 candidate 3"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 1"/><vers num="4.4.2"/><vers num="4.4.1"/><vers num="4.4.0"/><vers num="4.3.9"/><vers num="4.3.8"/><vers num="4.3.7"/><vers num="4.3.6"/><vers num="4.3.5"/><vers num="4.3.4"/><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.11"/><vers num="4.3.10"/><vers num="4.3.1"/><vers num="4.3"/><vers edition="Dev" num="4.2"/><vers num="4.2.3"/><vers num="4.2.2"/><vers num="4.2.1"/><vers num="4.2.0"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1.0"/><vers num="4.0.7 RC3"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC1"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5"/><vers num="4.0.4 pl1"/><vers num="4.0.4"/><vers num="4.0.3 pl1"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1 pl2"/><vers num="4.0.1 pl1"/><vers num="4.0.1"/><vers num="4.0.0"/><vers num="4.0 RC2"/><vers num="4.0 RC1"/><vers num="4.0 Beta 4 Patch Level 1"/><vers num="4.0 Beta 4"/><vers num="4.0 Beta 3"/><vers num="4.0 Beta 2"/><vers num="4.0 Beta 1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1495" published="2006-03-29" seq="2006-1495" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remote attackers to execute arbitrary SQL commands via the loginForm parameter in the &quot;forgotten password&quot; option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/1617"></ref><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/PHPCollab_NetOffice_SQLINJ.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17283">17283</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1142">ADV-2006-1142</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19449">19449</ref><ref source="BID" url="http://www.securityfocus.com/bid/17286">17286</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1141">ADV-2006-1141</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19452">19452</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25503">netoffice-sendpassword-bypass-security(25503)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25505">phpcollab-sendpassword-sql-injection(25505)</ref><ref source="OSVDB" url="http://www.osvdb.org/24226">24226</ref><ref source="OSVDB" url="http://www.osvdb.org/24230">24230</ref></refs><vuln_soft><prod name="NetOffice" vendor="NetOffice"><vers num="2.5.3 pl1"/></prod><prod name="PHPCollab" vendor="PhpCollab"><vers num="2.5.rc3"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1496" published="2006-03-29" seq="2006-1496" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1) a remote URL in the page parameter, which is processed by an fopen call, or (2) HTML or script in the page parameter, which is returned to the client in an error message for the failed fopen call.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/428737">20060324 VihorDesing Script Remote Command Exucetion And Cross Scripting Attack</ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-March/000650.html">[VIM] 20060326 clarification of &apos;VihorDesign&apos; (not VihorDesing) issues</ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-March/000651.html">[VIM] 20060326 clarification of &apos;VihorDesign&apos; (not VihorDesing) issues</ref><ref source="BID" url="http://www.securityfocus.com/bid/17226">17226</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19403">19403</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25483">vihordesign-index-xss(25483)</ref></refs><vuln_soft><prod name="VihorDesign" vendor="vihor"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1497" published="2006-03-29" seq="2006-1497" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in ViHor Design allows remote attackers to read arbitrary files via the page parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/428737">20060324 VihorDesing Script Remote Command Exucetion And Cross Scripting Attack</ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-March/000652.html">[VIM] 20060327 clarification of &apos;VihorDesign&apos; (not VihorDesing) issues</ref><ref source="BID" url="http://www.securityfocus.com/bid/17226">17226</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19403">19403</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1114">ADV-2006-1114</ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-March/000650.html">[VIM] 20060326 clarification of &quot;VihorDesign&quot; (not VihorDesing) issues</ref><ref source="BID" url="http://www.securityfocus.com/bid/17227">17227</ref><ref source="SREASON" url="http://securityreason.com/securityalert/625">625</ref></refs><vuln_soft><prod name="VihorDesign" vendor="vihor"><vers num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1498" published="2006-03-29" seq="2006-1498" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in MediaWiki before 1.5.8 and 1.4.15 allows remote attackers to inject arbitrary web script or HTML via crafted encoded links.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://mail.wikipedia.org/pipermail/mediawiki-announce/2006-March/000040.html">[MediaWiki-announce] 20060327 MediaWiki 1.5.8, 1.4.15 released [SECURITY]</ref><ref source="" url="http://www.mediawiki.org/wiki/MediaWiki"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17269">17269</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-01.xml">GLSA-200604-01</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_07_sr.html">SUSE-SR:2006:007</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19504">19504</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1194">ADV-2006-1194</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19508">19508</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19517">19517</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25588">
mediawiki-unspecified-xss(25588)</ref></refs><vuln_soft><prod name="MediaWiki" vendor="MediaWiki"><vers num="1.5.7"/><vers num="1.5.6"/><vers num="1.5.5"/><vers num="1.5.4"/><vers num="1.5.3"/><vers num="1.5.2"/><vers num="1.5.1"/><vers num="1.5.0"/><vers num="1.5 rc4"/><vers num="1.5 rc3"/><vers num="1.5 rc2"/><vers num="1.5 Beta4"/><vers num="1.5 Beta3"/><vers num="1.5 Beta2"/><vers num="1.5 Beta1"/><vers num="1.5 alpha2"/><vers num="1.5 alpha1"/><vers num="1.4.14"/><vers num="1.4.13"/><vers num="1.4.12"/><vers num="1.4.11"/><vers num="1.4.10"/><vers num="1.4.9"/><vers num="1.4.8"/><vers num="1.4.7"/><vers num="1.4.6"/><vers num="1.4.5"/><vers num="1.4.4"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1499" published="2006-03-29" seq="2006-1499" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in vCounter.php in vCounter 1.0 allows remote attackers to execute arbitrary SQL commands via the URI (_SERVER[REQUEST_URI] variable).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/108/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1147">ADV-2006-1147</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19422">19422</ref><ref source="BID" url="http://www.securityfocus.com/bid/17302">17302</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25500">vcounter-url-sql-injection(25500)</ref><ref source="OSVDB" url="http://www.osvdb.org/24234">24234</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430353/100/0/threaded">20060407 [eVuln] vCounter - sourceworkshop SQL Injection Vulnerability</ref></refs><vuln_soft><prod name="vCounter" vendor="Source Workshop"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1500" published="2006-03-29" seq="2006-1500" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Tilde CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1145">ADV-2006-1145</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19447">19447</ref><ref source="BID" url="http://www.securityfocus.com/bid/17299">17299</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25510">tildecms-index-sql-injection(25510)</ref><ref source="OSVDB" url="http://www.osvdb.org/24233">24233</ref><ref source="" url="http://osvdb.org/ref/24/24233-tilde.txt"></ref></refs><vuln_soft><prod name="Tilde CMS" vendor="Tilde"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1501" published="2006-03-29" seq="2006-1501" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in OneOrZero 1.6.3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly in the kans action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1146">ADV-2006-1146</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19446">19446</ref><ref source="BID" url="http://www.securityfocus.com/bid/17298">17298</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25511">oneorzero-helpdesk-index-sql-injection(25511)</ref><ref source="OSVDB" url="http://www.osvdb.org/24228">24228</ref><ref source="" url="http://osvdb.org/ref/24/24228-oneorzero.txt"></ref></refs><vuln_soft><prod name="OneOrZero" vendor="OneOrZero"><vers num="1.6.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1502" published="2006-03-29" seq="2006-1502" severity="Medium" type="CVE"><desc><descript source="cve">Multiple integer overflows in MPlayer 1.0pre7try2 allow remote attackers to cause a denial of service and trigger heap-based buffer overflows via (1) a certain ASF file handled by asfheader.c that causes the asf_descrambling function to be passed a negative integer after the conversion from a char to an int or (2) an AVI file with a crafted wLongsPerEntry or nEntriesInUse value in the indx chunk, which is handled in aviheader.c.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044615.html">20060329 [xfocus-SD-060329]MPlayer: Multiple integer overflows</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429251/100/0/threaded">20060329 [xfocus-SD-060329]MPlayer: Multiple integer overflows</ref><ref adv="1" source="XFocus" url="http://www.xfocus.org/advisories/200603/11.html">[xfocus-SD-060329]</ref><ref source="BID" url="http://www.securityfocus.com/bid/17295">17295</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1156">ADV-2006-1156</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19418">19418</ref><ref source="OSVDB" url="http://www.osvdb.org/24246">24246</ref><ref source="OSVDB" url="http://www.osvdb.org/24247">24247</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015842">1015842</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25513">mplayer-asfheader-integer-overflow(25513)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25514">mplayer-aviheader-integer-overflow(25514)</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:068">MDKSA-2006:068</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19565">19565</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-01.xml">GLSA-200605-01</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19919">19919</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:068">MDKSA-2006:068</ref><ref source="SREASON" url="http://securityreason.com/securityalert/532">532</ref><ref source="SREASON" url="http://securityreason.com/securityalert/647">647</ref></refs><vuln_soft><prod name="MPlayer" vendor="MPlayer"><vers num="1.0 pre7try2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-28" modified="2006-04-25" name="CVE-2006-1503" published="2006-03-29" seq="2006-1503" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in includes/functions_install.php in Virtual War (VWar) 1.5.0 R11 and earlier allows remote attackers to include and execute arbitrary PHP code via a URL in the vwar_root parameter.  NOTE: this is a different vulnerability than CVE-2006-1636.</descript></desc><sols><sol source="nvd">Successful exploitation requires that the &quot;register_globals&quot; parameter is enabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429090/100/0/threaded">20060328 VWar &lt;= 1.5.0 R11 Remote Code Execution Exploit</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1144">ADV-2006-1144</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19438">19438</ref><ref source="BID" url="http://www.securityfocus.com/bid/17290">17290</ref><ref source="OSVDB" url="http://www.osvdb.org/24239">24239</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25497">virtual-war-functionsinstall-file-include(25497)</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-April/000679.html">[VIM] 20060403 Vendor ACK for VWar issue - VWar used by PhpNuke Clan</ref></refs><vuln_soft><prod name="Virtual War" vendor="VWar"><vers num="1.5.0 R11"/><vers num="1.5.0 R10"/><vers num="1.5.0 R9"/><vers num="1.5.0 R8"/><vers num="1.5.0 R7"/><vers num="1.5.0 R6"/><vers num="1.5.0 R5"/><vers num="1.5.0 R4"/><vers num="1.5.0 R3"/><vers num="1.5.0 R2"/><vers num="1.5.0 R1"/><vers num="1.5"/><vers num="1.4"/><vers num="1.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.1.8"/><vers num="1.1.7"/><vers num="1.1.6"/><vers num="1.1.5"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1.0"/><vers num="1.0.9"/><vers num="1.0.8"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-28" modified="2006-03-30" name="CVE-2006-1504" published="2006-03-29" seq="2006-1504" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0 (aka Arab Dynamic Portal or ADP) stable allow remote attackers to inject arbitrary web script or HTML via the title parameter in (1) online.php and (2) download.php.</descript></desc><sols><sol source="nvd">Successful exploitation requires that the &quot;register_globals&quot; parameter is enabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429109/100/0/threaded">20060328 ArabPortal 2.0 Stable CrossSiteScripting</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1150">ADV-2006-1150</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19445">19445</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25515">arabportal-online-download-xss(25515)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17285">17285</ref><ref source="OSVDB" url="http://www.osvdb.org/24220">24220</ref><ref source="OSVDB" url="http://www.osvdb.org/24221">24221</ref><ref source="SREASON" url="http://securityreason.com/securityalert/673">673</ref></refs><vuln_soft><prod name="Arab Portal" vendor="Arab Portal"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-02-26" modified="2006-03-30" name="CVE-2006-1505" published="2006-03-29" seq="2006-1505" severity="Medium" type="CVE"><desc><descript source="cve">base_maintenance.php in Basic Analysis and Security Engine (BASE) before 1.2.4 (melissa), when running in standalone mode, allows remote attackers to bypass authentication, possibly by setting the standalone parameter to &quot;yes&quot;.</descript></desc><sols><sol source="nvd">Succesful exploitation requires that the product is running in standalone mode.</sol></sols><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="Sourceforge" url="http://cvs.sourceforge.net/viewcvs.py/secureideas/base-php4/docs/CHANGELOG?rev=1.233&amp;view=markup">changelog</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/24101">24101</ref><ref source="BID" url="http://www.securityfocus.com/bid/17354">17354</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1192">ADV-2006-1192</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19510">19510</ref></refs><vuln_soft><prod name="BASE" vendor="Basic Analysis and Security Engine"><vers num="1.1 Elizabeth"/><vers num="1.1.2 Zora"/><vers num="1.1.3 Lynn"/><vers num="1.1.4 Cheryl"/><vers num="1.2 Betty"/><vers num="1.2.1 Kris"/><vers num="1.2.2 Cindy"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1506" published="2006-03-29" seq="2006-1506" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in rsh in Sun Microsystems Sun Grid Engine 5.3 before 20060327 and N1 Grid Engine 6.0 before 20060327 allows local users to gain root privileges.</descript></desc><sols><sol source="nvd">This vulnerability affects Sun Microsystems, Sun Grid Engine 5.3 before 20060327 &amp; N1 Grid Engine 6.0 before 20060327.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102268-1">102268</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015835">1015835</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1155">ADV-2006-1155</ref></refs><vuln_soft><prod name="Sun Grid Engine" vendor="Sun"><vers num="5.3"/></prod><prod name="N1 Grid Engine" vendor="Sun"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-28" modified="2006-03-30" name="CVE-2006-1507" published="2006-03-29" seq="2006-1507" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the error parameter to include.php, possibly due to a problem in login/login.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429249/100/0/threaded">20060328 XSS in PHPKIT Version 1.6.03</ref><ref source="BID" url="http://www.securityfocus.com/bid/17291">17291</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25594">
phpkit-error-xss(25594)</ref></refs><vuln_soft><prod name="PHPKIT" vendor="PHPKIT"><vers num="1.6.03"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-27" modified="2006-03-30" name="CVE-2006-1508" published="2006-03-29" seq="2006-1508" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MH Software Connect Daily Web Calendar Software 3.2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) calendar_id, (2) style_sheet, and (3) start parameters in (a) ViewDay.html; the (4) txtSearch and (5) opgSearch parameters in (b) ViewSearch.html; the (6) calendar_id and (7) approved parameters in (c) ViewYear.html; the (8) item_type_id parameter in (d) ViewCal.html; and the (9) week parameter in (e) ViewWeek.html.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Blogspot" url="http://pridels.blogspot.com/2006/03/connect-daily-multiple-xss-vuln.html">Connect Daily Multiple XSS vuln. </ref><ref source="BID" url="http://www.securityfocus.com/bid/17287">17287</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1125">ADV-2006-1125</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19434">19434</ref><ref source="OSVDB" url="http://www.osvdb.org/24181">24181</ref><ref source="OSVDB" url="http://www.osvdb.org/24182">24182</ref><ref source="OSVDB" url="http://www.osvdb.org/24183">24183</ref><ref source="OSVDB" url="http://www.osvdb.org/24184">24184</ref><ref source="OSVDB" url="http://www.osvdb.org/24185">24185</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25474">connectdailywebcalendar-multiple-xss(25474)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/connect-daily-multiple-xss-vuln.html"></ref></refs><vuln_soft><prod name="Connect Daily" vendor="MH Software"><vers num="3.2.9" prev="1"/><vers num="3.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-30" name="CVE-2006-1509" published="2006-03-29" seq="2006-1509" severity="Medium" type="CVE"><desc><descript source="cve">/sbin/passwd in HP-UX B.11.00, B.11.11, and B.11.23 before 20060326 &quot;does not recover gracefully from some error conditions,&quot; which allows local users to cause a denial of service.</descript></desc><sols><sol source="nvd">This vulnerability affects all versions of HP-UX B.11.00, B.11.11, and B.11.23 before 20060326.</sol></sols><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref patch="1" source="HP" url="http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00619550">HPSBUX02103</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17280">17280</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1208">ADV-2006-1208</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19490">19490</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25596">
hpux-passwd-dos(25596)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1412">oval:org.mitre.oval:def:1412</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1660">oval:org.mitre.oval:def:1660</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1690">oval:org.mitre.oval:def:1690</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="B.11.00"/><vers num="B.11.11"/><vers edition="IA64 64-bit" num="B.11.23"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-11-27" modified="2006-08-28" name="CVE-2006-1510" published="2006-03-29" seq="2006-1510" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file with a large static method.</descript></desc><sols><sol source="nvd">Succesful exploitation can only occur when ntdll.dll system library is used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK packages.</sol></sols><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044482.html">20060327 Buffer OverFlow in ILASM and ILDASM</ref><ref patch="1" source="OWASP" url="http://owasp.net/forums/234/showpost.aspx">ILDASM Exception Creator</ref><ref source="OWASP" url="http://owasp.net/forums/257/showpost.aspx">To MSRC: Buffer OverFlow in ILASM and ILDASM</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17243">17243</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1113">ADV-2006-1113</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19406">19406</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25439">ms-dotnet-ildasm-bo(25439)</ref></refs><vuln_soft><prod name=".NET Framework" vendor="Microsoft"><vers edition="SDK" num="1.0 SP2"/><vers edition="SDK" num="1.0 SP1"/><vers num="1.0"/><vers edition="SDK" num="1.1 SP1"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-11-27" modified="2006-08-28" name="CVE-2006-1511" published="2006-03-29" seq="2006-1511" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044482.html">20060327 Buffer OverFlow in ILASM and ILDASM</ref><ref source="" url="http://owasp.net/forums/234/showpost.aspx"></ref><ref source="" url="http://owasp.net/forums/257/showpost.aspx"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17243">17243</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1113">ADV-2006-1113</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19406">19406</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25438">ms-dotnet-ilasm-bo(25438)</ref></refs><vuln_soft><prod name=".NET Framework" vendor="Microsoft"><vers edition="SDK" num="1.0 SP2"/><vers edition="SDK" num="1.0 SP1"/><vers edition="SDK" num="1.0"/><vers edition="SDK" num="1.1 SP1"/><vers edition="SDK" num="1.1"/></prod></vuln_soft></entry><entry modified="2006-04-25" name="CVE-2006-1512" published="2006-04-24" reject="1" seq="2006-1512" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-1712.  Reason: This candidate is a reservation duplicate of CVE-2006-1712.  Notes: All CVE users should reference CVE-2006-1712 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-1513" published="2006-04-25" seq="2006-1513" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in abc2ps before 1.3.3 allow user-assisted attackers to execute arbitrary code via crafted ABC music files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1041">DSA-1041</ref><ref source="BID" url="http://www.securityfocus.com/bid/17689">17689</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1511">ADV-2006-1511</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19787">19787</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19807">19807</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26043">
abc2ps-abc-bo(26043)</ref></refs><vuln_soft><prod name="abc2ps" vendor="abc2ps"><vers num="1.3.0"/><vers num="1.2.5"/><vers num="1.2.2e4"/><vers num="1.2.2e3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-27" name="CVE-2006-1514" published="2006-04-27" seq="2006-1514" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the abcmidi-yaps translator in abcmidi 20050101, and other versions, allow remote attackers to execute arbitrary code via crafted ABC music files that trigger the overflows during translation into PostScript.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1043">DSA-1043</ref><ref source="BID" url="http://www.securityfocus.com/bid/17704">17704</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1531">ADV-2006-1531</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/24974">24974</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19829">19829</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19826">19826</ref></refs><vuln_soft><prod name="abcMIDI" vendor="abcMIDI"><vers num="2006-04-22" prev="1"/><vers num="2005-01-01"/><vers num="2004-12-04"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-06-05" name="CVE-2006-1515" published="2006-05-31" seq="2006-1515" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the addnewword function in typespeed 0.4.4 and earlier might allow remote attackers to execute arbitrary code via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1084">DSA-1084</ref><ref source="BID" url="http://www.securityfocus.com/bid/18194">18194</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2087">ADV-2006-2087</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20379">20379</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20393">20393</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200606-20.xml">GLSA-200606-20</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20708">20708</ref></refs><vuln_soft><prod name="typespeed" vendor="typespeed"><vers num="0.4.4"/><vers num="0.4.3"/><vers num="0.4.2"/><vers num="0.4.1"/><vers num="0.4.0"/><vers num="0.3.5"/><vers num="0.3.4"/><vers num="0.3.3"/><vers num="0.3.2"/><vers num="0.3.1"/><vers num="0.3"/><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-02" modified="2006-05-05" name="CVE-2006-1516" published="2006-05-05" seq="2006-1516" severity="Medium" type="CVE"><desc><descript source="cve">The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432733/100/0/threaded">20060502 MySQL Anonymous Login Handshake - Information Leakage.</ref><ref patch="1" source="" url="http://www.wisec.it/vulns.php?page=7"></ref><ref patch="1" source="" url="http://dev.mysql.com/doc/refman/5.0/en/news-5-0-21.html"></ref><ref source="" url="http://bugs.debian.org/365938"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1633">ADV-2006-1633</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016017">1016017</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19929">19929</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-283-1">USN-283-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/17780">17780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20002">20002</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-13.xml">GLSA-200605-13</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:084">MDKSA-2006:084</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20073">20073</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20076">20076</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/434164/100/0/threaded">20060516 UPDATE: [ GLSA 200605-13 ] MySQL: Information leakage</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1071">DSA-1071</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0028">2006-0028</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20223">20223</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1073">DSA-1073</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20241">20241</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20253">20253</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1079">DSA-1079</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20333">20333</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.599377">SSA:2006-155-01</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-06-02.html">SUSE-SR:2006:012</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20424">20424</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20457">20457</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0544.html">RHSA-2006:0544</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20625">20625</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Jun/0011.html">SUSE-SA:2006:036</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20762">20762</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26236">
mysql-login-packet-info-disclosure(26236)</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="SREASON" url="http://securityreason.com/securityalert/840">840</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-236703-1">236703</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1326/references">ADV-2008-1326</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29847">29847</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="5.0.9"/><vers num="5.0.8"/><vers num="5.0.7"/><vers num="5.0.6"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3 Beta"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.18"/><vers num="5.0.17"/><vers num="5.0.16"/><vers num="5.0.15"/><vers num="5.0.14"/><vers num="5.0.13"/><vers num="5.0.12"/><vers num="5.0.11"/><vers num="5.0.10"/><vers num="5.0.1"/><vers num="5.0.0 alpha"/><vers num="5.0.0.0"/><vers num="5.0"/><vers num="4.1.9"/><vers num="4.1.8"/><vers num="4.1.7"/><vers num="4.1.6"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3 beta"/><vers num="4.1.3.0"/><vers num="4.1.2 alpha"/><vers num="4.1.18"/><vers num="4.1.17"/><vers num="4.1.16"/><vers num="4.1.15"/><vers num="4.1.14"/><vers num="4.1.13"/><vers num="4.1.12"/><vers num="4.1.11"/><vers num="4.1.10a"/><vers num="4.1.10"/><vers num="4.1.0 alpha"/><vers num="4.1.0.0"/><vers num="4.1"/><vers num="4.0.9 gamma"/><vers num="4.0.9"/><vers num="4.0.8 gamma"/><vers num="4.0.8"/><vers num="4.0.7 gamma"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5a"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3"/><vers num="4.0.26"/><vers num="4.0.25"/><vers num="4.0.24"/><vers num="4.0.23"/><vers num="4.0.21"/><vers num="4.0.20"/><vers num="4.0.2"/><vers num="4.0.19"/><vers num="4.0.18"/><vers num="4.0.17"/><vers num="4.0.16"/><vers num="4.0.15"/><vers num="4.0.14"/><vers num="4.0.13"/><vers num="4.0.12"/><vers num="4.0.11 gamma"/><vers num="4.0.11"/><vers num="4.0.10"/><vers num="4.0.1"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-02" modified="2006-05-05" name="CVE-2006-1517" published="2006-05-05" seq="2006-1517" severity="Medium" type="CVE"><desc><descript source="cve">sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to obtain sensitive information via a COM_TABLE_DUMP request with an incorrect packet length, which includes portions of memory in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432734/100/0/threaded">20060502 MySQL COM_TABLE_DUMP Information Leakage and Arbitrary commandexecution.</ref><ref patch="1" source="" url="http://www.wisec.it/vulns.php?page=8"></ref><ref patch="1" source="" url="http://dev.mysql.com/doc/refman/5.0/en/news-5-0-21.html"></ref><ref patch="1" source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=365939"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1633">ADV-2006-1633</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016016">1016016</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19929">19929</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-283-1">USN-283-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/17780">17780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20002">20002</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-13.xml">GLSA-200605-13</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:084">MDKSA-2006:084</ref><ref source="OSVDB" url="http://www.osvdb.org/25228">25228</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20073">20073</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20076">20076</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/434164/100/0/threaded">20060516 UPDATE: [ GLSA 200605-13 ] MySQL: Information leakage</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1071">DSA-1071</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0028">2006-0028</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20223">20223</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1073">DSA-1073</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20241">20241</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20253">20253</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1079">DSA-1079</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20333">20333</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.599377">SSA:2006-155-01</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-06-02.html">SUSE-SR:2006:012</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20424">20424</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20457">20457</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0544.html">RHSA-2006:0544</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20625">20625</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Jun/0011.html">SUSE-SA:2006:036</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20762">20762</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26228">
mysql-sqlparcecc-information-disclosure(26228)</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="SREASON" url="http://securityreason.com/securityalert/839">839</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-236703-1">236703</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1326/references">ADV-2008-1326</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29847">29847</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="5.0.9"/><vers num="5.0.8"/><vers num="5.0.7"/><vers num="5.0.6"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3 Beta"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.18"/><vers num="5.0.17"/><vers num="5.0.16"/><vers num="5.0.15"/><vers num="5.0.14"/><vers num="5.0.13"/><vers num="5.0.12"/><vers num="5.0.11"/><vers num="5.0.10"/><vers num="5.0.1"/><vers num="5.0.0 alpha"/><vers num="5.0.0.0"/><vers num="5.0"/><vers num="4.1.9"/><vers num="4.1.8"/><vers num="4.1.7"/><vers num="4.1.6"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3 beta"/><vers num="4.1.3.0"/><vers num="4.1.2 alpha"/><vers num="4.1.18"/><vers num="4.1.17"/><vers num="4.1.16"/><vers num="4.1.15"/><vers num="4.1.14"/><vers num="4.1.13"/><vers num="4.1.12"/><vers num="4.1.11"/><vers num="4.1.10a"/><vers num="4.1.10"/><vers num="4.1.0 alpha"/><vers num="4.1.0.0"/><vers num="4.1"/><vers num="4.0.9 gamma"/><vers num="4.0.9"/><vers num="4.0.8 gamma"/><vers num="4.0.8"/><vers num="4.0.7 gamma"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5a"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3"/><vers num="4.0.26"/><vers num="4.0.25"/><vers num="4.0.24"/><vers num="4.0.23"/><vers num="4.0.21"/><vers num="4.0.20"/><vers num="4.0.2"/><vers num="4.0.19"/><vers num="4.0.18"/><vers num="4.0.17"/><vers num="4.0.16"/><vers num="4.0.15"/><vers num="4.0.14"/><vers num="4.0.13"/><vers num="4.0.12"/><vers num="4.0.11 gamma"/><vers num="4.0.11"/><vers num="4.0.10"/><vers num="4.0.1"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-25" modified="2006-05-10" name="CVE-2006-1518" published="2006-05-05" seq="2006-1518" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via crafted COM_TABLE_DUMP packets with invalid length values.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432734/100/0/threaded">20060502 MySQL COM_TABLE_DUMP Information Leakage and Arbitrary commandexecution.</ref><ref patch="1" source="" url="http://www.wisec.it/vulns.php?page=8"></ref><ref patch="1" source="" url="http://dev.mysql.com/doc/refman/5.0/en/news-5-0-21.html"></ref><ref patch="1" source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=365939"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1633">ADV-2006-1633</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016016">1016016</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19929">19929</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/602457">VU#602457</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1071">DSA-1071</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1073">DSA-1073</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20241">20241</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20253">20253</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1079">DSA-1079</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20333">20333</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-06-02.html">SUSE-SR:2006:012</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20457">20457</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Jun/0011.html">SUSE-SA:2006:036</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20762">20762</ref><ref source="BID" url="http://www.securityfocus.com/bid/17780">
17780</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26232">
mysql-comtabledump-bo(26232)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/839">839</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="5.0.9"/><vers num="5.0.8"/><vers num="5.0.7"/><vers num="5.0.6"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3 Beta"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.18"/><vers num="5.0.17"/><vers num="5.0.16"/><vers num="5.0.15"/><vers num="5.0.14"/><vers num="5.0.13"/><vers num="5.0.12"/><vers num="5.0.11"/><vers num="5.0.10"/><vers num="5.0.1"/><vers num="5.0.0 alpha"/><vers num="5.0.0.0"/><vers num="5.0"/><vers num="5.0.20"/><vers num="5.0.19"/></prod></vuln_soft></entry><entry modified="2006-05-15" name="CVE-2006-1519" published="2006-05-15" reject="1" seq="2006-1519" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-2224.  Reason: This candidate is a duplicate of CVE-2006-2224.  Notes: All CVE users should reference CVE-2006-2224 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-09" modified="2006-05-23" name="CVE-2006-1520" published="2006-05-22" seq="2006-1520" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in ANSI C Sender Policy Framework library (libspf) before 1.0.0-p5, when debugging is enabled, allows remote attackers to execute arbitrary code via format string specifiers, possibly in an e-mail address.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://permalink.gmane.org/gmane.mail.spam.spf.devel/849"></ref><ref patch="1" source="" url="http://www.gossamer-threads.com/lists/spf/devel/27053?page=last"></ref><ref patch="1" source="" url="http://www.libspf.org/index.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1846">ADV-2006-1846</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26535">libspf-debugging-format-string(26535)</ref></refs><vuln_soft><prod name="libspf" vendor="libspf"><vers num="1.0.0 p4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1522" published="2006-04-10" seq="2006-1522" severity="Medium" type="CVE"><desc><descript source="cve">The sys_add_key function in the keyring code in Linux kernel 2.6.16.1 and 2.6.17-rc1, and possibly earlier versions, allows local users to cause a denial of service (OOPS) via keyctl requests that add a key to a user key instead of a keyring key, which causes an invalid dereference in the __keyring_search_one function.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><local/></range><refs><ref patch="1" source="Bugzilla" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=188466">Bugzilla Bug 188466 </ref><ref patch="1" source="LINUX" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=c3a9d6541f84ac3ff566982d08389b87c1c36b4e"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17451">17451</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19573">19573</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1307">ADV-2006-1307</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:086">MDKSA-2006:086</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20157">20157</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0493.html">RHSA-2006:0493</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20237">20237</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-302-1">USN-302-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20716">20716</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21745">21745</ref><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.3"></ref><ref source="FEDORA" url="http://lwn.net/Alerts/180820/">
FEDORA-2006-423</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1475">
ADV-2006-1475</ref><ref source="OSVDB" url="http://www.osvdb.org/24507">
24507</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19735">
19735</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25722">
linux-keyringsearchone-dos(25722)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:086">MDKSA-2006:086</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.17-rc1"/><vers num="2.6.17"/><vers num="2.6.16.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1523" published="2006-04-12" seq="2006-1523" severity="High" type="CVE"><desc><descript source="cve">The __group_complete_signal function in the RCU signal handling (signal.c) in Linux kernel 2.6.16, and possibly other versions, has unknown impact and attack vectors related to improper use of BUG_ON.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=114476543426600&amp;w=2">[linux-kernel] 20060411 [PATCH] __group_complete_signal: remove bogus BUG_ON</ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=188604"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17640">17640</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.16"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-30" name="CVE-2006-1524" published="2006-04-19" seq="2006-1524" severity="Low" type="CVE"><desc><descript source="cve">madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability.  NOTE: this description was originally written in a way that combined two separate issues.  The mprotect issue now has a separate name, CVE-2006-2071.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.6"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17587">17587</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19664">19664</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19657">19657</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1097">DSA-1097</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20671">20671</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="OSVDB" url="http://www.osvdb.org/24714">24714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref><ref source="FEDORA" url="http://lwn.net/Alerts/180820/">
FEDORA-2006-423</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1391">
ADV-2006-1391</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1475">
ADV-2006-1475</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19735">
19735</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25870">
linux-madvise-security-bypass(25870)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.16.1"/><vers num="2.6.16-rc1"/><vers num="2.6.16"/><vers num="2.6.15.4"/><vers num="2.6.15.3"/><vers num="2.6.15.2"/><vers num="2.6.15.1"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.15"/><vers num="2.6.14.5"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.14"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13-rc7"/><vers num="2.6.13-rc6"/><vers num="2.6.13-rc4"/><vers num="2.6.13-rc1"/><vers num="2.6.13"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12-rc5"/><vers num="2.6.12-rc4"/><vers num="2.6.12-rc1"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11-rc4"/><vers num="2.6.11-rc3"/><vers num="2.6.11-rc2"/><vers num="2.6.11"/><vers num="2.6.10-rc2"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1-rc2"/><vers num="2.6.1-rc1"/><vers num="2.6.1"/><vers num="2.6 test 9 CVS"/><vers num="2.6-test9"/><vers num="2.6-test8"/><vers num="2.6-test7"/><vers num="2.6-test6"/><vers num="2.6-test5"/><vers num="2.6-test4"/><vers num="2.6-test3"/><vers num="2.6-test2"/><vers num="2.6-test11"/><vers num="2.6-test10"/><vers num="2.6-test1"/><vers num="2.6"/><vers num="2.5.69"/><vers num="2.5.68"/><vers num="2.5.67"/><vers num="2.5.66"/><vers num="2.5.65"/><vers num="2.5.64"/><vers num="2.5.63"/><vers num="2.5.62"/><vers num="2.5.61"/><vers num="2.5.60"/><vers num="2.5.59"/><vers num="2.5.58"/><vers num="2.5.57"/><vers num="2.5.56"/><vers num="2.5.55"/><vers num="2.5.54"/><vers num="2.5.53"/><vers num="2.5.52"/><vers num="2.5.51"/><vers num="2.5.50"/><vers num="2.5.49"/><vers num="2.5.48"/><vers num="2.5.47"/><vers num="2.5.46"/><vers num="2.5.45"/><vers num="2.5.44"/><vers num="2.5.43"/><vers num="2.5.42"/><vers num="2.5.41"/><vers num="2.5.40"/><vers num="2.5.39"/><vers num="2.5.38"/><vers num="2.5.37"/><vers num="2.5.36"/><vers num="2.5.35"/><vers num="2.5.34"/><vers num="2.5.33"/><vers num="2.5.32"/><vers num="2.5.31"/><vers num="2.5.30"/><vers num="2.5.29"/><vers num="2.5.28"/><vers num="2.5.27"/><vers num="2.5.26"/><vers num="2.5.25"/><vers num="2.5.24"/><vers num="2.5.23"/><vers num="2.5.22"/><vers num="2.5.21"/><vers num="2.5.20"/><vers num="2.5.19"/><vers num="2.5.18"/><vers num="2.5.17"/><vers num="2.5.16"/><vers num="2.5.15"/><vers num="2.5.14"/><vers num="2.5.13"/><vers num="2.5.12"/><vers num="2.5.11"/><vers num="2.5.10"/><vers num="2.5.9"/><vers num="2.5.8"/><vers num="2.5.7"/><vers num="2.5.6"/><vers num="2.5.5"/><vers num="2.5.4"/><vers num="2.5.3"/><vers num="2.5.2"/><vers num="2.5.1"/><vers num="2.5.0"/><vers num="2.4.33-pre1"/><vers num="2.4.32-pre2"/><vers num="2.4.32-pre1"/><vers num="2.4.32"/><vers num="2.4.31-pre1"/><vers num="2.4.31"/><vers num="2.4.30-rc3"/><vers num="2.4.30-rc2"/><vers num="2.4.30"/><vers num="2.4.29-rc2"/><vers num="2.4.29-rc1"/><vers num="2.4.29"/><vers num="2.4.28"/><vers num="2.4.27-pre5"/><vers num="2.4.27-pre4"/><vers num="2.4.27-pre3"/><vers num="2.4.27-pre2"/><vers num="2.4.27-pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24-ow1"/><vers num="2.4.24"/><vers num="2.4.23-pre9"/><vers num="2.4.23-ow2"/><vers num="2.4.23"/><vers num="2.4.22"/><vers num="2.4.21-pre7"/><vers num="2.4.21-pre4"/><vers num="2.4.21-pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.19-pre6"/><vers num="2.4.19-pre5"/><vers num="2.4.19-pre4"/><vers num="2.4.19-pre3"/><vers num="2.4.19-pre2"/><vers num="2.4.19-pre1"/><vers num="2.4.19"/><vers num="2.4.18-pre-8"/><vers num="2.4.18-pre-7"/><vers num="2.4.18-pre-6"/><vers num="2.4.18-pre-5"/><vers num="2.4.18-pre-4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3"/><vers num="2.4.2"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.6.15.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-1525" published="2006-04-19" seq="2006-1525" severity="Medium" type="CVE"><desc><descript source="cve">ip_route_input in Linux kernel 2.6 before 2.6.16.8 allows local users to cause a denial of service (panic) via a request for a route for a multicast IP address, which triggers a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.8"></ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189346"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17593">17593</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1399">ADV-2006-1399</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19709">19709</ref><ref source="OSVDB" url="http://www.osvdb.org/24715">24715</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25872">linux-ip-route-input-dos(25872)</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-281-1">USN-281-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19955">19955</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:086">MDKSA-2006:086</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20157">20157</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0493.html">RHSA-2006:0493</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20237">20237</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1097">DSA-1097</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20671">20671</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21745">21745</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref><ref source="FEDORA" url="http://lwn.net/Alerts/180820/">
FEDORA-2006-423</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1475">
ADV-2006-1475</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19735">
19735</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21476">
21476</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:086">MDKSA-2006:086</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.16.7"/><vers num="2.6.16.1"/><vers num="2.6.16-rc1"/><vers num="2.6.16"/><vers num="2.6.15.4"/><vers num="2.6.15.3"/><vers num="2.6.15.2"/><vers num="2.6.15.1"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.15"/><vers num="2.6.14.5"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.14"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13-rc7"/><vers num="2.6.13-rc6"/><vers num="2.6.13-rc4"/><vers num="2.6.13-rc1"/><vers num="2.6.13"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12-rc5"/><vers num="2.6.12-rc4"/><vers num="2.6.12-rc1"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11-rc4"/><vers num="2.6.11-rc3"/><vers num="2.6.11-rc2"/><vers num="2.6.11"/><vers num="2.6.10-rc2"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1-rc2"/><vers num="2.6.1-rc1"/><vers num="2.6.1"/><vers num="2.6 test 9 CVS"/><vers num="2.6-test9"/><vers num="2.6-test8"/><vers num="2.6-test7"/><vers num="2.6-test6"/><vers num="2.6-test5"/><vers num="2.6-test4"/><vers num="2.6-test3"/><vers num="2.6-test2"/><vers num="2.6-test11"/><vers num="2.6-test10"/><vers num="2.6-test1"/><vers num="2.6"/><vers num="2.6.15.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-02" modified="2006-05-09" name="CVE-2006-1526" published="2006-05-02" seq="2006-1526" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up to allows attackers to cause a denial of service (crash), as demonstrated by the (1) XRenderCompositeTriStrip and (2) XRenderCompositeTriFan requests in the rendertest from XCB xcb/xcb-demo, which leads to an incorrect memory allocation due to a typo in an expression that uses a &quot;&amp;&quot; instead of a &quot;*&quot; operator. NOTE: the subject line of the original announcement used an incorrect CVE number for this issue.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="MLIST" url="http://lists.freedesktop.org/archives/xorg/2006-May/015136.html">[xorg] 20060502 [CVE-2006-1525] X.Org security advisory: Buffer overflow in the Xrender extension</ref><ref source="" url="https://bugs.freedesktop.org/show_bug.cgi?id=6642"></ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-02.xml">GLSA-200605-02</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:081">MDKSA-2006:081</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata38.html#xorg">[3.8] 007: SECURITY FIX: May 2, 2006</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0451.html">RHSA-2006:0451</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_05_03.html">SUSE-SA:2006:023</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-280-1">USN-280-1</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1617">ADV-2006-1617</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016018">1016018</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19915">19915</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19921">19921</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19943">19943</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19900">19900</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19916">19916</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19951">19951</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19956">19956</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102339-1">102339</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0024">2006-0024</ref><ref source="BID" url="http://www.securityfocus.com/bid/17795">17795</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19983">19983</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436327/100/0/threaded">FLSA:190777</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/633257">VU#633257</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26200">xorg-xrender-bo(26200)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:081">MDKSA-2006:081</ref></refs><vuln_soft><prod name="X11R6" vendor="X.Org"><vers num="6.9"/><vers num="6.8.1"/><vers num="6.8"/><vers num="6.7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-03" name="CVE-2006-1527" published="2006-05-03" seq="2006-1527" severity="Medium" type="CVE"><desc><descript source="cve">The SCTP-netfilter code in Linux kernel before 2.6.16.13 allows remote attackers to trigger a denial of service (infinite loop) via unknown vectors that cause an invalid SCTP chunk size to be processed by the for_each_sctp_chunk function.</descript></desc><sols><sol source="nvd">Upgrade to Linux Kernel version 2.6.16.13 :
http://www.kernel.org/</sol></sols><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.13"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1632">ADV-2006-1632</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0024">2006-0024</ref><ref source="BID" url="http://www.securityfocus.com/bid/17806">17806</ref><ref source="OSVDB" url="http://www.osvdb.org/25229">25229</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19926">19926</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:086">MDKSA-2006:086</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20157">20157</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0493.html">RHSA-2006:0493</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20237">20237</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-302-1">USN-302-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20716">20716</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21745">21745</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26194">
linux-sctp-netfilter-dos(26194)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:086">MDKSA-2006:086</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.16.12"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-06-24" name="CVE-2006-1528" published="2006-05-18" seq="2006-1528" severity="Medium" type="CVE"><desc><descript source="cve">Linux kernel before 2.6.13 allows local users to cause a denial of service (crash) via a dio transfer from the sg driver to memory mapped (mmap) IO space.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=168791"></ref><ref source="" url="http://linux.bkbits.net:8080/linux-2.6/cset@43220081yu9ClBQNuqSSnW_9amW7iQ"></ref><ref source="" url="http://marc.theaimsgroup.com/?l=linux-scsi&amp;m=112540053711489&amp;w=2"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0493.html">RHSA-2006:0493</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20237">20237</ref><ref source="BID" url="http://www.securityfocus.com/bid/18101">18101</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-302-1">USN-302-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20716">20716</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:123">MDKSA-2006:123</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21045">21045</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_42_kernel.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21179">21179</ref><ref source="" url="http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.33.1"></ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_47_kernel.html">SUSE-SA:2006:047</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3330">ADV-2006-3330</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21555">21555</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/28510">kernel-sg-dos(28510)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21745">21745</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1183">DSA-1183</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1184">DSA-1184</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/22082">22082</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/22093">22093</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21498">21498</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:123">MDKSA-2006:123</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.12 rc6"/><vers num="2.6.12 rc5"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc3"/><vers num="2.6.12 rc2"/><vers num="2.6.12 rc1"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12"/><vers num="2.6.11 rc5"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11 rc1"/><vers num="2.6.11.9"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11.10"/><vers num="2.6.11.1"/><vers edition="x86_64" num="2.6.11"/><vers num="2.6.11"/><vers num="2.6.10 rc3"/><vers num="2.6.10 rc2"/><vers num="2.6.10 rc1"/><vers num="2.6.10"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6.9 rc4"/><vers num="2.6.9 rc3"/><vers num="2.6.9 rc2"/><vers num="2.6.9 rc1"/><vers num="2.6.9 final"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8 rc4"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers edition="PowerPC_smp" num="2.6.8.1.5"/><vers edition="PowerPC" num="2.6.8.1.5"/><vers edition="Power4_smp" num="2.6.8.1.5"/><vers edition="Power4" num="2.6.8.1.5"/><vers edition="Power3_smp" num="2.6.8.1.5"/><vers edition="Power3" num="2.6.8.1.5"/><vers edition="K7_smp" num="2.6.8.1.5"/><vers edition="K7" num="2.6.8.1.5"/><vers edition="AMD64_Xeon" num="2.6.8.1.5"/><vers edition="AMD64_K8_smp" num="2.6.8.1.5"/><vers edition="AMD64_K8" num="2.6.8.1.5"/><vers edition="AMD64" num="2.6.8.1.5"/><vers edition="686_smp" num="2.6.8.1.5"/><vers edition="686" num="2.6.8.1.5"/><vers edition="386" num="2.6.8.1.5"/><vers num="2.6.8.1.5"/><vers num="2.6.8.1"/><vers num="2.6.8"/><vers num="2.6.7 rc3"/><vers num="2.6.7 rc2"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc3"/><vers num="2.6.6 rc2"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5 rc3"/><vers num="2.6.5 rc2"/><vers num="2.6.5 rc1"/><vers num="2.6.5"/><vers num="2.6.4 rc3"/><vers num="2.6.4 rc2"/><vers num="2.6.4 rc1"/><vers num="2.6.4"/><vers num="2.6.3 rc4"/><vers num="2.6.3 rc3"/><vers num="2.6.3 rc2"/><vers num="2.6.3 rc1"/><vers num="2.6.3"/><vers num="2.6.2 rc3"/><vers num="2.6.2 rc2"/><vers num="2.6.2 rc1"/><vers num="2.6.2"/><vers num="2.6.1 rc3"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-15" name="CVE-2006-1529" published="2006-04-14" seq="2006-1529" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML.  NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530, CVE-2006-1531, and CVE-2006-1723 are different.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product releases:
Mozilla, Firefox, 1.5.0.2
Mozilla, Thunderbird, 1.5.0.2
Mozilla, SeaMonkey, 1.0.1
</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Mozilla" url="http://www.mozilla.org/security/announce/2006/mfsa2006-20.html">Security Advisory 2006-20</ref><ref source="Bugzilla" url="https://bugzilla.mozilla.org/show_bug.cgi?id=315254"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/350262">VU#350262</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015919">1015919</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015921">1015921</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015920">1015920</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19649">19649</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded">HPSBUX02153</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1947">oval:org.mitre.oval:def:1947</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3748">ADV-2006-3748</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22066">22066</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5.0.1"/><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="Preview Release"/><vers num="1.5.0.1"/><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-15" name="CVE-2006-1530" published="2006-04-14" seq="2006-1530" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML.  NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530, CVE-2006-1531, and CVE-2006-1723 are different.</descript></desc><sols><sol source="nvd">This vulnerability is addresses in the following product releases: 
Mozilla, Firefox, 1.5.0.2
Mozilla, Thunderbird, 1.5.0.2
Mozilla, SeaMonkey, 1.0.1
</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Mozilla" url="http://www.mozilla.org/security/announce/2006/mfsa2006-20.html">Security Advisory 2006-20</ref><ref source="Bugzilla" url="https://bugzilla.mozilla.org/show_bug.cgi?id=326615"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/350262">VU#350262</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015919">1015919</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015921">1015921</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015920">1015920</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19649">19649</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded">HPSBUX02153</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1903">oval:org.mitre.oval:def:1903</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3748">ADV-2006-3748</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22066">22066</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5.0.1" prev="1"/><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12" prev="1"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0" prev="1"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.1" prev="1"/><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-15" name="CVE-2006-1531" published="2006-04-14" seq="2006-1531" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML.  NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530, CVE-2006-1531, and CVE-2006-1723 are different.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-20.html"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/350262">VU#350262</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015919">1015919</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015921">1015921</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015920">1015920</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19649">19649</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded">HPSBUX02153</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2023">oval:org.mitre.oval:def:2023</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3748">ADV-2006-3748</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22066">22066</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5.0.1" prev="1"/><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12" prev="1"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0" prev="1"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.1" prev="1"/><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-10" name="CVE-2006-1532" published="2006-03-30" seq="2006-1532" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in PHP Classifieds 6.18, 6.20, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchword parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1143">ADV-2006-1143</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19440">19440</ref><ref source="" url="http://osvdb.org/ref/24/24232-php_classifieds.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17305">17305</ref><ref source="OSVDB" url="http://www.osvdb.org/24232">24232</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25507">phpclassifieds-search-xss(25507)</ref></refs><vuln_soft><prod name="PHP Classifieds" vendor="DeltaScripts"><vers num="6.18"/><vers num="6.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-31" name="CVE-2006-1533" published="2006-03-30" seq="2006-1533" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in newsletter.php in Sourceworkshop newsletter 1.0 allows remote attackers to execute arbitrary SQL commands via the newsletteremail parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/107/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1148">ADV-2006-1148</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19425">19425</ref><ref source="BID" url="http://www.securityfocus.com/bid/17304">17304</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25498">newsletter-script-sql-injection(25498)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430375/100/0/threaded">20060407 [eVuln] newsletter - sourceworkshop SQL Injection Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/24229">24229</ref></refs><vuln_soft><prod name="newsletter" vendor="Sourceworkshop"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-28" modified="2006-03-31" name="CVE-2006-1534" published="2006-03-30" seq="2006-1534" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Null news allow remote attackers to execute arbitrary SQL commands via (1) the user_email parameter in (a) lostpass.php, and the (2) user_email and (3) user_username parameters in (b) sub.php and (c) unsub.php.</descript></desc><sols><sol source="nvd">Succesful exploitation of this vulnerability requires the &quot;magic_quotes_gpc&quot; parameter to be disabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Evuln" url="http://evuln.com/vulns/109/summary.html">EV0109</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1151">ADV-2006-1151</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19413">19413</ref><ref source="BID" url="http://www.securityfocus.com/bid/17300">17300</ref><ref source="OSVDB" url="http://www.osvdb.org/24240">24240</ref><ref source="OSVDB" url="http://www.osvdb.org/24241">24241</ref><ref source="OSVDB" url="http://www.osvdb.org/24242">24242</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25502">nullnews-multiple-sql-injection(25502)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430298/100/0/threaded">20060408 [eVuln] Null news SQL Injection Vulnerability</ref><ref source="SREASON" url="http://securityreason.com/securityalert/682">682</ref></refs><vuln_soft><prod name="Null News" vendor="Null News"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-31" name="CVE-2006-1535" published="2006-03-30" seq="2006-1535" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in Phoetux.net PhxContacts 0.93.1 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the m parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429259/100/0/threaded">20060328 PhxContacts &lt;= 0.93.1 beta Multiple SQL injection &amp; xss</ref><ref source="BID" url="http://www.securityfocus.com/bid/17307">17307</ref></refs><vuln_soft><prod name="PhxContacts" vendor="phoetux.net"><vers num="0.93.1"/><vers num="0.93"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-28" modified="2006-03-31" name="CVE-2006-1536" published="2006-03-30" seq="2006-1536" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Phoetux.net PhxContacts 0.93.1 beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) motclef and (2) nbr_line_view parameters in (a) carnet.php, and the (3) id_contact parameter in (b) contact_view.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429259/100/0/threaded">20060328 PhxContacts &lt;= 0.93.1 beta Multiple SQL injection &amp; xss</ref><ref source="BID" url="http://www.securityfocus.com/bid/17306">17306</ref></refs><vuln_soft><prod name="PhxContacts" vendor="phoetux.net"><vers num="0.93.1"/><vers num="0.93"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-29" modified="2006-03-31" name="CVE-2006-1537" published="2006-03-30" seq="2006-1537" severity="Medium" type="CVE"><desc><descript source="cve">Craig Knudsen WebCalendar 1.1.0-CVS allows remote attackers to obtain sensitive information via a direct request to (1) includes/index.php, (2) tests/add_duration_test.php, (3) tests/all_tests.php, (4) groups.php, (5) nonusers.php, (6) includes/settings.php, (7) includes/init.php, (8) includes/settings.php.orig, (9) includes/js/admin.php, (10) includes/js/edit_entry.php, (11) includes/js/edit_layer.php, (12) includes/js/export_import.php, (13) includes/js/popups.php, (14) includes/js/pref.php, or (15) includes/menu/index.php, which reveal the path in various error messages.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429267/100/0/threaded">20060329 Full path disclosure in Webcalendar 1.1.0-CVS</ref><ref source="OSVDB" url="http://www.osvdb.org/24522">24522</ref><ref source="OSVDB" url="http://www.osvdb.org/24523">24523</ref><ref source="OSVDB" url="http://www.osvdb.org/24524">24524</ref><ref source="OSVDB" url="http://www.osvdb.org/24525">24525</ref><ref source="OSVDB" url="http://www.osvdb.org/24526">24526</ref><ref source="OSVDB" url="http://www.osvdb.org/24527">24527</ref><ref source="OSVDB" url="http://www.osvdb.org/24528">24528</ref><ref source="OSVDB" url="http://www.osvdb.org/24529">24529</ref><ref source="OSVDB" url="http://www.osvdb.org/24530">24530</ref><ref source="OSVDB" url="http://www.osvdb.org/24531">24531</ref><ref source="OSVDB" url="http://www.osvdb.org/24532">24532</ref><ref source="OSVDB" url="http://www.osvdb.org/24533">24533</ref><ref source="OSVDB" url="http://www.osvdb.org/24534">24534</ref><ref source="OSVDB" url="http://www.osvdb.org/24535">24535</ref><ref source="OSVDB" url="http://www.osvdb.org/24536">24536</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25539">
webcalendar-multiple-path-disclosure(25539)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/651">651</ref></refs><vuln_soft><prod name="WebCalendar" vendor="WebCalendar"><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-29" modified="2006-03-31" name="CVE-2006-1538" published="2006-03-30" seq="2006-1538" severity="Medium" type="CVE"><desc><descript source="cve">The Enova X-Wall ASIC encrypts with a key obtained via Microwire from a serial EEPROM that stores the key in cleartext, which allows local users with physical access to obtain the key by reading and duplicating an EEPROM that is located on a hardware token, or by sniffing the Microwire bus.</descript></desc><sols><sol source="nvd">Physical access to the device or hardware token is required to perform
the attack.</sol></sols><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429253/100/0/threaded">20060329 [HV-INFO] Enova hardware encryption: false sense of security</ref><ref source="Hexview" url="http://www.hexview.com/docs/20060328-1.txt">Enova hardware encryption: False sense of security</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25527">enova-xwall-insecure-encryption-key(25527)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/648">648</ref></refs><vuln_soft><prod name="X-Wall ASIC" vendor="Enova"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-02-10" modified="2006-03-31" name="CVE-2006-1539" published="2006-03-30" seq="2006-1539" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the checkscores function in scores.c in tetris-bsd in bsd-games before 2.17-r1 in Gentoo Linux might allow local users with games group membership to gain privileges by modifying tetris-bsd.scores to contain crafted executable content, which is executed when another user launches tetris-bsd.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-26.xml">GLSA-200603-26</ref><ref patch="1" source="Gentoo" url="http://bugs.gentoo.org/show_bug.cgi?id=122399">Bug#:  122399 </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17308">17308</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19442">19442</ref><ref source="OSVDB" url="http://www.osvdb.org/24261">24261</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25611">bsdgames-tetrisbsd-checkscores-bo(25611)</ref></refs><vuln_soft><prod name="tetris-bsd" vendor="bsd-games"><vers edition="Linux" num="Gold"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-27" modified="2006-08-28" name="CVE-2006-1540" published="2006-03-30" seq="2006-1540" severity="Low" type="CVE"><desc><descript source="cve">MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain &quot;01 00 00 00&quot; byte sequence with an &quot;FF FF FF FF&quot; byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll; (2) an Excel .xlw document, which triggers an access violation in excel.exe; (3) a Word document, which triggers an access violation in mso.dll in winword.exe; and (4) a PowerPoint document, which triggers an access violation in powerpnt.txt.  NOTE: after the initial disclosure, this issue was demonstrated by triggering an integer overflow using an inconsistent size for a Unicode &quot;Sheet Name&quot; string.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17252">17252</ref><ref source="" url="http://www.milw0rm.com/exploits/1615"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015855">1015855</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-038.mspx">MS06-038</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2756">ADV-2006-2756</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21012">21012</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27609">office-property-string-bo(27609)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27607">office-string-parse-bo(27607)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/439697/100/0/threaded">20060710 SYMSA-2006-007: Microsoft Office Malformed String Parsing Vulnerability</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-192A.html">TA06-192A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/609868">VU#609868</ref><ref source="BID" url="http://www.securityfocus.com/bid/18889">18889</ref><ref source="OSVDB" url="http://www.osvdb.org/27150">27150</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:639">oval:org.mitre.oval:def:639</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="XP SP3"/><vers num="XP SP1"/><vers num="XP SP2"/><vers num=""/><vers edition="Mac" num="v. X"/><vers edition="Mac" num="2004"/><vers num="2003 SP2"/><vers num="2003 SP1"/><vers edition="Student_Teacher" num="2003"/><vers edition="Korean" num="2000"/><vers edition="Japanese" num="2000"/><vers edition="Chinese" num="2000"/><vers num="2000 SP3"/><vers num="2000 SP1"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-29" modified="2006-03-31" name="CVE-2006-1541" published="2006-03-30" seq="2006-1541" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Default.asp in EzASPSite 2.0 RC3 and earlier allows remote attackers to execute arbitrary SQL commands and obtain the SHA1 hash of the admin password via the Scheme parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://milw0rm.com/exploits/1623">exploit 1623</ref><ref source="NukedX" url="http://www.nukedx.com/?viewdoc=22">Advisory: EzASPSite &lt;= 2.0 RC3 Remote SQL Injection Exploit Vulnerability.</ref><ref source="BID" url="http://www.securityfocus.com/bid/17309">17309</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1164">ADV-2006-1164</ref><ref source="OSVDB" url="http://www.osvdb.org/24256">24256</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19441">19441</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25544">ezaspsite-default-sql-injection(25544)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429487/100/0/threaded">20060329 EzASPSite &lt;= 2.0 RC3 Remote SQL Injection Exploit Vulnerability.</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114367573519326&amp;w=2">20060329 EzASPSite &lt;= 2.0 RC3 Remote SQL Injection Exploit Vulnerability.</ref></refs><vuln_soft><prod name="EzASPSite" vendor="EzASPSite"><vers num="2.0 RC3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-18" modified="2006-03-31" name="CVE-2006-1542" published="2006-03-30" seq="2006-1542" severity="Low" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allows local users to cause a &quot;stack overflow,&quot; and possibly gain privileges, by running a script from a current working directory that has a long name, related to the realpath function.  NOTE: this might not be a vulnerability. However, the fact that it appears in a programming language interpreter could mean that some applications are affected, although attack scenarios might be limited because the attacker might already need to cross privilege boundaries to cause an exploitable program to be placed in a directory with a long name; or, depending on the method that Python uses to determine the current working directory, setuid applications might be affected.</descript></desc><sols><sol source="nvd">Successful exploitation requires that the Python is running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="Milw0rm" url="http://milw0rm.com/exploits/1591">exploit 1591</ref><ref source="Gotfault" url="http://www.gotfault.net/research/exploit/gexp-python.py">Python &lt;= 2.4.2 realpath() Local Stack Overflow</ref></refs><vuln_soft><prod name="Python" vendor="Python Software Foundation"><vers num="2.4.2" prev="1"/><vers num="2.4"/><vers num="2.3.4"/><vers num="2.3.3"/><vers num="2.3.2"/><vers num="2.3.1"/><vers num="2.3"/><vers num="2.2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-31" name="CVE-2006-1543" published="2006-03-30" seq="2006-1543" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) loginvar parameter in (a) admin/admin.php, and the (2) news and (3) nom parameters in (b) news.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.evuln.com/vulns/112"></ref><ref source="OSVDB" url="http://www.osvdb.org/24273">24273</ref><ref source="OSVDB" url="http://www.osvdb.org/24274">24274</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25529">vnews-adminnews-sql-injection(25529)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17316">17316</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1173">ADV-2006-1173</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19435">19435</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430674/100/0/threaded">20060411 [eVuln] VNews Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="VNews" vendor="vscripts"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-31" name="CVE-2006-1544" published="2006-03-30" seq="2006-1544" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in news.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) autorkomentarza and (2) tresckomentarza parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.evuln.com/vulns/112"></ref><ref source="OSVDB" url="http://www.osvdb.org/24275">24275</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25530">vnews-news-xss(25530)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17317">17317</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1173">ADV-2006-1173</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19435">19435</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430674/100/0/threaded">20060411 [eVuln] VNews Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="VNews" vendor="vscripts"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-31" name="CVE-2006-1545" published="2006-03-30" seq="2006-1545" severity="High" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in admin/config.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allows remote authenticated administrators to execute code by inserting the code into variables that are stored in admin/config.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.evuln.com/vulns/112"></ref><ref source="OSVDB" url="http://www.osvdb.org/24276">24276</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25531">vnews-config-file-include(25531)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1173">ADV-2006-1173</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19435">19435</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430674/100/0/threaded">20060411 [eVuln] VNews Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="VNews" vendor="vscripts"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-31" name="CVE-2006-1546" published="2006-03-30" seq="2006-1546" severity="High" type="CVE"><desc><descript source="cve">Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a &apos;org.apache.struts.taglib.html.Constants.CANCEL&apos; parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://mail-archives.apache.org/mod_mbox/struts-user/200601.mbox/%3c20060121221800.15814.qmail@web32607.mail.mud.yahoo.com%3e">[struts-user] 20060121 Validation Security Hole?</ref><ref source="MLIST" url="http://mail-archives.apache.org/mod_mbox/struts-dev/200601.mbox/%3cdr169r$623$2@sea.gmane.org%3e">[struts-devel] 20060122 Re: Validation Security Hole?</ref><ref source="" url="http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html"></ref><ref source="" url="http://issues.apache.org/bugzilla/show_bug.cgi?id=38374"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17342">17342</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1205">ADV-2006-1205</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015856">1015856</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19493">19493</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html">SUSE-SR:2006:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20117">20117</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25612">
struts-iscancelled-security-bypass(25612)</ref></refs><vuln_soft><prod name="Struts" vendor="Apache Software Foundation"><vers num="1.2.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-02-06" modified="2006-03-31" name="CVE-2006-1547" published="2006-03-30" seq="2006-1547" severity="High" type="CVE"><desc><descript source="cve">ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APACHE" url="http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html">Bug 38534</ref><ref source="APACHE" url="http://issues.apache.org/bugzilla/show_bug.cgi?id=38534">Bug 38534 </ref><ref source="BID" url="http://www.securityfocus.com/bid/17342">17342</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1205">ADV-2006-1205</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015856">1015856</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19493">19493</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html">SUSE-SR:2006:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20117">20117</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25613">
struts-actionform-dos(25613)</ref></refs><vuln_soft><prod name="Struts" vendor="Apache Software Foundation"><vers num="1.2.8" prev="1"/><vers num="1.2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-31" name="CVE-2006-1548" published="2006-03-30" seq="2006-1548" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://struts.apache.org/struts-doc-1.2.9/userGuide/release-notes.html"></ref><ref source="" url="http://issues.apache.org/bugzilla/show_bug.cgi?id=38749"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17342">17342</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1205">ADV-2006-1205</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015856">1015856</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19493">19493</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html">SUSE-SR:2006:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20117">20117</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25614">
struts-lookupmap-xss(25614)</ref></refs><vuln_soft><prod name="Struts" vendor="Apache Software Foundation"><vers num="1.2.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-05-14" name="CVE-2006-1549" published="2006-04-10" seq="2006-1549" severity="Medium" type="CVE"><desc><descript source="cve">PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function.  NOTE: it has been reported by a reliable third party that some later versions are also affected.</descript></desc><sols><sol source="nvd">Upgrade to PHP 5.1.3-RC3</sol></sols><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430453/100/0/threaded">20060409 function *() php/apache Crash PHP 4.4.2 and 5.1.2</ref><ref source="" url="http://securityreason.com/achievement_securityalert/35"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1290">ADV-2006-1290</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015880">1015880</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430598/100/0/threaded">20060410 Re: function *() php/apache Crash PHP 4.4.2 and 5.1.2</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430742/100/0/threaded">20060412 Re: function *() php/apache Crash PHP 4.4.2 and 5.1.2</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431018/100/0/threaded">20060414 Re: Re: function *() php/apache Crash PHP 4.4.2 and 5.1.2</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/044982.html">20060408 function *() php/apache Crash PHP 4.4.2 and 5.1.2</ref><ref source="" url="http://www.php-security.org/MOPB/MOPB-02-2007.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25704">php-function-dos(25704)</ref><ref source="OSVDB" url="http://www.osvdb.org/24485">24485</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2312">2312</ref><ref source="SREASON" url="http://securityreason.com/securityalert/676">676</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.4.0.2" prev="1"/><vers num="5.1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-1550" published="2006-03-30" seq="2006-1550" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the xfig import code (xfig-import.c) in Dia 0.87 and later before 0.95-pre6 allow user-assisted attackers to have an unknown impact via a crafted xfig file, possibly involving an invalid (1) color index, (2) number of points, or (3) depth.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429357/100/0/threaded">20060329 Buffer overflows in Dia XFig import</ref><ref source="MLIST" url="http://mail.gnome.org/archives/dia-list/2006-March/msg00149.html">[dia-list] 20060329 Vulnerability in xfig import code</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17310">17310</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015853">1015853</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19469">19469</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:062">MDKSA-2006:062</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19505">19505</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1025">DSA-1025</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00021.html">FEDORA-2006-261</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-266-1">USN-266-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19507">19507</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19543">19543</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19546">19546</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-14.xml">GLSA-200604-14</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19765">19765</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_28.html">SUSE-SR:2006:009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19897">19897</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0280.html">RHSA-2006:0280</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19959">19959</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25566">
diaxfig-xfig-import-bo(25566)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:062">MDKSA-2006:062</ref></refs><vuln_soft><prod name="DIA" vendor="DIA"><vers num="0.92.2"/><vers num="0.88.1"/><vers num="0.94"/><vers num="0.93"/><vers num="0.91"/><vers num="0.87"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-30" modified="2006-04-14" name="CVE-2006-1551" published="2006-04-13" seq="2006-1551" severity="High" type="CVE"><desc><descript source="cve">Eval injection vulnerability in pajax_call_dispatcher.php in PAJAX 0.5.1 and earlier allows remote attackers to execute arbitrary code via the (1) $method and (2) $args parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.redteam-pentesting.de/advisories/rt-sa-2006-001.php"></ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0270.html">20060413 PAJAX Remote Code Injection and File Inclusion Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17519">17519</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1353">ADV-2006-1353</ref><ref source="OSVDB" url="http://www.osvdb.org/24618">24618</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19653">19653</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431029/100/0/threaded">

20060413 PAJAX Remote Code Injection and File Inclusion Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25859">
pajax-pajaxcalldispatcher-code-execution(25859)</ref></refs><vuln_soft><prod name="PAJAX" vendor="Georges Auberger"><vers num="0.5.1"/><vers num="0.5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-16" name="CVE-2006-1552" published="2006-03-31" seq="2006-1552" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated using Safari, aka &quot;Deja-Doom&quot;.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://drunkenblog.com/drunkenblog-archives/000760.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17321">17321</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26412">macos-imageio-jpeg-bo(26412)</ref><ref source="OSVDB" url="http://www.osvdb.org/25597">25597</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod><prod name="Safari" vendor="Apple"><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/><vers num="1.3"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/><vers num="Beta2"/></prod><prod name="Safari RSS" vendor="Apple"><vers num="2.0 pre"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1553" published="2006-03-31" seq="2006-1553" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in functions/final_functions.php in VSNS Lemon 3.2.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Evuln" url="http://evuln.com/vulns/106/description.html">EV0106</ref><ref source="BID" url="http://www.securityfocus.com/bid/17281">17281</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19420">19420</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015836">1015836</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430345/100/0/threaded">20060406 [eVuln] VSNS Lemon Multiple Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/24211">24211</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25456">vsns-lemon-finalfunctions-sql-injection(25456)</ref></refs><vuln_soft><prod name="VSNS Lemon" vendor="Tachyon"><vers num="3.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-27" modified="2006-03-31" name="CVE-2006-1554" published="2006-03-31" seq="2006-1554" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in VSNS Lemon 3.2.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter while adding a comment.</descript></desc><sols><sol source="nvd">Successful exploitation requires that the &quot;magic_quotes_gpc&quot; parameter is disabled.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Evuln" url="http://evuln.com/vulns/106/description.html">EV0106</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19420">19420</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015836">1015836</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430345/100/0/threaded">20060406 [eVuln] VSNS Lemon Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17395">17395</ref><ref source="OSVDB" url="http://www.osvdb.org/24212">24212</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25457">vsns-lemon-name-xss(25457)</ref></refs><vuln_soft><prod name="VSNS Lemon" vendor="Tachyon"><vers num="3.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-27" modified="2006-04-25" name="CVE-2006-1555" published="2006-03-31" seq="2006-1555" severity="High" type="CVE"><desc><descript source="cve">VSNS Lemon 3.2.0 allows remote attackers to bypass authentication and access password-protected articles by setting the vsns[topic_id] cookie to the targeted topic.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="Evuln" url="http://evuln.com/vulns/106/description.html">EV0106</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19420">19420</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015836">1015836</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430345/100/0/threaded">20060406 [eVuln] VSNS Lemon Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17396">17396</ref><ref source="OSVDB" url="http://www.osvdb.org/24213">24213</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25459">vsns-lemon-cookie-auth-bypass(25459)</ref></refs><vuln_soft><prod name="VSNS Lemon" vendor="Tachyon"><vers num="3.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-28" modified="2006-03-31" name="CVE-2006-1556" published="2006-03-31" seq="2006-1556" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in view_caricatier.php in AL-Caricatier 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) CatName, (2) CaricatierID, or (3) CatID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429095/100/0/threaded">20060328 XSS in AL-Caricatier</ref><ref source="BID" url="http://www.securityfocus.com/bid/17289">17289</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17292">17292</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25493">
alcaricatier-viewcaricatier-xss(25493)</ref></refs><vuln_soft><prod name="AL-Caricatier" vendor="AL-Caricatier"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-30" modified="2006-03-31" name="CVE-2006-1557" published="2006-03-31" seq="2006-1557" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in X-Changer 0.2 allow remote attackers to execute arbitrary SQL commands via the (1) from and (2) into parameters in a calculate action, and the (3) id parameter in an edit action to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429359/100/0/threaded">20060330 X-Changer &lt;=v0.2 Demo SQL injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/17322">17322</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1188">ADV-2006-1188</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19459">19459</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25549">xchanger-index-sql-injection(25549)</ref><ref source="OSVDB" url="http://www.osvdb.org/24288">24288</ref><ref source="SREASON" url="http://securityreason.com/securityalert/654">654</ref></refs><vuln_soft><prod name="X-Changer" vendor="SkinTech"><vers num="0.20"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-28" modified="2006-03-31" name="CVE-2006-1558" published="2006-03-31" seq="2006-1558" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in PHP Script Index allows remote attackers to inject arbitrary web script or HTML via the search parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://osvdb.org/ref/24/24243-script_index.txt">[OSVDB Mods] PHP Script Index - Cross Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/17297">17297</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1158">ADV-2006-1158</ref><ref source="OSVDB" url="http://www.osvdb.org/24243">24243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19443">19443</ref></refs><vuln_soft><prod name="PHP Script Index" vendor="PHP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-31" name="CVE-2006-1559" published="2006-03-31" seq="2006-1559" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in PHP Script Index allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1158">ADV-2006-1158</ref></refs><vuln_soft><prod name="PHP Script Index" vendor="PHP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-29" modified="2006-03-31" name="CVE-2006-1560" published="2006-03-31" seq="2006-1560" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in SkinTech phpNewsManager 1.48 allow remote attackers to execute arbitrary SQL commands via unspecified parameters, possibly (1) id and (2) topicid, in (a) browse.php, (b) category.php, (c) gallery.php, (d) poll.php, and (e) possibly other unspecified scripts.  NOTE: portions of the description details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Evuln" url="http://evuln.com/vulns/110">EV0110</ref><ref source="BID" url="http://www.securityfocus.com/bid/17301">17301</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1152">ADV-2006-1152</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25512">phpnewsmanager-multiple-sql-injection(25512)</ref><ref source="OSVDB" url="http://www.osvdb.org/24265">24265</ref><ref source="OSVDB" url="http://www.osvdb.org/24266">24266</ref><ref source="OSVDB" url="http://www.osvdb.org/24267">24267</ref><ref source="OSVDB" url="http://www.osvdb.org/24268">24268</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19391">19391</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430311/100/0/threaded">20060408 [eVuln] phpNewsManager Multiple SQL Injections</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430478/100/0/threaded">20060410 [eVuln] phpNewsManager Multiple SQL Injections</ref><ref source="SREASON" url="http://securityreason.com/securityalert/680">680</ref></refs><vuln_soft><prod name="phpNewsManager" vendor="SkinTech"><vers num="1.48"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-29" modified="2006-03-31" name="CVE-2006-1561" published="2006-03-31" seq="2006-1561" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allows remote attackers to execute arbitrary SQL commands via the x parameter.</descript></desc><sols><sol source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is set to off.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Evuln" url="http://evuln.com/vulns/111">EV0111</ref><ref source="BID" url="http://www.securityfocus.com/bid/17320">17320</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1174">ADV-2006-1174</ref><ref source="OSVDB" url="http://www.osvdb.org/24270">24270</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19448">19448</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25519">vbook-index-sql-injection(25519)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430624/100/0/threaded">20060411 [eVuln] [V]Book Multiple Vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/696">696</ref></refs><vuln_soft><prod name="VBook" vendor="vscripts"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-29" modified="2006-03-31" name="CVE-2006-1562" published="2006-03-31" seq="2006-1562" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) autor, (2) www, (3) temat, and (4) tresc parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Evuln" url="http://evuln.com/vulns/111">EV0111</ref><ref source="BID" url="http://www.securityfocus.com/bid/17319">17319</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1174">ADV-2006-1174</ref><ref source="OSVDB" url="http://www.osvdb.org/24271">24271</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19448">19448</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25521">vbook-index-xss(25521)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430624/100/0/threaded">20060411 [eVuln] [V]Book Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="VBook" vendor="vscripts"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-29" modified="2006-03-31" name="CVE-2006-1563" published="2006-03-31" seq="2006-1563" severity="High" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in config.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allows remote administrators to execute arbitrary PHP code into the config file, which is included other [V]Book scripts.</descript></desc><sols><sol source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is set to off.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Evuln" url="http://evuln.com/vulns/111">EV0111</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1174">ADV-2006-1174</ref><ref source="OSVDB" url="http://www.osvdb.org/24272">24272</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19448">19448</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25522">vbook-config-file-include(25522)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430624/100/0/threaded">20060411 [eVuln] [V]Book Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="VBook" vendor="vscripts"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-27" modified="2006-03-31" name="CVE-2006-1564" published="2006-03-31" seq="2006-1564" severity="Medium" type="CVE"><desc><descript source="cve">Untrusted search path vulnerability in libapache2-svn 1.3.0-4 for Subversion in Debian GNU/Linux includes RPATH values under the /tmp/svn directory for the (1) mod_authz_svn.so and (2) mod_dav_svn.so modules, which might allow local users to gain privileges by installing malicious libraries in that directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="Debian" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359234">Debian Bug report logs - #359234</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17288">17288</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25680">
libapache2-svn-file-upload(25680)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="3.1 sparc"/><vers num="3.1 s_390"/><vers num="3.1 ppc"/><vers num="3.1 mipsel"/><vers num="3.1 mips"/><vers num="3.1 m68k"/><vers num="3.1 ia-64"/><vers num="3.1 ia-32"/><vers num="3.1 hppa"/><vers num="3.1 arm"/><vers num="3.1 amd64"/><vers num="3.1 alpha"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-27" modified="2006-04-03" name="CVE-2006-1565" published="2006-03-31" seq="2006-1565" severity="Medium" type="CVE"><desc><descript source="cve">Untrusted search path vulnerability in libgpib-perl 3.2.06-2 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the LinuxGpib.so module, which might allow local users to gain privileges by installing malicious libraries in that directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="Debian" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359239">#359239</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17288">17288</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25681">
libgpib-perl-buildd-file-upload(25681)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="3.1 sparc"/><vers num="3.1 s_390"/><vers num="3.1 ppc"/><vers num="3.1 mipsel"/><vers num="3.1 mips"/><vers num="3.1 m68k"/><vers num="3.1 ia-64"/><vers num="3.1 ia-32"/><vers num="3.1 hppa"/><vers num="3.1 arm"/><vers num="3.1 amd64"/><vers num="3.1 alpha"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-27" modified="2006-04-03" name="CVE-2006-1566" published="2006-03-31" seq="2006-1566" severity="Medium" type="CVE"><desc><descript source="cve">Untrusted search path vulnerability in libtunepimp-perl 0.4.2-1 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the tunepimp.so module, which might allow local users to gain privileges by installing malicious libraries in that directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="Debian" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359241">#359241</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17288">17288</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25682">
libtunepimp-perl-buildd-file-upload(25682)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="3.1 sparc"/><vers num="3.1 s_390"/><vers num="3.1 ppc"/><vers num="3.1 mipsel"/><vers num="3.1 mips"/><vers num="3.1 m68k"/><vers num="3.1 ia-64"/><vers num="3.1 ia-32"/><vers num="3.1 hppa"/><vers num="3.1 arm"/><vers num="3.1 amd64"/><vers num="3.1 alpha"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-31" modified="2006-04-03" name="CVE-2006-1567" published="2006-03-31" seq="2006-1567" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in searchresults.asp in SiteSearch Indexer 3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchField parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Blogspot" url="http://pridels.blogspot.com/2006/03/sitesearch-indexer-35-xss-vuln.html">SiteSearch Indexer 3.5 XSS vuln. </ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1185">ADV-2006-1185</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19467">19467</ref><ref source="BID" url="http://www.securityfocus.com/bid/17332">17332</ref><ref source="OSVDB" url="http://www.osvdb.org/24289">24289</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25564">sitesearch-indexer-searchfield-xss(25564)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/sitesearch-indexer-35-xss-vuln.html"></ref></refs><vuln_soft><prod name="Indexer" vendor="SiteSearch"><vers num="3.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-30" modified="2006-04-03" name="CVE-2006-1568" published="2006-03-31" seq="2006-1568" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in register.php in RedCMS 0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) email, (2) location, or (3) website parameters.</descript></desc><sols><sol source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is disabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Evuln" url="http://evuln.com/vulns/115/summary.html">EV0115</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1186">ADV-2006-1186</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19475">19475</ref><ref source="BID" url="http://www.securityfocus.com/bid/17336">17336</ref><ref source="OSVDB" url="http://www.osvdb.org/24296">24296</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25577">redcms-register-xss(25577)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431001/100/0/threaded">20060413 [eVuln] RedCMS Multiple XSS and SQL Injection Vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/708">708</ref></refs><vuln_soft><prod name="RedCMS" vendor="RedCMS"><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-30" modified="2006-04-03" name="CVE-2006-1569" published="2006-03-31" seq="2006-1569" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in RedCMS 0.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters to (a) login.php or (b) register.php; or (3) u parameter to (c) profile.php.</descript></desc><sols><sol source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is disabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Evuln" url="http://evuln.com/vulns/115/summary.html">EV0115</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1186">ADV-2006-1186</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19475">19475</ref><ref source="BID" url="http://www.securityfocus.com/bid/17336">17336</ref><ref source="OSVDB" url="http://www.osvdb.org/24297">24297</ref><ref source="OSVDB" url="http://www.osvdb.org/24298">24298</ref><ref source="OSVDB" url="http://www.osvdb.org/24299">24299</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25578">redcms-multiple-sql-injection(25578)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431001/100/0/threaded">20060413 [eVuln] RedCMS Multiple XSS and SQL Injection Vulnerabilities</ref></refs><vuln_soft><prod name="RedCMS" vendor="RedCMS"><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-03" name="CVE-2006-1570" published="2006-03-31" seq="2006-1570" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Esqlanelapse 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Sourceforge" url="http://sourceforge.net/project/shownotes.php?release_id=406021">Release Name: Esqlanelapse 2.5</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1183">ADV-2006-1183</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19474">19474</ref><ref source="BID" url="http://www.securityfocus.com/bid/17331">17331</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25568">esqlanelapse-xss(25568)</ref><ref source="OSVDB" url="http://www.osvdb.org/24300">24300</ref></refs><vuln_soft><prod name="Esqlanelapse" vendor="Esqlanelapse"><vers num="2.0"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-30" modified="2006-04-03" name="CVE-2006-1571" published="2006-03-31" seq="2006-1571" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in loginprocess.php in qliteNews 2005.07.01 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.</descript></desc><sols><sol source="nvd">Successful exploitation requires &quot;magic_quotes_gpc&quot; to be disabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Evuln" url="http://evuln.com/vulns/114/summary.html">EV0114</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1182">ADV-2006-1182</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19476">19476</ref><ref source="BID" url="http://www.securityfocus.com/bid/17333">17333</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25565">qlitenews-loginprocess-sql-injection(25565)</ref><ref source="OSVDB" url="http://www.osvdb.org/24301">24301</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430873/100/0/threaded">20060413 [eVuln] qliteNews SQL Injection Vulnerability</ref><ref source="SREASON" url="http://securityreason.com/securityalert/701">701</ref></refs><vuln_soft><prod name="qliteNews" vendor="r2xDesign"><vers num="2005-07-01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-30" modified="2006-04-03" name="CVE-2006-1572" published="2006-03-31" seq="2006-1572" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in post.php in Oxygen 1.1.3 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a newthread action.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429474/100/0/threaded">20060330 Oxygen&lt;=1.x.x SQL injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/17324">17324</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1181">ADV-2006-1181</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19481">19481</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25570">oxygen-post-sql-injection(25570)</ref><ref source="OSVDB" url="http://www.osvdb.org/24287">24287</ref><ref source="SREASON" url="http://securityreason.com/securityalert/658">658</ref></refs><vuln_soft><prod name="Oxygen" vendor="o2php.com"><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.0.11"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-30" modified="2006-04-03" name="CVE-2006-1573" published="2006-03-31" seq="2006-1573" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in MediaSlash Gallery allows remote attackers to execute arbitrary PHP code via a URL in the rub parameter (part of the $page_menu variable).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429395/100/0/threaded">20060330 MediaSlash Gallery &apos;rub&apos; variable Remote File inlcusion Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17323">17323</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25583">mediaslash-index-file-include(25583)</ref><ref source="OSVDB" url="http://www.osvdb.org/24313">24313</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/434419/100/0/threaded">20060516 Re: MediaSlash Gallery &apos;rub&apos; variable Remote File inlcusion Vulnerability</ref><ref source="SREASON" url="http://securityreason.com/securityalert/657">657</ref></refs><vuln_soft><prod name="MediaSlash Gallery" vendor="mediaslash.com"><vers num="0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-31" modified="2006-04-03" name="CVE-2006-1574" published="2006-03-31" seq="2006-1574" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web, World Wide Web Desktop, World Wide Web for Scheduler, and Desktop for Scheduler, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript></desc><sols><sol source="nvd">Apply patch :
http://www.hitachi-support.com/security_e/vuls_e/HS06-005_e/index-e.html</sol></sols><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS06-005_e/index-e.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1180">ADV-2006-1180</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19483">19483</ref><ref source="BID" url="http://www.securityfocus.com/bid/17337">17337</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25574">groupmax-www-xss(25574)</ref><ref source="OSVDB" url="http://www.osvdb.org/24295">24295</ref></refs><vuln_soft><prod name="Groupmax World Wide Web" vendor="Hitachi"><vers num="2"/><vers num="3"/></prod><prod name="Groupmax World Wide Web Scheduler" vendor="Hitachi"><vers num="2"/><vers num="3"/></prod><prod name="Groupmax World Wide Web Desktop" vendor="Hitachi"><vers num="5"/><vers num="6"/><vers num=""/></prod><prod name="Groupmax World Wide Web Desktop Scheduler" vendor="Hitachi"><vers num="5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-31" modified="2006-04-03" name="CVE-2006-1575" published="2006-04-02" seq="2006-1575" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in news.php in QLnews 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) autorx and (2) newsx parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/113/description.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17335">17335</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19479">19479</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25546">qlnews-news-xss(25546)</ref><ref source="OSVDB" url="http://www.osvdb.org/24290">24290</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430741/100/0/threaded">20060412 [eVuln] QLnews XSS and PHP Code Insertion Vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/699">699</ref></refs><vuln_soft><prod name="QLnews" vendor="vscripts.pl"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-31" modified="2006-04-03" name="CVE-2006-1576" published="2006-04-02" seq="2006-1576" severity="High" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in QLnews 1.2 allows remote authenticated administrators to execute arbitrary PHP code by modifying config.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/113/description.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17335">17335</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19479">19479</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25548">qlnews-config-file-include(25548)</ref><ref source="OSVDB" url="http://www.osvdb.org/24291">24291</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430741/100/0/threaded">20060412 [eVuln] QLnews XSS and PHP Code Insertion Vulnerabilities</ref></refs><vuln_soft><prod name="QLnews" vendor="vscripts.pl"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-31" modified="2006-04-03" name="CVE-2006-1577" published="2006-04-02" seq="2006-1577" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) start_day, (2) start_year, and (3) start_month parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/03/mantis-xss-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17326">17326</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1184">ADV-2006-1184</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19471">19471</ref><ref source="OSVDB" url="http://www.osvdb.org/24292">24292</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25579">mantis-viewallset-script-xss(25579)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1133">DSA-1133</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21400">21400</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/mantis-xss-vuln.html"></ref></refs><vuln_soft><prod name="Mantis" vendor="Mantis"><vers num="1.0.1"/><vers num="1.0.0 rc4"/><vers num="1.0.0 rc3"/><vers num="1.0.0 rc2"/><vers num="1.0.0 rc1"/><vers num="1.0.0a3"/><vers num="1.0.0a2"/><vers num="1.0.0a1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-31" modified="2006-04-03" name="CVE-2006-1578" published="2006-04-02" seq="2006-1578" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Keystone Digital Library Suite (DLS) 1.5.4 and earlier allow remote attackers to execute arbitrary SQL commands via the subject_type_id parameter in (1) the index page and (2) the search module.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/03/keystone-dls-sql-vuln.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25571">keystonedls-subjecttypeid-sql-injection(25571)</ref><ref source="" url="http://pridels0.blogspot.com/2006/03/keystone-dls-sql-vuln.html"></ref></refs><vuln_soft><prod name="Keystone Digital Library Suite" vendor="Index Data ApS"><vers num="1.5.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-03-31" modified="2007-05-22" name="CVE-2006-1579" published="2006-04-02" seq="2006-1579" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in topics.php in Dynamic Bulletin Board System (DbbS) 2.0-alpha and earlier allows remote attackers to execute arbitrary SQL commands via the limite parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429512/100/0/threaded">20060331 DbbS&lt;=2.0-alpha SQL injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/17338">17338</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25584">dbbs-topics-sql-injection(25584)</ref></refs><vuln_soft><prod name="DbbS" vendor="DbbS"><vers num="2.0-alpha" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-01" modified="2006-04-03" name="CVE-2006-1580" published="2006-04-02" seq="2006-1580" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Bugzero 4.3.1 and other versions allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in query.jsp and (2) entryId parameter in edit.jsp.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/bugzero-xss-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17351">17351</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1195">ADV-2006-1195</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19492">19492</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25601">bugzero-query-edit-xss(25601)</ref><ref source="OSVDB" url="http://www.osvdb.org/24328">
24328</ref><ref source="OSVDB" url="http://www.osvdb.org/24329">
24329</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/bugzero-xss-vuln.html"></ref></refs><vuln_soft><prod name="Bugzero" vendor="WEBsina"><vers num="4.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-31" modified="2006-04-03" name="CVE-2006-1581" published="2006-04-02" seq="2006-1581" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in Blank&apos;N&apos;Berg 0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the _path parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.silitix.com/bnb.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17345">17345</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015854">1015854</ref><ref source="OSVDB" url="http://www.osvdb.org/24373">24373</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19520">19520</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25617">
blanknberg-index-directory-traversal(25617)</ref></refs><vuln_soft><prod name="BlankNBerg" vendor="BlankNBerg"><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-31" modified="2006-04-03" name="CVE-2006-1582" published="2006-04-02" seq="2006-1582" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Blank&apos;N&apos;Berg 0.2 allows remote attackers to inject arbitrary web script or HTML via the _path parameter.  NOTE: this might be resultant from the directory traversal issue.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.silitix.com/bnb.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17346">17346</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015854">1015854</ref><ref source="OSVDB" url="http://www.osvdb.org/24374">24374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19520">19520</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25618">
blanknberg-index-xss(25618)</ref></refs><vuln_soft><prod name="BlankNBerg" vendor="BlankNBerg"><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-31" modified="2006-04-03" name="CVE-2006-1583" published="2006-04-02" seq="2006-1583" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Warcraft III Replay Parser for PHP 1.8c allows remote attackers to inject arbitrary web script or HTML via the page parameter.  NOTE: post-disclosure analysis by CVE suggests that the &quot;page&quot; parameter is not used in this product, and &quot;id&quot; might be the affected parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429535/100/0/threaded">20060331 Warcraft III Replay Parser Script Remote Command Exucetion Vulnerability And Cross-Site Scripting Attacking</ref><ref source="BID" url="http://www.securityfocus.com/bid/17334">17334</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25685">
warcraft3-replay-parser-index-xss(25685)</ref></refs><vuln_soft><prod name="Warcraft III Replay Parser PHP" vendor="Juliusz Julas Gonera"><vers num="1.8c"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-31" modified="2006-04-03" name="CVE-2006-1584" published="2006-04-02" seq="2006-1584" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in index.php in Warcraft III Replay Parser for PHP 1.8c allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to fopen function calls or file uploads.  NOTE: post-disclosure analysis by CVE suggests that the &quot;page&quot; parameter is not used in this product, and &quot;id&quot; might be the affected parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429535/100/0/threaded">20060331 Warcraft III Replay Parser Script Remote Command Exucetion Vulnerability And Cross-Site Scripting Attacking</ref><ref source="BID" url="http://www.securityfocus.com/bid/17334">17334</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25686">
warcraft3-replay-parser-index-file-include(25686)</ref></refs><vuln_soft><prod name="Warcraft III Replay Parser PHP" vendor="Juliusz Julas Gonera"><vers num="1.8c"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-30" modified="2006-04-03" name="CVE-2006-1585" published="2006-04-02" seq="2006-1585" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in MonAlbum 0.8.7 allow remote attackers to execute arbitrary SQL commands via (1) the pc parameter in (a) index.php and (2) pnom, (3) pcourriel, and (4) pcommentaire parameters in (b) image_agrandir.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429475/100/0/threaded">20060330 MonAlbum 0.8.7 SQL Injection</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25572">monalbum-image-imageagrandir-sql-injection(25572)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17327">17327</ref><ref source="" url="http://www.bash-x.net/undef/adv/monalbum.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1206">ADV-2006-1206</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19503">19503</ref><ref source="SREASON" url="http://securityreason.com/securityalert/660">660</ref></refs><vuln_soft><prod name="MonAlbum" vendor="3Dsrc"><vers num="0.8.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-01" modified="2006-04-03" name="CVE-2006-1586" published="2006-04-02" seq="2006-1586" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in admin_login.asp in ISP of Egypt SiteMan allows remote attackers to execute arbitrary SQL commands via the pass parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429607/100/0/threaded">20060401 SiteMan &lt;= All version SQL injection in admin_login.asp</ref><ref source="BID" url="http://www.securityfocus.com/bid/17347">17347</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1190">ADV-2006-1190</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19500">19500</ref><ref source="OSVDB" url="http://www.osvdb.org/24362">24362</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25595">siteman-adminlogin-sql-injection(25595)</ref></refs><vuln_soft><prod name="Site Man" vendor="Internet Solutions Professionals"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-03" name="CVE-2006-1587" published="2006-04-03" seq="2006-1587" severity="Low" type="CVE"><desc><descript source="cve">NetBSD 1.6 up to 3.0, when a user has &quot;set record&quot; in .mailrc with the default umask set, creates the record file with 0644 permissions, which allows local users to read the record file.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1015847">1015847</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19465">19465</ref><ref source="OSVDB" url="http://www.osvdb.org/24258">24258</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25581">bsd-mailrc-insecure-permissions(25581)</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="3.0"/><vers num="2.1"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6 Beta"/><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-03" name="CVE-2006-1588" published="2006-04-03" seq="2006-1588" severity="Low" type="CVE"><desc><descript source="cve">The bridge ioctl (if_bridge code) in NetBSD 1.6 through 3.0 does not clear sensitive memory before copying ioctl results to the requesting process, which allows local users to obtain portions of kernel memory.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="NETBSD" url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-005.txt.asc">NetBSD-SA2006-005</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/17312">17312</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015846">1015846</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19464">19464</ref><ref source="OSVDB" url="http://www.osvdb.org/24262">24262</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25582">bsd-ifbridge-information-disclosure(25582)</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="3.0"/><vers num="2.1"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6 Beta"/><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-03" name="CVE-2006-1589" published="2006-04-03" seq="2006-1589" severity="Medium" type="CVE"><desc><descript source="cve">The elf_load_file function in NetBSD 2.0 through 3.0 allows local users to cause a denial of service (kernel crash) via an ELF interpreter that does not have a PT_LOAD section in its header, which triggers a null dereference.</descript></desc><sols><sol source="nvd">The NetBSD 2.x versions are only affected if the kernel is compiled with the USE_TOPDOWN_VM option (not default in generic kernels).</sol></sols><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="NETBSD" url="ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2006-008.txt.asc">NetBSD-SA2006-008</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015848">1015848</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25690">netbsd-elfloadfile-dos(25690)</ref><ref source="OSVDB" url="http://www.osvdb.org/24576">24576</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="3.0"/><vers num="2.1"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-28" modified="2006-04-03" name="CVE-2006-1590" published="2006-04-03" seq="2006-1590" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the PrintFreshPage function in (1) Basic Analysis and Security Engine (BASE) 1.2.4 and (2) Analysis Console for Intrusion Databases (ACID) 0.9.6b23 allows remote attackers to inject arbitrary web script or HTML via the (a) back parameter to base_graph_main.php, (b) netmask parameter to base_stat_ipaddr.php, or (c) submit parameter to base_qry_alert.php within BASE, or (d) query string to acid_main.php in ACID, which causes the request URI ($_SERVER[&apos;REQUEST_URI&apos;]) to be inserted into a refresh operation.</descript></desc><sols><sol source="nvd">Analysis Console for Intrusion Databases - The vendor has discontinued this product and therefore has no patch or upgrade that mitigates this problem.

Basic Analysis and Security Engine - Upgrade to cvs version or version 1.2.5 (daiga) or higher, as it has been reported to fix this vulnerability. </sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://sourceforge.net/mailarchive/forum.php?thread_id=10064470&amp;forum_id=42223">[secureideas-base-devel] 20060328 3 XSS in BASE 1.2.4</ref><ref source="OSVDB" url="http://www.osvdb.org/24307">24307</ref><ref source="OSVDB" url="http://www.osvdb.org/20835">20835</ref><ref source="BID" url="http://www.securityfocus.com/bid/17391">17391</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1264">ADV-2006-1264</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19544">19544</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25671">base-multiple-scripts-xss(25671)</ref></refs><vuln_soft><prod name="Basic Analysis and Security Engine" vendor="Kevin Johnson"><vers num="1.1"/><vers num="1.1.2"/><vers num="1.1.3"/><vers num="1.1.4"/><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.4"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="0.9.7"/><vers num="0.9.7.1"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="1.0"/></prod><prod name="Analysis Console for Intrusion Databases (ACID)" vendor="Roman Danyliw"><vers num="0.9.6b23"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-31" modified="2006-08-28" name="CVE-2006-1591" published="2006-04-03" seq="2006-1591" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Microsoft Windows Help winhlp32.exe allows user-assisted attackers to execute arbitrary code via crafted embedded image data in a .hlp file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044748.html">20060331 Windows Help Heap Overflow</ref><ref adv="1" source="Open-Security" url="http://www.open-security.org/advisories/15">advisory #15 - Windows Help Heap Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/17325">17325</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25573">win-winhlp32-hlp-bo(25573)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430871/100/0/threaded">20060413 Windows Help Heap Overflow</ref><ref source="SREASON" url="http://securityreason.com/securityalert/700">700</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/><vers num="Terminal Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Enterprise 4.0 SP6a"/><vers num="Enterprise 4.0 SP6"/><vers num="Enterprise 4.0 SP5"/><vers num="Enterprise 4.0 SP4"/><vers num="Enterprise 4.0 SP3"/><vers num="Enterprise 4.0 SP2"/><vers num="Enterprise 4.0 SP1"/><vers num="Enterprise 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="SP1" num="Web"/><vers num="Web"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-31" modified="2006-04-10" name="CVE-2006-1592" published="2006-04-03" seq="2006-1592" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the is_client_wad_ok function in w_wad.cpp for (1) Zdaemon 1.08.01 and (2) X-Doom allows remote attackers to execute arbitrary code via a long filename argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429521/100/0/threaded">20060331 Buffer-overflow and in-game crash in Zdaemon 1.08.01</ref><ref adv="1" source="" url="http://aluigi.altervista.org/adv/zdaebof-adv.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1199">ADV-2006-1199</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19509">19509</ref><ref source="BID" url="http://www.securityfocus.com/bid/17340">17340</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1198">ADV-2006-1198</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19496">19496</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044775.html">20060331 Buffer-overflow and in-game crash in Zdaemon 1.08.01</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25592">zdaemon-isclientwadok-bo(25592)</ref></refs><vuln_soft><prod name="X-Doom" vendor="X-Doom"><vers num="1.06.07"/></prod><prod name="Zdaemon" vendor="Zdaemon"><vers num="1.08.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-31" modified="2006-04-10" name="CVE-2006-1593" published="2006-04-03" seq="2006-1593" severity="Medium" type="CVE"><desc><descript source="cve">The (1) ZD_MissingPlayer, (2) ZD_UseItem, and (3) ZD_LoadNewClientLevel functions in sv_main.cpp for (a) Zdaemon 1.08.01 and (b) X-Doom allows remote attackers to cause a denial of service (crash) via an invalid player slot or item number, which causes an invalid memory access, possibly due to an invalid array index.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429521/100/0/threaded">20060331 Buffer-overflow and in-game crash in Zdaemon 1.08.01</ref><ref source="" url="http://aluigi.altervista.org/adv/zdaebof-adv.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1199">ADV-2006-1199</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19509">19509</ref><ref source="BID" url="http://www.securityfocus.com/bid/17340">17340</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1198">ADV-2006-1198</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19496">19496</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044775.html">20060331 Buffer-overflow and in-game crash in Zdaemon 1.08.01</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25593">zdaemon-memory-access-dos(25593)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/662">662</ref></refs><vuln_soft><prod name="X-Doom" vendor="X-Doom"><vers num="1.06.07"/></prod><prod name="ZDaemon" vendor="ZDaemon"><vers num="1.08.01" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-30" modified="2006-04-03" name="CVE-2006-1594" published="2006-04-03" seq="2006-1594" severity="High" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in document/rqmkhtml.php in Claroline 1.7.4 and earlier allow remote attackers to use &quot;..&quot; (dot dot) sequences to (1) read arbitrary files via the file parameter in a rqEditHtml command to document/rqmkhtml.php or (2) execute arbitrary code via the includePath parameter to learnPath/include/scormExport.inc.php.</descript></desc><sols><sol source="nvd">Successful exploitation requires that &quot;register_globals&quot; is enabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/1627">exploit 1627</ref><ref source="Altervista" url="http://retrogod.altervista.org/claroline_174_incl_xpl.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1187">ADV-2006-1187</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19461">19461</ref><ref source="BID" url="http://www.securityfocus.com/bid/17343">17343</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25561">claroline-rqmkhtml-directory-traversal(25561)</ref></refs><vuln_soft><prod name="Claroline" vendor="Claroline"><vers num="1.7.2"/><vers num="1.6 rc1"/><vers num="1.6 beta"/><vers num="1.5.3"/><vers num="1.7.4" prev="1"/><vers num="1.6"/><vers num="1.5.4"/><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-30" modified="2006-04-03" name="CVE-2006-1595" published="2006-04-03" seq="2006-1595" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in document/rqmkhtml.php in Claroline 1.7.4 and earlier allows remote attackers to read arbitrary files via &quot;..&quot; sequences in the file parameter in a rqEditHtml command.</descript></desc><sols><sol source="nvd">Successful exploitation requires that &quot;register_globals&quot; is enabled.</sol></sols><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Milw0rm" url="http://www.milw0rm.com/exploits/1627">exploit 1627</ref><ref source="Altervista" url="http://retrogod.altervista.org/claroline_174_incl_xpl.html"></ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1905.html">20060331 Re: [Full-disclosure] Claroline &lt;= 1.7.4 (scormExport.inc.php) Remote Code Execution Exploit by rgod</ref><ref source="BID" url="http://www.securityfocus.com/bid/17344">17344</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1187">ADV-2006-1187</ref><ref source="OSVDB" url="http://www.osvdb.org/24285">24285</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19461">19461</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25562">claroline-rqmkhtml-xss(25562)</ref><ref source="OSVDB" url="http://www.osvdb.org/24284">24284</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1627">

1627</ref></refs><vuln_soft><prod name="Claroline" vendor="Claroline"><vers num="1.7.2"/><vers num="1.6 rc1"/><vers num="1.6 beta"/><vers num="1.6"/><vers num="1.5.4"/><vers num="1.5.3"/><vers num="1.5"/><vers num="1.7.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-31" modified="2006-04-03" name="CVE-2006-1596" published="2006-04-03" seq="2006-1596" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in learnPath/include/scormExport.inc.php in Claroline 1.7.4 and earlier allows remote attackers to execute arbitrary PHP code via the includePath parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/1627"></ref><ref source="" url="http://retrogod.altervista.org/claroline_174_incl_xpl.html"></ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1888.html">20060331 Claroline &lt;= 1.7.4 (scormExport.inc.php) Remote Code Execution Exploit by rgod</ref><ref source="BID" url="http://www.securityfocus.com/bid/17341">17341</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1187">ADV-2006-1187</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19461">19461</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25563">claroline-scormexportinc-file-include(25563)</ref><ref source="OSVDB" url="http://www.osvdb.org/24286">24286</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1627">

1627</ref></refs><vuln_soft><prod name="Claroline" vendor="Claroline"><vers num="1.7.4"/><vers num="1.7.2"/><vers num="1.6 rc1"/><vers num="1.6 beta"/><vers num="1.6"/><vers num="1.5.4"/><vers num="1.5.3"/><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-22" modified="2006-04-04" name="CVE-2006-1598" published="2006-04-03" seq="2006-1598" severity="High" type="CVE"><desc><descript source="cve">AN HTTPD 1.42n, and possibly other versions before 1.42p, allows remote attackers to obtain source code of scripts via crafted requests with (1) dot and (2) space characters in the file extension.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429667/100/0/threaded">20060403 Secunia Research: AN HTTPD Script Source Disclosure Vulnerability</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/secunia_research/2006-21/advisory">AN HTTPD Script Source Disclosure Vulnerability </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17350">17350</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1200">ADV-2006-1200</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19326">19326</ref><ref source="OSVDB" url="http://www.osvdb.org/24323">24323</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015858">1015858</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25591">anhttpd-script-source-disclosure(25591)</ref></refs><vuln_soft><prod name="AN-HTTPD" vendor="AN"><vers num="1.42n" prev="1"/><vers num="1.41c"/><vers num="1.41b"/><vers num="1.41"/><vers num="1.40"/><vers num="1.39"/><vers num="1.38"/><vers num="1.2b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-04" name="CVE-2006-1599" published="2006-04-03" seq="2006-1599" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in VCEngine.php in v-creator before 1.3-pre3, when the VC_CRYPTO_METHOD option is OPENSSL, allows remote attackers to execute arbitrary commands, possibly due to problems in the (1) enrypt and (2) decrypt functions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/forum/forum.php?forum_id=557129"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17328">17328</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1189">ADV-2006-1189</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19453">19453</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25560">vcreator-vcengine-command-execution(25560)</ref><ref source="OSVDB" url="http://www.osvdb.org/24304">24304</ref></refs><vuln_soft><prod name="v-creator" vendor="v-creator.com"><vers num="1.3 pre2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-04" name="CVE-2006-1600" published="2006-04-03" seq="2006-1600" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in category.php in PhpWebGallery 1.4.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429665/100/0/threaded">20060403 Phpwebgallery &lt;= 1.4.1 SQL injection Vulnerability</ref><ref source="SREASON" url="http://securityreason.com/securityalert/669">669</ref></refs><vuln_soft><prod name="PhpWebGallery" vendor="PhpWebGallery"><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.7" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="2.9" CVSS_score="1.7" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-04" name="CVE-2006-1601" published="2006-04-04" seq="2006-1601" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in SunPlex Manager in Sun Cluster 3.1 4/04 allows local users with solaris.cluster.gui authorization to view arbitrary files via unspecified vectors.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102278-1">102278</ref><ref source="BID" url="http://www.securityfocus.com/bid/17313">17313</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1175">ADV-2006-1175</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015849">1015849</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19444">19444</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25543">suncluster-sunplex-information-disclosure(25543)</ref></refs><vuln_soft><prod name="Sun Cluster" vendor="Sun"><vers num="3.1 4_04"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-04" name="CVE-2006-1602" published="2006-04-04" seq="2006-1602" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in includes/functions_common.php in the VWar Account module (vWar_Account) in PHPNuke Clan 3.0.1 allows remote attackers to include arbitrary files via a URL in the vwar_root2 parameter.  NOTE: it is possible that this issue stems from a problem in VWar itself, but this is not clear.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429615/100/0/threaded">20060401 PHPNuke-Clan 3.0.1 Remote File Inclusion Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/17356">17356</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1202">ADV-2006-1202</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19501">19501</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25609">phpnukeclan-functionscommon-file-include(25609)</ref><ref source="OSVDB" url="http://www.osvdb.org/24481">
24481</ref></refs><vuln_soft><prod name="PHPNuke-Clan" vendor="PHPNuke-Clan"><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-04" name="CVE-2006-1603" published="2006-04-04" seq="2006-1603" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in profile.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via the cur_password parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17355">17355</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1191">ADV-2006-1191</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19494">19494</ref><ref source="" url="http://osvdb.org/ref/24/24353-phpbb.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/24353">24353</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25599">phpbb-profile-script-xss(25599)</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.19"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-04" name="CVE-2006-1604" published="2006-04-04" seq="2006-1604" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Exponent CMS before 0.96.5 RC 1 has unknown impact and remote attack vectors related to variables that are not &quot;typecasted.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=406474&amp;group_id=118524"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17357">17357</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1201">ADV-2006-1201</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19498">19498</ref></refs><vuln_soft><prod name="Exponent CMS" vendor="Exponent"><vers num="0.96.4"/><vers num="0.96.1"/><vers num="0.95"/><vers num="0.94"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-04" name="CVE-2006-1605" published="2006-04-04" seq="2006-1605" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows remote attackers to execute arbitrary code via unknown vectors involving &quot;parsed PHP.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=406474&amp;group_id=118524"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17357">17357</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1201">ADV-2006-1201</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19498">19498</ref><ref source="OSVDB" url="http://www.osvdb.org/24358">24358</ref></refs><vuln_soft><prod name="Exponent CMS" vendor="Exponent"><vers num="0.96.4"/><vers num="0.96.1"/><vers num="0.95"/><vers num="0.94"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-04" name="CVE-2006-1606" published="2006-04-04" seq="2006-1606" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows &quot;directory disclosure&quot; with unknown attack vectors.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=406474&amp;group_id=118524"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17357">17357</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1201">ADV-2006-1201</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19498">19498</ref></refs><vuln_soft><prod name="Exponent CMS" vendor="Exponent"><vers num="0.96.4"/><vers num="0.96.1"/><vers num="0.95"/><vers num="0.94"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-04" name="CVE-2006-1607" published="2006-04-04" seq="2006-1607" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the banner module in Exponent CMS before 0.96.5 RC 1 allows &quot;php injection&quot; via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=406474&amp;group_id=118524"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17357">17357</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1201">ADV-2006-1201</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19498">19498</ref><ref source="OSVDB" url="http://www.osvdb.org/24358">24358</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25610">exponent-banner-php-command-execution(25610)</ref></refs><vuln_soft><prod name="Exponent CMS" vendor="Exponent"><vers num="0.96.4"/><vers num="0.96.1"/><vers num="0.95"/><vers num="0.94"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-10" name="CVE-2006-1608" published="2006-04-10" seq="2006-1608" severity="Low" type="CVE"><desc><descript source="cve">The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass safe mode and read arbitrary files via a source argument containing a compress.zlib:// URI.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref patch="1" source="Security Reason" url="http://securityreason.com/achievement_securityalert/37">SecurityAlert Id : 37</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19599">19599</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430461/100/0/threaded">20060409 copy() Safe Mode Bypass PHP 4.4.2 and 5.1.2</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1290">ADV-2006-1290</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015882">1015882</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:074">MDKSA-2006:074</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-320-1">USN-320-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/17439">17439</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/440869/100/0/threaded">20060718 new shell bypass safe mode</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/441210/100/0/threaded">20060723 Re: new shell bypass safe mode</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/044984.html">
20060408 copy() Safe Mode Bypass PHP 4.4.2 and 5.1.2</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19775">
19775</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21125">
21125</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25706">
php-copy-safemode-bypass(25706)</ref><ref source="" url="http://us.php.net/releases/5_1_3.php"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:074">MDKSA-2006:074</ref><ref source="OSVDB" url="http://www.osvdb.org/24487">24487</ref><ref source="SREASON" url="http://securityreason.com/securityalert/678">678</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.1.2"/><vers num="5.1.1"/><vers num="5.1.0"/><vers num="5.1"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0.0 RC3"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC1"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta1"/><vers num="5.0.0"/><vers num="5.0 candidate 3"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 1"/><vers num="4.4.2"/><vers num="4.4.1"/><vers num="4.4.0"/><vers num="4.3.9"/><vers num="4.3.8"/><vers num="4.3.7"/><vers num="4.3.6"/><vers num="4.3.5"/><vers num="4.3.4"/><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.11"/><vers num="4.3.10"/><vers num="4.3.1"/><vers num="4.3"/><vers edition="Dev" num="4.2"/><vers num="4.2.3"/><vers num="4.2.2"/><vers num="4.2.1"/><vers num="4.2.0"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1.0"/><vers num="4.0.7 RC3"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC1"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5"/><vers num="4.0.4 pl1"/><vers num="4.0.4"/><vers num="4.0.3 pl1"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1 pl2"/><vers num="4.0.1 pl1"/><vers num="4.0.1"/><vers num="4.0.0"/><vers num="4.0 RC2"/><vers num="4.0 RC1"/><vers num="4.0 Beta 4 Patch Level 1"/><vers num="4.0 Beta 4"/><vers num="4.0 Beta 3"/><vers num="4.0 Beta 2"/><vers num="4.0 Beta 1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-31" modified="2006-04-04" name="CVE-2006-1609" published="2006-04-04" seq="2006-1609" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Hitachi XFIT/S, XFIT/S/JCA, XFIT/S/ZGN, and XFIT/S ZENGIN TCP/IP Procedure allows remote attackers to cause a denial of service (server process and transfer control process stop) when the products &quot;receive data unexpectedly&quot;.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS06-004_e/index-e.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17329">17329</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19472">19472</ref><ref source="OSVDB" url="http://www.osvdb.org/24309">24309</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25567">xfits-data-dos(25567)</ref></refs><vuln_soft><prod name="XFIT S" vendor="Hitachi"><vers num="0"/></prod><prod name="XFIT S ZENGIN" vendor="Hitachi"><vers num="0"/></prod><prod name="XFIT S ZGIN" vendor="Hitachi"><vers num="0"/></prod><prod name="XFIT S JCA" vendor="Hitachi"><vers num="0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-01" modified="2006-04-25" name="CVE-2006-1610" published="2006-04-04" seq="2006-1610" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in lib/armygame.php in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allows remote attackers to execute arbitrary PHP code via a URL in the libpath parameter.  NOTE: this only occurs when register_globals is disabled.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429611/100/0/threaded">20060401 SQuery &lt;= 4.5 Remote File Inclusion Exploit</ref><ref source="" url="http://milw0rm.com/exploits/1629"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1204">ADV-2006-1204</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19482">19482</ref><ref source="OSVDB" url="http://www.osvdb.org/24400">24400</ref><ref source="BID" url="http://www.securityfocus.com/bid/17434">17434</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25605">squery-file-include(25605)</ref></refs><vuln_soft><prod name="SQuery" vendor="SQuery"><vers num="4.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-04" name="CVE-2006-1611" published="2006-04-04" seq="2006-1611" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in KGB Archiver before 1.1.5.22 allows remote attackers to overwrite arbitrary files wile decompressing an archive, possibly due to directory traversal sequences in a filename.</descript></desc><sols><sol source="nvd">This vulnerability affects all versions of KGB, Archiver before 1.1.5.22</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Sourceforge" url="http://sourceforge.net/project/shownotes.php?group_id=162546&amp;release_id=406411">Release Name: v1.1.5.22</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1207">ADV-2006-1207</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19511">19511</ref><ref source="BID" url="http://www.securityfocus.com/bid/17363">17363</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25606">kgb-archiver-archive-directory-traversal(25606)</ref></refs><vuln_soft><prod name="Archiver" vendor="KGB"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-01" modified="2006-04-04" name="CVE-2006-1612" published="2006-04-04" seq="2006-1612" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in visview.php in aWebNews 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) yname, (2) emailadd, (3) subject, and (4) comment parameters.</descript></desc><sols><sol source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is disabled.
</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Evuln" url="http://evuln.com/vulns/116/summary.html">EV0116</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1196">ADV-2006-1196</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19487">19487</ref><ref source="OSVDB" url="http://www.osvdb.org/24333">24333</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25589">awebnews-visview-xss(25589)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431007/100/0/threaded">20060414 [eVuln] aWebNews Multiple XSS and SQL Injection Vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/707">707</ref></refs><vuln_soft><prod name="aWebNews" vendor="aWeb Labs"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-01" modified="2006-04-05" name="CVE-2006-1613" published="2006-04-04" seq="2006-1613" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in aWebNews 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user123 variable in (a) login.php or (b) fpass.php; or (2) cid parameter to (c) visview.php.</descript></desc><sols><sol source="nvd">Condition: magic_quotes_gpc = off
</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Evuln" url="http://evuln.com/vulns/116/summary.html">EV0116</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1196">ADV-2006-1196</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19487">19487</ref><ref source="OSVDB" url="http://www.osvdb.org/24334">24334</ref><ref source="OSVDB" url="http://www.osvdb.org/24335">24335</ref><ref source="OSVDB" url="http://www.osvdb.org/24336">24336</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25590">awebnews-multiple-sql-injection(25590)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431007/100/0/threaded">20060414 [eVuln] aWebNews Multiple XSS and SQL Injection Vulnerabilities</ref></refs><vuln_soft><prod name="aWebNews" vendor="aWeb Labs"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-13" name="CVE-2006-1614" published="2006-04-06" seq="2006-1614" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the cli_scanpe function in the PE header parser (libclamav/pe.c) in Clam AntiVirus (ClamAV) before 0.88.1, when ArchiveMaxFileSize is disabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.overflow.pl/adv/clamavupxinteger.txt"></ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=407078&amp;group_id=86638"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1024">DSA-1024</ref><ref source="BID" url="http://www.securityfocus.com/bid/17388">17388</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1258">ADV-2006-1258</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19534">19534</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19536">19536</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430405/100/0/threaded">20060406 [Overflow.pl] Clam AntiVirus Win32-UPX Heap Overflow (not default configuration)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-06.xml">GLSA-200604-06</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:067">MDKSA-2006:067</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0020">2006-0020</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19570">19570</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0002.html">SUSE-SA:2006:020</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19608">19608</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19564">19564</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19567">19567</ref><ref source="OSVDB" url="http://www.osvdb.org/24457">24457</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015887">1015887</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="" url="http://up2date.astaro.com/2006/05/low_up2date_6202.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23719">23719</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25660">
clamav-pe-overflow(25660)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:067">MDKSA-2006:067</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.88"/><vers num="0.87.1"/><vers num="0.87"/><vers num="0.86.2"/><vers num="0.86.1"/><vers num="0.86"/><vers num="0.85.1"/><vers num="0.85"/><vers num="0.84 rc2"/><vers num="0.84 rc1"/><vers num="0.84"/><vers num="0.83"/><vers num="0.82"/><vers num="0.81"/><vers num="0.80 rc4"/><vers num="0.80 rc3"/><vers num="0.80 rc2"/><vers num="0.80 rc1"/><vers num="0.80"/><vers num="0.75.1"/><vers num="0.70"/><vers num="0.68.1"/><vers num="0.68"/><vers num="0.67"/><vers num="0.65"/><vers num="0.60"/><vers num="0.54"/><vers num="0.53"/><vers num="0.52"/><vers num="0.51"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1615" published="2006-04-06" seq="2006-1615" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute arbitrary code.  NOTE: as of 20060410, it is unclear whether this is a vulnerability, as there is some evidence that the arguments are actually being sanitized properly.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="Sourceforge" url="http://sourceforge.net/project/shownotes.php?release_id=407078&amp;group_id=86638">Release Name: 0.88.1</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1024">DSA-1024</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17388">17388</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1258">ADV-2006-1258</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19534">19534</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19536">19536</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-06.xml">GLSA-200604-06</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:067">MDKSA-2006:067</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0020">2006-0020</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19570">19570</ref><ref adv="1" patch="1" source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0002.html">SUSE-SA:2006:020</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19608">19608</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19564">19564</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19567">19567</ref><ref source="OSVDB" url="http://www.osvdb.org/24458">24458</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="" url="http://up2date.astaro.com/2006/05/low_up2date_6202.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23719">23719</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25661">
clamav-output-format-string(25661)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:067">MDKSA-2006:067</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num=""/><vers num="0.87.1"/><vers num="0.87"/><vers num="0.86 rc1"/><vers num="0.86.2"/><vers num="0.86.1"/><vers num="0.86"/><vers num="0.85.1"/><vers num="0.85"/><vers num="0.84 rc2"/><vers num="0.84 rc1"/><vers num="0.84"/><vers num="0.83"/><vers num="0.82"/><vers num="0.81 rc1"/><vers num="0.81"/><vers num="0.80 rc4"/><vers num="0.80 rc3"/><vers num="0.80 rc2"/><vers num="0.80 rc1"/><vers num="0.80"/><vers num="0.75.1"/><vers num="0.75"/><vers num="0.74"/><vers num="0.73"/><vers num="0.72"/><vers num="0.71"/><vers num="0.70"/><vers num="0.68.1"/><vers num="0.68"/><vers num="0.67"/><vers num="0.65"/><vers num="0.60p"/><vers num="0.60"/><vers num="0.54"/><vers num="0.53"/><vers num="0.52"/><vers num="0.51"/><vers num="0.24"/><vers num="0.23"/><vers num="0.22"/><vers num="0.21"/><vers num="0.20"/><vers num="0.15"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-05" name="CVE-2006-1616" published="2006-04-05" seq="2006-1616" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Advanced Poll 2.02 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to comments.php or (2) poll_id parameter to page.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://ns79.hosteur.com/~secuti/advancedpoll.txt"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25676">advancedpoll-comments-page-sql-injection(25676)</ref></refs><vuln_soft><prod name="Advanced Poll" vendor="Advanced Poll"><vers num="2.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-05" name="CVE-2006-1617" published="2006-04-05" seq="2006-1617" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Advanced Poll 2.02 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to comments.php or (2) poll_id parameter to page.php.  NOTE: it is possible that this issue is resultant from CVE-2006-1616.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://ns79.hosteur.com/~secuti/advancedpoll.txt"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25677">advancedpoll-comments-page-xss(25677)</ref></refs><vuln_soft><prod name="Advanced Poll" vendor="Advanced Poll"><vers num="2.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-05" name="CVE-2006-1618" published="2006-04-05" seq="2006-1618" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the (1) Con_message and (2) conPrintf functions in con_main.c in Doomsday engine 1.8.6 allows remote attackers to execute arbitrary code via format string specifiers in an argument to the JOIN command, and possibly other command arguments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://aluigi.altervista.org/adv/doomsdayfs-adv.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1221">ADV-2006-1221</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19515">19515</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429857/100/0/threaded">20060403 Format string in Doomsday 1.8.6</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-05.xml">GLSA-200604-05</ref><ref source="BID" url="http://www.securityfocus.com/bid/17369">17369</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015860">1015860</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19519">19519</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/044865.html">20060403 Format string in Doomsday 1.8.6</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25622">doomsday-conmessage-conprintf-format-string(25622)</ref></refs><vuln_soft><prod name="Doomsday" vendor="Doomsday"><vers num="1.8.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-12" name="CVE-2006-1619" published="2006-04-05" seq="2006-1619" severity="Medium" type="CVE"><desc><descript source="cve">IBM WebSphere Application Server 4.0.1 through 4.0.3 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a large header.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg21053738">PQ62144</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1214">ADV-2006-1214</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015857">1015857</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25619">websphere-http-header-dos(25619)</ref></refs><vuln_soft><prod name="WebSphere Application Server" vendor="IBM"><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-14" name="CVE-2006-1620" published="2006-04-05" seq="2006-1620" severity="Medium" type="CVE"><desc><descript source="cve">admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an &quot;Update User&quot; ActionType with a modified UserName parameter and the PassCheck parameter set to TRUE.  It was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429731/100/0/threaded">20060402 Hosting Controller AccountActions.asp and saveuploadfiles.asp vulns (PoC)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25673">hosting-controller-accountactions-password(25673)</ref><ref source="OSVDB" url="http://www.osvdb.org/24773">24773</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485028/100/0/threaded">20071213 Hosting Controller - Multiple Security Bugs (Extremely Critical)</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4730">4730</ref><ref source="BID" url="http://www.securityfocus.com/bid/26862">26862</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39038">hostingcontroller-multiple-security-bypass(39038)</ref><ref source="" url="http://hostingcontroller.com/english/logs/Post-Hotfix-3_3-sec-Patch-ReleaseNotes.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/28973">28973</ref></refs><vuln_soft><prod name="Hosting Controller" vendor="Hosting Controller"><vers num="2002 RC 1"/><vers num="6.1 Hotfix 3.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-05" name="CVE-2006-1621" published="2006-04-05" seq="2006-1621" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in admin/folders/saveuploadfiles.asp in Hosting Controller 2002 RC 1 allows remote authenticated users to overwrite arbitrary files via an absolute path in the OpenPath parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429731/100/0/threaded">20060402 Hosting Controller AccountActions.asp and saveuploadfiles.asp vulns (PoC)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25675">hosting-controller-Saveupload-file-upload(25675)</ref><ref source="OSVDB" url="http://www.osvdb.org/24772">24772</ref></refs><vuln_soft><prod name="Hosting Controller" vendor="Hosting Controller"><vers num="2002 RC 1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-01" modified="2006-04-05" name="CVE-2006-1622" published="2006-04-05" seq="2006-1622" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in PHPSelect linksubmit allows remote attackers to inject arbitrary web script or HTML via (1) the description parameter to linklist.php and possibly other vectors involving (2) index.php and (3) linksubmit.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429608/100/0/threaded">20060401 linksubmit &lt;= All version Html Tag Injector in index.php</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25607">linksubmit-linksubmit-xss(25607)</ref></refs><vuln_soft><prod name="PHPSelect" vendor="PHPSelect"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-07-03" name="CVE-2006-1623" published="2006-04-05" seq="2006-1623" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in main.php in an unspecified &quot;file created by Andries Bruinsma,&quot; possibly a FleXiBle Development (FXB) application, allows remote attackers to include and execute arbitrary PHP code.  NOTE: this disclosure is extremely vague and has very little information about the specific vulnerability type.  In addition, there is little public information on the named product. Finally, an XSS vector is implied in the subject line, but because there is no other information and evidence of a cut-and-paste error, it will not be assigned a separate CVE identifier unless additional information is provided.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429613/100/0/threaded">20060401 FleXiBle Development Script Remote Command Exucetion And XSS Attacking</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-April/000680.html">[VIM] 20060404 FleXiBle Development Script Remote Command Exucetion And XSS Attacking</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430334/100/0/threaded">20060405 Re: FleXiBle Development Script Remote Command Exucetion And XSS Attacking</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25600">flexible-development-main-command-execution(25600)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25603">flexible-development-main-xss(25603)</ref></refs><vuln_soft><prod name="FleXiBle Development" vendor="Andries Bruinsma"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-31" modified="2006-04-05" name="CVE-2006-1624" published="2006-04-05" seq="2006-1624" severity="High" type="CVE"><desc><descript source="cve">The default configuration of syslogd in the Linux sysklogd package does not enable the -x (disable name lookups) option, which allows remote attackers to cause a denial of service (traffic amplification) via messages with spoofed source IP addresses.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429618/100/0/threaded">20060331 DoS-ing sysklogd?</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429739/100/0/threaded">20060402 RE: DoS-ing sysklogd?</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25672">
sysklogd-sourceip-dos(25672)</ref></refs><vuln_soft><prod name="Linux Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-02" modified="2006-10-05" name="CVE-2006-1625" published="2006-04-05" seq="2006-1625" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.10 allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode email tag, as demonstrated using the onmousemove event.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429748/100/0/threaded">20060402 MyBB 1.10 New CrossSiteScripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/17368">17368</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1216">ADV-2006-1216</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19516">19516</ref><ref source="OSVDB" url="http://www.osvdb.org/24375">24375</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25615">mybb-email-img-bbcode-xss(25615)</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" discovered="2006-04-03" modified="2007-01-04" name="CVE-2006-1626" published="2006-04-05" seq="2006-1626" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 6 for Windows XP SP2 and earlier allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading.  NOTE: this is a different vulnerability than CVE-2006-1192.</descript></desc><sols><sol source="nvd">This vulnerability affects any version of Windows OS previous to XP SP2 that is using Internet Explorer 6.0</sol></sols><loss_types><avail/><int/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429719/100/0/threaded">20060403 Another Internet Explorer Address Bar Spoofing Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429891/100/0/threaded">20060404 Another way to spoof Internet Explorer Address Bar</ref><ref source="" url="http://secunia.com/Internet_Explorer_Address_Bar_Spoofing_Vulnerability_Test/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17404">17404</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1218">ADV-2006-1218</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19521">19521</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-021.mspx">MS06-021</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2319">ADV-2006-2319</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016291">1016291</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/440851/100/100/threaded">20060721 about bid 17404</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1600">oval:org.mitre.oval:def:1600</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1604">oval:org.mitre.oval:def:1604</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1806">oval:org.mitre.oval:def:1806</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1842">oval:org.mitre.oval:def:1842</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1881">oval:org.mitre.oval:def:1881</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1918">oval:org.mitre.oval:def:1918</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25634">
ie-swf-addressbar-spoofing(25634)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows XP SP2" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1627" published="2006-04-13" seq="2006-1627" severity="High" type="CVE"><desc><descript source="cve">Adobe Document Server for Reader Extensions 6.0 does not provide proper access control, which allows remote authenticated users to perform privileged actions by modifying the (1) actionID and (2) pageID parameters.  NOTE: due to an error during reservation, this identifier was inadvertently associated with multiple issues.  Other CVE identifiers have been assigned to handle other problems that are covered by the same disclosure.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2005-68/advisory/"></ref><ref source="" url="http://www.adobe.com/support/techdocs/322699.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1342">ADV-2006-1342</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15924">15924</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430869/100/0/threaded">20060413 Secunia Research: Adobe Document Server for Reader ExtensionsMultiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17500">17500</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015905">1015905</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25769">
adobe-access-control-bypass(25769)</ref></refs><vuln_soft><prod name="Document Reader" vendor="Adobe"><vers edition="Reader Extensions" num="6.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1628" published="2006-04-13" seq="2006-1628" severity="Medium" type="CVE"><desc><descript source="cve">Adobe LiveCycle Workflow 7.01 and LiveCycle Forum Manager 7.01 allows users to authenticate and perform privileged actions when their account is marked &quot;OBSOLETE&quot; but the account is also active, within the authentication system.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.adobe.com/support/techdocs/333036.html"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19620">19620</ref><ref source="BID" url="http://www.securityfocus.com/bid/17511">17511</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1343">ADV-2006-1343</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015906">1015906</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25779">
adobe-livecycle-information-disclosure(25779)</ref></refs><vuln_soft><prod name="LiveCycle Forum Manager" vendor="Adobe"><vers num="7.01"/></prod><prod name="LiveCycle Workflow" vendor="Adobe"><vers num="7.01"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1629" published="2006-04-06" seq="2006-1629" severity="High" type="CVE"><desc><descript source="cve">OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.</descript></desc><sols><sol source="nvd">OpenVPN version 2.0.6 fixes this vulnerability. </sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OS Reviews" url="http://www.osreviews.net/reviews/security/openvpn-print">Virtual Private Networks Made Easy</ref><ref patch="1" source="OpenVPN" url="http://openvpn.net/changelog.html">OpenVPN 2.0.x Change Log</ref><ref source="Sourceforge" url="http://sourceforge.net/mailarchive/forum.php?thread_id=10093825&amp;forum_id=8482">Email Archive</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17392">17392</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1261">ADV-2006-1261</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19531">19531</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:069">MDKSA-2006:069</ref><ref source="OSVDB" url="http://www.osvdb.org/24444">24444</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19598">19598</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1045">DSA-1045</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_28.html">SUSE-SR:2006:009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19837">19837</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19897">19897</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25667">openvpn-ldpreload-code-execution(25667)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:069">MDKSA-2006:069</ref></refs><vuln_soft><prod name="OpenVPN" vendor="OpenVPN"><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1630" published="2006-04-06" seq="2006-1630" severity="Medium" type="CVE"><desc><descript source="cve">The cli_bitset_set function in libclamav/others.c in Clam AntiVirus (ClamAV) before 0.88.1 allows remote attackers to cause a denial of service via unspecified vectors that trigger an &quot;invalid memory access.&quot;</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=407078&amp;group_id=86638"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1024">DSA-1024</ref><ref source="BID" url="http://www.securityfocus.com/bid/17388">17388</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1258">ADV-2006-1258</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19534">19534</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19536">19536</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-06.xml">GLSA-200604-06</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:067">MDKSA-2006:067</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0020">2006-0020</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19570">19570</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0002.html">SUSE-SA:2006:020</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19608">19608</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19564">19564</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19567">19567</ref><ref source="OSVDB" url="http://www.osvdb.org/24459">24459</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="" url="http://up2date.astaro.com/2006/05/low_up2date_6202.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23719">23719</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25662">
clamav-others-dos(25662)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:067">MDKSA-2006:067</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.88"/><vers num="0.87.1"/><vers num="0.87"/><vers num="0.86.2"/><vers num="0.86.1"/><vers num="0.86"/><vers num="0.85.1"/><vers num="0.85"/><vers num="0.84 rc2"/><vers num="0.84 rc1"/><vers num="0.84"/><vers num="0.83"/><vers num="0.82"/><vers num="0.81"/><vers num="0.80 rc4"/><vers num="0.80 rc3"/><vers num="0.80 rc2"/><vers num="0.80 rc1"/><vers num="0.80"/><vers num="0.75.1"/><vers num="0.70"/><vers num="0.68.1"/><vers num="0.68"/><vers num="0.67"/><vers num="0.65"/><vers num="0.60"/><vers num="0.54"/><vers num="0.53"/><vers num="0.52"/><vers num="0.51"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-06" name="CVE-2006-1631" published="2006-04-05" seq="2006-1631" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the HTTP compression functionality in Cisco CSS 11500 Series Content Services switches allows remote attackers to cause a denial of service (device reload) via (1) &quot;valid, but obsolete&quot; or (2) &quot;specially crafted&quot; HTTP requests.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20060405-css.shtml">20060405 Cisco 11500 Content Services Switch HTTP Request Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17383">17383</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1257">ADV-2006-1257</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015870">1015870</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19552">19552</ref><ref source="OSVDB" url="http://www.osvdb.org/24433">24433</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25642">cisco-css-http-comp-dos(25642)</ref></refs><vuln_soft><prod name="Content Service Switch" vendor="Cisco"><vers num="11500"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-06" name="CVE-2006-1634" published="2006-04-06" seq="2006-1634" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in LucidCMS 2.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the command parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/429744">20060402 Multiple Vulnerabilities in LucidCMS</ref><ref source="BID" url="http://www.securityfocus.com/bid/17360">17360</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25632">
lucidcms-index-login-panel-xss(25632)</ref></refs><vuln_soft><prod name="lucidCMS" vendor="lucidCMS"><vers num="2.0.0 RC4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-06" name="CVE-2006-1635" published="2006-04-06" seq="2006-1635" severity="Medium" type="CVE"><desc><descript source="cve">LucidCMS 2.0.0 RC4 allows remote attackers to obtain sensitive information via a direct request to /lucid_phplib/translator.php, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/429744">20060402 Multiple Vulnerabilities in LucidCMS</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25633">
lucidcms-translator-path-disclosure(25633)</ref></refs><vuln_soft><prod name="LucidCMS" vendor="LucidCMS"><vers num="2.0.0 RC4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1636" published="2006-04-06" seq="2006-1636" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in get_header.php in VWar 1.5.0 R12 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter.  NOTE: this is a different vulnerability than CVE-2006-1503.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/VWar_1.5.0_R12.pl"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17358">17358</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429742/100/0/threaded">20060402 VWar &lt;= 1.5.0 R12 Remote File Inclusion Exploit</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1228">ADV-2006-1228</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19524">19524</ref><ref source="OSVDB" url="http://www.osvdb.org/24480">
24480</ref></refs><vuln_soft><prod name="Virtual War" vendor="VWar"><vers num="1.5.0 R12"/><vers num="1.5.0 R11"/><vers num="1.5.0 R10"/><vers num="1.5.0 R9"/><vers num="1.5.0 R8"/><vers num="1.5.0 R7"/><vers num="1.5.0 R6"/><vers num="1.5.0 R5"/><vers num="1.5.0 R4"/><vers num="1.5.0 R3"/><vers num="1.5.0 R2"/><vers num="1.5.0 R1"/><vers num="1.5"/><vers num="1.4"/><vers num="1.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.1.8"/><vers num="1.1.7"/><vers num="1.1.6"/><vers num="1.1.5"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1.0"/><vers num="1.0.9"/><vers num="1.0.8"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-23" name="CVE-2006-1637" published="2006-04-06" seq="2006-1637" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in aWebBB 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) tname or (2) fpost parameters to (a) post.php; (3) fullname, (4) emailadd, (5) country, (6) sig, or (7) otherav parameters to (b) editac.php; or (8) fullname, (9) emailadd, or (10) country parameters to (c) register.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/117/summary.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19486">19486</ref><ref source="BID" url="http://www.securityfocus.com/bid/17352">17352</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1197">ADV-2006-1197</ref><ref source="OSVDB" url="http://www.osvdb.org/24337">24337</ref><ref source="OSVDB" url="http://www.osvdb.org/24338">24338</ref><ref source="OSVDB" url="http://www.osvdb.org/24339">24339</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25585">awebbb-multiple-xss(25585)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431064/100/0/threaded">20060415 [eVuln] aWebBB Multiple XSS and SQL Injection Vulnerabilities</ref></refs><vuln_soft><prod name="aWebBB" vendor="aWeb Labs"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1638" published="2006-04-06" seq="2006-1638" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in aWebBB 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) Username parameter to (a) accounts.php, (b) changep.php, (c) editac.php, (d) feedback.php, (e) fpass.php, (f) login.php, (g) post.php, (h) reply.php, or (i) reply_log.php; (2) p parameter to (j) dpost.php; (3) c parameter to (k) list.php or (l) ndis.php; or (12) q parameter to (m) search.php.</descript></desc><sols><sol source="nvd">Successful exploitation requires &quot;magic_quotes_gpc&quot; to be disabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Evuln" url="http://evuln.com/vulns/117/summary.html">EV0117</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19486">19486</ref><ref source="BID" url="http://www.securityfocus.com/bid/17352">17352</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1197">ADV-2006-1197</ref><ref source="OSVDB" url="http://www.osvdb.org/24340">24340</ref><ref source="OSVDB" url="http://www.osvdb.org/24341">24341</ref><ref source="OSVDB" url="http://www.osvdb.org/24342">24342</ref><ref source="OSVDB" url="http://www.osvdb.org/24343">24343</ref><ref source="OSVDB" url="http://www.osvdb.org/24344">24344</ref><ref source="OSVDB" url="http://www.osvdb.org/24345">24345</ref><ref source="OSVDB" url="http://www.osvdb.org/24346">24346</ref><ref source="OSVDB" url="http://www.osvdb.org/24347">24347</ref><ref source="OSVDB" url="http://www.osvdb.org/24348">24348</ref><ref source="OSVDB" url="http://www.osvdb.org/24349">24349</ref><ref source="OSVDB" url="http://www.osvdb.org/24350">24350</ref><ref source="OSVDB" url="http://www.osvdb.org/24351">24351</ref><ref source="OSVDB" url="http://www.osvdb.org/24352">24352</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25587">awebbb-multiple-sql-injection(25587)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431064/100/0/threaded">20060415 [eVuln] aWebBB Multiple XSS and SQL Injection Vulnerabilities</ref></refs><vuln_soft><prod name="aWebBB" vendor="aWeb Labs"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1639" published="2006-04-06" seq="2006-1639" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in wpBlog 0.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter.</descript></desc><sols><sol source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is disabled.  This vulnerability may affect all previous versions of Wire Plastik Design, wpBlog before 0.4</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Evuln" url="http://evuln.com/vulns/119/summary.html">EV0119</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1238">ADV-2006-1238</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19538">19538</ref><ref source="BID" url="http://www.securityfocus.com/bid/17381">17381</ref><ref source="OSVDB" url="http://www.osvdb.org/24385">24385</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25628">wpblog-index-sql-injection(25628)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431186/100/0/threaded">20060417 [eVuln] Wire Plastik wpBlog SQL Injection Vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015951">1015951</ref><ref source="SREASON" url="http://securityreason.com/securityalert/734">734</ref></refs><vuln_soft><prod name="wpBlog" vendor="Wire Plastik Design"><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1640" published="2006-04-06" seq="2006-1640" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in news.php in CzarNews 1.14 allows remote attackers to inject arbitrary web script or HTML via the email parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://evuln.com/vulns/118/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1237">ADV-2006-1237</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19541">19541</ref><ref source="BID" url="http://www.securityfocus.com/bid/17380">17380</ref><ref source="OSVDB" url="http://www.osvdb.org/24381">24381</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431132/100/0/threaded">20060417 [eVuln] CzarNews XSS and Multiple SQL Injection Vulnerabilities</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015957">1015957</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25623">
czarnews-news-xss(25623)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/732">732</ref></refs><vuln_soft><prod name="CzarNews" vendor="Czaries Network"><vers num="1.14"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1641" published="2006-04-06" seq="2006-1641" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in CzarNews 1.14 allow remote attackers to execute arbitrary SQL commands via the (1) usern or (2) passw parameters to (a) cn_auth.php, (3) s parameter to (b) news.php, or (4) a parameter to (c) dpost.php.</descript></desc><sols><sol source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is disabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Evuln" url="http://evuln.com/vulns/118/summary.html">EV0118</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1237">ADV-2006-1237</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19541">19541</ref><ref source="BID" url="http://www.securityfocus.com/bid/17380">17380</ref><ref source="OSVDB" url="http://www.osvdb.org/24382">24382</ref><ref source="OSVDB" url="http://www.osvdb.org/24383">24383</ref><ref source="OSVDB" url="http://www.osvdb.org/24384">24384</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431132/100/0/threaded">20060417 [eVuln] CzarNews XSS and Multiple SQL Injection Vulnerabilities</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015957">1015957</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25624">
czarnews-multiple-sql-injection(25624)</ref></refs><vuln_soft><prod name="CzarNews" vendor="Czaries Network"><vers num="1.14" prev="1"/><vers num="1.13b"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1642" published="2006-04-06" seq="2006-1642" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Interact 2.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) the search_terms parameter to (a) search.php, and (2) the first_name, (3) last_name, (4) email, (5) password, and (6) confirm_password parameters to (b) userinput.php.  NOTE: the provenance of this information is unknown; the details are obtained from third party.  In addition, the lack of precision in the third party descriptions makes it unclear whether the named vectors are correct.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1244">ADV-2006-1244</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19488">19488</ref><ref source="OSVDB" url="http://www.osvdb.org/24389">24389</ref><ref source="OSVDB" url="http://www.osvdb.org/24461">24461</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25652">interact-search-xss(25652)</ref></refs><vuln_soft><prod name="Interact" vendor="Interact"><vers num="2.1.1" prev="1"/><vers num="2.1"/><vers num="2.0"/><vers num="1.9.1"/><vers num="1.9"/><vers num="1.8.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1643" published="2006-04-06" seq="2006-1643" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.php in Interact 2.1.1 allows remote attackers to execute arbitrary SQL commands via the user_name parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1244">ADV-2006-1244</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19488">19488</ref><ref source="BID" url="http://www.securityfocus.com/bid/17385">17385</ref><ref source="OSVDB" url="http://www.osvdb.org/24390">24390</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25653">interact-login-sql-injection(25653)</ref></refs><vuln_soft><prod name="Interact" vendor="Interact"><vers num="2.1.1" prev="1"/><vers num="2.1"/><vers num="2.0"/><vers num="1.9.1"/><vers num="1.9"/><vers num="1.8.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1644" published="2006-04-06" seq="2006-1644" severity="Medium" type="CVE"><desc><descript source="cve">login.php in Interact 2.1.1 generates different responses depending on whether or not a username is valid, which allows remote attackers to determine valid usernames.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1244">ADV-2006-1244</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19488">19488</ref><ref source="OSVDB" url="http://www.osvdb.org/24388">24388</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25651">interact-login-error-info-disclosure(25651)</ref></refs><vuln_soft><prod name="Interact" vendor="Interact"><vers num="2.1.1" prev="1"/><vers num="2.1"/><vers num="2.0"/><vers num="1.9.1"/><vers num="1.9"/><vers num="1.8.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-02" modified="2006-04-07" name="CVE-2006-1645" published="2006-04-06" seq="2006-1645" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Anton Vlasov and Rostislav Gaitkuloff ReloadCMS 1.2.5 and earlier allows remote attackers to inject arbitrary web script or HTML and gain leverage to execute arbitrary PHP code via the User-Agent HTTP header, which is displayed by admin/modules/general/statistic.php in the administration panel.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429666/100/0/threaded">20060402 ReloadCMS &lt;= 1.2.5stable Cross site scripting / remote command execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/17353">17353</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1193">ADV-2006-1193</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19470">19470</ref><ref source="OSVDB" url="http://www.osvdb.org/24327">24327</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25604">
reloadcms-useragent-xss(25604)</ref></refs><vuln_soft><prod name="ReloadCMS" vendor="ReloadCMS"><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2.0 p1"/><vers num="1.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1646" published="2006-04-06" seq="2006-1646" severity="Medium" type="CVE"><desc><descript source="cve">The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in the Shoichi Sakane KAME Project racoon, as used by NetBSD 1.6, 2.x before 20060119, certain FreeBSD releases, and possibly other distributions of BSD or Linux operating systems, when running in aggressive mode, allows remote attackers to cause a denial of service (daemon crash) via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c09/isakmp/"></ref><ref source="" url="http://www.niscc.gov.uk/niscc/docs/re-20051114-01014.pdf?lang=en"></ref><ref source="" url="http://mail-index.netbsd.org/source-changes/2006/01/19/0017.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19463">19463</ref></refs><vuln_soft><prod name="Internet Key Exchange" vendor="Internet Key Exchange"><vers num="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-02-05" modified="2006-04-07" name="CVE-2006-1647" published="2006-04-06" seq="2006-1647" severity="High" type="CVE"><desc><descript source="cve">An unspecified &quot;logical programming mistake&quot; in SMART SynchronEyes Student and Teacher 6.0, and possibly earlier versions, allows remote attackers to cause a denial of service via a large packet to the Teacher discovery port (UDP port 5496), which causes a thread to terminate and prevents communications on that port.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429843/100/0/threaded">20060404 SMART Technologies SynchronEyes Remote Denial of Services</ref><ref source="BID" url="http://www.securityfocus.com/bid/17373">17373</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1241">ADV-2006-1241</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015869">1015869</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19535">19535</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25659">
synchroneyes-datagram-dos(25659)</ref></refs><vuln_soft><prod name="SynchronEyes" vendor="SMART Technologies"><vers num="6.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-02-05" modified="2006-04-07" name="CVE-2006-1648" published="2006-04-06" seq="2006-1648" severity="Medium" type="CVE"><desc><descript source="cve">SMART SynchronEyes Student and Teacher 6.0, and possibly earlier versions, allows remote attackers to cause a denial of service (memory consumption) via a certain packet to the Teacher discovery port that causes SynchronEyes to connect to the attacker&apos;s machine and read a value that is used as a parameter to malloc.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429843/100/0/threaded">20060404 SMART Technologies SynchronEyes Remote Denial of Services</ref><ref source="BID" url="http://www.securityfocus.com/bid/17373">17373</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1241">ADV-2006-1241</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015869">1015869</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19535">19535</ref><ref source="OSVDB" url="http://www.osvdb.org/24392">24392</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25663">
synchroneyes-packet-dos(25663)</ref></refs><vuln_soft><prod name="SynchronEyes" vendor="SMART Technologies"><vers num="6.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" discovered="2006-03-24" modified="2006-12-21" name="CVE-2006-1649" published="2006-04-06" seq="2006-1649" severity="High" type="CVE"><desc><descript source="cve">The &quot;restore to&quot; selection in the &quot;quarantine a file&quot; capability of ESET NOD32 before 2.51.26 allows a restore to any directory that permits read access by the invoking user, which allows local users to create new files despite write-access directory permissions.</descript></desc><sols><sol source="nvd">ESET NOD32 Antivirus version 2.51.26 fixes this vulnerability.  All versions of this product prior to 2.51.26 are vulnerable.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429892/100/0/threaded">20060404 NOD32 local privilege escalation vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17374">17374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19054">19054</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1242">ADV-2006-1242</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015867">1015867</ref><ref source="OSVDB" url="http://www.osvdb.org/24393">24393</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25640">nod32-restoreto-file-upload(25640)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/672">672</ref></refs><vuln_soft><prod name="NOD32 Antivirus" vendor="Eset Software"><vers num="2.5"/><vers num="1.0.13"/><vers num="1.0.12"/><vers num="1.0.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" discovered="2006-04-04" modified="2007-08-27" name="CVE-2006-1650" published="2006-04-06" seq="2006-1650" severity="Medium" type="CVE"><desc><descript source="cve">Firefox 1.5.0.1 allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading.  NOTE: a followup was unable to replicate this issue.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429927/100/0/threaded">20060404 Re: Another Internet Explorer Address Bar Spoofing Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430348/30/5730/threaded">20060406 Re: Re: Another Internet Explorer Address Bar Spoofing Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25634">ie-swf-addressbar-spoofing(25634)</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-03" modified="2006-04-07" name="CVE-2006-1651" published="2006-04-06" seq="2006-1651" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Microsoft ISA Server 2004 allows remote attackers to bypass certain filtering rules, including ones for (1) ICMP and (2) TCP, via IPv6 packets.  NOTE: An established researcher has disputed this issue, saying that &quot;Neither ISA Server 2004 nor Windows 2003 Basic Firewall support IPv6 filtering ... This is different network protocol.&quot;</descript></desc><sols><sol source="nvd">This vulnerability has been disputed.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429816/100/0/threaded">20060403 Bypassing ISA Server 2004 with IPv6</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429846/100/0/threaded">20060404 Re: Bypassing ISA Server 2004 with IPv6</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430281/100/0/threaded">20060405 Re: Re: Bypassing ISA Server 2004 with IPv6</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430684/100/0/threaded">20060410 Re: Bypassing ISA Server 2004 with IPv6</ref></refs><vuln_soft><prod name="ISA Server" vendor="Microsoft"><vers num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-04" modified="2006-08-28" name="CVE-2006-1652" published="2006-04-06" seq="2006-1652" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-assisted remote attackers to execute arbitrary code via a malicious server that sends a long string to a client that connects on TCP port 5900, which triggers an overflow in Log::ReallyPrint; and (2) allow remote attackers to cause a denial of service (server crash) via a long HTTP GET request to TCP port 5800, which triggers an overflow in VNCLog::ReallyPrint.</descript></desc><sols><sol source="nvd">There are two seperate vulnerabilities here;  One allows escalated priveleges to authenticated users, the other allows remote unauthenticated users to cause a Denial of Service (DoS).</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429930/100/0/threaded">20060404 Buffer-overflow in Ultr@VNC 1.0.1 viewer and server</ref><ref source="Milw0rm" url="http://milw0rm.com/exploits/1642">exploit 1642</ref><ref source="Milw0rm" url="http://milw0rm.com/exploits/1643">exploit 1643</ref><ref source="BID" url="http://www.securityfocus.com/bid/17378">17378</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430287/100/0/threaded">20060405 Re: Buffer-overflow in Ultr@VNC 1.0.1 viewer and server</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1240">ADV-2006-1240</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19513">19513</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430711/100/0/threaded">20060411 Re: Buffer-overflow in Ultr@VNC 1.0.1 viewer POC</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/044901.html">
20060404 Buffer-overflow in Ultr@VNC 1.0.1 viewer and server</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25650">
ultr@vnc-vnclogreallyprint-bo(25650)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25648">
untr@vnc-error-bo(25648)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/674">674</ref></refs><vuln_soft><prod name="tabbed_viewer" vendor="UltraVNC"><vers num="1.29"/></prod><prod name="VNC Viewer" vendor="UltraVNC"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1653" published="2006-04-06" seq="2006-1653" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in loadkernel.php in AngelineCMS 0.8.1 allows remote attackers to execute arbitrary PHP code via a URL in the installPath parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://advisories.echo.or.id/adv/adv27-K-159-2006.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17371">17371</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429983/100/0/threaded">20060404 [ECHO_ADV_27$2006] AngelineCMS 0.8.1 Installpath Remote File Inclusion</ref><ref source="OSVDB" url="http://www.osvdb.org/24610">24610</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25658">
angelinecms-loadkernel-file-include(25658)</ref></refs><vuln_soft><prod name="AngelineCMS" vendor="AngelineCMS"><vers num="0.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1654" published="2006-04-06" seq="2006-1654" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0085.html">20060404 [SEC-1 LTD] HP Colour LaserJet 2500 and 4600 Toolbox Directory Traversal Vulnerability</ref><ref patch="1" source="HP" url="http://www.securityfocus.com/archive/1/archive/1/429893/100/0/threaded">HPSBPI2109</ref><ref source="BID" url="http://www.securityfocus.com/bid/17367">17367</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1230">ADV-2006-1230</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015862">1015862</ref><ref source="HP" url="http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00634759">HPSBPI2109</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429984/100/0/threaded">20060404 [SEC-1 LTD] HP Colour LaserJet 2500 and 4600 Toolbox Directory Traversal Vulnerability</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19529">19529</ref><ref source="OSVDB" url="http://www.osvdb.org/24396">24396</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25627">hp-laserjet-toolbox-directory-traversal(25627)</ref></refs><vuln_soft><prod name="Color LaserJet" vendor="HP"><vers num="4600 Toolbox"/><vers num="2500 Toolbox"/><vers num="2500"/><vers num="2500L"/><vers num="2500Lse"/><vers num="2500n"/><vers num="2500tn"/><vers num="4600"/><vers num="4600dn"/><vers num="4600dtn"/><vers num="4600hdn"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-03" modified="2006-08-28" name="CVE-2006-1655" published="2006-04-06" seq="2006-1655" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in mpg123 0.59r allow user-assisted attackers to trigger a segmentation fault and possibly have other impacts via a certain MP3 file, as demonstrated by mpg1DoS3.  NOTE: this issue might be related to CVE-2004-0991, but it is not clear.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="SecurityFocus" url="http://downloads.securityfocus.com/vulnerabilities/exploits/mpg1DoS3.pl">mpg123 DoS Proof of Concept</ref><ref source="BID" url="http://www.securityfocus.com/bid/17365">17365</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1074">DSA-1074</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20240">20240</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20275">20275</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:092">MDKSA-2006:092</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20281">20281</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:092">MDKSA-2006:092</ref></refs><vuln_soft><prod name="mpg123" vendor="mpg123"><vers num="0.59r"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-02" modified="2006-04-07" name="CVE-2006-1656" published="2006-04-06" seq="2006-1656" severity="High" type="CVE"><desc><descript source="cve">vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is invalid and non-numeric, which might cause local users to inadvertently execute dangerous commands as root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="GNU" url="https://savannah.nongnu.org/patch/?func=detailitem&amp;item_id=4966"></ref><ref patch="1" source="Debian" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=360438">#360438</ref><ref source="GNU" url="https://savannah.nongnu.org/bugs/?func=detailitem&amp;item_id=15996"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17361">17361</ref></refs><vuln_soft><prod name="util-vserver" vendor="VServer"><vers num="0.30.210" prev="1"/><vers num="0.30.209"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1657" published="2006-04-07" seq="2006-1657" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Chucky A. Ivey N.T. 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter, which is not filtered when the administrator views the &quot;Login Log&quot; page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/121/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1243">ADV-2006-1243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19526">19526</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431344/100/0/threaded">20060419 [eVuln] N.T. Version 1.1.0 XSS and PHP Code Insertion Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17387">17387</ref><ref source="OSVDB" url="http://www.osvdb.org/24397">24397</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25638">
nt-index-xss(25638)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/741">741</ref></refs><vuln_soft><prod name="N.T." vendor="Chucky A. Ivey"><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1658" published="2006-04-07" seq="2006-1658" severity="High" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in ticker.db.php in Chucky A. Ivey N.T.  1.1.0 allows remote administrators to insert arbitrary PHP code into the config file, which is included other N.T. scripts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/121/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1243">ADV-2006-1243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19526">19526</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431344/100/0/threaded">20060419 [eVuln] N.T. Version 1.1.0 XSS and PHP Code Insertion Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17387">17387</ref><ref source="OSVDB" url="http://www.osvdb.org/24398">24398</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25639">
nt-ticker-file-include(25639)</ref></refs><vuln_soft><prod name="N.T." vendor="Chucky A. Ivey"><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" discovered="2006-03-31" modified="2007-01-04" name="CVE-2006-1659" published="2006-04-07" seq="2006-1659" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Softbiz Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in image_desc.php, (2) provided parameter in template.php, (3) cid parameter in suggest_image.php, (4) img_id parameter in insert_rating.php, and (5) cid parameter in images.php.</descript></desc><sols><sol source="nvd">This vulnerability most likely affects all versions of Softbiz, Image Gallery.</sol></sols><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429763/100/0/threaded">20060331 SQL Injection in Softbiz Image Gallery</ref><ref source="BID" url="http://www.securityfocus.com/bid/17339">17339</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1217">ADV-2006-1217</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19523">19523</ref><ref source="OSVDB" url="http://www.osvdb.org/24368">24368</ref><ref source="OSVDB" url="http://www.osvdb.org/24369">24369</ref><ref source="OSVDB" url="http://www.osvdb.org/24370">24370</ref><ref source="OSVDB" url="http://www.osvdb.org/24371">24371</ref><ref source="OSVDB" url="http://www.osvdb.org/24372">24372</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25616">
softbizimagegallery-multiple-sql-injection(25616)</ref></refs><vuln_soft><prod name="Image Gallery" vendor="Softbiz"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1660" published="2006-04-07" seq="2006-1660" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in image_desc.php in Softbiz Image Gallery allows remote attackers to inject arbitrary web script or HTML via msg parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript></desc><sols><sol source="nvd">This vulnerability most likely affects all versions of Softbiz, Image Gallery.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1217">ADV-2006-1217</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19523">19523</ref></refs><vuln_soft><prod name="Image Gallery" vendor="Softbiz"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-04-05" modified="2007-01-04" name="CVE-2006-1661" published="2006-04-07" seq="2006-1661" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SKForum 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) areaID parameter in area.View.action, (2) time parameter in planning.View.action, and (3) userID parameter in user.View.action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Blogspot" url="http://pridels.blogspot.com/2006/04/skforum-xss-vuln.html">SKForum XSS vuln. </ref><ref source="BID" url="http://www.securityfocus.com/bid/17389">17389</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1260">ADV-2006-1260</ref><ref source="OSVDB" url="http://www.osvdb.org/24430">24430</ref><ref source="OSVDB" url="http://www.osvdb.org/24431">24431</ref><ref source="OSVDB" url="http://www.osvdb.org/24432">24432</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19484">19484</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25641">skforum-multiple-xss(25641)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/skforum-xss-vuln.html"></ref></refs><vuln_soft><prod name="SKForum" vendor="SK Soft"><vers num="1.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1662" published="2006-04-07" seq="2006-1662" severity="High" type="CVE"><desc><descript source="cve">The frontpage option in Limbo CMS 1.0.4.2 and 1.0.4.1 allows remote attackers to execute arbitrary PHP commands via the Itemid parameter in index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/426428">20060228 Limbo CMS code execution</ref><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429946/100/0/threaded">20060404 Re: Limbo CMS code execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/16902">16902</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0728.html">
20060228 Limbo CMS code execution</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24992">
limbocms-index-code-execution(24992)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/519">519</ref></refs><vuln_soft><prod name="Limbo CMS" vendor="Limbo CMS"><vers num="1.0.4.2"/><vers num="1.0.4.1"/></prod></vuln_soft></entry><entry modified="2006-04-13" name="CVE-2006-1663" published="2006-04-07" reject="1" seq="2006-1663" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0996.  Reason: This candidate is a reservation duplicate of CVE-2006-0996.  Notes: All CVE users should reference CVE-2006-0996 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1664" published="2006-04-07" seq="2006-1664" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, allows remote attackers to execute arbitrary code via a crafted MPEG stream.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.securityfocus.com/data/vulnerabilities/exploits/xinelib_poc.pl"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17370">17370</ref><ref source="" url="http://milw0rm.com/exploits/1641"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015868">1015868</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-16.xml">GLSA-200604-16</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19853">19853</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19856">19856</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25670">
xinelib-mpeg-bo(25670)</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?group_id=9655&amp;release_id=571608"></ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00956.html">FEDORA-2008-1043</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00976.html">FEDORA-2008-1047</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28666">28666</ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=128838"></ref></refs><vuln_soft><prod name="xine-lib" vendor="xine"><vers num="1.1.1"/><vers num="1.1.0"/><vers num="1.0.3a"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.13"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-12" name="CVE-2006-1665" published="2006-04-07" seq="2006-1665" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0.1 stable allow remote attackers to inject arbitrary web script or HTML via the (1) adminJump and (2) forum_middle parameters in (a) forum.php, and the (3) form parameter in (b) members.php, (c) pm.php, and (d) mail.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429940/100/0/threaded">20060404 ArabPortal 2.0.1 Stable [ 9 CrossSiteScripting &amp; 1 SQL Injection ] MultBugz</ref><ref source="BID" url="http://www.securityfocus.com/bid/17375">17375</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25657">
arabportal-multiple-xss(25657)</ref></refs><vuln_soft><prod name="Arab Portal" vendor="Arab Portal"><vers num="2.0.1 stable"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1666" published="2006-04-07" seq="2006-1666" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in forum.php in Arab Portal 2.0.1 stable allows remote attackers to execute arbitrary SQL commands via the mineID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/429940/100/0/threaded">20060404 ArabPortal 2.0.1 Stable [ 9 CrossSiteScripting &amp; 1 SQL Injection ] MultBugz</ref><ref source="BID" url="http://www.securityfocus.com/bid/17375">17375</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25656">
arabportal-forum-sql-injection(25656)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/644">644</ref></refs><vuln_soft><prod name="Arab Portal" vendor="Arab Portal"><vers num="2.0.1 stable"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-10" name="CVE-2006-1667" published="2006-04-07" seq="2006-1667" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to execute arbitrary SQL commands via the limitquery_s parameter when the $projectid variable is less than 1, which prevents the $limitquery_s from being set within slides.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://bash-x.net/undef/adv/craftygallery.html"></ref><ref source="" url="http://bash-x.net/undef/exploits/crappy_syntax.txt"></ref><ref source="" url="http://milw0rm.com/exploits/1645"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17379">17379</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1239">ADV-2006-1239</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19478">19478</ref><ref source="OSVDB" url="http://www.osvdb.org/24386">24386</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25654">crafty-slides-sql-injection(25654)</ref></refs><vuln_soft><prod name="Crafty Syntax Image Gallery" vendor="Crafty Syntax Image Gallery"><vers num="3.1g"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-04" modified="2006-04-07" name="CVE-2006-1668" published="2006-04-07" seq="2006-1668" severity="High" type="CVE"><desc><descript source="cve">newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to upload and execute arbitrary PHP code via a multipart/form-data POST with a .jpg filename in the fullimage parameter and the ext parameter set to .php.</descript></desc><sols><sol source="nvd">Successful exploitation requires privileges to upload images.  This product is also known as PHP thumbnail Photo Gallery.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://bash-x.net/undef/adv/craftygallery.html"></ref><ref source="" url="http://bash-x.net/undef/exploits/crappy_syntax.txt"></ref><ref source="Milw0rm" url="http://milw0rm.com/exploits/1645">exploit 1645</ref><ref source="BID" url="http://www.securityfocus.com/bid/17379">17379</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1239">ADV-2006-1239</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19478">19478</ref><ref source="OSVDB" url="http://www.osvdb.org/24387">24387</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25655">crafty-http-post-code-execution(25655)</ref></refs><vuln_soft><prod name="Crafty Syntax Image Gallery" vendor="Crafty Syntax Image Gallery"><vers num="3.1g" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" discovered="2006-04-05" modified="2007-01-04" name="CVE-2006-1669" published="2006-04-07" seq="2006-1669" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in chat/messagesL.php3 in phpHeaven Team PHPMyChat 0.14.5 and earlier allows remote attackers to execute arbitrary SQL commands via the T parameter.  NOTE: this issue can be leveraged to execute arbitrary shell commands since the username is later processed in an eval() call, but since the username originated from the SQL injection, it could be a resultant issue.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://milw0rm.com/exploits/1646">exploit 1646</ref><ref source="BID" url="http://www.securityfocus.com/bid/17382">17382</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430358/100/0/threaded">20060405 PHPMyChat &lt;= 0.14.5 remote commands execution</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015873">1015873</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25687">
phpmychat-messagesl-sql-injection(25687)</ref></refs><vuln_soft><prod name="phpMyChat" vendor="phpHeaven"><vers num="0.14.5" prev="1"/><vers num="0.14.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-07" name="CVE-2006-1670" published="2006-04-07" seq="2006-1670" severity="High" type="CVE"><desc><descript source="cve">Control cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (memory exhaustion and possibly card reset) by sending an invalid response when the final ACK is expected, aka bug ID CSCei45910.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20060405-ons.shtml">20060405 Cisco Optical Networking System 15000 Series and Cisco Transport Controller Vulnerabilities</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17384">17384</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1256">ADV-2006-1256</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015872">1015872</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19553">19553</ref><ref source="OSVDB" url="http://www.osvdb.org/24434">24434</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25643">
cisco-ons-iplan-ack-dos(25643)</ref></refs><vuln_soft><prod name="ONS 15454 MSPP" vendor="Cisco"><vers num=""/></prod><prod name="ONS 15600" vendor="Cisco"><vers num="1.3 (0)"/><vers num="1.1 (1)"/><vers num="1.1 (0)"/><vers num="1.1"/><vers num="1.0"/></prod><prod name="ONS 15327" vendor="Cisco"><vers num="4.14"/><vers num="4.6 (1)"/><vers num="4.6 (0)"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod><prod name="ONS 15600 Series" vendor="Cisco"><vers num=""/></prod><prod name="ONS 15310-CL Series" vendor="Cisco"><vers num=""/></prod><prod name="ONS 15454 MSTP" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-10" name="CVE-2006-1671" published="2006-04-07" seq="2006-1671" severity="Medium" type="CVE"><desc><descript source="cve">Control cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (card reset) via (1) a &quot;crafted&quot; IP packet to a device with secure mode EMS-to-network-element access, aka bug ID CSCsc51390; (2) a &quot;crafted&quot; IP packet to a device with IP on the LAN interface, aka bug ID CSCsd04168; and (3) a &quot;malformed&quot; OSPF packet, aka bug ID CSCsc54558.</descript></desc><sols><sol source="nvd">The vendor has released fixes to address these issues.</sol></sols><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20060405-ons.shtml">20060405 Cisco Optical Networking System 15000 Series and Cisco Transport Controller Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17384">17384</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1256">ADV-2006-1256</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015872">1015872</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19553">19553</ref><ref source="OSVDB" url="http://www.osvdb.org/24435">24435</ref><ref source="OSVDB" url="http://www.osvdb.org/24436">24436</ref><ref source="OSVDB" url="http://www.osvdb.org/24437">24437</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25646">
cisco-ons-ospf-dos(25646)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25644">
cisco-ons-cc-ems-dos(25644)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25645">
cisco-ons-cc-ip-dos(25645)</ref></refs><vuln_soft><prod name="ONS 15600" vendor="Cisco"><vers num="1.3 (0)"/><vers num="1.1 (1)"/><vers num="1.1 (0)"/><vers num="1.1"/><vers num="1.0"/></prod><prod name="ONS 15600 Series" vendor="Cisco"><vers num="0"/></prod><prod name="ONS 15310-CL Series" vendor="Cisco"><vers num="0"/></prod><prod name="ONS 15454" vendor="Cisco"><vers num="MSTP 0"/><vers num="MSPP 0"/></prod><prod name="ONS 15327" vendor="Cisco"><vers num="4.14"/><vers num="4.6 (1)"/><vers num="4.6 (0)"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod><prod name="Transport Controller" vendor="Cisco"><vers num="4.0.x"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-10" name="CVE-2006-1672" published="2006-04-07" seq="2006-1672" severity="High" type="CVE"><desc><descript source="cve">The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a wildcard that grants the java.security.AllPermission permission to any http URL containing &quot;fs/LAUNCHER.jar&quot;, which allows remote attackers to execute arbitrary code on a CTC workstation, aka bug ID CSCea25049.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20060405-ons.shtml">20060405 Cisco Optical Networking System 15000 Series and Cisco Transport Controller Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17384">17384</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1256">ADV-2006-1256</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015871">1015871</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19553">19553</ref><ref source="OSVDB" url="http://www.osvdb.org/24438">24438</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25647">cisco-ons-ctc-code-execution(25647)</ref></refs><vuln_soft><prod name="ONS 15600" vendor="Cisco"><vers num="1.3 (0)"/><vers num="1.1 (1)"/><vers num="1.1 (0)"/><vers num="1.1"/><vers num="1.0"/></prod><prod name="ONS 15600 Series" vendor="Cisco"><vers num="0"/></prod><prod name="ONS 15310-CL Series" vendor="Cisco"><vers num="0"/></prod><prod name="ONS 15454" vendor="Cisco"><vers num="MSTP 0"/><vers num="MSPP 0"/></prod><prod name="ONS 15327" vendor="Cisco"><vers num="4.14"/><vers num="4.6 (1)"/><vers num="4.6 (0)"/><vers num="4.1 (3)"/><vers num="4.1 (2)"/><vers num="4.1 (1)"/><vers num="4.1 (0)"/><vers num="4.0 (2)"/><vers num="4.0 (1)"/><vers num="4.0"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod><prod name="Transport Controller" vendor="Cisco"><vers num="4.0.x"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-05" modified="2006-04-10" name="CVE-2006-1673" published="2006-04-07" seq="2006-1673" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in vbugs.php in Dark_Wizard vBug Tracker 3.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/vbug-tracker-for-vbulletin-35x-xss.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17407">17407</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1267">ADV-2006-1267</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19562">19562</ref><ref source="OSVDB" url="http://www.osvdb.org/24448">24448</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25649">
vbulletin-vbugtracker-vbugs-xss(25649)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/vbug-tracker-for-vbulletin-35x-xss.html"></ref></refs><vuln_soft><prod name="vBug Tracker" vendor="Jelsoft"><vers num="3.5.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-10" name="CVE-2006-1674" published="2006-04-10" seq="2006-1674" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in PHPWebGallery 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vulnerability than CVE-2006-1675.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.Silitix.com/phpwebgallery"></ref></refs><vuln_soft><prod name="PhpWebGallery" vendor="PhpWebGallery"><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-10" name="CVE-2006-1675" published="2006-04-10" seq="2006-1675" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHPWebGallery 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) num, and (3) search parameters to (a) category.php, and the (4) slideshow, (5) show_metadata, and (6) start parameters to (b) picture.php, a different vulnerability than CVE-2006-1674.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17421">17421</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430481/100/0/threaded">20060410 PHPWebGallery Multiple Cross Site Scripting Vulnerabilities</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1301">ADV-2006-1301</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19610">19610</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25733">
phpwebgallery-category-picture-xss(25733)</ref></refs><vuln_soft><prod name="PhpWebGallery" vendor="PhpWebGallery"><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-1676" published="2006-04-10" seq="2006-1676" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the display function in the Topics module for MAXdev MDPro (MD-Pro) 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a display action, which is not properly handled in PNuserapi.PHP.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430370/100/0/threaded">20060406 MAXDEV CMS Multiple vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17399">17399</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1282">ADV-2006-1282</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19578">19578</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/437831/100/100/threaded">20060620 Re: MAXDEV CMS Multiple vulnerabilities</ref><ref source="" url="http://www.maxdev.com/Article592.phtml"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25710">mdpro-index-sql-injection(25710)</ref></refs><vuln_soft><prod name="MD-Pro" vendor="MAXdev"><vers num="1.0.72"/><vers num="1.0.73"/><vers num="1.0.75" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-06-30" name="CVE-2006-1677" published="2006-04-10" seq="2006-1677" severity="Medium" type="CVE"><desc><descript source="cve">MAXdev MDPro 1.0.73 and 1.0.72, and possibly other versions before 1.076, allows remote attackers to obtain the full path of the server via a direct request to includes/legacy.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430370/100/0/threaded">20060406 MAXDEV CMS Multiple vulnerabilities</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1282">ADV-2006-1282</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19578">19578</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/437831/100/100/threaded">20060620 Re: MAXDEV CMS Multiple vulnerabilities</ref><ref source="" url="http://www.maxdev.com/Article592.phtml"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25714">
mdpro-legacy-path-disclosure(25714)</ref></refs><vuln_soft><prod name="MD-Pro" vendor="MAXdev"><vers num="1.0.72"/><vers num="1.0.73"/><vers num="1.0.75" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-11" name="CVE-2006-1678" published="2006-04-10" seq="2006-1678" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.8.0.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors in unspecified scripts in the themes directory.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2006-1"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17390">17390</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1263">ADV-2006-1263</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19556">19556</ref><ref source="OSVDB" url="http://www.osvdb.org/24450">24450</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25689">phpmyadmin-themes-xss(25689)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_28.html">SUSE-SR:2006:009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19897">19897</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1207">DSA-1207</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22781">22781</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.7.0 pl2"/><vers num="2.7.0 Beta1"/><vers num="2.7.0 pl1"/><vers num="2.7.0"/><vers num="2.6.4 rc1"/><vers num="2.6.4 pl4"/><vers num="2.6.4 pl3"/><vers num="2.6.4 pl1"/><vers num="2.6.3 pl1"/><vers num="2.6.2 rc1"/><vers num="2.6.2"/><vers num="2.6.1 pl3"/><vers num="2.6.1 pl1"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.0 pl3"/><vers num="2.6.0 pl2"/><vers num="2.6.0 pl1"/><vers num="2.5.7 pl1"/><vers num="2.5.7"/><vers num="2.5.6 rc1"/><vers num="2.5.5 pl1"/><vers num="2.5.5 rc2"/><vers num="2.5.5 rc1"/><vers num="2.5.5"/><vers num="2.5.4"/><vers num="2.5.3"/><vers num="2.5.2"/><vers num="2.5.1"/><vers num="2.5.0"/><vers num="2.4.0"/><vers num="2.3.2"/><vers num="2.3.1"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.0 rc3"/><vers num="2.2.0 rc2"/><vers num="2.2.0 rc1"/><vers num="2.2.0 pre2"/><vers num="2.2.0 pre1"/><vers num="2.2.0"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1679" published="2006-04-10" seq="2006-1679" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in modules/online.php in Jupiter CMS 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the layout parameter to index.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430391/100/0/threaded">20060407 Multiple vulnerability in jupiter CMS</ref><ref source="BID" url="http://www.securityfocus.com/bid/17405">17405</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1302">ADV-2006-1302</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19582">19582</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25700">
jupitercm-index-xss(25700)</ref></refs><vuln_soft><prod name="Jupiter CMS" vendor="Jupiter CMS"><vers num="1.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-11" name="CVE-2006-1680" published="2006-04-10" seq="2006-1680" severity="Low" type="CVE"><desc><descript source="cve">Jupiter CMS 1.1.5, when display_errors is enabled, allows remote attackers to obtain the full server path via a direct request to modules/online.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430391/100/0/threaded">20060407 Multiple vulnerability in jupiter CMS</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1302">ADV-2006-1302</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19582">19582</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25703">
jupitercm-online-path-disclosure(25703)</ref></refs><vuln_soft><prod name="Jupiter CMS" vendor="Jupiter CMS"><vers num="1.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-04" modified="2006-04-11" name="CVE-2006-1681" published="2006-04-10" seq="2006-1681" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Cherokee HTTPD 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a malformed request that generates an HTTP 400 error, which is not properly handled when the error message is generated.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430385/100/0/threaded">20060406 XSS Bug in Cherokee Webserver</ref><ref source="BID" url="http://www.securityfocus.com/bid/17408">17408</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/19587">19587</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1292">ADV-2006-1292</ref><ref source="OSVDB" url="http://www.osvdb.org/24469">24469</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25698">
cherokee-handlererror-xss(25698)</ref></refs><vuln_soft><prod name="Cherokee HTTPD" vendor="Cherokee"><vers num="0.5"/><vers num="0.4.17"/><vers num="0.4.9"/><vers num="0.4.8"/><vers num="0.4.7"/><vers num="0.4.6"/><vers num="0.2.7"/><vers num="0.2.6"/><vers num="0.2.5"/><vers num="0.2"/><vers num="0.1.6"/><vers num="0.1.5"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1682" published="2006-04-10" seq="2006-1682" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in webplus.exe in TalentSoft Web+Shop 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the deptname parameter, possibly involving the webpshop/ department.wml script.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/web-shop-50-xss.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17418">17418</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1289">ADV-2006-1289</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19594">19594</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25721">
webshop-deptname-xss(25721)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/web-shop-50-xss.html"></ref></refs><vuln_soft><prod name="Web+ Shop" vendor="TalentSoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-11" name="CVE-2006-1683" published="2006-04-10" seq="2006-1683" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in admin/login.php in Chipmunk Guestbook allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the User name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430315/100/0/threaded">20060407 SQL Injection in Chipmunk Guestbook</ref><ref source="BID" url="http://www.securityfocus.com/bid/17483">17483</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1323">ADV-2006-1323</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19584">19584</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25695">
chipmunk-guestbook-login-sql-injection(25695)</ref></refs><vuln_soft><prod name="Chipmunk Guestbook" vendor="Chipmunk PHP Scripts"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-11" name="CVE-2006-1684" published="2006-04-10" seq="2006-1684" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in ecotwo Shopsystem 1.0-192 and earlier allows remote attackers to include arbitrary local files via (1) the lang parameter in news.php and (2) other unspecified vectors.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/ecotwo-shopsystem-vuln.html"></ref><ref source="" url="http://pridels0.blogspot.com/2006/04/ecotwo-shopsystem-vuln.html"></ref></refs><vuln_soft><prod name="Shopsystem" vendor="ecotwo"><vers num="1.0_192"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-11" name="CVE-2006-1685" published="2006-04-10" seq="2006-1685" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in modules.php in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allow remote attackers to execute arbitrary SQL commands via the (1) group, (2) seite, and (3) id parameter, possibly involving the artikel functionality.  NOTE: this vulnerability also allows resultant path disclosure when the SQL queries are invalid.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/apt-webshop-system-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1293">ADV-2006-1293</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19592">19592</ref><ref source="BID" url="http://www.securityfocus.com/bid/17425">17425</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25731">
apt-webshop-sql-injection(25731)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/apt-webshop-system-vuln.html"></ref></refs><vuln_soft><prod name="APT-webshop-system" vendor="APT"><vers edition="Light" num="3.0"/><vers edition="Basic" num="3.0"/><vers edition="Pro" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-11" name="CVE-2006-1686" published="2006-04-10" seq="2006-1686" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in modules.php in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to access unspecified files via a modified warp parameter.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/apt-webshop-system-vuln.html"></ref><ref source="" url="http://pridels0.blogspot.com/2006/04/apt-webshop-system-vuln.html"></ref></refs><vuln_soft><prod name="APT-webshop-system" vendor="APT"><vers edition="Light" num="3.0"/><vers edition="Basic" num="3.0"/><vers edition="Pro" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-11" name="CVE-2006-1687" published="2006-04-10" seq="2006-1687" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to inject arbitrary web script or HTML via the message parameter, probably involving the basket functionality.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/apt-webshop-system-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1293">ADV-2006-1293</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19592">19592</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/apt-webshop-system-vuln.html"></ref></refs><vuln_soft><prod name="APT-webshop-system" vendor="APT"><vers edition="Light" num="3.0"/><vers edition="Basic" num="3.0"/><vers edition="Pro" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1688" published="2006-04-10" seq="2006-1688" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allow remote attackers to execute arbitrary PHP code via a URL in the libpath parameter to scripts in the lib directory including (1) ase.php, (2) devi.php, (3) doom3.php, (4) et.php, (5) flashpoint.php, (6) gameSpy.php, (7) gameSpy2.php, (8) gore.php, (9) gsvari.php, (10) halo.php, (11) hlife.php, (12) hlife2.php, (13) igi2.php, (14) main.lib.php, (15) netpanzer.php, (16) old_hlife.php, (17) pkill.php, (18) q2a.php, (19) q3a.php, (20) qworld.php, (21) rene.php, (22) rvbshld.php, (23) savage.php, (24) simracer.php, (25) sof1.php, (26) sof2.php, (27) unreal.php, (28) ut2004.php, and (29) vietcong.php. NOTE: the lib/armygame.php vector is already covered by CVE-2006-1610. The provenance of most of these additional vectors is unknown, although likely from post-disclosure analysis.  NOTE: this only occurs when register_globals is disabled.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/24401">24401</ref><ref source="OSVDB" url="http://www.osvdb.org/24402">24402</ref><ref source="OSVDB" url="http://www.osvdb.org/24403">24403</ref><ref source="OSVDB" url="http://www.osvdb.org/24404">24404</ref><ref source="OSVDB" url="http://www.osvdb.org/24405">24405</ref><ref source="OSVDB" url="http://www.osvdb.org/24406">24406</ref><ref source="OSVDB" url="http://www.osvdb.org/24407">24407</ref><ref source="OSVDB" url="http://www.osvdb.org/24408">24408</ref><ref source="OSVDB" url="http://www.osvdb.org/24421">24421</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19482">19482</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430289/100/0/threaded">20060408 Autonomous LAN party File iNclusion</ref><ref source="" url="http://liz0zim.no-ip.org/alp.txt"></ref><ref source="" url="http://www.blogcu.com/Liz0ziM/431845/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1284">ADV-2006-1284</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19588">19588</ref><ref source="BID" url="http://www.securityfocus.com/bid/17434">17434</ref><ref source="OSVDB" url="http://www.osvdb.org/24409">24409</ref><ref source="OSVDB" url="http://www.osvdb.org/24410">24410</ref><ref source="OSVDB" url="http://www.osvdb.org/24411">24411</ref><ref source="OSVDB" url="http://www.osvdb.org/24412">24412</ref><ref source="OSVDB" url="http://www.osvdb.org/24413">24413</ref><ref source="OSVDB" url="http://www.osvdb.org/24414">24414</ref><ref source="OSVDB" url="http://www.osvdb.org/24415">24415</ref><ref source="OSVDB" url="http://www.osvdb.org/24416">24416</ref><ref source="OSVDB" url="http://www.osvdb.org/24417">24417</ref><ref source="OSVDB" url="http://www.osvdb.org/24418">24418</ref><ref source="OSVDB" url="http://www.osvdb.org/24419">24419</ref><ref source="OSVDB" url="http://www.osvdb.org/24420">24420</ref><ref source="OSVDB" url="http://www.osvdb.org/24422">24422</ref><ref source="OSVDB" url="http://www.osvdb.org/24423">24423</ref><ref source="OSVDB" url="http://www.osvdb.org/24424">24424</ref><ref source="OSVDB" url="http://www.osvdb.org/24425">24425</ref><ref source="OSVDB" url="http://www.osvdb.org/24426">24426</ref><ref source="OSVDB" url="http://www.osvdb.org/24427">24427</ref><ref source="OSVDB" url="http://www.osvdb.org/24428">24428</ref><ref source="OSVDB" url="http://www.osvdb.org/24429">24429</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015884">1015884</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/439874/100/0/threaded">20060710 SQuery &lt;= 4.5(libpath) Remote File Inclusion Exploit</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/441015/100/0/threaded">20060724 SQuery v.x (devi.php) (armygame.php) Remote File Inclusion</ref><ref source="SREASON" url="http://securityreason.com/securityalert/679">679</ref></refs><vuln_soft><prod name="SQuery" vendor="SQuery"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-11" name="CVE-2006-1689" published="2006-04-10" seq="2006-1689" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in su in HP HP-UX B.11.11, when using the LDAP netgroup feature, allows local users to gain unspecified access.</descript></desc><sols><sol source="nvd">HP-UX B.11.11:
Install PHCO_34545 or later.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/430411/100/0/threaded">HPSBUX02111</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1272">ADV-2006-1272</ref><ref source="OSVDB" url="http://www.osvdb.org/24449">24449</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015874">1015874</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19560">19560</ref><ref source="BID" url="http://www.securityfocus.com/bid/17400">17400</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25691">
hpux-su-ldap-privilege-escalation(25691)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1754">oval:org.mitre.oval:def:1754</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="B.11.11"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-11" name="CVE-2006-1690" published="2006-04-11" seq="2006-1690" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in subscribe.php in MWNewsletter 1.0.0b allows remote attackers to inject arbitrary web script or HTML via the user_name parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/123/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1270">ADV-2006-1270</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19568">19568</ref><ref source="BID" url="http://www.securityfocus.com/bid/17412">17412</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0447.html">

20060421 [eVuln] MWNewsletter SQL Injection and XSS Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/24446">
24446</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25684">
mwnewsletter-subscribe-xss(25684)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/752">752</ref></refs><vuln_soft><prod name="MWNewsletter" vendor="Manic Web"><vers num="1.0.0b" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-11" name="CVE-2006-1691" published="2006-04-11" seq="2006-1691" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in MWNewsletter 1.0.0b allows remote attackers to execute arbitrary SQL commands via the user_name parameter to unsubscribe.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/123/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1270">ADV-2006-1270</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19568">19568</ref><ref source="BID" url="http://www.securityfocus.com/bid/17412">17412</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0447.html">

20060421 [eVuln] MWNewsletter SQL Injection and XSS Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/24905">
24905</ref><ref source="OSVDB" url="http://www.osvdb.org/24445">
24445</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25683">
mwnewsletter-unsubscribe-sql-injection(25683)</ref></refs><vuln_soft><prod name="MWNewsletter" vendor="Manic Web"><vers num="1.0.0b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-11" name="CVE-2006-1692" published="2006-04-11" seq="2006-1692" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in MWNewsletter 1.0.0b allow remote attackers to execute arbitrary SQL commands via the (1) user_email parameter to (a) unsubscribe.php or (b) subscribe.php; or the (2) user_name parameter to subscribe.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information, although it is likely that this was discovered during post-disclosure analysis.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1270">ADV-2006-1270</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19568">19568</ref><ref source="OSVDB" url="http://www.osvdb.org/24905">
24905</ref><ref source="OSVDB" url="http://www.osvdb.org/24445">
24445</ref></refs><vuln_soft><prod name="MWNewsletter" vendor="Manic Web"><vers num="1.0.0b"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-11" name="CVE-2006-1693" published="2006-04-11" seq="2006-1693" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in GlobalSCAPE Secure FTP Server before 3.1.4 Build 01.10.2006 allows attackers to cause a denial of service (application crash) via a &quot;custom command&quot; with a long argument.</descript></desc><sols><sol source="nvd">This issue is addressed in Secure FTP Server 3.1.4 Build 01.10.2006.</sol></sols><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://www.globalscape.com/gsftps/history.asp"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17398">17398</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/19547">19547</ref><ref source="OSVDB" url="http://www.osvdb.org/24451">24451</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25665">globalscape-custom-commands-dos(25665)</ref></refs><vuln_soft><prod name="Secure FTP Server" vendor="GlobalSCAPE"><vers num="3.1.3 Build2005-10-10"/><vers num="3.1.1 Build2005-08-08"/><vers num="3.0.4 Build2005-06-15"/><vers num="3.0.3 Build2005-04-29"/><vers num="3.0.2 Build2005-04-12"/><vers num="3.0"/><vers num="2.0 Build2004-03-16"/><vers num="2.0 Build2004-03-11"/><vers num="3.1 Build2005-07-06"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-11" name="CVE-2006-1694" published="2006-04-11" seq="2006-1694" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in members.php in XBrite Members 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/1655"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17424">17424</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1283">ADV-2006-1283</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19602">19602</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25708">
xbritemembers-id-sql-injection(25708)</ref></refs><vuln_soft><prod name="XBrite Members" vendor="XBrite"><vers num="1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-11" name="CVE-2006-1695" published="2006-04-11" seq="2006-1695" severity="Low" type="CVE"><desc><descript source="cve">The fbgs script in the fbi package 2.01-1.4, when the TMPDIR environment variable is not defined, allows local users to overwrite arbitrary files via a symlink attack on temporary files in /var/tmp/fbps-[PID].</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=361370"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1281">ADV-2006-1281</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19559">19559</ref><ref source="BID" url="http://www.securityfocus.com/bid/17436">17436</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-13.xml">GLSA-200604-13</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19766">19766</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1068">DSA-1068</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20166">20166</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_19_sr.html">SUSE-SR:2006:019</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21459">
21459</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25729">
fbida-fbgs-tmpdir-symlink(25729)</ref></refs><vuln_soft><prod name="fbida" vendor="fbida"><vers num="2.03"/><vers num="2.02"/><vers num="2.01"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-11" name="CVE-2006-1696" published="2006-04-11" seq="2006-1696" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Gallery before 1.5.3 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=408602&amp;group_id=7130"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1285">ADV-2006-1285</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19580">19580</ref><ref source="BID" url="http://www.securityfocus.com/bid/17437">17437</ref><ref source="OSVDB" url="http://www.osvdb.org/24466">
24466</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25707">
gallery-unspecified-xss(25707)</ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="1.5.2 pl2"/><vers num="1.5.2 pl1"/><vers num="1.5.2"/><vers num="1.5.2 rc3"/><vers num="1.5.2 rc2"/><vers num="1.5.1 rc2"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4.4 pl5"/><vers num="1.4.4 pl4"/><vers num="1.4.4 pl3"/><vers num="1.4.4 pl2"/><vers num="1.4.3 pl2"/><vers num="1.4.3 pl1"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4 pl2"/><vers num="1.4 pl1"/><vers num="1.4"/><vers num="1.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-05" name="CVE-2006-1697" published="2006-04-11" seq="2006-1697" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) Your Name, (2) E-Mail, or (3) Comments fields when posting a message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430356/100/0/threaded">20060408 Matt Wright Guestbook Xss Script Injection</ref><ref source="" url="http://liz0zim.no-ip.org/mattguestbook.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1287">ADV-2006-1287</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19586">19586</ref><ref source="BID" url="http://www.securityfocus.com/bid/17438">17438</ref><ref source="OSVDB" url="http://www.osvdb.org/24479">24479</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25697">
guestbook-guestbook-parameters-xss(25697)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/681">681</ref></refs><vuln_soft><prod name="Matt Wright GuestBook" vendor="Matt Wright"><vers num="2.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-05" name="CVE-2006-1698" published="2006-04-11" seq="2006-1698" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) url, (2) city, (3) state, or (4) country parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information, although it is likely that they are the result of post-disclosure analysis.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1287">ADV-2006-1287</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19586">19586</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25697">
guestbook-guestbook-parameters-xss(25697)</ref></refs><vuln_soft><prod name="Matt Wright GuestBook" vendor="Matt Wright"><vers num="2.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-12" name="CVE-2006-1699" published="2006-04-11" seq="2006-1699" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Aweb Banner Generator 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the banner parameter in view mode.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17416">17416</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015877">1015877</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1348">ADV-2006-1348</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19621">19621</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25782">
awebbannergenerator-index-xss(25782)</ref></refs><vuln_soft><prod name="Banner Generator" vendor="Aweb"><vers num="3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-12" name="CVE-2006-1700" published="2006-04-11" seq="2006-1700" severity="High" type="CVE"><desc><descript source="cve">Buy.php in Aweb Scripts Seller uses predictable cookies for authentication based on the time and the script number, which allows remote attackers to bypass authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17417">17417</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015878">1015878</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19626">19626</ref></refs><vuln_soft><prod name="Scripts Seller" vendor="Aweb"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-12" name="CVE-2006-1701" published="2006-04-11" seq="2006-1701" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Pages module in Shadowed Portal allows remote attackers to inject arbitrary web script or HTML via the page parameter to load.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430376/100/0/threaded">20060408 Shadowed Portal Cross Site Scripting</ref><ref source="" url="http://liz0zim.no-ip.org/shad0w.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1286">ADV-2006-1286</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19595">19595</ref><ref source="BID" url="http://www.securityfocus.com/bid/17430">17430</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25716">
shadowedportal-load-xss(25716)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/685">685</ref></refs><vuln_soft><prod name="Shadowed Portal" vendor="Shadowed Portal"><vers num="5.7d2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1702" published="2006-04-11" seq="2006-1702" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in spip_login.php3 in SPIP 1.8.3 allows remote attackers to execute arbitrary PHP code via a URL in the url parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430443/100/0/threaded">20060409 Vulnerabilities in SPIP</ref><ref source="BID" url="http://www.securityfocus.com/bid/17423">17423</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25711">
spip-spiplogin-file-include(25711)</ref></refs><vuln_soft><prod name="SPIP" vendor="SPIP"><vers num="1.8.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1703" published="2006-04-11" seq="2006-1703" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in lire.php in Sire 2.0 nws allows remote attackers to execute arbitrary PHP code via a URL in the rub parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430301/100/0/threaded">20060407 Sire 2.0 Nws Remote File inclusion &amp; Arbitary Files Upload</ref><ref source="BID" url="http://www.securityfocus.com/bid/17428">17428</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015885">1015885</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25726">
sire-lire-file-include(25726)</ref></refs><vuln_soft><prod name="Sire" vendor="Hubert Plisson"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1704" published="2006-04-11" seq="2006-1704" severity="Medium" type="CVE"><desc><descript source="cve">Sire 2.0 nws allows remote attackers to upload arbitrary image files without authentication via a direct request to upload.php.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430301/100/0/threaded">20060407 Sire 2.0 Nws Remote File inclusion &amp; Arbitary Files Upload</ref><ref source="BID" url="http://www.securityfocus.com/bid/17431">17431</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015885">1015885</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25727">
sire-upload-auth-bypass(25727)</ref></refs><vuln_soft><prod name="Sire" vendor="Hubert Plisson"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-02-24" modified="2006-05-01" name="CVE-2006-1705" published="2006-04-11" seq="2006-1705" severity="Low" type="CVE"><desc><descript source="cve">Oracle Database 9.2.0.0 to 10.2.0.3 allows local users with &quot;SELECT&quot; privileges for a base table to insert, update, or delete data by creating a crafted view then performing the operations on that view.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="" url="http://www.red-database-security.com/advisory/oracle_modify_data_via_views.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17426">17426</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1297">ADV-2006-1297</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015886">1015886</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19574">19574</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430434/100/0/threaded">20060410 Oracle read-only user can insert/update/delete data via specially crafted views</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/805737">VU#805737</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/044990.html">
20060410 Oracle read-only user can insert/update/delete data via specially crafted views</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25696">
oracle-base-table-data-manipulation(25696)</ref></refs><vuln_soft><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.3"/><vers num="Standard 9.2.0.7"/><vers num="Standard 9.2.0.6"/><vers num="Standard 9.2.0.5"/><vers num="Standard 9.2.0.3"/><vers num="Standard 9.2.0.2"/><vers num="Standard 9.2.0.1"/><vers num="Standard 9.2"/><vers num="Personal 9.2.0.6"/><vers num="Personal 9.2.0.5"/><vers num="Personal 9.2.0.3"/><vers num="Personal 9.2.0.2"/><vers num="Personal 9.2.0.1"/><vers num="Personal 9.2"/><vers num="Enterprise 9.2.0.6"/><vers num="Enterprise 9.2.0.5"/><vers num="Enterprise 9.2.0.3"/><vers num="Enterprise 9.2.0.2"/><vers num="Enterprise 9.2.0.1"/><vers num="Enterprise 9.2.0"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.2.3"/><vers num="Standard 10.2.0.1"/><vers num="Standard 10.1.0.5"/><vers num="Standard 10.1.0.4.2"/><vers num="Standard 10.1.0.4"/><vers num="Standard 10.1.0.3.1"/><vers num="Standard 10.1.0.3"/><vers num="Standard 10.1.0.2"/><vers num="Personal 10.2.3"/><vers num="Personal 10.1.0.4"/><vers num="Personal 10.1.0.3.1"/><vers num="Personal 10.1.0.3"/><vers num="Personal 10.1.0.2"/><vers num="Enterprise 10.2.3"/><vers num="Enterprise 10.1.0.4"/><vers num="Enterprise 10.1.0.3.1"/><vers num="Enterprise 10.1.0.3"/><vers num="Enterprise 10.1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1706" published="2006-04-11" seq="2006-1706" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (3) brandID, and (4) album parameters to (c) index.php.  NOTE: this issue also produces resultant full path disclosure from invalid SQL queries.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/shopweezle-20-multiple-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17441">17441</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1291">ADV-2006-1291</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19593">19593</ref><ref source="OSVDB" url="http://www.osvdb.org/24470">24470</ref><ref source="OSVDB" url="http://www.osvdb.org/24471">24471</ref><ref source="OSVDB" url="http://www.osvdb.org/24472">24472</ref><ref source="OSVDB" url="http://www.osvdb.org/24473">24473</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25724">shopweezle-multiple-path-disclosure(25724)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25723">shopweezle-multiple-sql-injection(25723)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/shopweezle-20-multiple-vuln.html"></ref></refs><vuln_soft><prod name="Shopweezle" vendor="kansok communications"><vers num="2.0"/><vers num="2.0 PERSONAL"/><vers num="2.0 PROFESSIONAL"/><vers num="2.0 PROFESSIONAL PLUS"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1707" published="2006-04-11" seq="2006-1707" severity="Medium" type="CVE"><desc><descript source="cve">index.php in Shopweezle 2.0 allows remote attackers to include arbitrary local files via the url parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/shopweezle-20-multiple-vuln.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/24474">24474</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25725">
shopweezle-index-file-include(25725)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/shopweezle-20-multiple-vuln.html"></ref></refs><vuln_soft><prod name="Shopweezle" vendor="kansok communications"><vers num="2.0"/><vers num="2.0 PERSONAL"/><vers num="2.0 PROFESSIONAL"/><vers num="2.0 PROFESSIONAL PLUS"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1708" published="2006-04-11" seq="2006-1708" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in member.php in Clansys 1.1 allows remote attackers to execute arbitrary SQL commands via the showid parameter in the member page to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/1662"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1295">ADV-2006-1295</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19609">19609</ref><ref source="BID" url="http://www.securityfocus.com/bid/17456">17456</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015935">1015935</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1662">

1662</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25746">
clansys-index-sql-injection(25746)</ref></refs><vuln_soft><prod name="Clansys" vendor="Clansys"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-04-10" modified="2007-01-04" name="CVE-2006-1709" published="2006-04-11" seq="2006-1709" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in shop_main.cgi in interaktiv.shop 5 allows remote attackers to inject arbitrary web script or HTML via the (1) pn and (2) sbeg parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Blogspot" url="http://pridels.blogspot.com/2006/04/interaktivshop-v5-xss-vuln.html">interaktiv.shop v.5 XSS vuln. </ref><ref source="BID" url="http://www.securityfocus.com/bid/17485">17485</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1326">ADV-2006-1326</ref><ref source="OSVDB" url="http://www.osvdb.org/24557">24557</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19622">19622</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25739">
interaktiv-shopmain-xss(25739)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/interaktivshop-v5-xss-vuln.html"></ref></refs><vuln_soft><prod name="interaktiv.shop" vendor="Interaktiv"><vers num="5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-08" modified="2006-04-12" name="CVE-2006-1710" published="2006-04-11" seq="2006-1710" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in admin.php in Design Nation DNGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) email and (2) id parameters.</descript></desc><sols><sol source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is disabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://milw0rm.com/exploits/1653">exploit 1653</ref><ref source="BID" url="http://www.securityfocus.com/bid/17435">17435</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1299">ADV-2006-1299</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19601">19601</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25699">dnguestbook-admin-sql-injection(25699)</ref></refs><vuln_soft><prod name="DNGuestbook" vendor="Design Nation"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-12" name="CVE-2006-1711" published="2006-04-11" seq="2006-1711" severity="Medium" type="CVE"><desc><descript source="cve">Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="" url="https://svn.plone.org/svn/plone/PloneHotfix20060410/trunk/README.txt"></ref><ref source="" url="http://dev.plone.org/plone/ticket/5432"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1032">DSA-1032</ref><ref source="BID" url="http://www.securityfocus.com/bid/17484">17484</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1340">ADV-2006-1340</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19633">19633</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19640">19640</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25781">
plone-memberid-data-manipulation(25781)</ref></refs><vuln_soft><prod name="Plone" vendor="Plone"><vers num="2.0.5"/><vers num="2.1.2"/><vers num="2.5 Beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-12" name="CVE-2006-1712" published="2006-04-11" seq="2006-1712" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the private archive script (private.py) in GNU Mailman 2.1.7 allows remote attackers to inject arbitrary web script or HTML via the action argument.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="MLIST" url="http://mail.python.org/pipermail/mailman-announce/2006-April/000084.html">[Mailman-Announce] 20060407 Released: Mailman 2.1.8 release candidate</ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=129136"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17403">17403</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1269">ADV-2006-1269</ref><ref source="OSVDB" url="http://www.osvdb.org/24442">24442</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015876">1015876</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19558">19558</ref><ref source="" url="http://www.mail-archive.com/mailman-checkins@python.org/msg06273.html"></ref></refs><vuln_soft><prod name="Mailman" vendor="GNU"><vers num="2.1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-10" modified="2006-04-12" name="CVE-2006-1713" published="2006-04-11" seq="2006-1713" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Christoph Roeder phpMyForum 4.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430480/100/0/threaded">20060410 phpMyForum Cross Site Scripting &amp; CRLF injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/17420">17420</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432455/100/0/threaded">20060425 Re: phpMyForum Cross Site Scripting &amp; CRLF injection</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25742">
phpmyforum-index-xss(25742)</ref></refs><vuln_soft><prod name="phpMyForum" vendor="phpMyForum"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-10" modified="2006-04-12" name="CVE-2006-1714" published="2006-04-11" seq="2006-1714" severity="High" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in index.php in Christoph Roeder phpMyForum 4.0 allows remote attackers to inject HTTP headers via hex-encoded CRLF sequences in the type parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430480/100/0/threaded">20060410 phpMyForum Cross Site Scripting &amp; CRLF injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/17420">17420</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432455/100/0/threaded">20060425 Re: phpMyForum Cross Site Scripting &amp; CRLF injection</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25750">
phpmyforum-index-crlf-injection(25750)</ref></refs><vuln_soft><prod name="phpMyForum" vendor="phpMyForum"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" discovered="2006-04-10" modified="2007-06-26" name="CVE-2006-1715" published="2006-04-11" seq="2006-1715" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in Christian Kindahl TUGZip 3.4.0.0, 3.3.0.0, and 3.1.0.2 allow user-assisted attackers to create files in arbitrary directories via a .. (dot dot) in an archive pack with a crafted (1) .gz, (2) .jar, (3) .rar, or (4) .zip file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430433/100/0/threaded">20060410 TUGZip Archive Extraction Directory traversal</ref><ref source="" url="http://www.hamid.ir/security/tugzip.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17432">17432</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25713">tugzip-archive-directory-traversal(25713)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/686">686</ref></refs><vuln_soft><prod name="TUGZip" vendor="TUGZip"><vers num="3.4"/><vers num="3.3"/><vers num="3.1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-02" modified="2006-04-12" name="CVE-2006-1716" published="2006-04-11" seq="2006-1716" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.10 allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode img tag.  NOTE: the email vector is already covered by CVE-2006-1625, although it might stem from the same core issue.</descript></desc><sols><sol source="nvd">Successful exploitation requires that unauthenticated users are allowed to post new threads (not the default setting).</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430344/100/0/threaded">20060407 [KAPDA::#38] - MyBB 1.1.0~functions_post.php~XSS Attack</ref><ref adv="1" source="Kapda" url="http://kapda.ir/advisory-305.html">MyBB 1.1.0~XSS Vulnerability</ref><ref source="" url="http://myimei.com/security/2006-03-12/mybb-110functions_postphpxss-attack.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17413">17413</ref><ref source="OSVDB" url="http://www.osvdb.org/24375">24375</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19516">19516</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25615">mybb-email-img-bbcode-xss(25615)</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-09" modified="2006-04-12" name="CVE-2006-1717" published="2006-04-11" seq="2006-1717" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in newthread.php in MyBB (aka MyBulletinBoard) 1.10, when configured to permit new threads by unregistered users, allows remote attackers to inject arbitrary web script or HTML via the username.</descript></desc><sols><sol source="nvd">Successful exploitation requires that unauthenticated users are allowed to post new threads (not the default setting).</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430464/100/0/threaded">20060409 MyBB 1.10 &apos;newthread.php&apos; &lt; CrossSiteScripting &gt;</ref><ref source="BID" url="http://www.securityfocus.com/bid/17427">17427</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19516">19516</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25730">
mybb-newthread-xss(25730)</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-07" modified="2006-04-12" name="CVE-2006-1718" published="2006-04-11" seq="2006-1718" severity="Medium" type="CVE"><desc><descript source="cve">Magus Perde Clever Copy 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to view the database username and password via a direct request for connect.inc.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430369/100/0/threaded">20060407 [ECHO_ADV_28$2006] Clever Copy &lt;= 3.0 Connect.inc Critical Information Disclosure</ref><ref adv="1" source="" url="http://advisories.echo.or.id/adv/adv28-K-159-2006.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17461">17461</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1316">ADV-2006-1316</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19579">19579</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25720">
clevercopy-connect-disclose-information(25720)</ref></refs><vuln_soft><prod name="Clever Copy" vendor="Clever Copy"><vers num="3.0" prev="1"/><vers num="23.0"/><vers num="2.0a"/><vers num="2.0"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-07" modified="2006-04-12" name="CVE-2006-1719" published="2006-04-11" seq="2006-1719" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) via any scrollbar Cascading Style Sheets (CSS) property.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430431/100/0/threaded">20060410 Re: IE6 Crash</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430408/100/0/threaded">

20060407 IE6 Crash</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25852">
ie-css-scrollbar-dos(25852)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows Server 2003 SP1" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-07" modified="2006-04-12" name="CVE-2006-1720" published="2006-04-11" seq="2006-1720" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in SaphpLesson 3.0 allows remote attackers to inject arbitrary web script or HTML via the Word parameter.  NOTE: it is possible that this issue is resultant from SQL injection.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430293/100/0/threaded">20060407 Xss In SaphpLesson3.0</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015883">1015883</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1317">ADV-2006-1317</ref><ref source="BID" url="http://www.securityfocus.com/bid/17414">17414</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25719">
saphplesson-search-xss(25719)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/683">683</ref></refs><vuln_soft><prod name="SaphpLesson" vendor="Arabless"><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1721" published="2006-04-11" seq="2006-1721" severity="Low" type="CVE"><desc><descript source="cve">digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://labs.musecurity.com/advisories/MU-200604-01.txt"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17446">17446</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1306">ADV-2006-1306</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19618">19618</ref><ref source="" url="http://asg.web.cmu.edu/archive/message.php?mailbox=archive.cyrus-sasl&amp;msg=7775"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1042">DSA-1042</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-272-1">USN-272-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19809">19809</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19825">19825</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-09.xml">GLSA-200604-09</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19753">19753</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:073">MDKSA-2006:073</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0024">2006-0024</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19964">19964</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_05_05.html">SUSE-SA:2006:025</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Sep/msg00002.html">APPLE-SA-2006-09-29</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3852">ADV-2006-3852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22187">22187</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016960">1016960</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/044992.html">

20060410 [MU-200604-01] Cyrus SASL DIGEST-MD5 Pre-Authentication Denial of Service</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20014">
20014</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25738">
cyrus-sasl-digest-dos(25738)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-426.htm"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:073">MDKSA-2006:073</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0795.html">RHSA-2007:0795</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0878.html">RHSA-2007:0878</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070901-01-P.asc">20070901-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26708">26708</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26857">26857</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27237">27237</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/493080/100/0/threaded">20080604 VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues</ref><ref source="" url="http://www.vmware.com/security/advisories/VMSA-2008-0009.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1744">ADV-2008-1744</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30535">30535</ref></refs><vuln_soft><prod name="SASL" vendor="Cyrus"><vers num="2.1.20"/><vers num="2.1.19"/><vers num="2.1.18 r2"/><vers num="2.1.18 r1"/><vers num="2.1.18"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-04-10" modified="2007-05-22" name="CVE-2006-1722" published="2006-04-11" seq="2006-1722" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in suche.htm in ShopXS 4.0 allows remote attackers to inject arbitrary web script or HTML via the Suchstring1 (aka search) parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/shopxs-v40-xss-vuln_10.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25715">shopxs-search-xss(25715)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/shopxs-v40-xss-vuln_10.html"></ref></refs><vuln_soft><prod name="ShopXS" vendor="Suche"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-15" name="CVE-2006-1723" published="2006-04-14" seq="2006-1723" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML.  NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530, CVE-2006-1531, and CVE-2006-1723 are different.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product releases:
Mozilla, Firefox, 1.5.0.2
Mozilla, Thunderbird, 1.5.0.2
Mozilla, SeaMonkey, 1.0.1
</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Mozilla" url="http://www.mozilla.org/security/announce/2006/mfsa2006-20.html">Security Advisory 2006-20</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/350262">VU#350262</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015919">1015919</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015921">1015921</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015920">1015920</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19649">19649</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded">HPSBUX02153</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1574">oval:org.mitre.oval:def:1574</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3748">ADV-2006-3748</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22066">22066</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5.0.1"/><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="Preview Release"/><vers num="1.5.0.1"/><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-15" name="CVE-2006-1724" published="2006-04-14" seq="2006-1724" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to DHTML.</descript></desc><sols><sol source="nvd">Fixed in: 
  Firefox 1.5.0.2
  Thunderbird 1.5.0.2
  SeaMonkey 1.0.1</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-20.html"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=282105"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0328.html">RHSA-2006:0328</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/350262">VU#350262</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015919">1015919</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015921">1015921</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015920">1015920</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19649">19649</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html">TA06-107A</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html">FEDORA-2006-410</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html">FEDORA-2006-411</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19714">19714</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded">HPSBTU02118</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded">HPSBUX02153</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1901">oval:org.mitre.oval:def:1901</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19696">
19696</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19780">
19780</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3748">ADV-2006-3748</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22066">22066</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5.0.1" prev="1"/><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12" prev="1"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0" prev="1"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.1" prev="1"/><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-1725" published="2006-04-14" seq="2006-1725" severity="Low" type="CVE"><desc><descript source="cve">Mozilla Firefox 1.5 before 1.5.0.2 and SeaMonkey before 1.0.1 causes certain windows to become translucent due to an interaction between XUL content windows and the history mechanism, which might allow user-assisted remote attackers to trick users into executing arbitrary code.</descript></desc><sols><sol source="nvd">Fixed in: 
  Firefox 1.5.0.2
  SeaMonkey 1.0.1</sol></sols><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-29.html"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=327014"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19649">19649</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded">HPSBUX02153</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1471">oval:org.mitre.oval:def:1471</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25827">
mozilla-xul-window-spoofing(25827)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3748">ADV-2006-3748</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22066">22066</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5.0.1" prev="1"/><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12" prev="1"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0" prev="1"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.1" prev="1"/><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-06-24" name="CVE-2006-1726" published="2006-04-14" seq="2006-1726" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Firefox and Thunderbird 1.5 before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to bypass the js_ValueToFunctionObject check and execute arbitrary code via unknown vectors involving setTimeout and Firefox&apos; ForEach method.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product releases:
Mozilla, Firefox, 1.5.0.2
Mozilla, Thunderbird, 1.5.0.2
Mozilla, SeaMonkey, 1.0.1</sol></sols><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Mozilla" url="http://www.mozilla.org/security/announce/2006/mfsa2006-28.html">Security Advisory 2006-28</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/968814">VU#968814</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19649">19649</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html">TA06-107A</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015931">1015931</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015932">1015932</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015933">1015933</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded">HPSBTU02118</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded">HPSBUX02153</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1968">oval:org.mitre.oval:def:1968</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25825">mozilla-valuetofunctionobject-sec-bypass(25825)</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3748">ADV-2006-3748</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/22066">22066</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="Preview Release"/><vers num="1.5.0.1"/><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-15" name="CVE-2006-1727" published="2006-04-14" seq="2006-1727" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to gain chrome privileges via multiple attack vectors related to the use of XBL scripts with &quot;Print Preview&quot;.</descript></desc><sols><sol source="nvd">Fixed in: Firefox 1.5.0.2
  Firefox 1.0.8
  Thunderbird 1.5.0.2
  Thunderbird 1.0.8
  SeaMonkey 1.0.1
  Mozilla Suite 1.7.13</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-25.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0328.html">RHSA-2006:0328</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015926">1015926</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015927">1015927</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015928">1015928</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015929">1015929</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19649">19649</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html">FEDORA-2006-410</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html">FEDORA-2006-411</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19714">19714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">GLSA-200605-09</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3391">ADV-2006-3391</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded">HPSBUX02153</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1649">oval:org.mitre.oval:def:1649</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19696">
19696</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19729">
19729</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19780">
19780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">
20051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25824">
mozilla-printpreview-privilege-escalation(25824)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3748">ADV-2006-3748</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22066">22066</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5.0.1" prev="1"/><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12" prev="1"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0" prev="1"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.1" prev="1"/><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-06-24" name="CVE-2006-1728" published="2006-04-14" seq="2006-1728" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to the crypto.generateCRMFRequest method.</descript></desc><sols><sol source="nvd">Fixed in: Firefox 1.5.0.2
  Firefox 1.0.8
  Thunderbird 1.5.0.2
  Thunderbird 1.0.8
  SeaMonkey 1.0.1
  Mozilla Suite 1.7.13</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3391">ADV-2006-3391</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded">HPSBUX02153</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1698">oval:org.mitre.oval:def:1698</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102763-1">102763</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0058">ADV-2007-0058</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19696">
19696</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19729">
19729</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19780">
19780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">
20051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25812">
mozilla-generatecrmfrequest-code-execution(25812)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3748">ADV-2006-3748</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22066">22066</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-24.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0328.html">RHSA-2006:0328</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/932734">VU#932734</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015922">1015922</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015923">1015923</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015924">1015924</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015925">1015925</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19649">19649</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html">TA06-107A</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19794">19794</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html">FEDORA-2006-410</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html">FEDORA-2006-411</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19714">19714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">GLSA-200605-09</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded">HPSBTU02118</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5.0.1" prev="1"/><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12" prev="1"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0" prev="1"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.1" prev="1"/><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2006-1729" published="2006-04-14" seq="2006-1729" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler.</descript></desc><sols><sol source="nvd">Fixed in: Firefox 1.5.0.2
  Firefox 1.0.8
  SeaMonkey 1.0.1
  Mozilla Suite 1.7.13</sol></sols><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-23.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0328.html">RHSA-2006:0328</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19649">19649</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19794">19794</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html">FEDORA-2006-410</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html">FEDORA-2006-411</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19714">19714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_35_mozilla.html">SUSE-SA:2006:035</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3391">ADV-2006-3391</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded">HPSBUX02153</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1929">oval:org.mitre.oval:def:1929</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19696">19696</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19729">19729</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25823">mozilla-textbox-file-access(25823)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3748">ADV-2006-3748</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22066">22066</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5.0.1" prev="1"/><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12" prev="1"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0" prev="1"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.1" prev="1"/><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" discovered="2006-01-31" modified="2008-06-24" name="CVE-2006-1730" published="2006-04-14" seq="2006-1730" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via a large number in the CSS letter-spacing property that leads to a heap-based buffer overflow.</descript></desc><sols><sol source="nvd">Fixed in: Firefox 1.5.0.2
  Firefox 1.0.8
  Thunderbird 1.5.0.2
  Thunderbird 1.0.8
  SeaMonkey 1.0.1
  Mozilla Suite 1.7.13</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3391">ADV-2006-3391</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded">HPSBUX02153</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1614">oval:org.mitre.oval:def:1614</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19696">
19696</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19729">
19729</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19780">
19780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">
20051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25826">
mozilla-css-letterspacing-overflow(25826)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3748">ADV-2006-3748</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22066">22066</ref><ref source="SREASON" url="http://securityreason.com/securityalert/720">720</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref><ref adv="1" source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-22.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431060/100/0/threaded">20060415 ZDI-06-010: Mozilla Firefox CSS Letter-Spacing Heap Overflow Vulnerability</ref><ref adv="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-06-010.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0328.html">RHSA-2006:0328</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/179014">VU#179014</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015915">1015915</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015916">1015916</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015917">1015917</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015918">1015918</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19649">19649</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html">TA06-107A</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19794">19794</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html">FEDORA-2006-410</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html">FEDORA-2006-411</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19714">19714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">GLSA-200605-09</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded">HPSBTU02118</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5.0.1"/><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.1"/><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-15" name="CVE-2006-1731" published="2006-04-14" seq="2006-1731" severity="Low" type="CVE"><desc><descript source="cve">Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks.</descript></desc><sols><sol source="nvd">Fixed in: Firefox 1.5
  Firefox 1.0.8
  Thunderbird 1.5
  Thunderbird 1.0.8
  SeaMonkey 1.0
  Mozilla Suite 1.7.13</sol></sols><loss_types><int/></loss_types><vuln_types><access/><design/></vuln_types><range><network/><user_init/></range><refs><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html">FEDORA-2006-410</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html">FEDORA-2006-411</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19714">19714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">GLSA-200605-09</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3391">ADV-2006-3391</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1955">oval:org.mitre.oval:def:1955</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19696">
19696</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19729">
19729</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19780">
19780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">
20051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25820">
mozilla-valueof-xss(25820)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-19.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0328.html">RHSA-2006:0328</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19794">19794</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12" prev="1"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0" prev="1"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-15" name="CVE-2006-1732" published="2006-04-14" seq="2006-1732" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to bypass same-origin protections and conduct cross-site scripting (XSS) attacks via unspecified vectors involving the window.controllers array.</descript></desc><sols><sol source="nvd">This vulnerability also affects Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 
This vulnerability is addressed in the following product releases:
Mozilla, Firefox, 1.5
Mozilla, Firefox, 1.0.8
Mozilla, Thunderbird, 1.5
Mozilla, Thunderbird, 1.0.8
Mozilla, SeaMonkey, 1.0
Mozilla, Suite, 1.7.13
</sol></sols><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mozilla" url="http://www.mozilla.org/security/announce/2006/mfsa2006-17.html">Security Advisory 2006-17</ref><ref patch="1" source="Bugzilla" url="https://bugzilla.mozilla.org/show_bug.cgi?id=313373"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0328.html">RHSA-2006:0328</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19794">19794</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html">FEDORA-2006-410</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html">FEDORA-2006-411</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19714">19714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">GLSA-200605-09</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3391">ADV-2006-3391</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1887">oval:org.mitre.oval:def:1887</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19696">
19696</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19729">
19729</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19780">
19780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">
20051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25818">
mozilla-windows-controllers-xss(25818)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-06-24" name="CVE-2006-1733" published="2006-04-14" seq="2006-1733" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protect the compilation scope of privileged built-in XBL bindings, which allows remote attackers to execute arbitrary code via the (1) valueOf.call or (2) valueOf.apply methods of an XBL binding, or (3) &quot;by inserting an XBL method into the DOM&apos;s document.body prototype chain.&quot;</descript></desc><sols><sol source="nvd">This vulnerability also affects Mozilla, SeaMonkey, 1.0 and Mozilla, Suite, 1.7.13

This vulnerabiloity is addressed in the following product releases:
Mozilla, Firefox, 1.5
Mozilla, Firefox, 1.0.8
Mozilla, Thunderbird, 1.5
Mozilla, Thunderbird, 1.0.8
Mozilla, SeaMonkey, 1.0
Mozilla, Suite, 1.7.13
</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/19696">
19696</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19729">
19729</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19780">
19780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">
20051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25817">
mozilla-valueof-code-execution(25817)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref adv="1" patch="1" source="Mozilla" url="http://www.mozilla.org/security/announce/2006/mfsa2006-16.html">Security Advisory 2006-16</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0328.html">RHSA-2006:0328</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/488774">VU#488774</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html">TA06-107A</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19794">19794</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html">FEDORA-2006-410</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html">FEDORA-2006-411</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19714">19714</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">GLSA-200605-09</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded">HPSBTU02118</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2020">oval:org.mitre.oval:def:2020</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12" prev="1"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0" prev="1"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-13" name="CVE-2006-1734" published="2006-04-14" seq="2006-1734" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using the Object.watch method to access the &quot;clone parent&quot; internal function.</descript></desc><sols><sol source="nvd">Fixed in: Firefox 1.5
  Firefox 1.0.8
  Thunderbird 1.5
  Thunderbird 1.0.8
  SeaMonkey 1.0
  Mozilla Suite 1.7.13</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/19696">
19696</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19729">
19729</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19780">
19780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">
20051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25816">
mozilla-cloneparent-code-execution(25816)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-15.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0328.html">RHSA-2006:0328</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/842094">VU#842094</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html">TA06-107A</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19794">19794</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html">FEDORA-2006-410</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html">FEDORA-2006-411</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19714">19714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded">HPSBTU02118</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1247">oval:org.mitre.oval:def:1247</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">GLSA-200605-09</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12" prev="1"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0" prev="1"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-06-24" name="CVE-2006-1735" published="2006-04-14" seq="2006-1735" severity="High" type="CVE"><desc><descript source="cve">Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using an eval in an XBL method binding (XBL.method.eval) to create Javascript functions that are compiled with extra privileges.</descript></desc><sols><sol source="nvd">Fixed in: Firefox 1.5
  Firefox 1.0.8
  Thunderbird 1.5
  Thunderbird 1.0.8
  SeaMonkey 1.0
  Mozilla Suite 1.7.13</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/19696">
19696</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19729">
19729</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19780">
19780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">
20051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25815">
mozilla-xbl-code-execution(25815)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-14.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0328.html">RHSA-2006:0328</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/813230">VU#813230</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html">TA06-107A</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19794">19794</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html">FEDORA-2006-410</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html">FEDORA-2006-411</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19714">19714</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded">HPSBTU02118</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1037">oval:org.mitre.oval:def:1037</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">GLSA-200605-09</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12" prev="1"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0" prev="1"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-15" name="CVE-2006-1736" published="2006-04-14" seq="2006-1736" severity="Low" type="CVE"><desc><descript source="cve">Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to trick users into downloading and saving an executable file via an image that is overlaid by a transparent image link that points to the executable, which causes the executable to be saved when the user clicks the &quot;Save image as...&quot; option.  NOTE: this attack is made easier due to a GUI truncation issue that prevents the user from seeing the malicious extension when there is extra whitespace in the filename.</descript></desc><sols><sol source="nvd">Fixed in: Firefox 1.5
  Firefox 1.0.8
  SeaMonkey 1.0
  Mozilla Suite 1.7.13</sol></sols><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-13.html"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=293527"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19794">19794</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1548">oval:org.mitre.oval:def:1548</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25814">
mozilla-saveimageas-ext-spoofing(25814)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12" prev="1"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0" prev="1"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-17" name="CVE-2006-1737" published="2006-04-14" seq="2006-1737" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary bytecode via JavaScript with a large regular expression.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-11.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0328.html">RHSA-2006:0328</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/329500">VU#329500</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html">TA06-107A</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19794">19794</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html">FEDORA-2006-410</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html">FEDORA-2006-411</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19714">19714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded">HPSBTU02118</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1829">oval:org.mitre.oval:def:1829</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">
GLSA-200605-09</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19696">
19696</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19729">
19729</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19780">
19780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">
20051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25808">
mozilla-javascript-regexpr-memory-corruption(25808)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-17" name="CVE-2006-1738" published="2006-04-14" seq="2006-1738" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) by changing the (1) -moz-grid and (2) -moz-grid-group display styles.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-11.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0328.html">RHSA-2006:0328</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/252324">VU#252324</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html">TA06-107A</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19794">19794</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html">FEDORA-2006-410</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html">FEDORA-2006-411</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19714">19714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded">HPSBTU02118</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1687">oval:org.mitre.oval:def:1687</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">
GLSA-200605-09</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19696">
19696</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19729">
19729</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19780">
19780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">
20051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25811">
mozilla-mozgrid-memory-corruption(25811)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-07-30" name="CVE-2006-1739" published="2006-04-14" seq="2006-1739" severity="High" type="CVE"><desc><descript source="cve">The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain Cascading Style Sheets (CSS) that causes an out-of-bounds array write and buffer overflow.</descript></desc><sols><sol source="nvd">Fixed in: Firefox 1.5
  Firefox 1.0.8
  Thunderbird 1.5
  Thunderbird 1.0.8
  SeaMonkey 1.0
  Mozilla Suite 1.7.13</sol></sols><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">
GLSA-200605-09</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19696">
19696</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19729">
19729</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19780">
19780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">
20051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25810">
mozilla-css-memory-corruption(25810)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-11.html"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=265736"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0328.html">RHSA-2006:0328</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/935556">VU#935556</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-107A.html">TA06-107A</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19794">19794</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html">FEDORA-2006-410</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html">FEDORA-2006-411</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19714">19714</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded">HPSBTU02118</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1667">oval:org.mitre.oval:def:1667</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-15" name="CVE-2006-1740" published="2006-04-14" seq="2006-1740" severity="Low" type="CVE"><desc><descript source="cve">Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to spoof secure site indicators such as the locked icon by opening the trusted site in a popup window, then changing the location to a malicious site.</descript></desc><sols><sol source="nvd">Fixed in: Firefox 1.5
  Firefox 1.0.8
  SeaMonkey 1.0
  Mozilla Suite 1.7.13</sol></sols><loss_types><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-12.html"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=271194"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0328.html">RHSA-2006:0328</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19794">19794</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html">FEDORA-2006-410</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html">FEDORA-2006-411</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19714">19714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1811">oval:org.mitre.oval:def:1811</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19696">
19696</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19729">
19729</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25813">
mozilla-secure-site-spoofing(25813)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12" prev="1"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0" prev="1"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-06-24" name="CVE-2006-1741" published="2006-04-14" seq="2006-1741" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) &quot;using a modal alert to suspend an event handler while a new page is being loaded&quot;, (2) using eval(), and using certain variants involving (3) &quot;new Script;&quot; and (4) using window.__proto__ to extend eval, aka &quot;cross-site JavaScript injection&quot;.</descript></desc><sols><sol source="nvd">Fixed in: Firefox 1.5
  Firefox 1.0.8
  Mozilla Suite 1.7.13
  SeaMonkey 1.0</sol></sols><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-09.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0328.html">RHSA-2006:0328</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html">FEDORA-2006-410</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html">FEDORA-2006-411</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19714">19714</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1855">oval:org.mitre.oval:def:1855</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">GLSA-200605-09</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19696">19696</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19729">19729</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19780">19780</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20051">20051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25806">mozilla-eventhandler-xss(25806)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5.0.1" prev="1"/><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12" prev="1"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0" prev="1"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-15" name="CVE-2006-1742" published="2006-04-14" seq="2006-1742" severity="Medium" type="CVE"><desc><descript source="cve">The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly handle temporary variables that are not garbage collected, which might allow remote attackers to trigger operations on freed memory and cause memory corruption.</descript></desc><sols><sol source="nvd">Fixed in: Firefox 1.5
  Firefox 1.0.8
  Thunderbird 1.5
  Thunderbird 1.0.8
  SeaMonkey 1.0
  Mozilla Suite 1.7.13</sol></sols><loss_types><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19794">19794</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html">FEDORA-2006-410</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html">FEDORA-2006-411</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19714">19714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1087">oval:org.mitre.oval:def:1087</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">
GLSA-200605-09</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19696">
19696</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19729">
19729</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19780">
19780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">
20051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25807">
mozilla-garbage-memory-corruption(25807)</ref><ref source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-10.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0328.html">RHSA-2006:0328</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/492382">VU#492382</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers edition="Beta" num="1.0.5"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod><prod name="Mozilla suite" vendor="Mozilla"><vers num="1.7.12" prev="1"/><vers num="1.7.11"/><vers num="1.7.10"/><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Beta" num="1.0" prev="1"/><vers edition="Alpha" num="1.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.7" prev="1"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-20" name="CVE-2006-1743" published="2006-04-12" seq="2006-1743" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in form.php in JBook 1.4 allow remote attackers to execute arbitrary SQL commands via the (1) nom or (2) mail parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17458">17458</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1315">ADV-2006-1315</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19613">19613</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25735">
jbook-form-sql-injection(25735)</ref></refs><vuln_soft><prod name="JBook" vendor="JBook"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1744" published="2006-04-12" seq="2006-1744" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in pl_main.c in sail in BSDgames before 2.17-7 allows local users to execute arbitrary code via a long player name that is used in a scanf function call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="" url="http://www.pulltheplug.org/fu/?q=node/56"></ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=360989"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17401">17401</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1036">DSA-1036</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/24634">24634</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19687">19687</ref><ref source="SREASON" url="http://securityreason.com/securityalert/736">736</ref></refs><vuln_soft><prod name="BSDgames" vendor="Joey Hess"><vers num="2.17"/><vers num="2.14"/><vers num="2.13"/><vers num="2.12"/><vers num="2.9"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-13" name="CVE-2006-1745" published="2006-04-12" seq="2006-1745" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the error parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17406">17406</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1370">ADV-2006-1370</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19673">19673</ref></refs><vuln_soft><prod name="Bitweaver" vendor="Bitweaver"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-19" name="CVE-2006-1746" published="2006-04-12" seq="2006-1746" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in PHPList 2.10.2 and earlier allows remote attackers include arbitrary local files via the (1) GLOBALS[database_module] or (2) GLOBALS[language_module] parameters, which overwrite the underlying $GLOBALS variable.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/430475/30/30/threaded">20060410 PHPList &lt;= 2.10.2 remote commands execution</ref><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/430597">20060411 Re: PHPList &lt;= 2.10.2 remote commands execution</ref><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/PHPList-lfi.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17429">17429</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1296">ADV-2006-1296</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015889">1015889</ref><ref source="" url="http://tincan.co.uk/?lid=851"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/448411">20061012 new version of phplist fix XSS vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25701">
phplist-index-file-include(25701)</ref></refs><vuln_soft><prod name="PHPList" vendor="tincan"><vers num="2.10.2" prev="1"/><vers num="2.10.1"/><vers num="2.8.12"/><vers num="2.8.7"/><vers num="2.8.2"/><vers num="2.7.2"/><vers num="2.7.1"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1747" published="2006-04-12" seq="2006-1747" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter to (1) admin/admin.php, (2) war.php, (3) stats.php, (4) news.php, (5) joinus.php, (6) challenge.php, (7) calendar.php, (8) member.php, (9) popup.php, and other unspecified scripts in the admin folder.  NOTE: these are different attack vectors than CVE-2006-1636 and CVE-2006-1503.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://liz0zim.no-ip.org/vwar.txt"></ref><ref source="" url="http://www.blogcu.com/Liz0ziM/431925/"></ref><ref source="" url="http://www.milw0rm.com/exploits/1658"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17443">17443</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430389/100/0/threaded">20060408 Virtual War File &amp;#304;nclusion</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=115497619330609&amp;w=2">20060807 Virtual War v1.5.0 Remote File Include (vwar_root)</ref><ref source="BID" url="http://www.securityfocus.com/bid/19387">19387</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/28265">virtualwar-member-file-include(28265)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1658">
1658</ref></refs><vuln_soft><prod name="Virtual War" vendor="VWar"><vers num="1.5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-1748" published="2006-04-12" seq="2006-1748" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in XMB Forum 1.9.5 allows remote attackers to inject arbitrary web script or HTML by uploading a Flash (.SWF) video that contains a getURL function call, which causes the video to be rendered without disabling ActionScript.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17445">17445</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430432/100/0/threaded">20060409 XMB Forum 1.9.5-Final XSS</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25737">
xmb-swf-geturl-xss(25737)</ref></refs><vuln_soft><prod name="XMB Forum" vendor="XMB Software"><vers num="1.9.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-15" name="CVE-2006-1749" published="2006-04-12" seq="2006-1749" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in config.php in phpListPro 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the returnpath parameter.  NOTE: this issue was later reported to affect 2.01 as well.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/430614">20060411 phpListPro &lt;= 2.0 - Remote File Include Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17448">17448</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1325">ADV-2006-1325</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19625">19625</ref><ref source="OSVDB" url="http://www.osvdb.org/24540">24540</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25760">phplistpro-config-file-include(25760)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433562/100/0/threaded">20060508 PhpListPro 2.01 Remote File Include Vulnerability</ref></refs><vuln_soft><prod name="phpListPro" vendor="SmartISoft"><vers num="2.01"/><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2006-1750" published="2006-04-12" seq="2006-1750" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in Autogallery 0.41 allow remote attackers to inject arbitrary web script or HTML via the (1) pic or (2) show parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.elitemexico.org/12.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1328">ADV-2006-1328</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19629">19629</ref><ref source="BID" url="http://www.securityfocus.com/bid/17480">17480</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0220.html">20060411 Autogallery Multiple Cross-Site Scripting Vulnerabilitie</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25756">autogallery-index-xss(25756)</ref></refs><vuln_soft><prod name="Autogallery" vendor="JMB Software"><vers num="0.41"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2006-1751" published="2006-04-12" seq="2006-1751" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in MvBlog before 1.6 allow remote attackers to execute arbitrary SQL commands via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://dev.mvblog.org/cgi-bin/trac.cgi/ticket/54"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17481">17481</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1330">ADV-2006-1330</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19634">19634</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25765">mvblog-multiple-sql-injection(25765)</ref></refs><vuln_soft><prod name="MvBlog" vendor="Michiel van Baak"><vers num="1.5"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1752" published="2006-04-12" seq="2006-1752" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the backend in MvBlog before 1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) body fields in a comment.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://dev.mvblog.org/cgi-bin/trac.cgi/ticket/55"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17481">17481</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1330">ADV-2006-1330</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19634">19634</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25767">
mvblog-comment-xss(25767)</ref></refs><vuln_soft><prod name="MvBlog" vendor="Michiel van Baak"><vers num="1.5"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-1753" published="2006-04-18" seq="2006-1753" severity="Low" type="CVE"><desc><descript source="cve">A cron job in fcheck before 2.7.59 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product releases:
Fcheck, 2.7.59-7sarge1
Fcheck, 2.7.59-8
</sol></sols><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.us.debian.org/security/2006/dsa-1035">DSA-1035</ref><ref source="BID" url="http://www.securityfocus.com/bid/17524">17524</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19675">19675</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25830">
fcheck-tmpfile-symlink(25830)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="3.1 sparc"/><vers num="3.1 s_390"/><vers num="3.1 r1"/><vers num="3.1 ppc"/><vers num="3.1 mipsel"/><vers num="3.1 mips"/><vers num="3.1 m68k"/><vers num="3.1 ia-64"/><vers num="3.1 ia-32"/><vers num="3.1 hppa"/><vers num="3.1 arm"/><vers num="3.1 amd64"/><vers num="3.1 alpha"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1754" published="2006-04-12" seq="2006-1754" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in SWSoft Confixx 3.0.6, 3.0.8, and 3.1.2 allows remote attackers to execute arbitrary SQL commands via the SID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430671/100/0/threaded">20060411 Confixx 3.1.2 &lt;= SQL Injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/17476">17476</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1331">ADV-2006-1331</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19611">19611</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430890/100/0/threaded">20060413 Re: Confixx 3.1.2 &lt;= SQL Injection</ref><ref source="" url="http://download1.swsoft.com/Confixx/security_hotfix/release_notes.txt"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431421/100/0/threaded">20060419 Confixx SQL Injection exploit (confixx_exploit.pl)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25749">
confixx-index-sql-injection(25749)</ref></refs><vuln_soft><prod name="Confixx" vendor="SWSoft"><vers num="3.0.6"/><vers num="3.0.8"/><vers num="3.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1755" published="2006-04-12" seq="2006-1755" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in admin.php in MD News 1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/120/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17394">17394</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1259">ADV-2006-1259</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19530">19530</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431429/100/0/threaded">20060418 [eVuln] MD News Authentication Bypass and SQL Injection Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/24454">24454</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25635">
mdnews-admin-sql-injection(25635)</ref></refs><vuln_soft><prod name="MD News" vendor="Matthew Dingley"><vers num="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1756" published="2006-04-12" seq="2006-1756" severity="High" type="CVE"><desc><descript source="cve">MD News 1 allows remote attackers to bypass authentication via a direct request to a script in the Administration Area.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/120/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17394">17394</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1259">ADV-2006-1259</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19530">19530</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431429/100/0/threaded">20060418 [eVuln] MD News Authentication Bypass and SQL Injection Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/24455">24455</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25636">
mdnews-admin-security-bypass(25636)</ref></refs><vuln_soft><prod name="MD News" vendor="Matthew Dingley"><vers num="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1757" published="2006-04-12" seq="2006-1757" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Vegadns 0.99 allows remote attackers to inject arbitrary web script or HTML via the message parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430474/100/0/threaded">20060410 Vegadns blind sql injection and cross site scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/17433">17433</ref></refs><vuln_soft><prod name="Vegadns" vendor="Bill Shupp"><vers num="0.99"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1758" published="2006-04-12" seq="2006-1758" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Vegadns 0.99 allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430474/100/0/threaded">20060410 Vegadns blind sql injection and cross site scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/17433">17433</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1298">ADV-2006-1298</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19614">19614</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25741">
vegadns-index-sql-injection(25741)</ref></refs><vuln_soft><prod name="Vegadns" vendor="Bill Shupp"><vers num="0.99"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1759" published="2006-04-12" seq="2006-1759" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in allgemein_transfer.php in SWSoft Confixx 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the jahr parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430596/100/0/threaded">20060410 Confixx 3.1.2 &lt;= Cross Site Scripting Vuln</ref><ref source="BID" url="http://www.securityfocus.com/bid/17466">17466</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1331">ADV-2006-1331</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19611">19611</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015890">1015890</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25748">
confixx-transfer-xss(25748)</ref></refs><vuln_soft><prod name="Confixx" vendor="SWSoft"><vers num="3.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1760" published="2006-04-12" seq="2006-1760" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in JetPhoto allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) Classic.view/thumbnail.php, (2) Classic.view/gallery.php, (3) Classic.view/detail.php, or (4) Orange.view/detail.php; or (5) the name parameter in Orange.view/slideshow.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114472089719033&amp;w=2">20060411 JetPhoto Multiple Cross-Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/17449">17449</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1300">ADV-2006-1300</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19603">19603</ref><ref source="OSVDB" url="http://www.osvdb.org/24491">24491</ref><ref source="OSVDB" url="http://www.osvdb.org/24492">24492</ref><ref source="OSVDB" url="http://www.osvdb.org/24494">24494</ref><ref source="OSVDB" url="http://www.osvdb.org/24493">24493</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25745">
jetphoto-name-page-xss(25745)</ref></refs><vuln_soft><prod name="JetPhoto" vendor="jetphotosoft.com"><vers num="2.1"/><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-14" name="CVE-2006-1761" published="2006-04-12" seq="2006-1761" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in index.php in blur6ex 0.3.452 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter, which is not sanitized in the error message. NOTE: the vector in the shard parameter is not XSS and has been assigned a separate name.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430607/100/0/threaded">20060411 Multiple vulnerabilities in Blur6ex</ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-April/000691.html">[VIM] 20060412 Multiple vulnerabilities in Blur6ex (fwd)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17465">17465</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430885/100/0/threaded">20060413 Re: Multiple vulnerabilities in Blur6ex</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25757">
blur6ex-index-xss(25757)</ref></refs><vuln_soft><prod name="Blur6ex" vendor="Blursoft"><vers num="0.3.462"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-11" modified="2006-04-13" name="CVE-2006-1762" published="2006-04-12" seq="2006-1762" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in blur6ex 0.3.452 allows remote attackers to include arbitrary files via the shard parameter.  NOTE: this issue can be exploited to produce resultant XSS when the parameter has XSS manipulations, and path disclosure with other invalid values.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430607/100/0/threaded">20060411 Multiple vulnerabilities in Blur6ex</ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-April/000691.html">[VIM] 20060412 Multiple vulnerabilities in Blur6ex (fwd)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17465">17465</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430885/100/0/threaded">20060413 Re: Multiple vulnerabilities in Blur6ex</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25758">
blur6ex-index-path-disclosure(25758)</ref></refs><vuln_soft><prod name="Blur6ex" vendor="Blursoft"><vers num="0.3.462"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-11" modified="2006-06-20" name="CVE-2006-1763" published="2006-04-12" seq="2006-1763" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in index.php in blur6ex 0.3.452 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a (1) g_reply or (2) g_permaPost action to the blog shard (engine/shards/blog.php), or a (3) g_viewContent action to the content shard (engine/shards/content.php).</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430607/100/0/threaded">20060411 Multiple vulnerabilities in Blur6ex</ref><ref source="BID" url="http://www.securityfocus.com/bid/17465">17465</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25759">
blur6ex-index-sql-injection(25759)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/689">689</ref></refs><vuln_soft><prod name="Blur6ex" vendor="Blursoft"><vers num="0.3.462"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-13" name="CVE-2006-1764" published="2006-04-12" seq="2006-1764" severity="High" type="CVE"><desc><descript source="cve">Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as user name and password credentials.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1268">ADV-2006-1268</ref><ref source="OSVDB" url="http://www.osvdb.org/24447">24447</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19569">19569</ref></refs><vuln_soft><prod name="Hosting Controller" vendor="Hosting Controller"><vers num="6.1 Hotfix 2.9" prev="1"/><vers num="6.1 Hotfix 2.8"/><vers num="6.1 Hotfix 2.3"/><vers num="6.1 Hotfix 2.1"/><vers num="6.1 HotFix 2.0"/><vers num="6.1 Hotfix 1.9"/><vers num="6.1 Hotfix 1.7"/><vers num="6.1 Hotfix 1.4"/><vers num="6.1"/><vers num="2002 RC 1"/><vers num="2002"/><vers num="1.4b"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-10" modified="2006-04-13" name="CVE-2006-1765" published="2006-04-13" seq="2006-1765" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in JBook 1.3 allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430479/100/0/threaded">20060410 Jbook Cross Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/17419">17419</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19613">
19613</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25734">
jbook-index-xss(25734)</ref></refs><vuln_soft><prod name="JBook" vendor="JBook"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-01-04" name="CVE-2006-1766" published="2006-04-13" seq="2006-1766" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Papoo 2.1.5, and 3 beta1 and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) getlang and (2) reporeid parameter in (a) index.php, (3) menuid parameter in (b) plugin.php and (c) forumthread.php, and (4) msgid parameter in forumthread.php.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Blogspot" url="http://pridels.blogspot.com/2006/04/papoo-multiple-sql-vuln.html">Papoo Multiple SQL vuln. </ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25728">
papoo-multiple-scripts-sql-injection(25728)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/papoo-multiple-sql-vuln.html"></ref></refs><vuln_soft><prod name="Papoo" vendor="Papoo"><vers num="3 Beta1" prev="1"/><vers num="2.1.5"/><vers num="2.1.4"/><vers num="2.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-11" modified="2006-04-13" name="CVE-2006-1767" published="2006-04-13" seq="2006-1767" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in nicecoder.com INDEXU 5.0.0 and 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the theme_path parameter in (1) index.php, (2) become_editor.php, (3) add.php, (4) bad_link.php, (5) browse.php, (6) detail.php, (7) fav.php, (8) get_rated.php, (9) login.php, (10) mailing_list.php, (11) new.php, (12) modify.php, (13) pick.php, (14) power_search.php, (15) rating.php, (16) register.php, (17) review.php, (18) rss.php, (19) search.php, (20) send_pwd.php, (21) sendmail.php, (22) tell_friend.php, (23) top_rated.php, (24) user_detail.php, and (25) user_search.php; and the (26) base_path parameter in invoice.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430599/100/0/threaded">20060411 INDEXU &lt;= 5.0.1 (theme_path)and (base_path) Remote File Inclusion Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/17470">17470</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015891">1015891</ref><ref source="OSVDB" url="http://www.osvdb.org/24596">24596</ref><ref source="OSVDB" url="http://www.osvdb.org/24597">24597</ref><ref source="" url="http://ftp.kep.online.fr/Indexu_5.0.1_File_Inclusion_Exploit-by_King-Hacker_and-Khamaileon.txt"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016331">1016331</ref><ref source="OSVDB" url="http://www.osvdb.org/28406">
28406</ref><ref source="OSVDB" url="http://www.osvdb.org/28409">
28409</ref><ref source="OSVDB" url="http://www.osvdb.org/28410">
28410</ref><ref source="OSVDB" url="http://www.osvdb.org/28412">
28412</ref><ref source="OSVDB" url="http://www.osvdb.org/28413">
28413</ref><ref source="OSVDB" url="http://www.osvdb.org/28415">
28415</ref><ref source="OSVDB" url="http://www.osvdb.org/28416">
28416</ref><ref source="OSVDB" url="http://www.osvdb.org/28417">
28417</ref><ref source="OSVDB" url="http://www.osvdb.org/28419">
28419</ref><ref source="OSVDB" url="http://www.osvdb.org/28422">
28422</ref><ref source="OSVDB" url="http://www.osvdb.org/28425">
28425</ref><ref source="OSVDB" url="http://www.osvdb.org/28426">
28426</ref><ref source="OSVDB" url="http://www.osvdb.org/28427">
28427</ref></refs><vuln_soft><prod name="indexu" vendor="Nicecoder"><vers num="5.0.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-11" modified="2006-04-13" name="CVE-2006-1768" published="2006-04-13" seq="2006-1768" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) newuser_name, (2) newuser_email, and (3) newuser_hp parameters in the faction=register mode in index.php.</descript></desc><sols><sol source="nvd">Succesful exploitation requires that &quot;register_globals&quot; is enabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430669/100/0/threaded">20060411 Tritanium Bulletin Board 1.2.3 - XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/17473">17473</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1329">ADV-2006-1329</ref><ref source="OSVDB" url="http://www.osvdb.org/24556">24556</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19635">19635</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25751">
tritaniumbb-register-xss(25751)</ref></refs><vuln_soft><prod name="Tritanium Bulletin Board" vendor="Tritanium Scripts"><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-11" modified="2006-04-13" name="CVE-2006-1769" published="2006-04-13" seq="2006-1769" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in UserLand Manila 9.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the mode parameter in msgReader$1 and (2) the end of the URI in viewDepartment$.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430668/100/0/threaded">20060411 Manila &lt;= 9.5 - XSS Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17475">17475</ref><ref source="OSVDB" url="http://www.osvdb.org/24554">24554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19636">19636</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25753">manila-multiple-xss(25753)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/692">692</ref></refs><vuln_soft><prod name="Manila" vendor="UserLand"><vers num="9.5" prev="1"/><vers num="9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-11" modified="2006-04-13" name="CVE-2006-1770" published="2006-04-13" seq="2006-1770" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Azerbaijan Design &amp; Development Group (AZDG) AzDGVote allow remote attackers to execute arbitrary PHP code via a URL in the int_path parameter in (1) vote.php, (2) view.php, (3) admin.php, and (4) admin/index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430691/100/0/threaded">20060411 AzDGVote File inclusion</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1324">ADV-2006-1324</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19630">19630</ref><ref source="BID" url="http://www.securityfocus.com/bid/17447">17447</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25762">
azdgvote-intpath-file-inclusion(25762)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/695">695</ref></refs><vuln_soft><prod name="AzDGVote" vendor="Azerbaijan Development Group"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-04-11" modified="2007-08-27" name="CVE-2006-1771" published="2006-04-13" seq="2006-1771" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in misc in pbcs.dll in SAXoTECH SAXoPRESS, aka Saxotech Online (formerly Publicus) allows remote attackers to read arbitrary files and possibly execute arbitrary programs via a .. (dot dot) in the url parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430707/100/0/threaded">20060411 SAXoPRESS - directory traversal</ref><ref source="BID" url="http://www.securityfocus.com/bid/17474">17474</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1327">ADV-2006-1327</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19566">19566</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431037/30/5580/threaded">20060412 Re: SAXoPRESS - directory traversal aka Saxotech Online</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25768">saxopress-pbcs-directory-traversal(25768)</ref></refs><vuln_soft><prod name="SAXoPRESS" vendor="SAXoTECH"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-13" name="CVE-2006-1772" published="2006-04-13" seq="2006-1772" severity="High" type="CVE"><desc><descript source="cve">debconf in Debian GNU/Linux, when configuring mnogosearch in the mnogosearch-common 3.2.31-1 package, uses the world-readable config.dat file instead of the restricted passwords.dat for storing the cleartext database administrator password in the mnogosearch-common/database_admin_pass record, which allows local users to view the password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="DEBIAN" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=361775">#361775</ref><ref source="BID" url="http://www.securityfocus.com/bid/17477">17477</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19589">19589</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="3.1 sparc"/><vers num="3.1 s_390"/><vers num="3.1 ppc"/><vers num="3.1 mipsel"/><vers num="3.1 mips"/><vers num="3.1 m68k"/><vers num="3.1 ia-64"/><vers num="3.1 ia-32"/><vers num="3.1 hppa"/><vers num="3.1 arm"/><vers num="3.1 amd64"/><vers num="3.1 alpha"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-13" name="CVE-2006-1773" published="2006-04-13" seq="2006-1773" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands via the contentid parameter, possibly involving content/news.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.hamid.ir/security/phpkit.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17467">17467</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015888">1015888</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25743">
phpkit-contentid-sql-injection(25743)</ref></refs><vuln_soft><prod name="PHPKIT" vendor="PHPKIT"><vers edition="RC2" num="1.6.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-12-12" modified="2006-09-06" name="CVE-2006-1774" published="2006-04-13" seq="2006-1774" severity="High" type="CVE"><desc><descript source="cve">HP System Management Homepage (SMH) 2.1.3.132, when running on CompaqHTTPServer/9.9 on Windows, Linux, or Tru64 UNIX, and when &quot;Trust by Certificates&quot; is not enabled, allows remote attackers to bypass authentication via a crafted URL.</descript></desc><sols><sol source="nvd">The only way to prevent this is to set the Trust level to &quot;Trust by Certificates&quot;</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430688/100/0/threaded">20060411 [SRC-Telindus advisory] - HP System Management Homepage Remote Unauthorized Access</ref><ref source="" url="http://src.telindus.com/articles/hpsm_vulnerability.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015901">1015901</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25761">
hp-smh-auth-bypass(25761)</ref></refs><vuln_soft><prod name="System Management Homepage" vendor="HP"><vers num="2.1.3.132"/></prod><prod name="CompaqHTTPServer/9.9" vendor="HP"><vers num="x"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-13" name="CVE-2006-1775" published="2006-04-13" seq="2006-1775" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.19 allow remote attackers to inject arbitrary web script or HTML via the (1) Site Description field in (a) admin_board.php, the (2) Group name and (3) Group description fields in (b) admin_groups.php and (c) groupcp.php, the (4) Theme Name field in (d) admin_styles.php, and the (5) Rank Title field in (e) admin_ranks.php.  NOTE: the profile.php/Current password vector is already covered by CVE-2006-1603.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://osvdb.org/ref/24/24353-phpbb.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/24354">24354</ref><ref source="OSVDB" url="http://www.osvdb.org/24355">24355</ref><ref source="OSVDB" url="http://www.osvdb.org/24356">24356</ref><ref source="OSVDB" url="http://www.osvdb.org/24357">24357</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.19"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-11" name="CVE-2006-1776" published="2006-04-13" seq="2006-1776" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the s parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430743/100/0/threaded">20060412 Simplog &lt;=0.9.2 multiple vulnerabilities</ref><ref source="" url="http://milw0rm.com/exploits/1663"></ref><ref source="" url="http://retrogod.altervista.org/simplog_092_incl_xpl.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1332">ADV-2006-1332</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19628">19628</ref><ref source="BID" url="http://www.securityfocus.com/bid/17490">17490</ref><ref source="OSVDB" url="http://www.osvdb.org/24559">24559</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015904">1015904</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25775">
simplog-index-file-include(25775)</ref></refs><vuln_soft><prod name="Simplog" vendor="Simplog"><vers num="0.9.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-11" name="CVE-2006-1777" published="2006-04-13" seq="2006-1777" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the s parameter, as demonstrated by injecting PHP sequences into an Apache error_log file, which is then included by doc/index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430743/100/0/threaded">20060412 Simplog &lt;=0.9.2 multiple vulnerabilities</ref><ref source="" url="http://milw0rm.com/exploits/1663"></ref><ref source="" url="http://retrogod.altervista.org/simplog_092_incl_xpl.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1332">ADV-2006-1332</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19628">19628</ref><ref source="BID" url="http://www.securityfocus.com/bid/17490">17490</ref><ref source="OSVDB" url="http://www.osvdb.org/24559">24559</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015904">1015904</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25775">
simplog-index-file-include(25775)</ref></refs><vuln_soft><prod name="Simplog" vendor="Simplog"><vers num="0.9.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-11" name="CVE-2006-1778" published="2006-04-13" seq="2006-1778" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) blogid parameter in (a) index.php and (b) archive.php, the (2) m and (3) y parameters in archive.php, and the (4) sql parameter in (c) server.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430743/100/0/threaded">20060412 Simplog &lt;=0.9.2 multiple vulnerabilities</ref><ref source="" url="http://milw0rm.com/exploits/1663"></ref><ref source="" url="http://retrogod.altervista.org/simplog_092_incl_xpl.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1332">ADV-2006-1332</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19628">19628</ref><ref source="BID" url="http://www.securityfocus.com/bid/17491">17491</ref><ref source="OSVDB" url="http://www.osvdb.org/24560">24560</ref><ref source="OSVDB" url="http://www.osvdb.org/24561">24561</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015904">1015904</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25776">
simplog-index-archive-sql-injection(25776)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/702">702</ref></refs><vuln_soft><prod name="Simplog" vendor="Simplog"><vers num="0.9.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-11" name="CVE-2006-1779" published="2006-04-13" seq="2006-1779" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the btag parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430743/100/0/threaded">20060412 Simplog &lt;=0.9.2 multiple vulnerabilities</ref><ref source="" url="http://milw0rm.com/exploits/1663"></ref><ref source="" url="http://retrogod.altervista.org/simplog_092_incl_xpl.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1332">ADV-2006-1332</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19628">19628</ref><ref source="BID" url="http://www.securityfocus.com/bid/17493">17493</ref><ref source="OSVDB" url="http://www.osvdb.org/24562">24562</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015904">1015904</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25778">
simplog-login-xss(25778)</ref></refs><vuln_soft><prod name="Simplog" vendor="Simplog"><vers num="0.9.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-13" name="CVE-2006-1780" published="2006-04-13" seq="2006-1780" severity="Low" type="CVE"><desc><descript source="cve">The Bourne shell (sh) in Solaris 8, 9, and 10 allows local users to cause a denial of service (sh crash) via an unspecified attack vector that causes sh processes to crash during creation of temporary files.</descript></desc><sols><sol source="nvd">Apply patches.</sol></sols><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102282-1">102282</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1333">ADV-2006-1333</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19627">19627</ref><ref source="BID" url="http://www.securityfocus.com/bid/17478">17478</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015902">1015902</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-122.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21493">21493</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:881">oval:org.mitre.oval:def:881</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25744">
solaris-sh-dos(25744)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="8.0"/><vers edition="SPARC" num="9.0"/><vers edition="SPARC" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2006-1781" published="2006-04-13" seq="2006-1781" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.  NOTE: It was later reported that 1.4.2 and earlier are affected.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/monstertoplist.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1350">ADV-2006-1350</ref><ref source="BID" url="http://www.securityfocus.com/bid/17546">17546</ref><ref source="OSVDB" url="http://www.osvdb.org/24650">24650</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19688">19688</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25774">monstertoplist-functions-file-include(25774)</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3530">3530</ref><ref source="BID" url="http://www.securityfocus.com/bid/23074">23074</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/monstertoplist.html"></ref></refs><vuln_soft><prod name="Monster Top List" vendor="Circle R"><vers num="1.4.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-13" name="CVE-2006-1782" published="2006-04-13" seq="2006-1782" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig; or &quot;insecurely&quot; runs LDAP2 commands with the -w option, including (2) ldapadd, (3) ldapdelete, (4) ldapmodify, (5) ldapmodrdn, and (6) ldapsearch.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102113-1">102113</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19638">19638</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1334">ADV-2006-1334</ref><ref source="OSVDB" url="http://www.osvdb.org/24563">24563</ref><ref source="OSVDB" url="http://www.osvdb.org/24564">24564</ref><ref source="OSVDB" url="http://www.osvdb.org/24565">24565</ref><ref source="OSVDB" url="http://www.osvdb.org/24566">24566</ref><ref source="OSVDB" url="http://www.osvdb.org/24567">24567</ref><ref source="OSVDB" url="http://www.osvdb.org/24568">24568</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015903">1015903</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-122.htm"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17479">17479</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21493">21493</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1840">oval:org.mitre.oval:def:1840</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25747">
solaris-ldap2-password-disclosure(25747)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="9.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-1783" published="2006-04-13" seq="2006-1783" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in PatroNet CMS allows remote attackers to inject arbitrary web script or HTML via the URI.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17495">17495</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430868/100/0/threaded">20060412 PatroNet CMS Xss Vuln</ref></refs><vuln_soft><prod name="CMS" vendor="Patronet"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1784" published="2006-04-13" seq="2006-1784" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings_dir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/1665"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1341">ADV-2006-1341</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19642">19642</ref><ref source="BID" url="http://www.securityfocus.com/bid/17514">17514</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25780">
sphider-configset-file-inclusion(25780)</ref></refs><vuln_soft><prod name="Sphider" vendor="Sphider"><vers num="1.3"/><vers num="1.3 RC2"/><vers num="1.3 RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-07-26" modified="2006-04-15" name="CVE-2006-1785" published="2006-04-13" seq="2006-1785" severity="Low" type="CVE"><desc><descript source="cve">Adobe Document Server for Reader Extensions 6.0 allows remote authenticated users to inject arbitrary web script via a leading (1) ftp or (2) http URI in the ReaderURL variable in the &quot;Update Download Site&quot; section of ads-readerext.  NOTE: it is not clear whether the vendor advisory addresses this issue.  In addition, since the issue requires administrative privileges to exploit, it is not clear whether this crosses security boundaries.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/secunia_research/2005-68/advisory/">Adobe Document Server for Reader Extensions Multiple Vulnerabilities</ref><ref adv="1" source="ADOBE" url="http://www.adobe.com/support/techdocs/322699.html">Security Advisory: Adobe Document Server for Reader Extensions authentication vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1342">ADV-2006-1342</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15924">15924</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430869/100/0/threaded">20060413 Secunia Research: Adobe Document Server for Reader ExtensionsMultiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17500">17500</ref><ref source="OSVDB" url="http://www.osvdb.org/24588">
24588</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25770">
adobe-readerurl-xss(25770)</ref></refs><vuln_soft><prod name="Document Server" vendor="Adobe"><vers edition="Reader Extensions" num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-07-25" modified="2006-04-15" name="CVE-2006-1786" published="2006-04-13" seq="2006-1786" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Adobe Document Server for Reader Extensions 6.0 allows remote attackers to inject arbitrary web script or HTML via (1) the actionID parameter in ads-readerext and (2) the op paremeter in AlterCast.  NOTE: it is not clear whether the vendor advisory addresses this issue.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/secunia_research/2005-68/advisory/">Adobe Document Server for Reader Extensions Multiple Vulnerabilities</ref><ref adv="1" source="ADOBE" url="http://www.adobe.com/support/techdocs/322699.html">Security Advisory: Adobe Document Server for Reader Extensions authentication vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1342">ADV-2006-1342</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15924">15924</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430869/100/0/threaded">20060413 Secunia Research: Adobe Document Server for Reader ExtensionsMultiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17500">17500</ref><ref source="OSVDB" url="http://www.osvdb.org/24590">
24590</ref><ref source="OSVDB" url="http://www.osvdb.org/24589">
24589</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25771">
adobe-actionid-op-xss(25771)</ref></refs><vuln_soft><prod name="Document Server" vendor="Adobe"><vers edition="Reader Extensions" num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-07-26" modified="2006-04-15" name="CVE-2006-1787" published="2006-04-13" seq="2006-1787" severity="Low" type="CVE"><desc><descript source="cve">Adobe Document Server for Reader Extensions 6.0 includes a user&apos;s session (jsession) ID in the HTTP Referer header, which allows remote attackers to gain access to PDF files that are being processed within that session.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/secunia_research/2005-68/advisory/">Adobe Document Server for Reader Extensions Multiple Vulnerabilities</ref><ref adv="1" source="ADOBE" url="http://www.adobe.com/support/techdocs/322699.html">Security Advisory: Adobe Document Server for Reader Extensions authentication vulnerability</ref><ref adv="1" patch="1" source="ADOBE" url="http://www.adobe.com/support/techdocs/331915.html">Adobe Document Server for Reader Extensions 6.0 session ID parameter is exposed</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1342">ADV-2006-1342</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15924">15924</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430869/100/0/threaded">20060413 Secunia Research: Adobe Document Server for Reader ExtensionsMultiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17500">17500</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25773">
adobe-jsessionid-information-disclosure(25773)</ref></refs><vuln_soft><prod name="Document Server" vendor="Adobe"><vers edition="Reader Extensions" num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-07-26" modified="2006-04-15" name="CVE-2006-1788" published="2006-04-13" seq="2006-1788" severity="Low" type="CVE"><desc><descript source="cve">Adobe Document Server for Reader Extensions 6.0, during log on, provides different error messages depending on whether the user ID is valid or invalid, which allows remote attackers to more easily identify valid user IDs via brute force attacks.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/secunia_research/2005-68/advisory/">Adobe Document Server for Reader Extensions Multiple Vulnerabilities</ref><ref adv="1" patch="1" source="ADOBE" url="http://www.adobe.com/support/techdocs/331917.html">User authentication changes for Adobe Document Server for Reader Extensions 6.0</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1342">ADV-2006-1342</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15924">15924</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430869/100/0/threaded">20060413 Secunia Research: Adobe Document Server for Reader ExtensionsMultiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17500">17500</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25772">
adobe-error-account-enumeration(25772)</ref></refs><vuln_soft><prod name="Document Server" vendor="Adobe"><vers edition="Reader Extensions" num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-30" modified="2006-04-15" name="CVE-2006-1789" published="2006-04-13" seq="2006-1789" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in pajax_call_dispatcher.php in PAJAX 0.5.1 and earlier allows remote attackers to read arbitrary files via the $className variable.</descript></desc><sols><sol source="nvd">Users of PAJAX should upgrade to the latest version pajax-0.5.2 [1].</sol></sols><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.redteam-pentesting.de/advisories/rt-sa-2006-001.php"></ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0270.html">20060413 PAJAX Remote Code Injection and File Inclusion Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17519">17519</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1353">ADV-2006-1353</ref><ref source="OSVDB" url="http://www.osvdb.org/24618">24618</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19653">19653</ref><ref source="OSVDB" url="http://www.osvdb.org/24862">24862</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431029/100/0/threaded">20060413 PAJAX Remote Code Injection and File Inclusion Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25860">
pajax-pajaxcalldispatcher-dir-traversal(25860)</ref></refs><vuln_soft><prod name="PAJAX" vendor="Georges Auberger"><vers num="0.5.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-07-22" name="CVE-2006-1790" published="2006-04-14" seq="2006-1790" severity="High" type="CVE"><desc><descript source="cve">A regression fix in Mozilla Firefox 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the InstallTrigger.install method, which leads to memory corruption.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-11.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0328.html">RHSA-2006:0328</ref><ref source="BID" url="http://www.securityfocus.com/bid/17516">17516</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1356">ADV-2006-1356</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19631">19631</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19794">19794</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc">20060404-01-U</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19811">19811</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html">FEDORA-2006-410</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html">FEDORA-2006-411</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html">SUSE-SA:2006:021</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19714">19714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19721">19721</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0329.html">RHSA-2006:0329</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436296/100/0/threaded">FLSA:189137-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/436338/100/0/threaded">FLSA:189137-2</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1266">oval:org.mitre.oval:def:1266</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">GLSA-200605-09</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19729">19729</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19780">19780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20051">20051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25809">mozilla-installtrigger-memory-corruption(25809)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:075">MDKSA-2006:075</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:076">MDKSA-2006:076</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-06-11" modified="2006-04-17" name="CVE-2006-1791" published="2006-04-14" seq="2006-1791" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in acc.php in QuickBlogger 1.4 allows remote attackers to read or include arbitrary local files via the request parameter.  NOTE: this issue can also produce resultant XSS when the associated include statement fails.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430878/100/0/threaded">20060412 QuickBlogger v1.4 Cross-Site Scripting</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15942">15942</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431059/100/0/threaded">20060414 Re: QuickBlogger v1.4 Cross-Site Scripting</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25795">
quickblogger-acc-xss(25795)</ref></refs><vuln_soft><prod name="QuickBlogger" vendor="JL Webworks"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-15" name="CVE-2006-1792" published="2006-04-15" seq="2006-1792" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edition before 1.22 has unknown attack vectors and impact related to &quot;authentication exploits&quot;.  NOTE: this is a different set of affected versions, and probably a different vulnerability than CVE-2006-1337.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.mailenable.com/enterprisehistory.asp"></ref><ref source="" url="http://www.mailenable.com/professionalhistory.asp"></ref><ref source="" url="http://www.mailenable.com/standardhistory.asp"></ref></refs><vuln_soft><prod name="MailEnable Professional" vendor="MailEnable"><vers num="1.73"/><vers num="1.72"/><vers num="1.71"/><vers num="1.7"/><vers num="1.6"/><vers num="1.54"/><vers num="1.53"/><vers num="1.52"/><vers num="1.51"/><vers num="1.5"/><vers num="1.2a"/><vers num="1.2"/><vers num="1.19"/><vers num="1.18"/><vers num="1.17"/></prod><prod name="MailEnable Standard" vendor="MailEnable"><vers num="1.93"/><vers num="1.92"/><vers num="1.91"/><vers num="1.9"/><vers num="1.8"/><vers num="1.72"/><vers num="1.71"/><vers num="1.704"/><vers num="1.703"/><vers num="1.702"/><vers num="1.701"/></prod><prod name="MailEnable Enterprise" vendor="MailEnable"><vers num="1.21"/><vers num="1.2"/><vers num="1.1"/><vers num="1.04"/><vers num="1.03"/><vers num="1.02"/><vers num="1.01"/><vers num="1.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-02-09" modified="2006-04-17" name="CVE-2006-1793" published="2006-04-17" seq="2006-1793" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) class.forumposts.php and (2) forumpollrenderer.php. NOTE: this issue is closely related to CVE-2006-0659.</descript></desc><sols><sol source="nvd">Succesful exploitation requires that register_globals = On &amp; allow_url_fopen = On</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/424708">20060209 runCMS &lt;= 1.3a2 possible remote code execution through the integrated FCKEditor package</ref><ref source="Altervista" url="http://retrogod.altervista.org/runcms_13a_xpl.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16578">16578</ref></refs><vuln_soft><prod name="RunCMS" vendor="RunCMS"><vers num="1.2" prev="1"/><vers num="1.1a"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-02-24" modified="2006-04-17" name="CVE-2006-1794" published="2006-04-17" seq="2006-1794" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function in (a) includes/mambo.php; and (3) the $filter variable to the showCategory function in the com_content component (content.php).</descript></desc><sols><sol source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is disabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-02/0463.html">20060224 Mambo Multiple Vulnerabilities</ref><ref patch="1" source="Gulftech" url="http://www.gulftech.org/?node=research&amp;article_id=00104-02242006">Mambo Multiple Vulnerabilities</ref><ref patch="1" source="Mambo Foundation" url="http://source.mambo-foundation.org/view/news/Announcements/Security_Patch_Released/">Security Patch Released </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16775">16775</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0719">ADV-2006-0719</ref><ref source="OSVDB" url="http://www.osvdb.org/23402">23402</ref><ref source="OSVDB" url="http://www.osvdb.org/23503">23503</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18935">18935</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24951">
mambo-index2-sql-injection(24951)</ref></refs><vuln_soft><prod name="Mambo" vendor="Mambo"><vers edition="h" num="4.5.3h" prev="1"/><vers num="4.5.3h"/><vers num="4.5.2.3"/><vers num="4.5.2.2"/><vers num="4.5.2.1"/><vers num="4.5.2"/><vers num="4.5.1_1.0.9"/><vers edition="Beta 2" num="4.5.1a"/><vers edition="Beta" num="4.5.1a"/><vers num="4.5.1a"/><vers edition="Beta" num="4.5_1.0.3 Beta"/><vers num="4.5_1.0.3 Beta"/><vers num="4.5_1.0.2"/><vers num="4.5_1.0.1"/><vers num="4.5_1.0.0"/><vers num="4.0.14"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-17" name="CVE-2006-1795" published="2006-04-17" seq="2006-1795" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in tablepublisher.cgi in UPDI Network Enterprise @1 Table Publisher 2006-03-23 allows remote attackers to inject arbitrary web script or HTML via the Title of Table field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.osvdb.org/24238"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17642">17642</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19723">19723</ref></refs><vuln_soft><prod name="@1 Table Publisher" vendor="UPDI Network Enterprise"><vers num="2006-03-23"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-09-18" modified="2006-04-17" name="CVE-2006-1796" published="2006-04-17" seq="2006-1796" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other versions before 2.0.1, allows remote attackers to inject arbitrary web script or HTML to Internet Explorer users via the request URI ($_SERVER[&apos;REQUEST_URI&apos;]).</descript></desc><sols><sol source="nvd">The vulnerability manifests itself only when viewed by IE.
This vulnerability is addressed in the following product release:
Wordpress 2.0.1-1</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="DEBIAN" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=328909">#328909</ref><ref patch="1" source="Wordpress" url="http://trac.wordpress.org/ticket/1686">Ticket #1686</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0" prev="1"/><vers num="2.0"/><vers num="1.5.2"/><vers num="1.5.1.3"/><vers num="1.5.1.2"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.71"/><vers num="0.7"/><vers num="(B2) 0.6.2.1"/><vers num="(B2) 0.6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-18" name="CVE-2006-1797" published="2006-04-18" seq="2006-1797" severity="Medium" type="CVE"><desc><descript source="cve">The kernel in NetBSD-current before September 28, 2005 allows local users to cause a denial of service (system crash) by using the SIOCGIFALIAS ioctl to gather information on a non-existent alias of a network interface, which causes a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="NETBSD" url="http://archives.neohapsis.com/archives/netbsd/2006-q2/0014.html">NetBSD-SA2006-012</ref><ref source="BID" url="http://www.securityfocus.com/bid/17497">17497</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015908">1015908</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19615">19615</ref><ref source="OSVDB" url="http://www.osvdb.org/24578">24578</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25766">
bsd-siocgifalias-ioctl-dos(25766)</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="3.0"/><vers num="2.1"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6 Beta"/><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-18" name="CVE-2006-1798" published="2006-04-18" seq="2006-1798" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in rateit.php in RateIt 2.2 allows remote attackers to execute arbitrary SQL commands via the rateit_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/124/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1358">ADV-2006-1358</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19637">19637</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431859/100/0/threaded">20060424 [eVuln] RateIt SQL Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17518">17518</ref><ref source="OSVDB" url="http://www.osvdb.org/24622">24622</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015983">1015983</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25801">rateit-rateit-sql-injection(25801)</ref></refs><vuln_soft><prod name="RateIt" vendor="RateIt"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-13" modified="2006-04-18" name="CVE-2006-1799" published="2006-04-18" seq="2006-1799" severity="High" type="CVE"><desc><descript source="cve">censtore.cgi in Censtore 7.3.002 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/1669">exploit 1669</ref><ref source="BID" url="http://www.securityfocus.com/bid/17515">17515</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1352">ADV-2006-1352</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19666">19666</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1669">

1669</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25905">
censtore-page-command-execution(25905)</ref></refs><vuln_soft><prod name="Censtore" vendor="Adcentrix"><vers num="7.3.002" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-12" modified="2006-04-18" name="CVE-2006-1800" published="2006-04-18" seq="2006-1800" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in posts.php in SimpleBBS 1.0.6 through 1.1 allows remote attackers to include and execute arbitrary files via &quot;..&quot; sequences in the language cookie, as demonstrated by by injecting the code into the gl_session cookie of users.php, which is stored in error.log.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/430872">20060412 SimpleBBS v1.1(posts.php) remote command execution</ref><ref source="World Defacers" url="http://www.worlddefacers.de/Public/WD-SMPL.txt">SimpleBBS v1.1(posts.php) remote command execution Xploit</ref><ref source="Security Focus" url="http://downloads.securityfocus.com/vulnerabilities/exploits/SimpleBBS-RCE-posts.php.pl">SimpleBBS v1.1(posts.php) remote command execution Xploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/17501">17501</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25788">
simplebbs-posts-command-execution(25788)</ref></refs><vuln_soft><prod name="SimpleBBS" vendor="SimpleMedia"><vers num="1.1"/><vers num="1.0.7"/><vers num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-13" modified="2006-04-18" name="CVE-2006-1801" published="2006-04-18" seq="2006-1801" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in planetsearchplus.php in planetSearch+ allows remote attackers to inject arbitrary web script or HTML via the search_exp parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431033/100/0/threaded">20060413 planetSearch+ - XSS Vulnerabilities</ref><ref source="Blogspot" url="http://d4igoro.blogspot.com/2006/04/planetsearch-xss-vulnerabilities.html">planetSearch+ - XSS Vulnerabilities</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1368">ADV-2006-1368</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19681">19681</ref><ref source="BID" url="http://www.securityfocus.com/bid/17527">17527</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25832">
planetsearchplus-script-xss(25832)</ref></refs><vuln_soft><prod name="planetSearch+" vendor="PlaNet Concept"><vers num="2005-10-26" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-18" name="CVE-2006-1802" published="2006-04-18" seq="2006-1802" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the twg_album parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431069/100/0/threaded">20060415 Tiny Web Gallery &lt;= 1.4 XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/17536">17536</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1369">ADV-2006-1369</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19660">19660</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/436451/30/4560/threaded">
20060606 Re: Tiny Web Gallery &lt;= 1.4 XSS</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25831">
tinywebgallery-index-xss(25831)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/717">717</ref></refs><vuln_soft><prod name="TinyWebGallery" vendor="TinyWebGallery"><vers num="1.3"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-18" name="CVE-2006-1803" published="2006-04-18" seq="2006-1803" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to inject arbitrary web script or HTML via the sql_query parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430902/100/0/threaded">20060412 phpMyAdmin 2.7.0-pl1</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431013/100/0/threaded">20060414 Re: phpMyAdmin 2.7.0-pl1</ref><ref source="BID" url="http://www.securityfocus.com/bid/17487">17487</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1372">ADV-2006-1372</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19659">19659</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_28.html">SUSE-SR:2006:009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19897">19897</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25796">
phpmyadmin-sql-xss(25796)</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.8.0.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-12" modified="2006-04-18" name="CVE-2006-1804" published="2006-04-18" seq="2006-1804" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter.</descript></desc><sols><sol source="nvd">This vulnerbability may affect earlier versions of phpMyAdmin as well.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431013/100/0/threaded">20060412 phpMyAdmin 2.7.0-pl1</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1372">ADV-2006-1372</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19659">19659</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_28.html">SUSE-SR:2006:009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19897">19897</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25858">
phpmyadmin-sql-sql-injection(25858)</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.8.0.3"/><vers num="2.7.0 pl1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-18" name="CVE-2006-1805" published="2006-04-18" seq="2006-1805" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in member.php in PowerClan 1.14 allows remote attackers to execute arbitrary SQL commands via the memberid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431005/100/0/threaded">20060413 PowerClan 1.14 - SQL Injection</ref><ref source="" url="http://d4igoro.blogspot.com/2006/04/powerclan-114-sql-injection.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1371">ADV-2006-1371</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19689">19689</ref><ref source="BID" url="http://www.securityfocus.com/bid/17528">17528</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25876">
powerclan-member-sql-injection(25876)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/706">706</ref></refs><vuln_soft><prod name="PowerClan" vendor="PowerScripts"><vers num="1.14"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-18" name="CVE-2006-1806" published="2006-04-18" seq="2006-1806" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Musicbox 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter in a search action.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/musicbox-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1373">ADV-2006-1373</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19672">19672</ref><ref source="BID" url="http://www.securityfocus.com/bid/17545">17545</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/441000/100/0/threaded">20060724 MusicBox &lt;= 2.3.4 XSS SQL injection Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27925">musicbox-multiple-xss(27925)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25835">
musicbox-index-xss(25835)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/musicbox-vuln.html"></ref></refs><vuln_soft><prod name="MusicBox" vendor="MusicBox"><vers num="2.3.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-18" name="CVE-2006-1807" published="2006-04-18" seq="2006-1807" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in index.php in Musicbox 2.3.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start parameter in a search action or (2) type parameter in a top action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/musicbox-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1373">ADV-2006-1373</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19672">19672</ref><ref source="BID" url="http://www.securityfocus.com/bid/17545">17545</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/441000/100/0/threaded">20060724 MusicBox &lt;= 2.3.4 XSS SQL injection Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27926">musicbox-multiple-sql-injection(27926)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25836">
musicbox-index-sql-injection(25836)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/musicbox-vuln.html"></ref></refs><vuln_soft><prod name="MusicBox" vendor="MusicBox"><vers num="2.3.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-18" name="CVE-2006-1808" published="2006-04-18" seq="2006-1808" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Lifetype 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the show parameter in a Template operation.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431008/100/0/threaded">20060414 Vulnerabilities in lifetype</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1367">ADV-2006-1367</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015941">1015941</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19646">19646</ref><ref source="BID" url="http://www.securityfocus.com/bid/17529">17529</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25899">
lifetype-index-xss(25899)</ref></refs><vuln_soft><prod name="Lifetype" vendor="Lifetype"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-18" name="CVE-2006-1809" published="2006-04-18" seq="2006-1809" severity="Medium" type="CVE"><desc><descript source="cve">index.php in Lifetype 1.0.3 allows remote attackers to obtain sensitive information via an invalid show parameter, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431008/100/0/threaded">20060414 Vulnerabilities in lifetype</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1015941">1015941</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25903">
lifetype-index-path-disclosure(25903)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/711">711</ref></refs><vuln_soft><prod name="Lifetype" vendor="Lifetype"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-18" name="CVE-2006-1810" published="2006-04-18" seq="2006-1810" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in FlexBB 0.5.5 BETA allow remote attackers to inject arbitrary web script or HTML via the (1) ICQ, (2) AIM, (3) MSN, (4) Google Talk, (5) Website Name, (6) Website Address, (7) Email Address, (8) Location, (9) Signature, and (10) Sub-Titles fields in the user profile.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431121/100/0/threaded">20060416 FlexBB v0.5.5 BETA [SQL Inj] [XSS] [Login bypass]</ref><ref source="BID" url="http://www.securityfocus.com/bid/17539">17539</ref></refs><vuln_soft><prod name="FlexBB" vendor="FlexBB"><vers num="0.5.5 BETA"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-18" name="CVE-2006-1811" published="2006-04-18" seq="2006-1811" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in FlexBB 0.5.5 BETA allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) forumid, or (3) threadid parameter to index.php; the (4) ICQ, (5) AIM, (6) MSN, (7) Google Talk, (8) Website Name, (9) Website Address, (10) Email Address, (11) Location, (12) Signature, and (13) Sub-Titles fields in the user profile; or (14) flexbb_password field in a cookie.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431121/100/0/threaded">20060416 FlexBB v0.5.5 BETA [SQL Inj] [XSS] [Login bypass]</ref><ref source="BID" url="http://www.securityfocus.com/bid/17574">17574</ref></refs><vuln_soft><prod name="FlexBB" vendor="FlexBB"><vers num="0.5.5 BETA"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-18" name="CVE-2006-1812" published="2006-04-18" seq="2006-1812" severity="Medium" type="CVE"><desc><descript source="cve">phpWebFTP 3.2 and earlier stores script.js under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431115/100/0/threaded">20060417 PhpWebFTP 3.2 Login Script</ref><ref source="BID" url="http://www.securityfocus.com/bid/17557">17557</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19706">19706</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25921">
phpwebftp-scriptjs-obtain-information(25921)</ref></refs><vuln_soft><prod name="phpWebFTP" vendor="phpWebFTP"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-18" name="CVE-2006-1813" published="2006-04-18" seq="2006-1813" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in phpWebFTP 3.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431115/100/0/threaded">20060417 PhpWebFTP 3.2 Login Script</ref><ref source="BID" url="http://www.securityfocus.com/bid/17557">17557</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1388">ADV-2006-1388</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19706">19706</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25920">
phpwebftp-index-directory-traversal(25920)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/723">723</ref></refs><vuln_soft><prod name="phpWebFTP" vendor="phpWebFTP"><vers num="3.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-18" name="CVE-2006-1814" published="2006-04-18" seq="2006-1814" severity="Low" type="CVE"><desc><descript source="cve">NetBSD 1.6, 2.0, 2.1 and 3.0 allows local users to cause a denial of service (memory exhaustion) by using the sysctl system call to lock a large buffer into physical memory.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17498">17498</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015909">1015909</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19616">19616</ref><ref source="OSVDB" url="http://www.osvdb.org/24579">24579</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25764">bsd-sysctl-dos(25764)</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="3.0"/><vers num="2.1"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6 Beta"/><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-1815" published="2006-04-18" seq="2006-1815" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) newuser_realname and (2) newuser_icq parameters, a different vector than CVE-2006-1768.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1329">ADV-2006-1329</ref><ref source="OSVDB" url="http://www.osvdb.org/24556">24556</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19635">19635</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25751">
tritaniumbb-register-xss(25751)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/693">693</ref></refs><vuln_soft><prod name="Tritanium Bulletin Board" vendor="Tritanium Scripts"><vers num="1.2.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-1816" published="2006-04-18" seq="2006-1816" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers to execute arbitrary code via a URL in the systempath parameter to (1) ImpExModule.php, (2) ImpExController.php, and (3) ImpExDisplay.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430881/100/0/threaded">20060412 Remote File Inclusion in VBulletin ImpEx</ref><ref source="OSVDB" url="http://www.osvdb.org/24690">24690</ref><ref source="OSVDB" url="http://www.osvdb.org/24691">24691</ref><ref source="OSVDB" url="http://www.osvdb.org/24692">24692</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19352">19352</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25789">
impex-multiple-file-inclusion(25789)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467666/100/0/threaded">
20070504 Remote File Include In Script impex</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34095">
impex-systempath-file-include(34095)</ref></refs><vuln_soft><prod name="vBulletin" vendor="Jelsoft"><vers num="3.5.1"/><vers num="3.5.2"/><vers num="3.5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-1817" published="2006-04-18" seq="2006-1817" severity="Low" type="CVE"><desc><descript source="cve">SQL injection vulnerability in authcheck.php in warforge.NEWS 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) authusername and possibly the (2) authpassword cookie.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/125/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1359">ADV-2006-1359</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432104/100/0/threaded">20060426 [eVuln] warforge.NEWS SQL Injection and Multiple XSS Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17520">17520</ref><ref source="BID" url="http://www.securityfocus.com/bid/17705">
17705</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25900">
warforgenews-authcheck-sql-injection(25900)</ref></refs><vuln_soft><prod name="Warforge.NEWS" vendor="The War Forge"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-1818" published="2006-04-18" seq="2006-1818" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly including the (1) first_name and (2) last_name parameter in myaccounts.php.  NOTE: portions of these details were obtained from third party sources instead of the original disclosure.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://evuln.com/vulns/125/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1359">ADV-2006-1359</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432104/100/0/threaded">20060426 [eVuln] warforge.NEWS SQL Injection and Multiple XSS Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17520">17520</ref></refs><vuln_soft><prod name="Warforge.NEWS" vendor="The War Forge"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-1819" published="2006-04-18" seq="2006-1819" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the loadConfig function in index.php in phpWebSite 0.10.2 and earlier allows remote attackers to include arbitrary local files and execute arbitrary PHP code via the hub_dir parameter, as demonstrated by including access_log.  NOTE: in some cases, arbitrary remote file inclusion could be performed under PHP 5 using an SMB share argument such as &quot;\\systemname\sharename&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/1673"></ref><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/PHPWebSite_fi_poc"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17521">17521</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1361">ADV-2006-1361</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015942">1015942</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19647">19647</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-04.xml">GLSA-200605-04</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19914">19914</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1673">

1673</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25867">
phpwebsite-index-hubdir-file-include(25867)</ref></refs><vuln_soft><prod name="phpWebSite" vendor="phpWebSite"><vers num="0.10.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-1820" published="2006-04-18" seq="2006-1820" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.  NOTE: this might be resultant from the directory traversal vulnerability.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431010/100/0/threaded">20060414 Vulnerabilities in MODx</ref><ref source="BID" url="http://www.securityfocus.com/bid/17533">17533</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015940">1015940</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1383">ADV-2006-1383</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19645">19645</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25894">
modx-index-xss(25894)</ref></refs><vuln_soft><prod name="MODxCMS" vendor="MODxCMS"><vers num="0.9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-1821" published="2006-04-18" seq="2006-1821" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the id parameter.</descript></desc><sols><sol source="nvd">To address this issue, the vendor has released a patch available at the following location:

http://modxcms.com/forums/index.php/topic,3982.0.html</sol></sols><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431010/100/0/threaded">20060414 Vulnerabilities in MODx</ref><ref source="BID" url="http://www.securityfocus.com/bid/17533">17533</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015940">1015940</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1383">ADV-2006-1383</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19645">19645</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25895">
modx-index-directory-traversal(25895)</ref></refs><vuln_soft><prod name="MODxCMS" vendor="MODxCMS"><vers num="0.9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-1822" published="2006-04-18" seq="2006-1822" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in FarsiNews 2.5.3 Pro and earlier allows remote attackers to inject arbitrary web script or HTML via the selected_search_arch parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431011/100/0/threaded">20060414 Farsinews Cross-Site Scripting &amp; Path disclosure vulnerability</ref><ref adv="1" source="" url="http://www.aria-security.net/advisory/farsinews/farsinews042006.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17534">17534</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015943">1015943</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1411">ADV-2006-1411</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19648">19648</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25833">
farsinews-search-xss(25833)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/710">710</ref></refs><vuln_soft><prod name="FarsiNews" vendor="FarsiNews"><vers num="2.5.3"/><vers num="2.5"/><vers num="2.1 Beta2"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-1823" published="2006-04-18" seq="2006-1823" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in FarsiNews 2.5.3 Pro and earlier allows remote attackers to obtain the installation path via &quot;..&quot; sequences in the archive parameter to index.php, which leaks the full pathname in an error message.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431011/100/0/threaded">20060414 Farsinews Cross-Site Scripting &amp; Path disclosure vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015943">1015943</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1411">ADV-2006-1411</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19648">19648</ref><ref source="SREASON" url="http://securityreason.com/securityalert/710">710</ref></refs><vuln_soft><prod name="FarsiNews" vendor="FarsiNews"><vers num="2.5.3"/><vers num="2.5"/><vers num="2.1 Beta2"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-20" name="CVE-2006-1824" published="2006-04-18" seq="2006-1824" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PhpGuestbook.php in PhpGuestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Website, and (3) Comment parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/phpguestbook-v10-script-insertion.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17594">17594</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1422">ADV-2006-1422</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19669">19669</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431070/100/0/threaded">20060415 PhpGuestbook &lt;= 1.0 XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/17537">17537</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25850">
phpguestbook-script-xss(25850)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/phpguestbook-v10-script-insertion.html"></ref></refs><vuln_soft><prod name="PhpGuestbook" vendor="PhpGuestbook"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-1825" published="2006-04-18" seq="2006-1825" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Blogspot" url="http://pridels.blogspot.com/2006/04/phplinks-2131-xss-vuln.html">phpLinks &lt;= 2.1.3.1 XSS vuln. </ref><ref source="BID" url="http://www.securityfocus.com/bid/17586">17586</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1378">ADV-2006-1378</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25890">
phplinks-index-xss(25890)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/phplinks-2131-xss-vuln.html"></ref></refs><vuln_soft><prod name="phpLinks" vendor="phpLinks"><vers num="2.1.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-15" modified="2006-04-19" name="CVE-2006-1826" published="2006-04-18" seq="2006-1826" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Snipe Gallery 3.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in view.php, (2) keyword parameter in search.php, and (3) image_id parameter in image.php.  NOTE: it is possible that vectors 1 and 3 are resultant from SQL injection.</descript></desc><sols><sol source="nvd">SQL Injection may occur if the magic quotes parameter is off.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431074/100/0/threaded">20060415 Snipe Gallery &lt;= 3.1.4 Multiple XSS</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431123/100/0/threaded">20060416 Re: Snipe Gallery &lt;= 3.1.4 Multiple XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/17543">17543</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015947">1015947</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25803">
snipe-view-image-xss(25803)</ref></refs><vuln_soft><prod name="Snipe Gallery" vendor="Snipe Gallery"><vers num="3.1.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-23" name="CVE-2006-1827" published="2006-04-18" seq="2006-1827" severity="Medium" type="CVE"><desc><descript source="cve">Integer signedness error in format_jpeg.c in Asterisk 1.2.6 and earlier allows remote attackers to execute arbitrary code via a length value that passes a length check as a negative number, but triggers a buffer overflow when it is used as an unsigned length.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="Cipher" url="http://www.cipher.org.uk/index.php?p=advisories/Asterisk_Codec_Integer_Overflow_07-04-2006.advisory">Bug: JPEG Reader (IOF)</ref><ref patch="1" source="Digium" url="http://ftp.digium.com/pub/asterisk/releases/asterisk-1.2.7-patch.gz">asterisk-1.2.7-patch</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1478">ADV-2006-1478</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19800">19800</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1048">DSA-1048</ref><ref source="BID" url="http://www.securityfocus.com/bid/17561">17561</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19872">19872</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_28.html">SUSE-SR:2006:009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19897">19897</ref></refs><vuln_soft><prod name="Asterisk" vendor="Digium"><vers num="1.2.6" prev="1"/><vers num="1.2.0 Beta1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0.9"/><vers num="1.0.8"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/><vers num="0.7.2"/><vers num="0.7.1"/><vers num="0.7.0"/><vers num="0.5.0"/><vers num="0.4.0"/><vers num="0.4"/><vers num="0.3.0"/><vers num="0.3"/><vers num="0.2.0"/><vers num="0.2"/><vers num="0.1.9.1"/><vers num="0.1.9"/><vers num="0.1.8"/><vers num="0.1.7"/><vers num="0.1.6"/><vers num="0.1.5"/><vers num="0.1.4"/><vers num="0.1.3"/><vers num="0.1.2"/><vers num="0.1.12"/><vers num="0.1.11"/><vers num="0.1.10"/><vers num="0.1.1"/><vers num="0.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-12" modified="2006-04-19" name="CVE-2006-1828" published="2006-04-19" seq="2006-1828" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in php121language.php in PHP121 1.4 allows remote attackers to execute arbitrary SQL commands and execute arbitrary code via the sess_username variable, as set by the php121un HTTP COOKIE parameter, which is used in multiple files including php121login.php.  NOTE: the code execution occurs because the SQL query results are used in an include statement.</descript></desc><sols><sol source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is disabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://milw0rm.com/exploits/1666">exploit 1666</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1349">ADV-2006-1349</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19643">19643</ref><ref source="" url="http://retrogod.altervista.org/php121im_14_sql_xpl.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015936">1015936</ref><ref source="BID" url="http://www.securityfocus.com/bid/17509">17509</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25785">
php121-php121login-sql-injection(25785)</ref></refs><vuln_soft><prod name="PHP121 Instant Messenger" vendor="PHP121"><vers num="1.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-20" name="CVE-2006-1829" published="2006-04-19" seq="2006-1829" severity="Medium" type="CVE"><desc><descript source="cve">EAServer Manager in Sybase EAServer 5.2 and 5.3 allows remote authenticated users, possibly guests, to obtain password credentials of abitrary users via unspecified vectors involving (1) connection caches, (2) open password prompts, and (3) stored custom connection profiles.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" source="" url="http://www.sybase.com/detail?id=1040117"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17508">17508</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1344">ADV-2006-1344</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015913">1015913</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19605">19605</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25777">
easerver-password-disclosure(25777)</ref></refs><vuln_soft><prod name="EAServer" vendor="Sybase"><vers num="5.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-20" name="CVE-2006-1830" published="2006-04-19" seq="2006-1830" severity="Low" type="CVE"><desc><descript source="cve">Sun Java Studio Enterprise 8, when installed as root, creates certain files with world-writable permissions, which allows local users to execute arbitrary commands via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102292-1">102292</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17517">17517</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1357">ADV-2006-1357</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19632">19632</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015930">1015930</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25822">
sun-javastudio-insecure-permissions(25822)</ref></refs><vuln_soft><prod name="Java Studio Enterprise" vendor="Sun"><vers num="8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-13" name="CVE-2006-1831" published="2006-04-19" seq="2006-1831" severity="High" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows remote attackers to execute arbitrary commands via a leading ; (semicolon) in the name parameter in a systemdoc action, which is injected into phpinfo.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/1677"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17523">17523</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1360">ADV-2006-1360</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19690">19690</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1677">1677</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25906">sysinfo-sysinfo-command-execution(25906)</ref></refs><vuln_soft><prod name="Sysinfo" vendor="Coder-World"><vers num="1.21"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-20" name="CVE-2006-1832" published="2006-04-19" seq="2006-1832" severity="Medium" type="CVE"><desc><descript source="cve">sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/1677"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17523">17523</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1360">ADV-2006-1360</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19690">19690</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1677">

1677</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25909">
sysinfo-debugger-information-disclosure(25909)</ref></refs><vuln_soft><prod name="Sysinfo" vendor="Coder-World"><vers num="1.21"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-20" name="CVE-2006-1833" published="2006-04-19" seq="2006-1833" severity="Low" type="CVE"><desc><descript source="cve">Intel RNG Driver in NetBSD 1.6 through 3.0 may incorrectly detect the presence of the pchb interface, which will cause it to always generate the same random number, which allows remote attackers to more easily crack encryption keys generated from the interface.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-009.txt.asc">NetBSD-SA2006-009</ref><ref source="OSVDB" url="http://www.osvdb.org/24577">24577</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015907">1015907</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19585">19585</ref><ref source="BID" url="http://www.securityfocus.com/bid/17496">17496</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25786">
netbsd-intel-rng-security-bypass(25786)</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="3.0"/><vers num="2.1"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6 Beta"/><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-20" name="CVE-2006-1834" published="2006-04-19" seq="2006-1834" severity="Medium" type="CVE"><desc><descript source="cve">Integer signedness error in Opera before 8.54 allows remote attackers to execute arbitrary code via long values in a stylesheet attribute, which pass a length check.  NOTE: a sign extension problem makes the attack easier with shorter strings.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114493114031891&amp;w=2">20060413 SEC Consult SA-20060314 :: Opera Browser CSS Attribute Integer Wrap / Buffer Overflow</ref><ref source="" url="http://www.sec-consult.com/259.html"></ref><ref source="" url="http://www.opera.com/docs/changelogs/windows/854/"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17513">17513</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1354">ADV-2006-1354</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015912">1015912</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430876/100/0/threaded">20060413 SEC Consult SA-20060314 :: Opera Browser CSS Attribute Integer Wrap / Buffer Overflow</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html">SUSE-SR:2006:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20117">20117</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200606-01.xml">GLSA-200606-01</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25829">
opera-wcsncpy-css-bo(25829)</ref></refs><vuln_soft><prod name="Opera" vendor="Opera Software"><vers num="8.53" prev="1"/><vers num="8.52"/><vers num="8.50"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-20" name="CVE-2006-1835" published="2006-04-19" seq="2006-1835" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in yearcal.php in Calendarix allows remote attackers to inject arbitrary web script or HTML via the ycyear parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431122/100/0/threaded">20060416 Calendarix </ref><ref source="BID" url="http://www.securityfocus.com/bid/17562">17562</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1376">ADV-2006-1376</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015954">1015954</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19710">19710</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25874">
calendarix-yearcal-xss(25874)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/727">727</ref></refs><vuln_soft><prod name="Calendarix" vendor="Vincent Hor"><vers num="0.6.2005-08-30"/></prod><prod name="Calendarix Advanced" vendor="Vincent Hor"><vers num="1.5.2005-05-01"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-28" name="CVE-2006-1836" published="2006-04-19" seq="2006-1836" severity="Medium" type="CVE"><desc><descript source="cve">Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://securityresponse.symantec.com/avcenter/security/Content/2006.04.17b.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17571">17571</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1386">ADV-2006-1386</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19682">19682</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431318/100/0/threaded">20060418 [Symantec Security Advisory] LiveUpdate for Macintosh Local Privilege Escalation</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015953">1015953</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25839">
liveupdate-exepath-env-privilege-escalation(25839)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/100">100</ref></refs><vuln_soft><prod name="Norton Personal Firewall" vendor="Symantec"><vers edition="Macintosh" num="3.1"/><vers edition="Macintosh" num="3.0"/></prod><prod name="Norton Utilities" vendor="Symantec"><vers edition="Macintosh" num="8.0"/></prod><prod name="Symantec AntiVirus" vendor="Symantec"><vers edition="Macintosh" num="10.0"/></prod><prod name="LiveUpdate" vendor="Symantec"><vers edition="Macintosh" num="3.5"/><vers edition="Macintosh" num="3.0.3"/><vers edition="Macintosh" num="3.0.2"/><vers edition="Macintosh" num="3.0.1"/><vers edition="Macintosh" num="3.0"/></prod><prod name="Norton Antivirus" vendor="Symantec"><vers edition="Macintosh" num="10.9.1"/><vers edition="Macintosh" num="10.0.1"/><vers edition="Macintosh" num="10.0.0"/><vers edition="Macintosh" num="9.0.3"/><vers edition="Macintosh" num="9.0.2"/><vers edition="Macintosh" num="9.0.1"/><vers edition="Macintosh" num="9.0.0"/></prod><prod name="Norton System Works" vendor="Symantec"><vers edition="Macintosh" num="3.0"/></prod><prod name="Norton Internet Security" vendor="Symantec"><vers edition="Macintosh" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-20" name="CVE-2006-1837" published="2006-04-19" seq="2006-1837" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in archiv2.php in Fuju News 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/1682"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17572">17572</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1374">ADV-2006-1374</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19677">19677</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25897">
fujunews-archiv2-sql-injection(25897)</ref></refs><vuln_soft><prod name="Fuju News" vendor="Clanscripte.net"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-20" name="CVE-2006-1838" published="2006-04-19" seq="2006-1838" severity="High" type="CVE"><desc><descript source="cve">edit_kategorie.php in Fuju News 1.0 allows remote attackers to bypass authentication by setting the authorized cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/1682"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17572">17572</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1374">ADV-2006-1374</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19677">19677</ref></refs><vuln_soft><prod name="Fuju News" vendor="Clanscripte.net"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-20" name="CVE-2006-1839" published="2006-04-19" seq="2006-1839" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in language.php in PHP Album 0.3.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary code via an FTP URL in the data_dir parameter, which satisfies the file_exists function call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431067/100/0/threaded">20060415 PHP Album &lt;= 0.3.2.3 remote commnads execution</ref><ref source="" url="http://retrogod.altervista.org/phpalbum_0323_incl_xpl.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1382">ADV-2006-1382</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19661">19661</ref><ref source="BID" url="http://www.securityfocus.com/bid/17526">17526</ref><ref source="OSVDB" url="http://www.osvdb.org/24741">24741</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25846">phpalbum-language-file-include(25846)</ref></refs><vuln_soft><prod name="PHP Album" vendor="PHP Album"><vers num="0.3.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-08-13" name="CVE-2006-1840" published="2006-04-19" seq="2006-1840" severity="Medium" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in Empire Server before 4.3.1 allow attackers to cause a denial of servicr (crash) via the (1) load, (2) spy and (3) bomb functions.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=410001&amp;group_id=24031"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1380">ADV-2006-1380</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19674">19674</ref><ref source="BID" url="http://www.securityfocus.com/bid/17585">17585</ref><ref source="OSVDB" url="http://www.osvdb.org/24700">24700</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25863">empireserver-unspecified(25863)</ref></refs><vuln_soft><prod name="Empire Server" vendor="Empire Server"><vers num="4.3.0"/><vers num="4.2.23"/><vers num="4.2.22"/><vers num="4.2.21"/><vers num="4.2.20"/><vers num="4.2.19"/><vers num="4.2.18"/><vers num="4.2.17"/><vers num="4.2.16"/><vers num="4.2.15"/><vers num="4.2.14"/><vers num="4.2.13"/><vers num="4.2.12"/><vers num="4.2.11"/><vers num="4.2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-20" name="CVE-2006-1841" published="2006-04-19" seq="2006-1841" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in boastMachine (bMachine) 2.7, and possibly other versions before 2.9b, allows remote attackers to inject arbitrary web script or HTML via the key parameter, as used by the search field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431120/100/0/threaded">20060416 Xss In bMachine 2?7</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1375">ADV-2006-1375</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19711">19711</ref><ref source="BID" url="http://www.securityfocus.com/bid/17550">17550</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25914">
boastmachine-search-xss(25914)</ref></refs><vuln_soft><prod name="boastMachine" vendor="Kailash Nadh"><vers num="2.9b"/><vers num="2.8"/><vers num="2.7"/><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-24" name="CVE-2006-1842" published="2006-04-19" seq="2006-1842" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) NAME and (2) COMMENTS parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431130/100/0/threaded">20060417 ShoutBOOK &lt;= 1.1 XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/17548">17548</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1385">ADV-2006-1385</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19704">19704</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015958">1015958</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25862">
shoutbook-global-xss(25862)</ref></refs><vuln_soft><prod name="ShoutBOOK" vendor="Cynical Games"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-20" name="CVE-2006-1843" published="2006-04-19" seq="2006-1843" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) LOCATION and (2) URL parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1385">ADV-2006-1385</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19704">19704</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25862">
shoutbook-global-xss(25862)</ref></refs><vuln_soft><prod name="ShoutBOOK" vendor="Cynical Games"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1844" published="2006-04-19" seq="2006-1844" severity="Low" type="CVE"><desc><descript source="cve">The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pppoeconf passwords, which might allow local users to gain privileges.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=356939"></ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/23922">23922</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19170">19170</ref></refs><vuln_soft><prod name="shadow" vendor="Debian"><vers num="4.0.14"/></prod><prod name="base-config" vendor="Debian"><vers num="2.53.10"/></prod></vuln_soft></entry><entry modified="2006-04-26" name="CVE-2006-1845" published="2006-04-19" reject="1" seq="2006-1845" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0537.  Reason: This candidate is a duplicate of CVE-2006-0537.  Notes: All CVE users should reference CVE-2006-0537 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><refs/></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-20" name="CVE-2006-1846" published="2006-04-19" seq="2006-1846" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Your_Account module in PHP-Nuke 7.8 might allows remote attackers to inject arbitrary HTML and web script via the ublock parameter, which is saved in the user&apos;s personal menu.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. In addition, it is unclear whether this issue is a vulnerability, since it is related to the user&apos;s personal menu, which presumably is not modifiable by others.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16774">16774</ref><ref source="OSVDB" url="http://www.osvdb.org/23431">23431</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18972">18972</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0687">
ADV-2006-0687</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="7.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-20" name="CVE-2006-1847" published="2006-04-19" seq="2006-1847" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the Your_Account module in PHP-Nuke 7.8 might allows remote attackers to execute arbitrary SQL commands via the user_id parameter in the Your_Home functionality.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16774">16774</ref><ref source="OSVDB" url="http://www.osvdb.org/23432">23432</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18972">18972</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0687">
ADV-2006-0687</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="7.8"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-21" name="CVE-2006-1848" published="2006-04-19" seq="2006-1848" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in stats_view.php in LinPHA 1.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date_from, (2) date_to, and (3) date parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431242/100/0/threaded">20060417 Linpha 1.1.0 - XSS Vulnerabilities</ref><ref source="" url="http://d4igoro.blogspot.com/2006/04/linpha-xss-vulnerabilities.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17581">17581</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1396">ADV-2006-1396</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19679">19679</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25916">
linpha-statsview-xss(25916)</ref></refs><vuln_soft><prod name="LinPHA" vendor="LinPHA"><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-21" name="CVE-2006-1849" published="2006-04-19" seq="2006-1849" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in members_only/index.cgi in xFlow 5.46.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) position and (2) id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/xflow-v5x-multiple-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1412">ADV-2006-1412</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19707">19707</ref><ref source="BID" url="http://www.securityfocus.com/bid/17614">17614</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25853">
xflow-index-sql-injection(25853)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/xflow-v5x-multiple-vuln.html"></ref></refs><vuln_soft><prod name="xFlow" vendor="Skymarx Solutions"><vers num="5.46.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-21" name="CVE-2006-1850" published="2006-04-19" seq="2006-1850" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in xFlow 5.46.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) level, (2) position, (3) id, and (4) action parameters to members_only/index.cgi, and the (5) page parameter to customer_area/index.cgi.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/xflow-v5x-multiple-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1412">ADV-2006-1412</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19707">19707</ref><ref source="BID" url="http://www.securityfocus.com/bid/17614">17614</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25854">
xflow-index-xss(25854)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/xflow-v5x-multiple-vuln.html"></ref></refs><vuln_soft><prod name="xFlow" vendor="Skymarx Solutions"><vers num="5.46.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-21" name="CVE-2006-1851" published="2006-04-19" seq="2006-1851" severity="Medium" type="CVE"><desc><descript source="cve">xFlow 5.46.11 and earlier allows remote attackers to determine the installation path of the application via the (1) action parameter to members_only/index.cgi and (2) page parameter customer_area/index.cgi, probably due to invalid values.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/xflow-v5x-multiple-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17614">17614</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25855">
xflow-index-path-disclosure(25855)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/xflow-v5x-multiple-vuln.html"></ref></refs><vuln_soft><prod name="xFlow" vendor="Skymarx Solutions"><vers num="5.46.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-21" name="CVE-2006-1852" published="2006-04-19" seq="2006-1852" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in category.php in Article Publisher Pro 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cname parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/article-publisher-pro-sql-inj.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/24730">24730</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25898">articlepublisher-category-sql-injection(25898)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/article-publisher-pro-sql-inj.html"></ref></refs><vuln_soft><prod name="Article Publisher Pro" vendor="ScriptsFrenzy"><vers num="1.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-21" name="CVE-2006-1853" published="2006-04-19" seq="2006-1853" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in ModernBill 4.3.2 and earlier allow remote attackers or administrators to execute arbitrary SQL commands via the (1) id parameter in (a) user.php, or (2) where and (3) order parameters to (b) admin.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/modernbill-multiple-sql-inj-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17596">17596</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1415">ADV-2006-1415</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19641">19641</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25926">
modernbill-user-sql-injection(25926)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/modernbill-multiple-sql-inj-vuln.html"></ref></refs><vuln_soft><prod name="ModernBill" vendor="ModernGigabyte"><vers num="4.3.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-16" name="CVE-2006-1854" published="2006-04-19" seq="2006-1854" severity="Low" type="CVE"><desc><descript source="cve">** DISPUTED **  Multiple cross-site scripting (XSS) vulnerabilities in BluePay Manager 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML during a login action via the (1) Account Name and (2) Username field.  NOTE: the vendor has disputed this vulnerability, saying that &quot;it does not exist currently in the Bluepay 2.0 product,&quot; and older versions might not have been affected either.  As of 20060512, CVE has not formally investigated this dispute.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/bluepay-manager-v20-script-insertion.html"></ref><ref source="" url="http://pridels0.blogspot.com/2006/04/bluepay-manager-v20-script-insertion.html"></ref></refs><vuln_soft><prod name="BluePay Manager" vendor="BluePay"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-19" name="CVE-2006-1855" published="2006-05-18" seq="2006-1855" severity="Low" type="CVE"><desc><descript source="cve">choose_new_parent in Linux kernel before 2.6.11.12 includes certain debugging code, which allows local users to cause a denial of service (panic) by causing certain circumstances involving termination of a parent process.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=127302"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0493.html">RHSA-2006:0493</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20237">20237</ref><ref source="BID" url="http://www.securityfocus.com/bid/18099">18099</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-302-1">USN-302-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20716">20716</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_42_kernel.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21179">21179</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21745">21745</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1184">DSA-1184</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22093">22093</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.11.9"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.11"/><vers num="2.6.11.10"/><vers num="2.6.11.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-22" name="CVE-2006-1856" published="2006-05-19" seq="2006-1856" severity="High" type="CVE"><desc><descript source="cve">Certain modifications to the Linux kernel 2.6.16 and earlier do not add the appropriate Linux Security Modules (LSM) file_permission hooks to the (1) readv and (2) writev functions, which might allow attackers to bypass intended access restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://lists.jammed.com/linux-security-module/2005/09/0019.html">[linux-security-module] 20050928 readv/writev syscalls are not checked by lsm</ref><ref source="MLIST" url="http://www.ussg.iu.edu/hypermail/linux/kernel/0604.3/0777.html">[linux-kernel] 20060426 [PATCH] LSM: add missing hook to do_compat_readv_writev()</ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=191524"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0493.html">RHSA-2006:0493</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20237">20237</ref><ref source="BID" url="http://www.securityfocus.com/bid/18105">18105</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-302-1">USN-302-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20716">20716</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:123">MDKSA-2006:123</ref><ref source="OSVDB" url="http://www.osvdb.org/25747">25747</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21045">21045</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21745">21745</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1184">DSA-1184</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22093">22093</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:123">MDKSA-2006:123</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.16"/><vers num="2.6.15.5"/><vers num="2.6.15.4"/><vers num="2.6.15.3"/><vers num="2.6.15.2"/><vers num="2.6.15.1"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.15"/><vers num="2.6.14.5"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.14"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13-rc7"/><vers num="2.6.13-rc6"/><vers num="2.6.13-rc4"/><vers num="2.6.13-rc1"/><vers num="2.6.13"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12-rc5"/><vers num="2.6.12-rc4"/><vers num="2.6.12-rc1"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11-rc4"/><vers num="2.6.11-rc3"/><vers num="2.6.11-rc2"/><vers num="2.6.11"/><vers num="2.6.10-rc2"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1-rc2"/><vers num="2.6.1-rc1"/><vers num="2.6.1"/><vers num="2.6 test 9 CVS"/><vers num="2.6-test9"/><vers num="2.6-test8"/><vers num="2.6-test7"/><vers num="2.6-test6"/><vers num="2.6-test5"/><vers num="2.6-test4"/><vers num="2.6-test3"/><vers num="2.6-test2"/><vers num="2.6-test11"/><vers num="2.6-test10"/><vers num="2.6-test1"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-22" name="CVE-2006-1857" published="2006-05-22" seq="2006-1857" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed HB-ACK chunk.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1893">ADV-2006-1893</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20185">20185</ref><ref source="BID" url="http://www.securityfocus.com/bid/18085">18085</ref><ref source="OSVDB" url="http://www.osvdb.org/25695">25695</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26584">linux-sctp-hback-dos(26584)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1097">DSA-1097</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20671">20671</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-302-1">USN-302-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20716">20716</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:123">MDKSA-2006:123</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21045">21045</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_42_kernel.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21179">21179</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0575.html">RHSA-2006:0575</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_47_kernel.html">SUSE-SA:2006:047</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21465">21465</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:150">MDKSA-2006:150</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/22417">22417</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21476">
21476</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21498">
21498</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:123">MDKSA-2006:123</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:150">MDKSA-2006:150</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.16.16"/><vers num="2.6.16.15"/><vers num="2.6.16.14"/><vers num="2.6.16.13"/><vers num="2.6.16.12"/><vers num="2.6.16.11"/><vers num="2.6.16.10"/><vers num="2.6.16.9"/><vers num="2.6.16.8"/><vers num="2.6.16.7"/><vers num="2.6.16.6"/><vers num="2.6.16.5"/><vers num="2.6.16.4"/><vers num="2.6.16.3"/><vers num="2.6.16.2"/><vers num="2.6.16.1"/><vers num="2.6.16-rc6"/><vers num="2.6.16-rc5"/><vers num="2.6.16-rc4"/><vers num="2.6.16-rc3"/><vers num="2.6.16-rc2"/><vers num="2.6.16-rc1"/><vers num="2.6.15.5"/><vers num="2.6.15.4"/><vers num="2.6.15.3"/><vers num="2.6.15.2"/><vers num="2.6.15.1"/><vers num="2.6.15-rc7"/><vers num="2.6.15-rc6"/><vers num="2.6.15-rc5"/><vers num="2.6.15-rc4"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.15"/><vers num="2.6.14.5"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14-rc5"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.14"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13-rc7"/><vers num="2.6.13-rc6"/><vers num="2.6.13-rc5"/><vers num="2.6.13-rc4"/><vers num="2.6.13-rc3"/><vers num="2.6.13-rc2"/><vers num="2.6.13-rc1"/><vers num="2.6.13"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12-rc6"/><vers num="2.6.12-rc5"/><vers num="2.6.12-rc4"/><vers num="2.6.12-rc3"/><vers num="2.6.12-rc2"/><vers num="2.6.12-rc1"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11-rc5"/><vers num="2.6.11-rc4"/><vers num="2.6.11-rc3"/><vers num="2.6.11-rc2"/><vers num="2.6.11-rc1"/><vers num="2.6.11"/><vers num="2.6.10-rc3"/><vers num="2.6.10-rc2"/><vers num="2.6.10-rc1"/><vers num="2.6.10"/><vers num="2.6.9-rc4"/><vers num="2.6.9-rc3"/><vers num="2.6.9-rc2"/><vers num="2.6.9-rc1"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8-rc4"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7-rc3"/><vers num="2.6.7-rc2"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc3"/><vers num="2.6.6-rc2"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5-rc3"/><vers num="2.6.5-rc2"/><vers num="2.6.5-rc1"/><vers num="2.6.5"/><vers num="2.6.4-rc3"/><vers num="2.6.4-rc2"/><vers num="2.6.4-rc1"/><vers num="2.6.4"/><vers num="2.6.3-rc3"/><vers num="2.6.3-rc2"/><vers num="2.6.3-rc1"/><vers num="2.6.3"/><vers num="2.6.2-rc3"/><vers num="2.6.2-rc2"/><vers num="2.6.2-rc1"/><vers num="2.6.2"/><vers num="2.6.1-rc2"/><vers num="2.6.1-rc1"/><vers num="2.6.1"/><vers num="2.6 test 9 CVS"/><vers num="2.6-test9"/><vers num="2.6-test8"/><vers num="2.6-test7"/><vers num="2.6-test6"/><vers num="2.6-test5"/><vers num="2.6-test4"/><vers num="2.6-test3"/><vers num="2.6-test2"/><vers num="2.6-test11"/><vers num="2.6-test10"/><vers num="2.6-test1"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-22" name="CVE-2006-1858" published="2006-05-22" seq="2006-1858" severity="High" type="CVE"><desc><descript source="cve">SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a chunk length that is inconsistent with the actual length of provided parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1893">ADV-2006-1893</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20185">20185</ref><ref source="BID" url="http://www.securityfocus.com/bid/18085">18085</ref><ref source="OSVDB" url="http://www.osvdb.org/25696">25696</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26585">linux-sctp-parameter-dos(26585)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1097">DSA-1097</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20671">20671</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-302-1">USN-302-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20716">20716</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:123">MDKSA-2006:123</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21045">21045</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_42_kernel.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21179">21179</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_47_kernel.html">SUSE-SA:2006:047</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0617.html">RHSA-2006:0617</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21605">21605</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:150">MDKSA-2006:150</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-203.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/22174">22174</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21476">
21476</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21498">
21498</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:123">MDKSA-2006:123</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:150">MDKSA-2006:150</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.16.16"/><vers num="2.6.16.15"/><vers num="2.6.16.14"/><vers num="2.6.16.13"/><vers num="2.6.16.12"/><vers num="2.6.16.11"/><vers num="2.6.16.10"/><vers num="2.6.16.9"/><vers num="2.6.16.8"/><vers num="2.6.16.7"/><vers num="2.6.16.6"/><vers num="2.6.16.5"/><vers num="2.6.16.4"/><vers num="2.6.16.3"/><vers num="2.6.16.2"/><vers num="2.6.16.1"/><vers num="2.6.16-rc6"/><vers num="2.6.16-rc5"/><vers num="2.6.16-rc4"/><vers num="2.6.16-rc3"/><vers num="2.6.16-rc2"/><vers num="2.6.16-rc1"/><vers num="2.6.15.5"/><vers num="2.6.15.4"/><vers num="2.6.15.3"/><vers num="2.6.15.2"/><vers num="2.6.15.1"/><vers num="2.6.15-rc7"/><vers num="2.6.15-rc6"/><vers num="2.6.15-rc5"/><vers num="2.6.15-rc4"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.15"/><vers num="2.6.14.5"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14-rc5"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.14"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13-rc7"/><vers num="2.6.13-rc6"/><vers num="2.6.13-rc5"/><vers num="2.6.13-rc4"/><vers num="2.6.13-rc3"/><vers num="2.6.13-rc2"/><vers num="2.6.13-rc1"/><vers num="2.6.13"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12-rc6"/><vers num="2.6.12-rc5"/><vers num="2.6.12-rc4"/><vers num="2.6.12-rc3"/><vers num="2.6.12-rc2"/><vers num="2.6.12-rc1"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11-rc5"/><vers num="2.6.11-rc4"/><vers num="2.6.11-rc3"/><vers num="2.6.11-rc2"/><vers num="2.6.11-rc1"/><vers num="2.6.11"/><vers num="2.6.10-rc3"/><vers num="2.6.10-rc2"/><vers num="2.6.10-rc1"/><vers num="2.6.10"/><vers num="2.6.9-rc4"/><vers num="2.6.9-rc3"/><vers num="2.6.9-rc2"/><vers num="2.6.9-rc1"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8-rc4"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7-rc3"/><vers num="2.6.7-rc2"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc3"/><vers num="2.6.6-rc2"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5-rc3"/><vers num="2.6.5-rc2"/><vers num="2.6.5-rc1"/><vers num="2.6.5"/><vers num="2.6.4-rc3"/><vers num="2.6.4-rc2"/><vers num="2.6.4-rc1"/><vers num="2.6.4"/><vers num="2.6.3-rc3"/><vers num="2.6.3-rc2"/><vers num="2.6.3-rc1"/><vers num="2.6.3"/><vers num="2.6.2-rc3"/><vers num="2.6.2-rc2"/><vers num="2.6.2-rc1"/><vers num="2.6.2"/><vers num="2.6.1-rc2"/><vers num="2.6.1-rc1"/><vers num="2.6.1"/><vers num="2.6 test 9 CVS"/><vers num="2.6-test9"/><vers num="2.6-test8"/><vers num="2.6-test7"/><vers num="2.6-test6"/><vers num="2.6-test5"/><vers num="2.6-test4"/><vers num="2.6-test3"/><vers num="2.6-test2"/><vers num="2.6-test11"/><vers num="2.6-test10"/><vers num="2.6-test1"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-11" modified="2006-05-12" name="CVE-2006-1859" published="2006-05-11" seq="2006-1859" severity="Low" type="CVE"><desc><descript source="cve">Memory leak in __setlease in fs/locks.c in Linux kernel before 2.6.16.16 allows attackers to cause a denial of service (memory consumption) via unspecified actions related to an &quot;uninitialised return value,&quot; aka &quot;slab leak.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.16.y.git;a=commit;h=1f0e637c94a9b041833947c79110d6c02fff8618"></ref><ref source="" url="http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.16.y.git;a=blobdiff;h=aa7f66091823dde953e15895dc427615701c39c7;hp=e75ac392a313f3fad823bf2e46a03f29701e3e34;hb=1f0e637c94a9b041833947c79110d6c02fff8618;f=fs/locks.c"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1767">ADV-2006-1767</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20083">20083</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0028">2006-0028</ref><ref source="BID" url="http://www.securityfocus.com/bid/18033">18033</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26438">linux-locks-setlease-dos(26438)</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-302-1">USN-302-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20716">20716</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:123">MDKSA-2006:123</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21045">21045</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_42_kernel.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21179">21179</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:123">MDKSA-2006:123</ref></refs><vuln_soft><prod name="Linux Kernel" vendor="Linux"><vers num="2.6.16.15"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-11" modified="2006-05-12" name="CVE-2006-1860" published="2006-05-11" seq="2006-1860" severity="Low" type="CVE"><desc><descript source="cve">lease_init in fs/locks.c in Linux kernel before 2.6.16.16 allows attackers to cause a denial of service (fcntl_setlease lockup) via actions that cause lease_init to free a lock that might not have been allocated on the stack.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.16"></ref><ref source="" url="http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.16.y.git;a=commit;h=1f0e637c94a9b041833947c79110d6c02fff8618"></ref><ref source="" url="http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.16.y.git;a=blobdiff;h=aa7f66091823dde953e15895dc427615701c39c7;hp=e75ac392a313f3fad823bf2e46a03f29701e3e34;hb=1f0e637c94a9b041833947c79110d6c02fff8618;f=fs/locks.c"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17943">17943</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1767">ADV-2006-1767</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/20083">20083</ref><ref source="OSVDB" url="http://www.osvdb.org/25425">25425</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0028">2006-0028</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26437">linux-locks-lease-init-dos(26437)</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-302-1">USN-302-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20716">20716</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:123">MDKSA-2006:123</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21045">21045</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_42_kernel.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21179">21179</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:123">MDKSA-2006:123</ref></refs><vuln_soft><prod name="Linux Kernel" vendor="Linux"><vers num="2.6.16.15"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-06-05" name="CVE-2006-1861" published="2006-05-23" seq="2006-1861" severity="High" type="CVE"><desc><descript source="cve">Multiple integer overflows in FreeType before 2.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to (1) bdf/bdflib.c, (2) sfnt/ttcmap.c, (3) cff/cffgload.c, and (4) the read_lwfn function and a crafted LWFN file in base/ftmac.c.  NOTE: item 4 was originally identified by CVE-2006-2493.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=190593"></ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=416463"></ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=190593#c8"></ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=128606"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18034">18034</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1868">ADV-2006-1868</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20100">20100</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/26553">freetype-lwfn-overflow(26553)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/436836/100/0/threaded">20060612 rPSA-2006-0100-1 freetype</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1095">DSA-1095</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:099">MDKSA-2006:099</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-291-1">USN-291-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20525">20525</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20591">20591</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20638">20638</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Jun/0012.html">SUSE-SA:2006:037</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20791">20791</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200607-02.xml">GLSA-200607-02</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21000">21000</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0500.html">RHSA-2006:0500</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21062">21062</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U">20060701-01-U</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016522">1016522</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21135">21135</ref><ref source="" url="https://issues.rpath.com/browse/RPL-429"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21385">21385</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-176.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21701">21701</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102705-1">
102705</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0381">
ADV-2007-0381</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23939">
23939</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200710-09.xml">GLSA-200710-09</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:099">MDKSA-2006:099</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2007-10/msg00006.html">SUSE-SR:2007:021</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27162">27162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27167">27167</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27271">27271</ref></refs><vuln_soft><prod name="FreeType" vendor="FreeType"><vers num="2.1.10"/><vers num="2.1.9"/><vers num="2.1.8"/><vers num="2.1.8 rc1"/><vers num="2.1.7"/><vers num="2.1.6"/><vers num="2.1.5"/><vers num="2.1.4"/><vers num="2.1.3"/><vers num="2.0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-25" name="CVE-2006-1862" published="2006-05-24" seq="2006-1862" severity="Medium" type="CVE"><desc><descript source="cve">The virtual memory implementation in Linux kernel 2.6.x allows local users to cause a denial of service (panic) by running lsof a large number of times in a way that produces a heavy system load.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0493.html">RHSA-2006:0493</ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189260"></ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189031"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/20237">20237</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21745">21745</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.9"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-30" name="CVE-2006-1863" published="2006-04-25" seq="2006-1863" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in CIFS in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via &quot;..\\&quot; sequences, a similar vulnerability to CVE-2006-1864.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="Bugzilla" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189434">Bugzilla Bug 189434</ref><ref patch="1" source="Kernel.org" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=296034f7de8bdf111984ce1630ac598a9c94a253"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17742">17742</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1542">ADV-2006-1542</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19868">19868</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0024">2006-0024</ref><ref source="OSVDB" url="http://www.osvdb.org/25068">25068</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:150">MDKSA-2006:150</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:151">MDKSA-2006:151</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21614">21614</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.11"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26141">
kernel-cifs-directory-traversal(26141)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:150">MDKSA-2006:150</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:151">MDKSA-2006:151</ref></refs><vuln_soft><prod name="Linux Kernel" vendor="Linux"><vers num="2.6.17" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-19" modified="2006-04-27" name="CVE-2006-1864" published="2006-04-26" seq="2006-1864" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in smbfs in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via &quot;..\\&quot; sequences, a similar vulnerability to CVE-2006-1863.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189435"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17735">17735</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19869">19869</ref><ref source="OSVDB" url="http://www.osvdb.org/25067">25067</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0026">2006-0026</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0493.html">RHSA-2006:0493</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20237">20237</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1097">DSA-1097</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20671">20671</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-302-1">USN-302-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20716">20716</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0579.html">RHSA-2006:0579</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0580.html">RHSA-2006:0580</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21035">21035</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:150">MDKSA-2006:150</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:151">MDKSA-2006:151</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21614">21614</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21745">21745</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0710.html">RHSA-2006:0710</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22497">22497</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451404/100/0/threaded">20061113 VMSA-2006-0006 - VMware ESX Server 2.5.3 Upgrade Patch 4</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451419/100/200/threaded">20061113 VMSA-2006-0005 - VMware ESX Server 2.5.4 Upgrade Patch 1</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451417/100/200/threaded">20061113 VMSA-2006-0007 - VMware ESX Server 2.1.3 Upgrade Patch 2</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451426/100/200/threaded">20061113 VMSA-2006-0008 - VMware ESX Server 2.0.2 Upgrade Patch 2</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-254.htm"></ref><ref source="" url="http://www.vmware.com/download/esx/esx-202-200610-patch.html"></ref><ref source="" url="http://www.vmware.com/download/esx/esx-213-200610-patch.html"></ref><ref source="" url="http://www.vmware.com/download/esx/esx-254-200610-patch.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4502">ADV-2006-4502</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22875">22875</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23064">23064</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21476">
21476</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26137">
kernel-smbfs-directory-traversal(26137)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:150">MDKSA-2006:150</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:151">MDKSA-2006:151</ref></refs><vuln_soft><prod name="Linux Kernel" vendor="Linux"><vers num="2.6.16.8"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.16-rc7"/><vers num="2.6.16-rc6"/><vers num="2.6.16-rc5"/><vers num="2.6.16-rc4"/><vers num="2.6.16-rc3"/><vers num="2.6.16-rc2"/><vers num="2.6.16-rc1"/><vers num="2.6.16.7"/><vers num="2.6.16.4"/><vers num="2.6.16.3"/><vers num="2.6.16.2"/><vers num="2.6.16.1"/><vers num="2.6.16 -rc1"/><vers num="2.6.16"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-13" name="CVE-2006-1865" published="2006-04-21" seq="2006-1865" severity="High" type="CVE"><desc><descript source="cve">Argument injection vulnerability in Beagle before 0.2.5 allows attackers to execute arbitrary commands via crafted filenames that inject command line arguments when Beagle launches external helper applications while indexing.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189282"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17611">17611</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_28.html">SUSE-SR:2006:009</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19897">19897</ref><ref source="" url="http://scary.beasts.org/security/CESA-2006-002.html"></ref><ref source="FEDORA" url="http://lists.seifried.org/pipermail/security/2006-April/013163.html">FEDORA-2006-440</ref><ref source="OSVDB" url="http://www.osvdb.org/24938">24938</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19781">19781</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19778">19778</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26104">beagle-indexing-command-execution(26104)</ref></refs><vuln_soft><prod name="Beagle" vendor="Beagle"><vers num="0.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1866" published="2006-04-20" seq="2006-1866" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and other versions have unknown impact and attack vectors in the (1) Advanced Replication component, as identified by Vuln# DB01, and (2) Oracle Spatial component, as identified by Vuln# DB10.  NOTE: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed a claim by a reliable independent researcher that states that DB01 is an unknown issue in the DBMS_REPUTIL package, and DB10 is SQL injection in the INSERT_CATALOG, UPDATE_CATALOG, and DELETE_CATALOG functions of the SDO_CATALOG package.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/139049">VU#139049</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-109A.html">
TA06-109A</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26050">
oracle-dbmsreputil-sql-injection(26050)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26054">
oracle-sdocatalog-sql-injection(26054)</ref></refs><vuln_soft><prod name="Oracle9i Database Server Release 1" vendor="Oracle"><vers num="9.0.1.5"/></prod><prod name="Oracle10g Database Server Release 1" vendor="Oracle"><vers num="10.1.0.5"/></prod><prod name="Oracle9i Database Server Release 2" vendor="Oracle"><vers num="9.2.0.7"/></prod><prod name="Oracle8i Database Server Release 3" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-21" name="CVE-2006-1867" published="2006-04-20" seq="2006-1867" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Database Server 9.2.0.6 has unknown impact and attack vectors in the Advanced Replication component, aka Vuln# DB02.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26068">
oracle-database-multiple-unspecified(26068)</ref></refs><vuln_soft><prod name="Oracle9i Database Server Release 2" vendor="Oracle"><vers num="9.2.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1868" published="2006-04-20" seq="2006-1868" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Advanced Replication component in Oracle Database Server 10.1.0.4 allows database users to execute arbitrary code via the VERIFY_LOG procedure of the DBMS_SNAPSHOT_UTL package, aka Vuln# DB03.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431588/100/0/threaded">20060420 [Argeniss] Oracle Database 10gR1 Buffer overflow in VERIFY_LOG procedure</ref><ref adv="1" source="" url="http://www.argeniss.com/research/ARGENISS-ADV-040603.txt"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html"></ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/797465">VU#797465</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-109A.html">
TA06-109A</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26049">
oracle-dbmssnapshotutl-bo(26049)</ref></refs><vuln_soft><prod name="Oracle10g Database Server Release 1" vendor="Oracle"><vers num="10.1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-21" name="CVE-2006-1869" published="2006-04-20" seq="2006-1869" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Database Server 8.1.7.4 and 9.0.1.5 has unknown impact and attack vectors in the Dictionary component, aka Vuln# DB04.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/241481">VU#241481</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-109A.html">
TA06-109A</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26052">
oracle-dictionary-constraint-modification(26052)</ref></refs><vuln_soft><prod name="Oracle9i Database Server Release 1" vendor="Oracle"><vers num="9.0.1.5"/></prod><prod name="Oracle8i Database Server Release 3" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-05-14" name="CVE-2006-1870" published="2006-04-20" seq="2006-1870" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.2 has unknown impact and attack vectors in the Export component, aka Vuln# DB05.  NOTE: details are unavailable from Oracle, but as of 20060427, they have not publicly commented on whether DB05 is the same issue as CVE-2006-2081.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431353/100/0/threaded">20060419 Oracle 10g 10.2.0.2.0 DBA exploit</ref><ref adv="1" source="" url="http://www.red-database-security.com/exploits/oracle-sql-injection-oracle-dbms_export_extension.html"></ref><ref adv="1" source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html"></ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/452681">VU#452681</ref><ref adv="1" source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref></refs><vuln_soft><prod name="Oracle9i Database Server Release 1" vendor="Oracle"><vers num="9.0.1.5"/></prod><prod name="Oracle10g Database Server Release 1" vendor="Oracle"><vers num="10.1.0.5"/></prod><prod name="Oracle9i Database Server Release 2" vendor="Oracle"><vers num="9.2.0.7"/></prod><prod name="Oracle8i Database Server Release 3" vendor="Oracle"><vers num="8.1.7.4"/></prod><prod name="Oracle10g Database Server Release 2" vendor="Oracle"><vers num="10.2.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2005-11-01" modified="2008-05-14" name="CVE-2006-1871" published="2006-04-20" seq="2006-1871" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Oracle Database Server 9.2.0.7 and 10.1.0.5 allows remote attackers to execute arbitrary SQL commands via the DELETE_FROM_TABLE function in the DBMS_LOGMNR_SESSION (Log Miner) package, aka Vuln# DB06.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_logmnr_session.html"></ref><ref source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431345/30/5490/threaded">20060418 SQL Injection in package SYS.DBMS_LOGMNR_SESSION</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045280.html">20060418 SQL Injection in package SYS.DBMS_LOGMNR_SESSION</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26047">oracle-dbmslogmnrsession-sql-injection(26047)</ref></refs><vuln_soft><prod name="Oracle10g Database Server Release 1" vendor="Oracle"><vers num="10.1.0.5"/></prod><prod name="Oracle9i Database Server Release 2" vendor="Oracle"><vers num="9.2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-21" name="CVE-2006-1872" published="2006-04-20" seq="2006-1872" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Database Server 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors in the Oracle Enterprise Manager Intelligent Agent component, aka Vuln# DB07.</descript></desc><sols><sol source="nvd">Apply patches :
http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</sol></sols><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26068">
oracle-database-multiple-unspecified(26068)</ref></refs><vuln_soft><prod name="Oracle Database Server" vendor="Oracle"><vers num="9.0.1.5"/><vers num="9.2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-05-15" name="CVE-2006-1873" published="2006-04-20" seq="2006-1873" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Database Server 9.2.0.7, 10.1.0.4, and 10.2.0.1 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB08.</descript></desc><sols><sol source="nvd">Apply patches :
http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26068">oracle-database-multiple-unspecified(26068)</ref></refs><vuln_soft><prod name="Oracle Database Server" vendor="Oracle"><vers num="9.2.0.7"/><vers num="10.1.0.4"/><vers num="10.2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-13" name="CVE-2006-1874" published="2006-04-20" seq="2006-1874" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, and 9.2.0.6 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB09.  NOTE: Oracle has not disputed reliable claims that this issue is SQL injection in MDSYS.PRVT_IDX using the (1) EXECUTE_INSERT, (2) EXECUTE_DELETE, (3) EXECUTE_UPDATE, (4) EXECUTE UPDATE, and (5) CRT_DUMMY functions.</descript></desc><sols><sol source="nvd">Apply patches.</sol></sols><loss_types><avail/><conf/><int/></loss_types><vuln_types><input bound="1"/><other/></vuln_types><range><network/></range><refs><ref source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26053">oracle-prvtidx-sql-injection(26053)</ref></refs><vuln_soft><prod name="Oracle Database Server" vendor="Oracle"><vers num="8.1.7.4"/><vers num="9.0.1.5"/><vers num="9.2.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-13" name="CVE-2006-1875" published="2006-04-20" seq="2006-1875" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Database Server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB11.  NOTE: Oracle has not disputed reliable researcher claims that this issue is SQL injection in MDSYS.SDO_LRS_TRIG_INS.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref patch="1" source="ORACLE" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html">Oracle Critical Patch Update - April 2006 </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26055">oracle-sdolrstrigins-sql-injection(26055)</ref></refs><vuln_soft><prod name="Oracle Database Server" vendor="Oracle"><vers num="9.0.1.5"/><vers num="9.2.0.7"/><vers num="10.1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-05-15" name="CVE-2006-1876" published="2006-04-20" seq="2006-1876" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Database Server 9.2.0.7 and 10.1.0.4 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB12.  NOTE: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the (1) GEN_RID_RANGE_BY_AREA and (2) GEN_RID_RANGE functions in the MDSYS.SDO_PRIDX package.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/240249">VU#240249</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26051">oracle-sdopridx-sql-injection(26051)</ref></refs><vuln_soft><prod name="Oracle10g Database Server Release 1" vendor="Oracle"><vers num="10.1.0.4"/></prod><prod name="Oracle9i Database Server Release 2" vendor="Oracle"><vers num="9.2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-05-15" name="CVE-2006-1877" published="2006-04-20" seq="2006-1877" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, and 9.2.0.7 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB13.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="OSVDB" url="http://www.osvdb.org/24861">24861</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26068">oracle-database-multiple-unspecified(26068)</ref></refs><vuln_soft><prod name="Oracle9i Database Server Release 1" vendor="Oracle"><vers num="9.0.1.5"/></prod><prod name="Oracle9i Database Server Release 2" vendor="Oracle"><vers num="9.2.0.7"/></prod><prod name="Oracle8i Database Server Release 3" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-21" name="CVE-2006-1878" published="2006-04-20" seq="2006-1878" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in phpFaber TopSites allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431073/100/0/threaded">20060415 phpFaber TopSites Script Cross-Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/17542">17542</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1394">ADV-2006-1394</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015945">1015945</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19652">19652</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25804">
phpfabertopsites-index-xss(25804)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/719">719</ref><ref source="SREASON" url="http://securityreason.com/securityalert/760">760</ref></refs><vuln_soft><prod name="TopSites" vendor="phpFaber"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-21" name="CVE-2006-1879" published="2006-04-20" seq="2006-1879" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in the Email Server component in Oracle Collaboration Suite 9.0.4.2, 10.1.1, 10.1.2.0, and 10.1.2.1 have unknown impact and attack vectors, aka Vuln# (1) OCS01, (2) OCS02, (3) OCS03, and (4) OCS04.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="ORACLE" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html">Oracle Critical Patch Update - April 2006 </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/549146">VU#549146</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/879041">VU#879041</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-109A.html">
TA06-109A</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26057">
oracle-collab-unauth-access(26057)</ref></refs><vuln_soft><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="9.0.4.2"/><vers num="10.1.1"/><vers num="10.1.2.0"/><vers num="10.1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-21" name="CVE-2006-1880" published="2006-04-20" seq="2006-1880" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, as identified by Vuln# (1) APPS01 in the (a) Application Install component; (2) APPS09 in the (b) Oracle Diagnostics Interfaces component; (3) APPS10 in the (c) Oracle General Ledger component; (4) APPS12 and (5) APPS13 in the (d) Oracle Receivables component.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="ORACLE" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html">Oracle Critical Patch Update - April 2006 </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/940729">VU#940729</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26058">
oracle-ebusiness-multiple-unspecifed(26058)</ref></refs><vuln_soft><prod name="Oracle E-Business Suite and Applications" vendor="Oracle"><vers num="11.5.10CU2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-21" name="CVE-2006-1881" published="2006-04-20" seq="2006-1881" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Financials for Asia/Pacific component in Oracle E-Business Suite and Applications 11.5.9 has unknown impact and attack vectors.  component, aka Vuln# APPS02.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="ORACLE" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html">Oracle Critical Patch Update - April 2006</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26058">
oracle-ebusiness-multiple-unspecifed(26058)</ref></refs><vuln_soft><prod name="Oracle E-Business Suite and Applications" vendor="Oracle"><vers num="11.5.9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-21" name="CVE-2006-1882" published="2006-04-20" seq="2006-1882" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10 have unknown impact and attack vectors, as identified by Vuln# (1) APPS03 in (a) iProcurement; (2) APPS04 in (b) Oracle Application Object Library; (3) APPS06, (4) APPS07, and (5) APPS08 in (c) Oracle Applications Technology Stack; and (6) APPS11 in (d) Oracle Order Capture.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="ORACLE" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html">Oracle Critical Patch Update - April 2006 </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/619194">VU#619194</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/824833">VU#824833</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26058">
oracle-ebusiness-multiple-unspecifed(26058)</ref></refs><vuln_soft><prod name="Oracle E-Business Suite and Applications" vendor="Oracle"><vers num="11.5.10"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-21" name="CVE-2006-1883" published="2006-04-20" seq="2006-1883" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite and Applications 11.5.10CU1 has unknown impact and attack vectors, aka Vuln# APPS05.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="ORACLE" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html">Oracle Critical Patch Update - April 2006 </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26058">
oracle-ebusiness-multiple-unspecifed(26058)</ref></refs><vuln_soft><prod name="Oracle E-Business Suite and Applications" vendor="Oracle"><vers num="11.5.10CU1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-22" name="CVE-2006-1884" published="2006-04-20" seq="2006-1884" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01.</descript></desc><sols><sol source="nvd">The vendor has addressed this issue through the release of product updates: 
http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html 

</sol></sols><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="ORACLE" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html">Oracle Critical Patch Update - April 2006 </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26058">oracle-ebusiness-multiple-unspecifed(26058)</ref></refs><vuln_soft><prod name="Oracle9i Release 2" vendor="Oracle"><vers num="9.2.0.6"/><vers num="9.2.0.7"/></prod><prod name="Database 10g" vendor="Oracle"><vers num="10.2.0.1"/><vers num="10.2.0.2"/><vers num="10.2.0.4"/><vers num="10.2.0.4.2"/><vers num="10.2.0.5"/></prod><prod name="Oracle 9i Collaboration Suite Release 2" vendor="Oracle"><vers num="9.0.4.2"/></prod><prod name="Oracle 8i Database Release 3" vendor="Oracle"><vers num="8.1.7.4"/></prod><prod name="OneWorld Tools" vendor="OneWorld"><vers num="8.95"/><vers num="8.95.J1"/></prod><prod name="Pharmaceutical Applications" vendor="Oracle"><vers num="4.5.0"/><vers num="4.5.1"/><vers num="4.5.2"/></prod><prod name="Oracle 9i Application Server Release 1" vendor="Oracle"><vers num="1.0.2.2"/></prod><prod name="PeopleSoft Enterprise Tools" vendor="Oracle"><vers num="8.46.12"/><vers num="8.46GA"/><vers num="8.47.04"/><vers num="8.47GA"/></prod><prod name="Oracle 8 Database Release 8.0.6" vendor="Oracle"><vers num="8.0.6.3"/></prod><prod name="Application Server 10g" vendor="Oracle"><vers num="10.1.2.0.1"/><vers num="10.1.2.0.2"/><vers num="10.1.2.1.0"/><vers num="10.1.2.0.0"/><vers num="9.0.4.1"/><vers num="9.0.4.2"/><vers num="10.1.3.0.0"/></prod><prod name="E-Business Suite" vendor="Oracle"><vers num="11.0"/><vers num="11i 11.5.1"/><vers num="11i 11.5.10"/><vers num="11i 11.5.10 CU1"/><vers num="11i 11.5.10 CU2"/></prod><prod name="Collaboration Suite 10g release 1" vendor="Oracle"><vers num="10.1.1"/><vers num="10.1.2.0"/><vers num="10.1.2.1"/></prod><prod name="Developer Suite" vendor="Oracle"><vers num="6i"/><vers num="9.0.4.2"/></prod><prod name="Workflow" vendor="Oracle"><vers num="11.5.1"/><vers num="11.5.9.5"/></prod><prod name="Orace9i Release 1" vendor="Oracle"><vers num="9.0.1.4"/><vers num="9.0.1.5"/></prod><prod name="Enterprise Manager Grid Control 10g" vendor="Oracle"><vers num="10.1.0.3"/><vers num="10.1.0.4"/><vers num="10.2.0.1"/></prod><prod name="EnterpriseOne Tools" vendor="JDEdwards"><vers num="8.95"/><vers num="8.95.J1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-21" name="CVE-2006-1885" published="2006-04-20" seq="2006-1885" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in the Reporting Framework component in Oracle Enterprise Manager 9.0.1.5 and 9.2.0.7 have unknown impact and attack vectors, aka Vuln# (1) EM01 and (2) EM02.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="ORACLE" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html">Oracle Critical Patch Update - April 2006 </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/443265">VU#443265</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26056">
oracle-reporting-framework-access(26056)</ref></refs><vuln_soft><prod name="Oracle Enterprise Manager" vendor="Oracle"><vers num="9.0.1.5"/><vers num="9.2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-21" name="CVE-2006-1886" published="2006-04-20" seq="2006-1886" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise 8.46.12 and 8.47.04 has unknown impact and attack vectors, aka Vuln# PSE01.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="ORACLE" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html">Oracle Critical Patch Update - April 2006 </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-109A.html">
TA06-109A</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26059">
oracle-peopletools-unspecified(26059)</ref></refs><vuln_soft><prod name="Oracle PeopleSoft Enterprise" vendor="Oracle"><vers num="8.46.12"/><vers num="8.47.04"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-21" name="CVE-2006-1887" published="2006-04-20" seq="2006-1887" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Security Server 8.95.J1 has unknown impact and attack vectors, aka Vuln# JDE01.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="ORACLE" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html">Oracle Critical Patch Update - April 2006 </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17590">17590</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1397">ADV-2006-1397</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015961">1015961</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19712">19712</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded">HPSBMA02113</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1571">ADV-2006-1571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19859">19859</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-109A.html">
TA06-109A</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26069">
oracle-jdedwards-enterpriseone-unspecified(26069)</ref></refs><vuln_soft><prod name="JD Edwards EnterpriseOne" vendor="Oracle"><vers num="8.95.J1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-04-17" modified="2007-07-03" name="CVE-2006-1888" published="2006-04-20" seq="2006-1888" severity="Medium" type="CVE"><desc><descript source="cve">phpGraphy 0.9.11 and earlier allows remote attackers to bypass authentication and gain administrator privileges via a direct request to index.php with the editwelcome parameter set to 1, which can then be used to modify the main page to inject arbitrary HTML and web script.  NOTE: XSS attacks are resultant from this issue, since normal functionality allows the admin to modify pages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431128/100/0/threaded">20060417 - PHPGraphy &lt;= 0.9.11 </ref><ref source="ALTERVISTA" url="http://retrogod.altervista.org/phpgraphy_0911_adv.html">PHPGraphy &lt;= 0.9.11 &apos;editwelcome&apos; unauthorized access / cross site scripting</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17567">17567</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431268/100/0/threaded">20060418 Re: - PHPGraphy &lt;= 0.9.11 </ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1379">ADV-2006-1379</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19705">19705</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015971">1015971</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25892">phpgraphy-index-xss(25892)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/733">733</ref></refs><vuln_soft><prod name="phpGraphy" vendor="phpGraphy"><vers num="0.9.11" prev="1"/><vers num="0.9.10"/><vers num="0.9.9a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-21" name="CVE-2006-1889" published="2006-04-20" seq="2006-1889" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the search action handler in index.php in Nils Asmussen (aka SCRIPTSOLUTION) Boardsolution 1.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the &quot;Search for&quot; item (keyword parameter).</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431072/100/0/threaded">20060415 Boardsolution &lt;= 1.12 XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/17549">17549</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1413">ADV-2006-1413</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015948">1015948</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19654">19654</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25805">
boardsolution-index-xss(25805)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/718">718</ref><ref source="SREASON" url="http://securityreason.com/securityalert/766">766</ref></refs><vuln_soft><prod name="Boardsolution" vendor="Script-solution.de"><vers num="1.12" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-16" modified="2006-08-08" name="CVE-2006-1890" published="2006-04-20" seq="2006-1890" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in myWebland myEvent 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter in (1) event.php and (2) initialize.php.  NOTE: vector 2 was later reported to affect 1.4 as well.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431125/100/0/threaded">20060416 MyEvent Remote File Execution And XSS Attacking</ref><ref source="BID" url="http://www.securityfocus.com/bid/17575">17575</ref><ref source="OSVDB" url="http://www.osvdb.org/24722">24722</ref><ref source="OSVDB" url="http://www.osvdb.org/24723">24723</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25882">myevent-event-initialize-file-include(25882)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016616">1016616</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1384">ADV-2006-1384</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19680">19680</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/28347">myevent-myevent-file-include(28347)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/726">726</ref><ref source="SREASON" url="http://securityreason.com/securityalert/767">767</ref></refs><vuln_soft><prod name="myEvent" vendor="myWebland"><vers num="1.2"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-16" modified="2006-04-21" name="CVE-2006-1891" published="2006-04-20" seq="2006-1891" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Martin Scheffler betaboard 0.1 allows remote attackers to inject arbitrary web script or HTML via a user&apos;s profile, possibly using the FormVal_profile parameter.  NOTE: it is not clear whether this is a distributable product or a site-specific vulnerability.  If it is site-specific, then it should not be included in CVE.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431116/100/0/threaded">20060416 BetaBoard Cross Site Scripting vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045194.html">20060416 BetaBoard Cross Site Scripting vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17556">17556</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1377">ADV-2006-1377</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015955">1015955</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19700">19700</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25838">betaboard-editprofile-xss(25838)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/724">724</ref><ref source="SREASON" url="http://securityreason.com/securityalert/765">765</ref></refs><vuln_soft><prod name="BetaBoard" vendor="BetaBoard"><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-14" modified="2006-04-21" name="CVE-2006-1892" published="2006-04-20" seq="2006-1892" severity="Medium" type="CVE"><desc><descript source="cve">avast! 4 Linux Home Edition 1.0.5 allows local users to modify permissions of arbitrary files via a symlink attack on the /tmp/_avast4_ temporary directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431019/100/0/threaded">20060414 Avast Linux Home Edition (vulnerability on a temporary folder creation)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17535">17535</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1387">ADV-2006-1387</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19683">19683</ref><ref source="SREASON" url="http://securityreason.com/securityalert/712">712</ref><ref source="SREASON" url="http://securityreason.com/securityalert/764">764</ref></refs><vuln_soft><prod name="Avast Antivirus" vendor="ALWIL"><vers edition="Home" num="1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-13" modified="2006-04-21" name="CVE-2006-1893" published="2006-04-20" seq="2006-1893" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in print.php in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431030/100/0/threaded">20060413 Xss In ar-blog v 5.2</ref><ref source="BID" url="http://www.securityfocus.com/bid/17522">17522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25834">
arblog-print-xss(25834)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/763">763</ref></refs><vuln_soft><prod name="Ar-blog" vendor="Ar-blog"><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-13" modified="2006-04-21" name="CVE-2006-1894" published="2006-04-20" seq="2006-1894" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in RevoBoard 1.8, as derived from PunBB, allows remote attackers to inject arbitrary web script or HTML via a substitution cipher of the email tag, which is transformed when the application&apos;s e-mail address obfuscator reverses the transformation.  NOTE: it is not clear whether this is a site-specific issue; however, the claimed codebase relationship with PunBB might be relevant.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430886/100/0/threaded">20060413 RevoBoard [email] tag XSS</ref><ref source="SREASON" url="http://securityreason.com/securityalert/768">768</ref></refs><vuln_soft><prod name="RevoBoard" vendor="RevoBoard"><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-14" modified="2006-04-21" name="CVE-2006-1895" published="2006-04-20" seq="2006-1895" severity="Medium" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary PHP code by modifying a template in a way that (1) bypasses a loose &quot;.*&quot; regular expression to match BEGIN and END statements in overall_header.tpl, or (2) is used in an eval statement by includes/bbcode.php for bbcode.tpl.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431017/100/0/threaded">20060414 phpBB template file code execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/17573">17573</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25888">
phpbb-template-code-execution(25888)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/769">769</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-04-14" modified="2008-03-05" name="CVE-2006-1896" published="2006-04-20" seq="2006-1896" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature values, possibly involving the highlight functionality.  NOTE: the original report does not clarify whether this issue is static code injection, eval injection, or another type of vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431015/100/0/threaded">20060414 phpBB Admin command execution</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431387/100/0/threaded">20060418 Re: phpBB Admin command execution</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1066">DSA-1066</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20197">20197</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20093">20093</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25889">phpbb-admin-code-execution(25889)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/715">715</ref><ref source="SREASON" url="http://securityreason.com/securityalert/762">762</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-13" modified="2006-04-21" name="CVE-2006-1897" published="2006-04-20" seq="2006-1897" severity="Medium" type="CVE"><desc><descript source="cve">Webplus (aka talentsoft) Web+Shop 5.3.6, when Redirect URL for &quot;Script Not Found&quot; Error is not configured, allows remote attackers to obtain sensitive information via a quote (&apos;) or possibly other invalid value in the storeid parameter in store.wml in webplus.exe, which reveals the path in a &quot;Script Not Found&quot; error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430880/100/0/threaded">20060413 TalentSoft Web+Shop Path Disclosure</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/24621">24621</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19662">19662</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25802">
webplusshop-webplus-path-disclosure(25802)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/703">703</ref><ref source="SREASON" url="http://securityreason.com/securityalert/761">761</ref></refs><vuln_soft><prod name="Web+ Shop" vendor="TalentSoft"><vers num="5.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1898" published="2006-04-20" seq="2006-1898" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Ralph Capper Tiny PHP Forum (TPF) 3.6 allow remote attackers to inject arbitrary web script or HTML via (1) the uname parameter in a view action in profile.php and (2) a login name.  NOTE: the &quot;Access to hash password&quot; issue is already covered by CVE-2006-0103.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431133/100/0/threaded">20060417 Tiny PHP forum - vulns</ref><ref source="BID" url="http://www.securityfocus.com/bid/17553">17553</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25856">
tinyphpforum-profile-error-xss(25856)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/728">728</ref><ref source="SREASON" url="http://securityreason.com/securityalert/773">773</ref></refs><vuln_soft><prod name="TinyPHPForum" vendor="Ralph Capper"><vers num="3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1899" published="2006-04-20" seq="2006-1899" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in dev Neuron Blog 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) website parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431131/100/0/threaded">20060417 Neuron Blog &lt;= 1.1 XSS</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015960">1015960</ref><ref source="BID" url="http://www.securityfocus.com/bid/17552">17552</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1406">
ADV-2006-1406</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19703">
19703</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25913">
neuronblog-addcomment-xss(25913)</ref></refs><vuln_soft><prod name="Neuron Blog" vendor="dev"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-12-21" modified="2006-04-24" name="CVE-2006-1900" published="2006-04-20" seq="2006-1900" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote attackers to execute arbitrary code via a long value in (1) the COMPACT attribute of the COLGROUP element, (2) the ROWS attribute of the TEXTAREA element, and (3) the COLOR attribute of the LEGEND element; and via other unspecified attack vectors consisting of &quot;dozens of possible snippets.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://morph3us.org/advisories/20060412-amaya-94.txt"></ref><ref adv="1" source="" url="http://morph3us.org/advisories/20060412-amaya-94-2.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17507">17507</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1351">ADV-2006-1351</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/24623">24623</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/24624">24624</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19670">19670</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25791">amaya-various-attribute-bo(25791)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430877/100/0/threaded">20060412 [BuHa-Security] Stack Based Buffer Overflow Vulnerability in Amaya 9.4</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430879/100/0/threaded">20060412 [BuHa-Security] Stack Based Buffer Overflow Vulnerability in Amaya 9.4 #2</ref></refs><vuln_soft><prod name="Amaya" vendor="W3C"><vers num="9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1901" published="2006-04-20" seq="2006-1901" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Camino 1.0 and earlier allow remote attackers to cause a denial of service (null dereference and application crash or hang) via HTML with certain improperly nested elements.  NOTE: this might be the same issue as CVE-2006-1724.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431004/100/0/threaded">20060413 Camino Browser HTML Parsing Null Pointer Dereference Denial of Service Vulnerability</ref><ref source="SREASON" url="http://securityreason.com/securityalert/772">772</ref></refs><vuln_soft><prod name="Camino" vendor="Mozilla"><vers num="1.0"/><vers num="1.0 RC1"/><vers num="1.0 Beta2"/><vers num="1.0 Beta1"/><vers num="1.0 alpha1"/><vers num="0.9 alpha2"/><vers num="0.8.4"/><vers num="0.8.3"/><vers num="0.8.2"/><vers num="0.8.1"/><vers num="0.8"/><vers num="0.8 alpha1"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1902" published="2006-04-20" seq="2006-1902" severity="Low" type="CVE"><desc><descript source="cve">fold_binary in fold-const.c in GNU Compiler Collection (gcc) 4.1 improperly handles pointer overflow when folding a certain expr comparison to a corresponding offset comparison in cases other than EQ_EXPR and NE_EXPR, which might introduce buffer overflow vulnerabilities into applications that could be exploited by context-dependent attackers.  NOTE: followup posts have disputed whether this is a compiler problem or an application problem, since some of the reported expressions might be undefined in C standards.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431184/100/0/threaded">20060417 gcc 4.1 bug miscompiles pointer range checks, may place you at risk</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/431319/100/0/threaded">20060418 Re: gcc 4.1 bug miscompiles pointer range checks, may place you at risk</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/431297/100/0/threaded">20060418 Re: gcc 4.1 bug miscompiles pointer range checks, may place you at risk</ref><ref source="MLIST" url="http://gcc.gnu.org/ml/gcc-bugs/2006-04/msg01297.html">[gcc-bugs] 20060417 [Bug c/27180] New: pointer arithmetic overflow handling broken</ref><ref source="MLIST" url="http://gcc.gnu.org/ml/gcc-bugs/2006-04/msg01298.html">[gcc-bugs] 20060417 [Bug middle-end/27180] New: pointer arithmetic overflow handling broken</ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=356896"></ref><ref source="" url="http://gcc.gnu.org/bugzilla/show_bug.cgi?id=26763"></ref><ref source="" url="http://gcc.gnu.org/viewcvs/branches/gcc-4_1-branch/gcc/fold-const.c?r1=110549&amp;r2=112698&amp;pathrev=112698&amp;diff_format=h"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431245/100/0/threaded">20060418 RE: gcc 4.1 bug miscompiles pointer range checks, may place you at risk</ref></refs><vuln_soft><prod name="gcc" vendor="GNU"><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1903" published="2006-04-20" seq="2006-1903" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in UserLand Manila allow remote attackers to inject arbitrary web script or HTML (1) via the referer parameter in sendMail, and via attributes of (2) the A element and certain other HTML elements in web pages edited with the editInBrowser module.  NOTE: the msgReader$1 mode attack vector is already covered by CVE-2006-1769.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431058/100/0/threaded">20060414 manila.userland cross site scriptable</ref><ref source="BID" url="http://www.securityfocus.com/bid/17563">17563</ref><ref source="BID" url="http://www.securityfocus.com/bid/17565">17565</ref></refs><vuln_soft><prod name="Manila" vendor="UserLand"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1904" published="2006-04-20" seq="2006-1904" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in AnimeGenesis Gallery allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431135/100/0/threaded">20060417 AnimeGenesis &lt;= XSS</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1395">ADV-2006-1395</ref></refs><vuln_soft><prod name="Gallery" vendor="AnimeGenesis"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1905" published="2006-04-20" seq="2006-1905" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an EXTINFO line in a playlist file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431251/100/0/threaded">20060418 Remote Xine Format String Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17579">17579</ref><ref source="" url="http://sourceforge.net/mailarchive/message.php?msg_id=15429845"></ref><ref source="" url="http://open-security.org/advisories/16"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-15.xml">GLSA-200604-15</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1432">ADV-2006-1432</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015959">1015959</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19671">19671</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19854">19854</ref><ref source="OSVDB" url="http://www.osvdb.org/24747">24747</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25851">xine-playlist-format-string(25851)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:085">MDKSA-2006:085</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20066">20066</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_05_05.html">SUSE-SA:2006:025</ref></refs><vuln_soft><prod name="xine" vendor="xine"><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.18"/><vers num="0.9.13"/><vers num="0.9.8"/><vers num="1 rc8"/><vers num="1 rc7"/><vers num="1 rc6a"/><vers num="1 rc6"/><vers num="1 rc5"/><vers num="1 rc4"/><vers num="1 rc3b"/><vers num="1 rc3a"/><vers num="1 rc3"/><vers num="1 rc2"/><vers num="1 rc1"/><vers num="1 rc0a"/><vers num="1 rc0"/><vers num="1 beta9"/><vers num="1 beta8"/><vers num="1 beta7"/><vers num="1 beta6"/><vers num="1 beta5"/><vers num="1 beta4"/><vers num="1 beta3"/><vers num="1 beta2"/><vers num="1 beta12"/><vers num="1 beta11"/><vers num="1 beta10"/><vers num="1 beta1"/><vers num="1 alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1906" published="2006-04-20" seq="2006-1906" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in jjgan852 phpLister 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431308/100/0/threaded">20060418 phpLister v. 0.4.1 XSS Attacking</ref><ref source="" url="http://advisory.patriotichackers.com/index.php?itemid=3"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17591">17591</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25910">
phplister-index-xss(25910)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/735">735</ref><ref source="SREASON" url="http://securityreason.com/securityalert/770">770</ref></refs><vuln_soft><prod name="phpLister" vendor="jjgan852"><vers num="0.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1907" published="2006-04-20" seq="2006-1907" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in myEvent 1.x allow remote attackers to inject arbitrary SQL commands via the event_id parameter to (1) addevent.php or (2) del.php or (3) event_desc parameter to addevent.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19680">19680</ref><ref source="OSVDB" url="http://www.osvdb.org/24720">24720</ref><ref source="OSVDB" url="http://www.osvdb.org/24721">24721</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25886">myevent-addevent-del-sql-injection(25886)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1384">ADV-2006-1384</ref></refs><vuln_soft><prod name="myEvent" vendor="myWebland"><vers num="1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1908" published="2006-04-20" seq="2006-1908" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in addevent.php in myEvent 1.x allows remote attackers to inject arbitrary web script or HTML via the event_desc parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19680">19680</ref><ref source="OSVDB" url="http://www.osvdb.org/24719">24719</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1384">ADV-2006-1384</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25885">
myevent-addevent-xss(25885)</ref></refs><vuln_soft><prod name="myEvent" vendor="myWebland"><vers num="1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-22" name="CVE-2006-1909" published="2006-04-20" seq="2006-1909" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in Coppermine 1.4.4 allows remote attackers to read arbitrary files via a .//./ (modified dot dot slash) in the file parameter, which causes a regular expression to collapse the sequences into standard &quot;../&quot; sequences.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/431062">20060415 [KAPDA]CopperminePhotoGallery1.4.4~ PluginInclusionSystem(index.php)~ RemoteFileInclusion attack</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/431118/30/0/threaded">20060416 Re: [KAPDA]CopperminePhotoGallery1.4.4~ PluginInclusionSystem(index.php)~ RemoteFileInclusion attack</ref><ref source="BID" url="http://www.securityfocus.com/bid/17570">17570</ref><ref source="" url="http://myimei.com/security/2006-04-14/copperminephotogallery144-plugininclusionsystemindexphp-remotefileinclusion-attack.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1392">ADV-2006-1392</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19665">19665</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25866">
coppermine-index-file-include(25866)</ref></refs><vuln_soft><prod name="Coppermine Photo Gallery" vendor="Coppermine"><vers num="1.4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1910" published="2006-04-20" seq="2006-1910" severity="High" type="CVE"><desc><descript source="cve">config.php in S9Y Serendipity 1.0 beta 2 allows remote attackers to inject arbitrary PHP code by editing values that are stored in config.php and later executed.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17566">17566</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0282.html">20040614 Serendipity Blog vuln</ref></refs><vuln_soft><prod name="Serendipity" vendor="S9Y"><vers num="1.0 Beta2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-14" modified="2006-10-05" name="CVE-2006-1911" published="2006-04-20" seq="2006-1911" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in MyBB (MyBulletinBoard) 1.1 allows remote attackers to inject arbitrary web script or HTML via the attachment content disposition in an HTML attachment.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
MyBB, MyBB, 1.1.1</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MyBB" url="http://community.mybboard.net/showthread.php?tid=8232">MyBB 1.1.1 Released </ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1381">ADV-2006-1381</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19668">19668</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25864">
mybb-html-attachment-xss(25864)</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-05" name="CVE-2006-1912" published="2006-04-20" seq="2006-1912" severity="Medium" type="CVE"><desc><descript source="cve">MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL variable in (1) global.php and (2) inc/init.php, which allows remote attackers to initialize arbitrary variables that are processed by an @extract command, which could then be leveraged to conduct cross-site scripting (XSS) or SQL injection attacks.</descript></desc><sols><sol source="nvd">Upgrade to MyBB 1.1.1</sol></sols><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://myimei.com/security/2006-04-14/mybb110globalphpparameterextracting.html"></ref><ref source="" url="http://community.mybboard.net/showthread.php?tid=8232"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1381">ADV-2006-1381</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19668">19668</ref><ref source="OSVDB" url="http://www.osvdb.org/24710">24710</ref><ref source="OSVDB" url="http://www.osvdb.org/24711">24711</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25865">mybb-global-init-data-manipulation(25865)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431061/30/5580/threaded">

20060415 [KAPDA]MyBB1.1.0~global.php~ParameterExtracting</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1913" published="2006-04-20" seq="2006-1913" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in jax_guestbook.php in Jax Guestbook 3.50 allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17560">17560</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19843">19843</ref><ref source="OSVDB" url="http://www.osvdb.org/24991">24991</ref><ref source="" url="http://kiki91.altervista.org/exploit/jax.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1800">ADV-2006-1800</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20110">20110</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26448">jaxguestbook-admin-xss(26448)</ref></refs><vuln_soft><prod name="Jax Guestbook" vendor="Jax Scripts"><vers num="3.50" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-16" modified="2006-07-25" name="CVE-2006-1914" published="2006-04-20" seq="2006-1914" severity="Medium" type="CVE"><desc><descript source="cve">DbbS 2.0-alpha and earlier allows remote attackers to obtain sensitive information via an invalid (1) fcategoryid parameter to topics.php or (2) unavariabile, (3) GLOBALS, or (4) _SERVER[] parameters to script.php.  NOTE: this information leak might be resultant from a global variable overwrite issue.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/431117">20060416 DbbS&lt;=2.0-alpha Multiple Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25922">
dbbs-multiple-path-disclosure(25922)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/771">771</ref></refs><vuln_soft><prod name="DbbS" vendor="DbbS"><vers num="2.0-alpha" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-16" modified="2006-04-24" name="CVE-2006-1915" published="2006-04-20" seq="2006-1915" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in topics.php in DbbS 2.0-alpha and earlier allows remote attackers to execute arbitrary SQL commands via the fcategoryid parameter.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/431117">20060416 DbbS&lt;=2.0-alpha Multiple Vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/661">661</ref><ref source="SREASON" url="http://securityreason.com/securityalert/771">771</ref></refs><vuln_soft><prod name="DbbS" vendor="DbbS"><vers num="2.0-alpha" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-16" modified="2006-04-24" name="CVE-2006-1916" published="2006-04-20" seq="2006-1916" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in profile.php in DbbS 2.0-alpha and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ulocation or (2) uhobbies parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/431117">20060416 DbbS&lt;=2.0-alpha Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17559">17559</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25923">
dbbs-profile-xss(25923)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/771">771</ref></refs><vuln_soft><prod name="DbbS" vendor="DbbS"><vers num="2.0-alpha" prev="1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-16" modified="2006-04-24" name="CVE-2006-1917" published="2006-04-20" seq="2006-1917" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in member.php in Blackorpheus ClanMemberSkript 1.0 allows remote attackers to execute arbitrary SQL commands via the userID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/1683">exploit 1683</ref><ref source="Security Focus" url="http://downloads.securityfocus.com/vulnerabilities/exploits/Blackorpheus_poc">Blackorpheus ClanMemberSkript 1.0 remote sql injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/17558">17558</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1405">ADV-2006-1405</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19678">19678</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1683">

1683</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25902">
blackorpheus-member-sql-injection(25902)</ref></refs><vuln_soft><prod name="ClanMemberSkript" vendor="Blackorpheus"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1918" published="2006-04-20" seq="2006-1918" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Papoo 2.1.5 allow remote attackers to inject arbitrary web script or HTML via the menuid parameter to (1) index.php or (2) forum.php, or the (3) reporeid_print parameter to print.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1015939">1015939</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431009/100/0/threaded">20060414 Vulnerabilities in Papoo</ref><ref source="BID" url="http://www.securityfocus.com/bid/17530">17530</ref></refs><vuln_soft><prod name="Papoo" vendor="Papoo"><vers num="2.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1919" published="2006-04-20" seq="2006-1919" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in Internet Photoshow 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/1694"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1417">ADV-2006-1417</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19726">19726</ref><ref source="BID" url="http://www.securityfocus.com/bid/17620">17620</ref><ref source="OSVDB" url="http://www.osvdb.org/24743">24743</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25937">ip-index-file-include(25937)</ref></refs><vuln_soft><prod name="Internet Photoshow" vendor="Thomas Voecking"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-19" modified="2006-04-24" name="CVE-2006-1920" published="2006-04-20" seq="2006-1920" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in PMTool 1.2.2 allows remote attackers to execute arbitrary SQL commands via the order parameter in the include files (1) user.inc.php, (2) customer.inc.php, and (3) project.inc.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1416">ADV-2006-1416</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19685">19685</ref><ref source="BID" url="http://www.securityfocus.com/bid/17599">17599</ref><ref source="OSVDB" url="http://www.osvdb.org/24780">24780</ref><ref source="OSVDB" url="http://www.osvdb.org/24781">24781</ref><ref source="OSVDB" url="http://www.osvdb.org/24782">24782</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25877">pmtool-order-sql-injection(25877)</ref></refs><vuln_soft><prod name="PMTool" vendor="PMTool"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-18" modified="2006-04-24" name="CVE-2006-1921" published="2006-04-20" seq="2006-1921" severity="Medium" type="CVE"><desc><descript source="cve">nettools.php in PHP Net Tools 2.7.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the host parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/1695"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1420">ADV-2006-1420</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19694">19694</ref><ref source="BID" url="http://www.securityfocus.com/bid/17601">17601</ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-June/000839.html">[VIM] 20060609 [VIM] Update Regarding CVE-2006-1921 (fwd)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25941">
phpnettools-nettools-command-execution(25941)</ref></refs><vuln_soft><prod name="PHP Net Tools" vendor="PHP Net Tools"><vers num="2.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-19" modified="2006-04-24" name="CVE-2006-1922" published="2006-04-20" seq="2006-1922" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/totalcalendar-remote-code-execution.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1418">ADV-2006-1418</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19730">19730</ref><ref source="BID" url="http://www.securityfocus.com/bid/17618">17618</ref><ref source="OSVDB" url="http://www.osvdb.org/24748">24748</ref><ref source="OSVDB" url="http://www.osvdb.org/24751">24751</ref><ref source="" url="http://sweetphp.com/files/downloads/patches/TotalCalendar/Security_Patch.zip"></ref><ref source="" url="http://pridels0.blogspot.com/2006/04/totalcalendar-remote-code-execution.html"></ref></refs><vuln_soft><prod name="TotalCalendar" vendor="SweetPHP"><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-19" modified="2006-04-24" name="CVE-2006-1923" published="2006-04-20" seq="2006-1923" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) RSS/RSS.php and (2) possibly other vectors.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1424">ADV-2006-1424</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/19719">19719</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-April/000709.html">[VIM] 20060420 LinPHA provenance/acknowledgement</ref><ref source="BID" url="http://www.securityfocus.com/bid/17619">17619</ref><ref source="OSVDB" url="http://www.osvdb.org/24816">24816</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26269">
linpha-rss-xss(26269)</ref></refs><vuln_soft><prod name="LinPHA" vendor="LinPHA"><vers num="1.1.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-19" modified="2006-04-24" name="CVE-2006-1924" published="2006-04-20" seq="2006-1924" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in functions/db_api.php in LinPHA 1.1.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1424">ADV-2006-1424</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19719">19719</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-April/000709.html">[VIM] 20060420 LinPHA provenance/acknowledgement</ref><ref source="BID" url="http://www.securityfocus.com/bid/17619">17619</ref><ref source="OSVDB" url="http://www.osvdb.org/24817">24817</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26268">
linpha-functionsdbapi-sql-injection(26268)</ref></refs><vuln_soft><prod name="LinPHA" vendor="LinPHA"><vers num="1.1.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" discovered="2006-04-19" modified="2007-07-03" name="CVE-2006-1925" published="2006-04-20" seq="2006-1925" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify files via the source parameter in the (1) editnews or (2) doeditnews action.  NOTE: this can also produce resultant XSS when the target file does not exist.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/431340/30/0/threaded">20060418 CuteNews 1.4.1 &lt;= Cross Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/17592">17592</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431528/100/0/threaded">20060420 Re: CuteNews 1.4.1 &lt;= Cross Site Scripting</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25935">cutenews-index-source-xss(25935)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/775">775</ref></refs><vuln_soft><prod name="CuteNews" vendor="CutePHP"><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-19" modified="2006-04-24" name="CVE-2006-1926" published="2006-04-20" seq="2006-1926" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in showtopic.php in ThWboard 2.84 beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the pagenum parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431354/100/0/threaded">20060419 ThWboard &lt;= 3 Beta 2.84 SQL Injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/17606">17606</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/436813/100/0/threaded">20060611 ThWboard 3.0 &lt;= SQL Injection</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/436919/100/0/threaded">20060613 Re: BUGTRAQ:20060611 ThWboard 3.0 &lt;= SQL Injection</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25891">
thwboard-showtopic-sql-injection(25891)</ref></refs><vuln_soft><prod name="Thwboard" vendor="Thwboard"><vers num="2.84 Beta 3"/><vers num="2.83 Beta"/><vers num="2.82 Beta"/><vers num="2.81 Beta"/><vers num="2.8 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-19" modified="2006-04-24" name="CVE-2006-1927" published="2006-04-20" seq="2006-1927" severity="Medium" type="CVE"><desc><descript source="cve">Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 or Cisco 12000 series routers, allows remote attackers to cause a denial of service (Line card crash) via certain MPLS packets, as identified by Cisco bug ID CSCsc77475.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20060419-xr.shtml">20060419 Cisco IOS XR MPLS Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17607">17607</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1433">ADV-2006-1433</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015964">1015964</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19740">19740</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25881">cisco-iosxr-mpls-dos(25881)</ref></refs><vuln_soft><prod name="IOS XR for PRP" vendor="Cisco"><vers num="3.2.3"/></prod><prod name="IOS XR for CRS-1" vendor="Cisco"><vers num="3.2.3"/></prod><prod name="IOS XR" vendor="Cisco"><vers num="3.2.50"/><vers num="3.2.4"/><vers num="3.2.4"/><vers num="3.2.2"/><vers num="3.2.1"/><vers num="3.2"/><vers num="3.1.0"/><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-19" modified="2006-04-24" name="CVE-2006-1928" published="2006-04-20" seq="2006-1928" severity="Medium" type="CVE"><desc><descript source="cve">Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 routers, allows remote attackers to cause a denial of service (Modular Services Cards (MSC) crash or &quot;MPLS packet handling problems&quot;) via certain MPLS packets, as identified by Cisco bug IDs (1) CSCsd15970 and (2) CSCsd55531.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20060419-xr.shtml">20060419 Cisco IOS XR MPLS Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/17607">17607</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1433">ADV-2006-1433</ref><ref source="OSVDB" url="http://www.osvdb.org/24811">24811</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015964">1015964</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19740">19740</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25881">cisco-iosxr-mpls-dos(25881)</ref></refs><vuln_soft><prod name="IOS XR for PRP" vendor="Cisco"><vers num="3.2.3"/></prod><prod name="IOS XR for CRS-1" vendor="Cisco"><vers num="3.2.3"/></prod><prod name="IOS XR" vendor="Cisco"><vers num="3.2.50"/><vers num="3.2.4"/><vers num="3.2.4"/><vers num="3.2.2"/><vers num="3.2.1"/><vers num="3.2"/><vers num="3.1.0"/><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-20" modified="2006-04-24" name="CVE-2006-1929" published="2006-04-20" seq="2006-1929" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in include/common.php in I-Rater Platinum allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/i-rater-platinum-remote-file-inclusion.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1431">ADV-2006-1431</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19684">19684</ref><ref source="BID" url="http://www.securityfocus.com/bid/17623">17623</ref><ref source="OSVDB" url="http://www.osvdb.org/24777">
24777</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25963">
Irater-common-file-include(25963)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/i-rater-platinum-remote-file-inclusion.html"></ref></refs><vuln_soft><prod name="I-Rater Platinum" vendor="I-Rater"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-20" modified="2006-06-01" name="CVE-2006-1930" published="2006-04-20" seq="2006-1930" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  Multiple SQL injection vulnerabilities in userscript.php in Green Minute 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) huserid, (2) pituus, or (3) date parameters. NOTE: this issue has been disputed by the vendor, saying &quot;those parameters mentioned ARE checked (preg_match) before they are used in SQL-query...  If someone decided to add SQL-injection stuff to certain parameter, they would see an error text, but only because _nothing_ was passed inside that parameter (to MySQL-database).&quot;  As allowed by the vendor, CVE investigated this report on 20060525 and found that the demo site demonstrated a non-sensitive SQL error when given standard SQL injection manipulations.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/green-minute-sql-inj-vuln.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25942">greenminute-userscript-sql-injection(25942)</ref><ref source="" url="http://hoito.org/en/products/"></ref><ref source="" url="http://osvdb.org/ref/25/25207-dispute.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/25207">25207</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/green-minute-sql-inj-vuln.html"></ref></refs><vuln_soft><prod name="Green Minute" vendor="Hoito"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-20" modified="2006-04-24" name="CVE-2006-1931" published="2006-04-20" seq="2006-1931" severity="Medium" type="CVE"><desc><descript source="cve">The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a large amount of data.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-dev/27787"></ref><ref patch="1" source="" url="ftp://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.2-webrick-dos-1.patch"></ref><ref patch="1" source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189540"></ref><ref source="" url="ftp://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.2-xmlrpc-dos-1.patch"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:079">MDKSA-2006:079</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-273-1">USN-273-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/17645">17645</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015978">1015978</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19772">19772</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19804">19804</ref><ref source="OSVDB" url="http://www.osvdb.org/24972">24972</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16904">16904</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26102">ruby-socket-dos(26102)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-11.xml">GLSA-200605-11</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0427.html">RHSA-2006:0427</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20024">20024</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20064">20064</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-06-02.html">SUSE-SR:2006:012</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20457">20457</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1157">DSA-1157</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21657">21657</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:079">MDKSA-2006:079</ref></refs><vuln_soft><prod name="Ruby" vendor="Yukihiro Matsumoto"><vers num="1.8.1"/><vers num="1.8"/><vers num="1.6.7"/><vers num="1.6.6"/><vers num="1.6.5"/><vers num="1.6.4"/><vers num="1.6.3"/><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1932" published="2006-04-25" seq="2006-1932" severity="High" type="CVE"><desc><descript source="cve">Off-by-one error in the OID printing routine in Ethereal 0.10.x up to 0.10.14 has unknown impact and remote attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input bound="1"/><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.ethereal.com/appnotes/enpa-sa-00023.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1501">ADV-2006-1501</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:077">MDKSA-2006:077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17682">17682</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19769">19769</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html">FEDORA-2006-456</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html">FEDORA-2006-461</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml">GLSA-200604-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015985">1015985</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19805">19805</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19828">19828</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19839">19839</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1049">DSA-1049</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0420.html">RHSA-2006:0420</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19958">19958</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19962">19962</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html">SUSE-SR:2006:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20117">20117</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/20944">20944</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26012">
ethereal-oid-printing-offbyone(26012)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:077">MDKSA-2006:077</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.14"/><vers num="0.10.13"/><vers num="0.10.12"/><vers num="0.10.11"/><vers num="0.10.10"/><vers num="0.10.9"/><vers num="0.10.8"/><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.1"/><vers num="0.10.0a"/><vers num="0.10.0"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-24" modified="2006-04-26" name="CVE-2006-1933" published="2006-04-25" seq="2006-1933" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (large or infinite loops) viarafted packets to the (1) UMA and (2) BER dissectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.ethereal.com/appnotes/enpa-sa-00023.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1501">ADV-2006-1501</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:077">MDKSA-2006:077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17682">17682</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19769">19769</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html">FEDORA-2006-456</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html">FEDORA-2006-461</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml">GLSA-200604-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015985">1015985</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19805">19805</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19828">19828</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19839">19839</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1049">DSA-1049</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0420.html">RHSA-2006:0420</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19958">19958</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19962">19962</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html">SUSE-SR:2006:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20117">20117</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/20944">20944</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26024">
ethereal-ber-loop-dos(26024)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26008">
ethereal-uma-dissector-dos(26008)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:077">MDKSA-2006:077</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.9"/><vers num="0.10.8"/><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.13"/><vers num="0.10.12"/><vers num="0.10.11"/><vers num="0.10.10"/><vers num="0.10.1"/><vers num="0.10.0a"/><vers num="0.10.0"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-24" modified="2006-04-26" name="CVE-2006-1934" published="2006-04-25" seq="2006-1934" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the (1) ALCAP dissector, (2) Network Instruments file code, or (3) NetXray/Windows Sniffer file code.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.ethereal.com/appnotes/enpa-sa-00023.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1501">ADV-2006-1501</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:077">MDKSA-2006:077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17682">17682</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19769">19769</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html">FEDORA-2006-456</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html">FEDORA-2006-461</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml">GLSA-200604-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015985">1015985</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19805">19805</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19828">19828</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19839">19839</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1049">DSA-1049</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0420.html">RHSA-2006:0420</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19958">19958</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19962">19962</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html">SUSE-SR:2006:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20117">20117</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/20944">20944</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26014">
ethereal-alcap-dissector-bo(26014)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26026">
ethereal-net-instr-bo(26026)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26027">
ethereal-netxwin-sniffer-bo(26027)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:077">MDKSA-2006:077</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.9"/><vers num="0.10.8"/><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.13"/><vers num="0.10.12"/><vers num="0.10.11"/><vers num="0.10.10"/><vers num="0.10.1"/><vers num="0.10.0a"/><vers num="0.10.0"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-24" modified="2006-04-26" name="CVE-2006-1935" published="2006-04-25" seq="2006-1935" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Ethereal 0.9.15 up to 0.10.14 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the COPS dissector.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.ethereal.com/appnotes/enpa-sa-00023.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1501">ADV-2006-1501</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:077">MDKSA-2006:077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17682">17682</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19769">19769</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html">FEDORA-2006-456</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html">FEDORA-2006-461</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml">GLSA-200604-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015985">1015985</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19805">19805</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19828">19828</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19839">19839</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1049">DSA-1049</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0420.html">RHSA-2006:0420</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19958">19958</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19962">19962</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html">SUSE-SR:2006:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20117">20117</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/20944">20944</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26013">
ethereal-cops-dissector-bo(26013)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:077">MDKSA-2006:077</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.10.9"/><vers num="0.10.8"/><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.13"/><vers num="0.10.12"/><vers num="0.10.11"/><vers num="0.10.10"/><vers num="0.10.1"/><vers num="0.10.0a"/><vers num="0.10.0"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-24" modified="2006-04-26" name="CVE-2006-1936" published="2006-04-25" seq="2006-1936" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Ethereal 0.8.5 up to 0.10.14 allows remote attackers to execute arbitrary code via the telnet dissector.</descript></desc><loss_types><int/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.ethereal.com/appnotes/enpa-sa-00023.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1501">ADV-2006-1501</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:077">MDKSA-2006:077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17682">17682</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19769">19769</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html">FEDORA-2006-456</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html">FEDORA-2006-461</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml">GLSA-200604-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015985">1015985</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19805">19805</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19828">19828</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19839">19839</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1049">DSA-1049</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0420.html">RHSA-2006:0420</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19958">19958</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19962">19962</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html">SUSE-SR:2006:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20117">20117</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/20944">20944</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26029">
ethereal-telnet-dissector-bo(26029)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:077">MDKSA-2006:077</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.10.9"/><vers num="0.10.8"/><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.13"/><vers num="0.10.12"/><vers num="0.10.11"/><vers num="0.10.10"/><vers num="0.10.1"/><vers num="0.10.0a"/><vers num="0.10.0"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" discovered="2006-04-24" modified="2007-08-13" name="CVE-2006-1937" published="2006-04-25" seq="2006-1937" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via (1) multiple vectors in H.248, and the (2) X.509if, (3) SRVLOC, (4) H.245, (5) AIM, and (6) general packet dissectors; and (7) the statistics counter.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.ethereal.com/appnotes/enpa-sa-00023.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1501">ADV-2006-1501</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:077">MDKSA-2006:077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17682">17682</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19769">19769</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html">FEDORA-2006-456</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html">FEDORA-2006-461</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml">GLSA-200604-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015985">1015985</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19805">19805</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19828">19828</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19839">19839</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1049">DSA-1049</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0420.html">RHSA-2006:0420</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19958">19958</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19962">19962</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html">SUSE-SR:2006:010</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20117">20117</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20944">20944</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">20060501-01-U</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20210">20210</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26019">ethereal-aim-dos(26019)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26018">ethereal-general-dissector-dos(26018)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26011">ethereal-h245-dos(26011)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26007">ethereal-h248-dissector-dos(26007)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26031">ethereal-h248-dos(26031)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26010">ethereal-srvloc-dos(26010)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26015">ethereal-statistics-counter-dos(26015)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26009">ethereal-x509if-dissector-dos(26009)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:077">MDKSA-2006:077</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.9"/><vers num="0.10.8"/><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.13"/><vers num="0.10.12"/><vers num="0.10.11"/><vers num="0.10.10"/><vers num="0.10.1"/><vers num="0.10.0a"/><vers num="0.10.0"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1938" published="2006-04-25" seq="2006-1938" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Ethereal 0.8.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via the (1) Sniffer capture or (2) SMB PIPE dissector.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.ethereal.com/appnotes/enpa-sa-00023.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1501">ADV-2006-1501</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:077">MDKSA-2006:077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17682">17682</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19769">19769</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html">FEDORA-2006-456</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html">FEDORA-2006-461</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml">GLSA-200604-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015985">1015985</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19805">19805</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19828">19828</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19839">19839</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1049">DSA-1049</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0420.html">RHSA-2006:0420</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19958">19958</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19962">19962</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html">SUSE-SR:2006:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20117">20117</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/20944">20944</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26023">
ethereal-smbpipe-dos(26023)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26016">
ethereal-sniffer-capture-dos(26016)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:077">MDKSA-2006:077</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.4"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.9.14"/><vers num="0.9.13"/><vers num="0.9.12"/><vers num="0.9.11"/><vers num="0.9.10"/><vers num="0.9.1"/><vers num="0.9.0"/><vers num="0.9 .0"/><vers num="0.9"/><vers num="0.8.9"/><vers num="0.8.8"/><vers num="0.8.7"/><vers num="0.8.6"/><vers num="0.8.5"/><vers num="0.8.20"/><vers num="0.8.19"/><vers num="0.8.18"/><vers num="0.8.17a"/><vers num="0.8.17"/><vers num="0.8.16"/><vers num="0.8.15"/><vers num="0.8.14"/><vers num="0.8.13"/><vers num="0.8.12"/><vers num="0.8.11"/><vers num="0.8.10"/><vers num="0.8"/><vers num="0.10.9"/><vers num="0.10.8"/><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.13"/><vers num="0.10.12"/><vers num="0.10.11"/><vers num="0.10.10"/><vers num="0.10.1"/><vers num="0.10.0a"/><vers num="0.10.0"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-24" modified="2006-04-26" name="CVE-2006-1939" published="2006-04-25" seq="2006-1939" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Ethereal 0.9.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via (1) an invalid display filter, or the (2) GSM SMS, (3) ASN.1-based, (4) DCERPC NT, (5) PER, (6) RPC, (7) DCERPC, and (8) ASN.1 dissectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.ethereal.com/appnotes/enpa-sa-00023.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1501">ADV-2006-1501</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:077">MDKSA-2006:077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17682">17682</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19769">19769</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html">FEDORA-2006-456</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html">FEDORA-2006-461</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml">GLSA-200604-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015985">1015985</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19805">19805</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19828">19828</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19839">19839</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1049">DSA-1049</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0420.html">RHSA-2006:0420</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19958">19958</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19962">19962</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html">SUSE-SR:2006:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20117">20117</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/20944">20944</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26022">
ethereal-asn1-dissector-dos(26022)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26030">
ethereal-asn1based-dissector-dos(26030)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26021">
ethereal-dcerpc-dissector-dos(26021)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26032">
ethereal-dcerpcnt-dissector-dos(26032)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26017">
ethereal-display-filter-dos(26017)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26028">
ethereal-gsmsms-dissector-dos(26028)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26033">
ethereal-per-diss-dos(26033)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26020">
ethereal-rpc-dos(26020)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:077">MDKSA-2006:077</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.4"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.9.14"/><vers num="0.9.13"/><vers num="0.9.12"/><vers num="0.9.11"/><vers num="0.9.10"/><vers num="0.9.1"/><vers num="0.9.0"/><vers num="0.9 .0"/><vers num="0.9"/><vers num="0.10.9"/><vers num="0.10.8"/><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.13"/><vers num="0.10.12"/><vers num="0.10.11"/><vers num="0.10.10"/><vers num="0.10.1"/><vers num="0.10.0a"/><vers num="0.10.0"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-24" modified="2006-04-26" name="CVE-2006-1940" published="2006-04-25" seq="2006-1940" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Ethereal 0.10.4 up to 0.10.14 allows remote attackers to cause a denial of service (abort) via the SNDCP dissector.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.ethereal.com/appnotes/enpa-sa-00023.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1501">ADV-2006-1501</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:077">MDKSA-2006:077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17682">17682</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19769">19769</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00194.html">FEDORA-2006-456</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00195.html">FEDORA-2006-461</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-17.xml">GLSA-200604-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015985">1015985</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19805">19805</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19828">19828</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19839">19839</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1049">DSA-1049</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0420.html">RHSA-2006:0420</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19958">19958</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19962">19962</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html">SUSE-SR:2006:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20117">20117</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/20944">20944</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26025">
ethereal-sndcp-dissector-dos(26025)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:077">MDKSA-2006:077</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.9"/><vers num="0.10.8"/><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.13"/><vers num="0.10.12"/><vers num="0.10.11"/><vers num="0.10.10"/><vers num="0.10.1"/><vers num="0.10.0a"/><vers num="0.10.0"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-10" modified="2006-04-24" name="CVE-2006-1941" published="2006-04-20" seq="2006-1941" severity="Medium" type="CVE"><desc><descript source="cve">Neon Responder 5.4 for LANsurveyor allows remote attackers to cause a denial of service (application outage) via a crafted Clock Synchronisation packet that triggers an access violation.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431157/100/0/threaded">20060417 Neon Responder (Dos,Exploit)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17569">17569</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1442">ADV-2006-1442</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015950">1015950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19702">19702</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25904">
neonresponder-clocksynchronization-dos(25904)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/731">731</ref><ref source="SREASON" url="http://securityreason.com/securityalert/776">776</ref></refs><vuln_soft><prod name="Neon Responder" vendor="Neon Software"><vers edition="Windows" num="5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-18" modified="2006-10-04" name="CVE-2006-1942" published="2006-04-20" seq="2006-1942" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containing a SRC attribute with a non-image file:// URL, then tricking the user into selecting View Image for the broken image, as demonstrated using a .wma file to launch Windows Media Player, or by referencing an &quot;alternate web page.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431267/100/0/threaded">20060418 Another flaw in Firefox 1.5.0.2: to open files from remote</ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=334341"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19698">19698</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433138/100/0/threaded">20060505 Firefox 1.5.0.3 code execution exploit</ref><ref patch="1" source="" url="http://www.gavinsharp.com/tmp/ImageVuln.html"></ref><ref adv="1" source="" url="http://www.networksecurity.fi/advisories/netscape-view-image.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/24713">24713</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19988">19988</ref><ref adv="1" source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-39.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435795/100/0/threaded">20060602 rPSA-2006-0091-1 firefox thunderbird</ref><ref source="BID" url="http://www.securityfocus.com/bid/18228">18228</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2106">ADV-2006-2106</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016202">1016202</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20376">20376</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_35_mozilla.html">SUSE-SA:2006:035</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1118">DSA-1118</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1120">DSA-1120</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21183">21183</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21176">21176</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1134">DSA-1134</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21324">21324</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded">HPSBUX02153</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433539/30/5070/threaded">
20060507 Re: Firefox 1.5.0.3 code execution exploit</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20063">
20063</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25925">
firefox-viewimage-security-bypass(25925)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3748">ADV-2006-3748</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22066">22066</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="K-Meleon" vendor="K-Meleon Project"><vers num="0.9.13"/></prod><prod name="Netscape" vendor="Netscape"><vers num="8.1"/><vers num="8.0.4"/><vers num="7.2"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-24" name="CVE-2006-1943" published="2006-04-20" seq="2006-1943" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Smarter Scripts IntelliLink Pro 5.06 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter in addlink_lwp.cgi and the (2) id, (3) forgotid, and (4) forgotpass parameters in edit.cgi.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/intellilink-pro-xss-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17605">17605</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1409">ADV-2006-1409</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19701">19701</ref><ref source="OSVDB" url="http://www.osvdb.org/24732">24732</ref><ref source="OSVDB" url="http://www.osvdb.org/24733">24733</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25929">
intellilink-multiple-xss(25929)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/intellilink-pro-xss-vuln.html"></ref></refs><vuln_soft><prod name="IntelliLink Pro" vendor="Smarter Scripts"><vers num="5.06"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1944" published="2006-04-20" seq="2006-1944" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SibSoft CommuniMail 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the list_id parameter in mailadmin.cgi and (2) the form_id parameter in templates.cgi.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/communimail-xss-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17602">17602</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1407">ADV-2006-1407</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19667">19667</ref><ref source="OSVDB" url="http://www.osvdb.org/24735">24735</ref><ref source="OSVDB" url="http://www.osvdb.org/24736">24736</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25931">
communimail-multiple-xss(25931)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/communimail-xss-vuln.html"></ref></refs><vuln_soft><prod name="CommuniMail" vendor="SibSoft"><vers num="1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1945" published="2006-04-20" seq="2006-1945" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the config parameter.  NOTE: this might be the same core issue as CVE-2005-2732.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/awstats-65-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17621">17621</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200606-06.xml">GLSA-200606-06</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20496">
20496</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/awstats-65-vuln.html"></ref></refs><vuln_soft><prod name="AWStats" vendor="AWStats"><vers num="6.5_1.857" prev="1"/><vers num="6.5"/><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1946" published="2006-04-20" seq="2006-1946" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Visale 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the keyval parameter in pbpgst.cgi, (2) the catsubno parameter in pblscg.cgi, and (3) the listno parameter in pblsmb.cgi.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/visale-xss-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17598">17598</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1408">ADV-2006-1408</ref><ref source="OSVDB" url="http://www.osvdb.org/24716">24716</ref><ref source="OSVDB" url="http://www.osvdb.org/24717">24717</ref><ref source="OSVDB" url="http://www.osvdb.org/24718">24718</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19655">19655</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25928">
visale-multiple-xss(25928)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/visale-xss-vuln.html"></ref></refs><vuln_soft><prod name="Visale" vendor="Visale"><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1947" published="2006-04-20" seq="2006-1947" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in plexum.php in NicPlex Plexum X5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pagesize, (2) maxrec, and (3) startpos parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/plexum-x5-sql-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17617">17617</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1423">ADV-2006-1423</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19720">19720</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25918">
plexum-multiple-sql-injection(25918)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/plexum-x5-sql-vuln.html"></ref></refs><vuln_soft><prod name="Plexum" vendor="NicPlex"><vers num="X5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-1948" published="2006-04-20" seq="2006-1948" severity="Medium" type="CVE"><desc><descript source="cve">The &quot;Add Sender to Address Book&quot; operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Book when multiple messages are checked and a message uses AltFrom, which might allow user-assisted remote attackers to trick a user into sending e-mail to an unauthorized recipient.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www-1.ibm.com/support/docview.wss?rs=475&amp;uid=swg21232945"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015914">1015914</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="6.0"/><vers num="6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1949" published="2006-04-20" seq="2006-1949" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in plexcart.pl in NicPlex PlexCart X3 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/plexcart-x3-sql-inj.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/18033">
18033</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25917">
plexcartx3-catid-sql-injection(25917)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/plexcart-x3-sql-inj.html"></ref></refs><vuln_soft><prod name="PlexCart" vendor="NicPlex"><vers num="X3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-19" modified="2006-04-25" name="CVE-2006-1950" published="2006-04-20" seq="2006-1950" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in banners.cgi in PerlCoders BannerFarm 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) aff and (2) cat parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/bannerfarm-xss-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17613">17613</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1410">ADV-2006-1410</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19718">19718</ref><ref source="OSVDB" url="http://www.osvdb.org/24728">24728</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25919">
bannerfarm-banners-xss(25919)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/bannerfarm-xss-vuln.html"></ref></refs><vuln_soft><prod name="BannerFarm" vendor="PerlCoders Group"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1951" published="2006-04-24" seq="2006-1951" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in SolarWinds TFTP Server 8.1 and earlier allows remote attackers to download arbitrary files via a crafted GET request including &quot;....//&quot; sequences, which are collapsed into &quot;../&quot; sequences by filtering.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431729/100/0/threaded">20060421 Rapid7 Advisory R7-0019: Directory traversal vulnerability in SolarWinds TFTP Server for Windows</ref><ref adv="1" patch="1" source="" url="http://www.rapid7.com/advisories/R7-0019.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17648">17648</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0009.html">20060421 Rapid7 Advisory R7-0019: Directory traversal vulnerability in SolarWinds TFTP Server for Windows</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1561">ADV-2006-1561</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19848">19848</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25969">
tftp-dotdotdotdot-directory-traversal(25969)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/778">778</ref></refs><vuln_soft><prod name="TFTP Server" vendor="SolarWinds"><vers num="5.0.55 Standard"/><vers num="5.0.60Standard"/><vers num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1952" published="2006-04-24" seq="2006-1952" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in WinAgents TFTP Server for Windows 3.1 and earlier allows remote attackers to read arbitrary files via &quot;...&quot; (triple dot) sequences in a GET request.</descript></desc><sols><sol source="nvd">According to the vendor, WinAgents TFTP server version 3.2 fixes this directory traversal vulnerability.</sol></sols><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.rapid7.com/advisories/R7-0020.html"></ref><ref source="" url="http://www.winagents.com/en/news/410.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17718">17718</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1562">ADV-2006-1562</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19844">19844</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25971">
tftp-dotdotdot-directory-traversal(25971)</ref></refs><vuln_soft><prod name="TFTP Server" vendor="WinAgents"><vers edition="Windows" num="3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-17" name="CVE-2006-1953" published="2006-05-17" seq="2006-1953" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Caucho Resin 3.0.17 and 3.0.18 for Windows allows remote attackers to read arbitrary files via a &quot;C:%5C&quot; (encoded drive letter) in a URL.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Caucho Technology, Resin, 3.0.19

The following product releases are not vulnerable: 
Caucho Technology, Resin, 3.0.16 
Caucho Technology, Resin, 2.1.12 
Caucho Technology, Resin, 2.1.2 
Caucho Technology, Resin, 2.1.1
Caucho Technology, Resin, 2.0</sol></sols><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/434150/100/0/threaded">20060516 Caucho Resin Windows Directory Traversal Vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18005">18005</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1831">ADV-2006-1831</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0026.html">20060516 Caucho Resin Windows Directory Traversal Vulnerability</ref><ref source="" url="http://www.rapid7.com/advisories/R7-0024.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/25570">25570</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016109">1016109</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20125">20125</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26478">resin-webserver-directory-traversal(26478)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/904">904</ref></refs><vuln_soft><prod name="Resin" vendor="Caucho Technology"><vers edition="Windows" num="3.0.17"/><vers edition="Windows" num="3.0.18"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-18" modified="2006-04-25" name="CVE-2006-1954" published="2006-04-21" seq="2006-1954" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in authent.php4 in Nicolas Fischer (aka NFec) RechnungsZentrale V2 1.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the User field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/1699"></ref><ref source="" url="http://www.g-0.org/code/rz2-adv.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17588">17588</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0384.html">20060419 RechnungsZentrale V2 - SQL injection and Remote PHP inclusion vulnerabilities</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1425">ADV-2006-1425</ref><ref source="OSVDB" url="http://www.osvdb.org/24752">24752</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19728">19728</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25911">rechnungszentrale-authent-sql-injection(25911)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1699">
1699</ref></refs><vuln_soft><prod name="RechnungsZentrale" vendor="nfec.de"><vers num="V2 1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-18" modified="2006-04-25" name="CVE-2006-1955" published="2006-04-21" seq="2006-1955" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in authent.php4 in Nicolas Fischer (aka NFec) RechnungsZentrale V2 1.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/1699"></ref><ref source="" url="http://www.g-0.org/code/rz2-adv.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17589">17589</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0384.html">20060419 RechnungsZentrale V2 - SQL injection and Remote PHP inclusion vulnerabilities</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1425">ADV-2006-1425</ref><ref source="OSVDB" url="http://www.osvdb.org/24753">24753</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19728">19728</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25912">rechnungszentrale-authent-file-inclusion(25912)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1699">
1699</ref></refs><vuln_soft><prod name="RechnungsZentrale" vendor="nfec.de"><vers num="V2 1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-18" modified="2006-04-25" name="CVE-2006-1956" published="2006-04-21" seq="2006-1956" severity="Medium" type="CVE"><desc><descript source="cve">The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to obtain sensitive information via an invalid feed parameter, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431317/100/0/threaded">20060418 [KAPDA::#41] - Mambo/Joomla rss component vulnerability</ref><ref source="" url="http://irannetjob.com/content/view/209/28/"></ref><ref source="" url="http://www.kapda.ir/advisory-313.html"></ref></refs><vuln_soft><prod name="Mambo" vendor="Mambo"><vers edition="h" num="4.5.3h"/></prod><prod name="Joomla" vendor="Joomla"><vers num="1.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1957" published="2006-04-21" seq="2006-1957" severity="Medium" type="CVE"><desc><descript source="cve">The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to cause a denial of service (disk consumption and possibly web-server outage) via multiple requests with different values of the feed parameter.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431317/100/0/threaded">20060418 [KAPDA::#41] - Mambo/Joomla rss component vulnerability</ref><ref source="" url="http://irannetjob.com/content/view/209/28/"></ref><ref adv="1" source="" url="http://www.kapda.ir/advisory-313.html"></ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-04/0380.html">
20060419 Re: [KAPDA::#41] - Mambo/Joomla rss component vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26131">
mambo-joomla-rss-dos(26131)</ref></refs><vuln_soft><prod name="Mambo" vendor="Mambo"><vers num=""/></prod><prod name="Joomla" vendor="Joomla"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-19" modified="2006-04-25" name="CVE-2006-1958" published="2006-04-21" seq="2006-1958" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in WWWThreads RC 3 allow remote attackers to execute arbitrary SQL commands via (1) the forumreferrer cookie to register.php and (2) the messages parameter in message_list.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431400/100/0/threaded">20060419 WWWThread RC 3 MultBugs</ref><ref source="BID" url="http://www.securityfocus.com/bid/17615">17615</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1447">ADV-2006-1447</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19732">19732</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25936">
wwwthreads-multiple-sql-injection(25936)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/739">739</ref></refs><vuln_soft><prod name="WWWThreads" vendor="Wired Community Software"><vers num="RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1959" published="2006-04-21" seq="2006-1959" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in direct.php in ActualScripts ActualAnalyzer Lite 2.72 and earlier, Gold 7.63 and earlier, and Server 8.23 and earlier allows remote attackers to execute arbitrary code via a URL in the rf parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431351/100/0/threaded">20060419 [MajorSecurity]ActualAnalyzer - Remote File Include Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17597">17597</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1430">ADV-2006-1430</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19743">19743</ref><ref source="OSVDB" url="http://www.osvdb.org/24778">24778</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015967">1015967</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/434562/100/0/threaded">20060520 ActualAnalyzer Server &lt;=8.23 - Remote File Include Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25893">
actualanalyzer-direct-file-include(25893)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/742">742</ref></refs><vuln_soft><prod name="ActualAnalyzer" vendor="ActualScripts"><vers edition="Server" num="8.23" prev="1"/><vers edition="Lite" num="2.72"/><vers edition="Gold" num="7.63"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-19" modified="2006-04-25" name="CVE-2006-1960" published="2006-04-21" seq="2006-1960" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13 allows remote attackers to inject arbitrary web script or HTML, possibly via the displayMsg parameter to archiveApplyDisplay.jsp, aka bug ID CSCsc01095.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20060419-wlse.shtml">20060419 Multiple Vulnerabilities in the WLSE Appliance</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1434">ADV-2006-1434</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015965">1015965</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19736">19736</ref><ref source="" url="http://www.assurance.com.au/advisories/200604-cisco.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17604">17604</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431371/30/5490/threaded">

20060419 Multiple vulnerabilities in Linux based Cisco products</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431367/30/5490/threaded">
20060419 Re: Multiple vulnerabilities in Linux based Cisco products</ref><ref source="OSVDB" url="http://www.osvdb.org/24812">
24812</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25883">
cisco-wlse-user-xss(25883)</ref></refs><vuln_soft><prod name="Wireless LAN Solution Engine" vendor="Cisco"><vers num="2.13"/><vers num="2.12"/><vers num="2.11"/><vers num="2.10"/><vers num="2.9"/><vers num="2.8"/><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="Express 2.13"/><vers num="Express 2.12"/><vers num="Express 2.11"/><vers num="Express 2.10"/><vers num="Express 2.9"/><vers num="Express 2.8"/><vers num="Express 2.7"/><vers num="Express 2.6"/><vers num="Express 2.5"/><vers num="Express 2.4"/><vers num="Express 2.3"/><vers num="Express 2.2"/><vers num="Express 2.1"/><vers num="Express 2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-04-19" modified="2007-08-13" name="CVE-2006-1961" published="2006-04-21" seq="2006-1961" severity="High" type="CVE"><desc><descript source="cve">Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Management Solution (SMS) allow local users to gain Linux shell access via shell metacharacters in arguments to the &quot;show&quot; command in the application&apos;s command line interface (CLI), aka bug ID CSCsd21502 (WLSE), CSCsd22861 (URT), and CSCsd22859 (HSE).  NOTE: other issues might be addressed by the Cisco advisory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20060419-wlse.shtml">20060419 Multiple Vulnerabilities in the WLSE Appliance</ref><ref patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sr-20060419-priv.shtml">20060419 Response to Privilege Escalation on Multiple Cisco Products</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1434">ADV-2006-1434</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015965">1015965</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19736">19736</ref><ref source="" url="http://www.assurance.com.au/advisories/200604-cisco.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1435">ADV-2006-1435</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19739">19739</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19741">19741</ref><ref source="BID" url="http://www.securityfocus.com/bid/17604">17604</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431371/30/5490/threaded">20060419 Multiple vulnerabilities in Linux based Cisco products</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431367/30/5490/threaded">20060419 Re: Multiple vulnerabilities in Linux based Cisco products</ref><ref source="BID" url="http://www.securityfocus.com/bid/17609">17609</ref><ref source="OSVDB" url="http://www.osvdb.org/24813">24813</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25884">cisco-wlse-shell-privilege-escalation(25884)</ref></refs><vuln_soft><prod name="CiscoWorks 2000 Service Management Solution" vendor="Cisco"><vers num=""/></prod><prod name="Hosting Solution Engine" vendor="Cisco"><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7.0"/><vers num="1.7"/></prod><prod name="Wireless LAN Solution Engine" vendor="Cisco"><vers num="Express 2.9"/><vers num="Express 2.8"/><vers num="Express 2.7"/><vers num="Express 2.6"/><vers num="Express 2.5"/><vers num="Express 2.4"/><vers num="Express 2.3"/><vers num="Express 2.2"/><vers num="Express 2.13"/><vers num="Express 2.12"/><vers num="Express 2.11"/><vers num="Express 2.10"/><vers num="Express 2.1"/><vers num="Express 2.0"/><vers num="2.9"/><vers num="2.8"/><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.13"/><vers num="2.12"/><vers num="2.11"/><vers num="2.10"/><vers num="2.1"/><vers num="2.0"/></prod><prod name="Ethernet Subscriber Solution Engine" vendor="Cisco"><vers num=""/></prod><prod name="User Registration Tool" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-13" name="CVE-2006-1962" published="2006-04-21" seq="2006-1962" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in PCPIN Chat 5.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (login parameter) to main.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431390/100/0/threaded">20060419 PCPIN Chat &lt;= 5.0.4 </ref><ref source="" url="http://retrogod.altervista.org/pcpin_504_xpl.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17632">17632</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1441">ADV-2006-1441</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19708">19708</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015968">1015968</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/436029/100/0/threaded">20060604 Re: PCPIN Chat &lt;= 5.0.4 </ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25961">pcpin-chat-main-sql-injection(25961)</ref></refs><vuln_soft><prod name="PCPIN Chat" vendor="PCPIN"><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="4.0"/><vers num="3.2.3"/><vers num="3.2.1"/><vers num="3.2.0"/><vers num="3.1.7r"/><vers num="3.1.6"/><vers num="3.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="4.9" CVSS_score="5.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-19" modified="2006-04-25" name="CVE-2006-1963" published="2006-04-21" seq="2006-1963" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in main.php in PCPIN Chat 5.0.4 and earlier allows remote authenticated users to include and execute arbitrary PHP code via a &quot;..&quot; (dot dot) in a language cookie, as demonstrated by uploading then accessing a smiliefile image that actually contains PHP code.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431390/100/0/threaded">20060419 PCPIN Chat &lt;= 5.0.4 </ref><ref source="" url="http://retrogod.altervista.org/pcpin_504_xpl.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17632">17632</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1441">ADV-2006-1441</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19708">19708</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015968">1015968</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/436029/100/0/threaded">20060604 Re: PCPIN Chat &lt;= 5.0.4 &quot;login/language&quot; remote cmmnds xctn</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25962">
pcpin-chat-main-file-include(25962)</ref></refs><vuln_soft><prod name="PCPIN Chat" vendor="PCPIN"><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="4.0"/><vers num="3.2.3"/><vers num="3.2.1"/><vers num="3.2.0"/><vers num="3.1.7r"/><vers num="3.1.6"/><vers num="3.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-19" modified="2006-04-25" name="CVE-2006-1964" published="2006-04-21" seq="2006-1964" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Haberler.asp in ASPSitem 1.83 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431469/100/0/threaded">20060419 ASPSitem &lt;= 1.83 Remote SQL Injection Vulnerability</ref><ref patch="1" source="" url="http://www.nukedx.com/?getxpl=23"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17616">17616</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1439">ADV-2006-1439</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19693">19693</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25932">
aspsitem-haberler-sql-injection(25932)</ref></refs><vuln_soft><prod name="AspSitem" vendor="AspSitem"><vers num="1.83"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-20" modified="2006-04-25" name="CVE-2006-1965" published="2006-04-21" seq="2006-1965" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in aasi media Net Clubs Pro 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) onuser, (2) pass, (3) chatsys, (4) room, (5) username, and (6) to parameters in (a) sendim.cgi; the (7) username parameter in (b) imessage.cgi; the (8) password parameter in (c) login.cgi; and the (9) cat_id parameter in (d) viewcat.cgi.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/net-clubs-pro-xss-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17622">17622</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1436">ADV-2006-1436</ref><ref source="OSVDB" url="http://www.osvdb.org/24754">24754</ref><ref source="OSVDB" url="http://www.osvdb.org/24755">24755</ref><ref source="OSVDB" url="http://www.osvdb.org/24756">24756</ref><ref source="OSVDB" url="http://www.osvdb.org/24757">24757</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19651">19651</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25957">
netclubspro-multiple-xss(25957)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/net-clubs-pro-xss-vuln.html"></ref></refs><vuln_soft><prod name="Net Clubs Pro" vendor="Aasi Media"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-16" modified="2006-04-25" name="CVE-2006-1966" published="2006-04-21" seq="2006-1966" severity="Medium" type="CVE"><desc><descript source="cve">An unspecified Fortinet product, possibly Fortinet28, allows remote attackers to cause a denial of service via a &quot;small synflood&quot; to the SMTP port (TCP port 25), as demonstrated by a 10-microsecond wait between sending packets.  NOTE: this issue has been disputed in followup posts that suggest that a protection feature is triggering a RST.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431404/100/0/threaded">20060416 Fortinet28 box does not resist has small synflood!</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0449.html">20060418 Re: Fortinet28 box does not resist has small synflood!</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0472.html">20060418 Re: Fortinet28 box does not resist has small synflood!</ref></refs><vuln_soft><prod name="Fortinet28" vendor="Fortinet"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-20" modified="2006-08-28" name="CVE-2006-1967" published="2006-04-21" seq="2006-1967" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in calendar/Visitor.cgi in KCScripts Calendar, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/portal-pack-6-xss-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1440">ADV-2006-1440</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19695">19695</ref><ref source="BID" url="http://www.securityfocus.com/bid/17628">17628</ref><ref source="OSVDB" url="http://www.osvdb.org/24761">24761</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25940">portalpack-multiple-xss(25940)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/portal-pack-6-xss-vuln.html"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/503">503</ref></refs><vuln_soft><prod name="KCScripts Calendar" vendor="KCScripts"><vers num="6.1"/></prod><prod name="Portal Pack" vendor="KCScripts"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-20" modified="2006-10-06" name="CVE-2006-1968" published="2006-04-21" seq="2006-1968" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in news/NsVisitor.cgi in KCScripts News Publisher, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/portal-pack-6-xss-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1440">ADV-2006-1440</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19695">19695</ref><ref source="BID" url="http://www.securityfocus.com/bid/17628">17628</ref><ref source="OSVDB" url="http://www.osvdb.org/24762">24762</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25940">portalpack-multiple-xss(25940)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/portal-pack-6-xss-vuln.html"></ref></refs><vuln_soft><prod name="Portal Pack" vendor="KCScripts"><vers num="6.0"/></prod><prod name="KCScripts News Publisher" vendor="KCScripts"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1969" published="2006-04-21" seq="2006-1969" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search/search.cgi in an unspecified KCScripts script, probably Search Engine or Site Search, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the q parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/portal-pack-6-xss-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1440">ADV-2006-1440</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19695">19695</ref><ref source="BID" url="http://www.securityfocus.com/bid/17628">17628</ref><ref source="OSVDB" url="http://www.osvdb.org/24763">24763</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25940">portalpack-multiple-xss(25940)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/portal-pack-6-xss-vuln.html"></ref></refs><vuln_soft><prod name="Portal Pack" vendor="KCScripts"><vers num="6.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-20" modified="2006-04-25" name="CVE-2006-1970" published="2006-04-21" seq="2006-1970" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in classifieds/viewcat.cgi in KCScripts Classifieds, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/portal-pack-6-xss-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1440">ADV-2006-1440</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19695">19695</ref><ref source="BID" url="http://www.securityfocus.com/bid/17628">17628</ref><ref source="OSVDB" url="http://www.osvdb.org/24764">24764</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25940">portalpack-multiple-xss(25940)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/portal-pack-6-xss-vuln.html"></ref></refs><vuln_soft><prod name="Portal Pack" vendor="KCScripts"><vers num="6.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1971" published="2006-04-21" seq="2006-1971" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in KRANKIKOM ContentBoxX allows remote attackers to inject arbitrary web script or HTML via the action parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431386/100/0/threaded">20060419 ContentBoxx Login.php Cross-Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/17612">17612</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1438">ADV-2006-1438</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19733">19733</ref><ref source="OSVDB" url="http://www.osvdb.org/24768">24768</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25952">
contentboxx-login-xss(25952)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/740">740</ref><ref source="SREASON" url="http://securityreason.com/securityalert/779">779</ref></refs><vuln_soft><prod name="ContentBoxX" vendor="KRANKIKOM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1972" published="2006-04-21" seq="2006-1972" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in EasyGallery.php in Wingnut EasyGallery allows remote attackers to inject arbitrary web script or HTML via the ordner parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431430/100/0/threaded">20060419 EasyGallery Cross-Site Scripting</ref><ref source="" url="http://advisory.patriotichackers.com/index.php?itemid=5"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17624">17624</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1437">ADV-2006-1437</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19713">19713</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25943">
easygallery-script-xss(25943)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/746">746</ref></refs><vuln_soft><prod name="EasyGallery" vendor="Wingnut"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1973" published="2006-04-21" seq="2006-1973" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Linksys RT31P2 VoIP router allow remote attackers to cause a denial of service via malformed Session Initiation Protocol (SIP) messages.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/621566">VU#621566</ref><ref source="" url="http://www.kb.cert.org/vuls/id/MIMG-6GMMW4"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1443">ADV-2006-1443</ref><ref source="BID" url="http://www.securityfocus.com/bid/17631">17631</ref><ref source="OSVDB" url="http://www.osvdb.org/24810">24810</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19722">19722</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25915">
linksys-rt31p2-sip-dos(25915)</ref></refs><vuln_soft><prod name="RT31P2" vendor="Linksys"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-05" name="CVE-2006-1974" published="2006-04-21" seq="2006-1974" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in MyBB (MyBulletinBoard) before 1.04 allows remote attackers to execute arbitrary SQL commands via the referrer parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.securityfocus.com/bid/16443/exploit"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16443">16443</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC4"/><vers num="1.0 RC2"/><vers num="1.0 Preview Release 2"/><vers num="1.0 PR2"/><vers num="1.0 &quot;Final&quot;"/><vers num="1.0 Final"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1975" published="2006-04-21" seq="2006-1975" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in guestbook_newentry.php in PHP-Gastebuch 1.61 allows remote attackers to inject arbitrary web script or HTML via the Kommentar field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://osvdb.org/ref/23/23962-gastebuch.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/23962">23962</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19810">19810</ref></refs><vuln_soft><prod name="PHP-Gastebuch" vendor="Stadtaus.com"><vers num="1.61"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1976" published="2006-04-21" seq="2006-1976" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in addRequest.php in Prayer Request Board (PRB) Beta 1 before 20060320 allows remote attackers to inject arbitrary web script or HTML via the Request field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://osvdb.org/ref/23/23958-prb.txt"></ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/23958">23958</ref></refs><vuln_soft><prod name="Prayer Request Board" vendor="Geekforgod.net"><vers num="Beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1977" published="2006-04-21" seq="2006-1977" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in FlexBB 0.5.7 BETA and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) message parameters.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431071/100/0/threaded">20060415 FlexBB &lt;= 0.5.7 BETA XSS</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1393">ADV-2006-1393</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015946">1015946</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25868">
flexbb-newthread-xss(25868)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/777">777</ref></refs><vuln_soft><prod name="FlexBB" vendor="FlexBB"><vers num="0.5.7 BETA" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1978" published="2006-04-21" seq="2006-1978" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in inc/start.php in FlexBB 0.5.5 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_username COOKIE parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431156/100/0/threaded">20060417 FlexBB 0.5.5 Bypass Exploit</ref><ref source="" url="http://www.milw0rm.com/exploits/1686"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015949">1015949</ref><ref source="BID" url="http://www.securityfocus.com/bid/17568">17568</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1686">
1686</ref></refs><vuln_soft><prod name="FlexBB" vendor="FlexBB"><vers num="0.5.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1979" published="2006-04-21" seq="2006-1979" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in mwguest.php in Manic Web MWGuest 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the homepage parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431507/100/0/threaded">20060420 [eVuln] MWGuest XSS Vulnerability</ref><ref source="" url="http://evuln.com/vulns/122/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17630">17630</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25674">
mwguest-mwguest-xss(25674)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/747">747</ref></refs><vuln_soft><prod name="MWGuest" vendor="Manic Web"><vers num="2.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-08-13" name="CVE-2006-1980" published="2006-04-21" seq="2006-1980" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the (1) query string, (2) SID parameter, or (3) ilang parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/w2b-online-banking-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17626">17626</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19717">19717</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1445">ADV-2006-1445</ref><ref source="OSVDB" url="http://www.osvdb.org/24759">24759</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25947">w2bonlinebanking-sid-xss(25947)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/w2b-online-banking-vuln.html"></ref></refs><vuln_soft><prod name="Online Banking" vendor="W2B"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1981" published="2006-04-21" seq="2006-1981" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Java InputMethods on Mac OS X 10.4.5 may cause InputMethods to send input events for secure fields to the wrong text field, which might reveal the password to others who can view the screen.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=303658"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1398">ADV-2006-1398</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26167">
macosx-java-inputmethods-info-disclosure(26167)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-16" name="CVE-2006-1982" published="2006-04-21" seq="2006-1982" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the LZWDecodeVector function in Mac OS X before 10.4.6, as used in applications that use ImageIO or AppKit, allows remote attackers to execute arbitrary code via crafted TIFF images.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.security-protocols.com/sp-x24-advisory.php"></ref><ref patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=303411"></ref><ref source="" url="http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=3233"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17634">17634</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19686">19686</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1452">ADV-2006-1452</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="OSVDB" url="http://www.osvdb.org/31837">
31837</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-16" name="CVE-2006-1983" published="2006-04-21" seq="2006-1983" severity="Medium" type="CVE"><desc><descript source="cve">Multiple heap-based buffer overflows in Mac OS X 10.4.6 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) PredictorVSetField function for TIFF or (2) CFAllocatorAllocate function for GIF, as used in applications that use ImageIO or AppKit.  NOTE: the BMP vector has been re-assigned to CVE-2006-2238 because it affects a separate product family.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input buffer="1"/><other/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.security-protocols.com/sp-x27-advisory.php"></ref><ref adv="1" source="" url="http://www.security-protocols.com/sp-x28-advisory.php"></ref><ref adv="1" source="" url="http://www.security-protocols.com/sp-x30-advisory.php"></ref><ref source="" url="http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=3233"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17634">17634</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19686">19686</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1452">ADV-2006-1452</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/24820">24820</ref><ref source="OSVDB" url="http://www.osvdb.org/24821">24821</ref><ref source="OSVDB" url="http://www.osvdb.org/24822">24822</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016067">1016067</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25949">
macosx-cfallocatorallocate-bo(25949)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25951">
macosx-predictorvsetfield-bo(25951)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.6"/><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.6"/><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-16" name="CVE-2006-1984" published="2006-04-21" seq="2006-1984" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the _cg_TIFFSetField function in Mac OS X 10.4.6 and earlier, as used in applications that use ImageIO or AppKit, allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers a null dereference.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="" url="http://www.security-protocols.com/sp-x29-advisory.php"></ref><ref source="" url="http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=3233"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17634">17634</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19686">19686</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1452">ADV-2006-1452</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25950">
macosx-tiffsetfield-bo(25950)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-02-21" modified="2007-08-13" name="CVE-2006-1985" published="2006-04-21" seq="2006-1985" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to execute arbitrary code via a crafted archive (such as ZIP) that contains long path names, which triggers an error in the BOMStackPop function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://www.security-protocols.com/sp-x25-advisory.php"></ref><ref source="" url="http://www.security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=3233"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17634">17634</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19686">19686</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1452">ADV-2006-1452</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016082">1016082</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="OSVDB" url="http://www.osvdb.org/24819">24819</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25945">macosx-archivehelper-bo(25945)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.6"/><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.6"/><vers num="10.4.5"/><vers num="10.4.4"/><vers num="10.4.3"/><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod><prod name="Safari" vendor="Apple"><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1986" published="2006-04-21" seq="2006-1986" severity="High" type="CVE"><desc><descript source="cve">Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via a large CELLSPACING attribute in a TABLE tag, which triggers an error in KWQListIteratorImpl::KWQListIteratorImpl.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.security-protocols.com/sp-x26-advisory.php"></ref><ref source="" url="http://security-protocols.com/poc/sp-x26-1.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17634">17634</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19686">19686</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1452">ADV-2006-1452</ref><ref source="OSVDB" url="http://www.osvdb.org/24823">24823</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25946">
macosx-safari-dos(25946)</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1987" published="2006-04-21" seq="2006-1987" severity="High" type="CVE"><desc><descript source="cve">Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via an invalid FRAME tag, possibly due to (1) multiple SCROLLING attributes with no values, or (2) a SRC attribute with no value.  NOTE: due to lack of diagnosis by the researcher, it is unclear which vector is responsible.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.security-protocols.com/sp-x26-advisory.php"></ref><ref source="" url="http://security-protocols.com/poc/sp-x26-4.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17634">17634</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19686">19686</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1452">ADV-2006-1452</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25946">
macosx-safari-dos(25946)</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1988" published="2006-04-21" seq="2006-1988" severity="Medium" type="CVE"><desc><descript source="cve">The WebTextRenderer(WebInternal) _CG_drawRun:style:geometry: function in Apple Safari 2.0.3 allows remote attackers to cause a denial of service (application crash) via an HTML LI tag with a large VALUE attribute (list item number), which triggers a null dereference in QPainter::drawText, probably due to a failed memory allocation that uses the VALUE.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.security-protocols.com/sp-x26-advisory.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17634">17634</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19686">19686</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1452">ADV-2006-1452</ref><ref source="" url="http://security-protocols.com/poc/sp-x26-2.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/24823">24823</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25946">
macosx-safari-dos(25946)</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-06-30" name="CVE-2006-1989" published="2006-05-01" seq="2006-1989" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the get_database function in the HTTP client in Freshclam in ClamAV 0.80 to 0.88.1 might allow remote web servers to execute arbitrary code via long HTTP headers.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Clam Anti-Virus, ClamAV, 0.88.2</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CLAMAV" url="http://www.clamav.net/security/0.88.2.html">Security advisory: 0.88.2</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17754">17754</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1586">ADV-2006-1586</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19880">19880</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1050">DSA-1050</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-03.xml">GLSA-200605-03</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:080">MDKSA-2006:080</ref><ref source="OSVDB" url="http://www.osvdb.org/25120">25120</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19912">19912</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19963">19963</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0024">2006-0024</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19874">19874</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19964">19964</ref><ref source="" url="http://kolab.org/security/kolab-vendor-notice-09.txt"></ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html">SUSE-SR:2006:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20159">20159</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20117">20117</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_05_05.html">SUSE-SA:2006:025</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Jun/msg00000.html">APPLE-SA-2006-06-27</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2566">ADV-2006-2566</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/599220">VU#599220</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016392">1016392</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20877">20877</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26182">
clamav-freshclam-http-bo(26182)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:080">MDKSA-2006:080</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.88.1"/><vers num="0.88"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-1990" published="2006-04-24" seq="2006-1990" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function call, a different vulnerability than CVE-2002-1396.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.infigo.hr/en/in_focus/advisories/INFIGO-2006-04-02"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015979">1015979</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19803">19803</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1500">ADV-2006-1500</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0501.html">RHSA-2006:0501</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:091">MDKSA-2006:091</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20222">20222</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20269">20269</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_31_php.html">SUSE-SA:2006:031</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200605-08.xml">GLSA-200605-08</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:122">MDKSA-2006:122</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0568.html">RHSA-2006:0568</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-320-1">USN-320-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21050">21050</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21031">21031</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U">20060701-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21135">21135</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21252">21252</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21564">21564</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0549.html">RHSA-2006:0549</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-175.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21723">21723</ref><ref source="" url="https://issues.rpath.com/browse/RPL-683"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/22225">22225</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=304829"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html">APPLE-SA-2006-11-28</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-333A.html">TA06-333A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4750">ADV-2006-4750</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23155">23155</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/447866/100/0/threaded">

20061005 rPSA-2006-0182-1 php php-mysql php-pgsql</ref><ref source="TURBO" url="http://www.turbolinux.com/security/2006/TLSA-2006-38.txt">
TLSA-2006-38</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20052">
20052</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20676">
20676</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21125">
21125</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26001">
php-wordwrap-string-bo(26001)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:091">MDKSA-2006:091</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:122">MDKSA-2006:122</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.4.0.2"/><vers num="5.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-07-17" name="CVE-2006-1991" published="2006-04-24" seq="2006-1991" severity="Medium" type="CVE"><desc><descript source="cve">The substr_compare function in string.c in PHP 5.1.2 allows context-dependent attackers to cause a denial of service (memory access violation) via an out-of-bounds offset argument.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.infigo.hr/en/in_focus/advisories/INFIGO-2006-04-02"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015979">1015979</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1500">ADV-2006-1500</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:091">MDKSA-2006:091</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20269">20269</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_31_php.html">SUSE-SA:2006:031</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200605-08.xml">GLSA-200605-08</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-320-1">USN-320-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20052">
20052</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20676">
20676</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21125">
21125</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26003">
php-substrcompare-length-dos(26003)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:091">MDKSA-2006:091</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-06-19" name="CVE-2006-1992" published="2006-04-24" seq="2006-1992" severity="Low" type="CVE"><desc><descript source="cve">mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid pointer dererences including NULL dereferences.  NOTE: the possibility of code execution was originally theorized, but Microsoft has stated that this issue is non-exploitable.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431796/100/0/threaded">20060422 MSIE (mshtml.dll) OBJECT tag vulnerability</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0616.html">20060422 Re: MSIE (mshtml.dll) OBJECT tag vulnerability</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1507">ADV-2006-1507</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19762">19762</ref><ref source="BID" url="http://www.securityfocus.com/bid/17658">17658</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016001">1016001</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-021.mspx">MS06-021</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016291">1016291</ref><ref source="OSVDB" url="http://www.osvdb.org/27475">27475</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045422.html">
20060423 MSIE (mshtml.dll) OBJECT tag vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25978">
ie-object-memory-corruption(25978)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/781">781</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-24" modified="2006-05-04" name="CVE-2006-1993" published="2006-04-25" seq="2006-1993" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain Javascript that is not properly handled by the contentWindow.focus method in an iframe, which causes a reference to a deleted controller context object.  NOTE: this was originally claimed to be a buffer overflow in (1) js320.dll and (2) xpcom_core.dll, but the vendor disputes this claim.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431878/100/0/threaded">20060424 Firefox Remote Code Execution and DoS 1.5.0.2</ref><ref source="" url="http://www.securident.com/vuln/ff.txt"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17671">17671</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015981">1015981</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19802">19802</ref><ref adv="1" source="" url="http://www.mozilla.org/security/announce/2006/mfsa2006-30.html"></ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/866300">VU#866300</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1614">ADV-2006-1614</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1053">DSA-1053</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-06.xml">GLSA-200605-06</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1055">DSA-1055</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20019">20019</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20015">20015</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/434524/100/0/threaded">HPSBTU02118</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20214">20214</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1922">ADV-2006-1922</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446658/100/200/threaded">HPSBUX02153</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1790">oval:org.mitre.oval:def:1790</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20070">
20070</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25994">
firefox-iframe-contentwindowfocus-bo(25994)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3748">ADV-2006-3748</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22066">22066</ref><ref source="SREASON" url="http://securityreason.com/securityalert/780">780</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-21" modified="2006-04-26" name="CVE-2006-1994" published="2006-04-25" seq="2006-1994" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in dForum 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DFORUM_PATH parameter to (1) about.php, (2) admin.php, (3) anmelden.php, (4) losethread.php, (5) config.php, (6) delpost.php, (7) delthread.php, (8) dfcode.php, (9) download.php, (10) editanoc.php, (11) forum.php, (12) login.php, (13) makethread.php, (14) menu.php, (15) newthread.php, (16) openthread.php, (17) overview.php, (18) post.php, (19) suchen.php, (20) user.php, (21) userconfig.php, (22) userinfo.php, and (23) verwalten.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/431758">20060421 dForum &lt;= 1.5 Multiple Remote File Inclusion Vulnerabilities.</ref><ref adv="1" source="" url="http://www.nukedx.com/?viewdoc=27"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17650">17650</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1482">ADV-2006-1482</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19788">19788</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045369.html">
20060421 dForum &lt;= 1.5 Multiple Remote File Inclusion Vulnerabilities.</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26035">
dforum-dforumpath-parameter-file-include(26035)</ref></refs><vuln_soft><prod name="dForum" vendor="dForum"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-21" modified="2006-04-26" name="CVE-2006-1995" published="2006-04-25" seq="2006-1995" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to read arbitrary files via &quot;..&quot; sequences in the p parameter, which is not properly sanitized due to an rtrim function call with the arguments in the wrong order.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431716/100/0/threaded">20060421 Scry Gallery Directory Traversal &amp; Full Path Disclosure Vulnerabilites</ref><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/17649-directory-traversal.exploit"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17649">17649</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-April/000716.html">[VIM] 20060425 Interesting Scry stuff</ref><ref source="BID" url="http://www.securityfocus.com/bid/17668">17668</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1490">ADV-2006-1490</ref><ref source="OSVDB" url="http://www.osvdb.org/24889">24889</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19777">19777</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25991">
scry-gallery-index-directory-traversal(25991)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/784">784</ref></refs><vuln_soft><prod name="Scry Gallery" vendor="Scry Gallery"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-21" modified="2006-04-26" name="CVE-2006-1996" published="2006-04-25" seq="2006-1996" severity="Medium" type="CVE"><desc><descript source="cve">Scry Gallery 1.1 allows remote attackers to obtain sensitive information via an invalid p parameter, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431716/100/0/threaded">20060421 Scry Gallery Directory Traversal &amp; Full Path Disclosure Vulnerabilites</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-April/000716.html">[VIM] 20060425 Interesting Scry stuff</ref><ref source="BID" url="http://www.securityfocus.com/bid/17668">17668</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1490">ADV-2006-1490</ref><ref source="OSVDB" url="http://www.osvdb.org/24890">24890</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19777">19777</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25990">
scry-gallery-index-path-disclosure(25990)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/784">784</ref></refs><vuln_soft><prod name="Scry Gallery" vendor="Scry Gallery"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" discovered="2006-04-24" modified="2007-08-13" name="CVE-2006-1997" published="2006-04-25" seq="2006-1997" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Sybase Pylon Anywhere groupware synchronization server before 7.0 allows local users to obtain sensitive information such as email and PIM data of another user via unknown attack vectors.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://www.sybase.com/detail?id=1040213"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1477">ADV-2006-1477</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19784">19784</ref><ref source="BID" url="http://www.securityfocus.com/bid/17677">17677</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25989">pylon-groupware-unauth-access(25989)</ref></refs><vuln_soft><prod name="Pylon Anywhere" vendor="Sybase"><vers num="6.4.9"/><vers num="6.4.8"/><vers num="6.4.2"/><vers num="6.3.2"/><vers num="6.2.1"/><vers num="5.5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1998" published="2006-04-25" seq="2006-1998" severity="Low" type="CVE"><desc><descript source="cve">OpenTTD 0.4.7 and earlier allows local users to cause a denial of service (application exit) via a large invalid error number, which triggers an error.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://aluigi.altervista.org/adv/openttdx-adv.txt"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1480">ADV-2006-1480</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19768">19768</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431871/100/0/threaded">20060423 Denial of service bugs in OpenTTD 0.4.7</ref><ref source="BID" url="http://www.securityfocus.com/bid/17661">17661</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200609-03.xml">GLSA-200609-03</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21799">21799</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26000">
openttd-command-packet-dos(26000)</ref></refs><vuln_soft><prod name="OpenTTD" vendor="OpenTTD"><vers num="0.4.7"/><vers num="0.4.6"/><vers num="0.4.5"/><vers num="0.4.0.1"/><vers num="0.4.0"/><vers num="0.3.7"/><vers num="0.3.6"/><vers num="0.3.5"/><vers num="0.3.4"/><vers num="0.3.2.1"/><vers num="0.3.2"/><vers num="0.3.1"/><vers num="0.3.0"/><vers num="0.2.1"/><vers num="0.2.0"/><vers num="0.1.4"/><vers num="0.1.3"/><vers num="0.1.2"/><vers num="0.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-1999" published="2006-04-25" seq="2006-1999" severity="Medium" type="CVE"><desc><descript source="cve">The multiplayer menu in OpenTTD 0.4.7 allows remote attackers to cause a denial of service via a UDP packet with an incorrect size, which causes the client to return to the main menu.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://aluigi.altervista.org/adv/openttdx-adv.txt"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1480">ADV-2006-1480</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19768">19768</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431871/100/0/threaded">20060423 Denial of service bugs in OpenTTD 0.4.7</ref><ref source="BID" url="http://www.securityfocus.com/bid/17661">17661</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200609-03.xml">GLSA-200609-03</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21799">21799</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26004">
openttd-udp-packet-dos(26004)</ref></refs><vuln_soft><prod name="OpenTTD" vendor="OpenTTD"><vers num="0.4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-22" modified="2006-04-26" name="CVE-2006-2000" published="2006-04-25" seq="2006-2000" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in /lms/a2z.jsp in logMethods 0.9 allows remote attackers to inject arbitrary web script or HTML via the kwd parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/logmethods-xss-vuln.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19793">19793</ref><ref source="BID" url="http://www.securityfocus.com/bid/17675">17675</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1484">ADV-2006-1484</ref><ref source="OSVDB" url="http://www.osvdb.org/24876">24876</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25968">logmethods-lmsa2z-xss(25968)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/logmethods-xss-vuln.html"></ref></refs><vuln_soft><prod name="logMethods" vendor="logMethods"><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-2001" published="2006-04-25" seq="2006-2001" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the p parameter.  NOTE: this is a different vulnerability than the directory traversal vector.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431853/100/0/threaded">20060424 Scry Gallery XSS Vulnerability</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-April/000716.html">[VIM] 20060425 Interesting Scry stuff</ref><ref source="BID" url="http://www.securityfocus.com/bid/17668">17668</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1490">ADV-2006-1490</ref><ref source="OSVDB" url="http://www.osvdb.org/24891">24891</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19777">19777</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26101">
scry-gallery-index-xss(26101)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/783">783</ref></refs><vuln_soft><prod name="Scry Gallery" vendor="Scry Gallery"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-22" modified="2006-04-26" name="CVE-2006-2002" published="2006-04-25" seq="2006-2002" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in stats.php in MyGamingLadder 7.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir[base] parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431902/100/0/threaded">20060422 Advisory: My Gaming Ladder Combo System &lt;= 7.0 Remote File Inclusion Vulnerability.</ref><ref source="" url="http://www.nukedx.com/?viewdoc=28"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17657">17657</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19773">19773</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1483">ADV-2006-1483</ref><ref source="OSVDB" url="http://www.osvdb.org/24892">24892</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25992">mygamingladder-stats-file-inclusion(25992)</ref></refs><vuln_soft><prod name="MyGamingLadder" vendor="MyGamingLadder"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-05" name="CVE-2006-2003" published="2006-04-25" seq="2006-2003" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in cgi-bin/guest in Community Architect Guestbook allows remote attackers to inject arbitrary web script or HTML by signing the guestbook, which is displayed by fsguestbook.html.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1446">ADV-2006-1446</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19742">19742</ref><ref source="OSVDB" url="http://www.osvdb.org/24784">24784</ref></refs><vuln_soft><prod name="Community Architect Guestbook" vendor="Community Architect"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-2004" published="2006-04-25" seq="2006-2004" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in RI Blog 1.1 allow remote attackers to execute arbitrary SQL command via the (1) username or (2) password fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://colander.altervista.org/advisory/riblog.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17654">17654</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19783">19783</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431868/100/0/threaded">20060423 RIblog Remote SQL Injection Exploit</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1489">ADV-2006-1489</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26132">
riblog-login-sql-injection(26132)</ref></refs><vuln_soft><prod name="RI Blog" vendor="Michael Romedahl"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-23" modified="2006-05-10" name="CVE-2006-2005" published="2006-04-25" seq="2006-2005" severity="High" type="CVE"><desc><descript source="cve">Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an &quot;include&quot; statement that is injected into the eval statement.  NOTE: this issue has been described as file inclusion by some sources, but that is just one attack; the primary vulnerability is eval injection.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431873/100/0/threaded">20060423 Advisory: Clansys &lt;= 1.1 PHP Code Insertion Vulnerability.</ref><ref source="" url="http://www.nukedx.com/?getxpl=29"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17660">17660</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015988">1015988</ref><ref source="OSVDB" url="http://www.osvdb.org/25083">25083</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25976">clansys-index-file-include(25976)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/782">782</ref></refs><vuln_soft><prod name="Clansys" vendor="Clansys"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-2006" published="2006-04-25" seq="2006-2006" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in IZArc Archiver 3.5 beta 3 allow remote attackers to write arbitrary files via a ..\ (dot dot backslash) in a (1) .rar, (2) .tar, (3) .zip, (4) .jar, or (5) .gz archive.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17664">17664</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1488">ADV-2006-1488</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19791">19791</ref><ref source="OSVDB" url="http://www.osvdb.org/24895">24895</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26039">
izarc-extract-directory-traversal(26039)</ref></refs><vuln_soft><prod name="IZArc" vendor="Ivan Zahariev"><vers num="3.5 Beta 3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-2007" published="2006-04-25" seq="2006-2007" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Winny 2.0 b7.1 and earlier allows remote attackers to execute arbitrary code via long strings to certain commands sent to the file transfer port.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.eeye.com/html/research/advisories/AD20060421.html"></ref><ref source="" url="http://jvn.jp/jp/JVN%2374294680/index.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17666">17666</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19795">19795</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1486">ADV-2006-1486</ref><ref source="OSVDB" url="http://www.osvdb.org/24883">24883</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/167033">VU#167033</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25986">
winny-file-transfer-bo(25986)</ref></refs><vuln_soft><prod name="Winny" vendor="Winny"><vers num="2.0b5.7"/><vers num="2.0b7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-2008" published="2006-04-25" seq="2006-2008" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in movie_cls.php in Built2Go PHP Movie Review 2B and earlier allows remote attackers to execute arbitrary PHP code via a URL in the full_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/1711"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1481">ADV-2006-1481</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19749">19749</ref><ref source="BID" url="http://www.securityfocus.com/bid/17679">17679</ref><ref source="OSVDB" url="http://www.osvdb.org/24887">24887</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26063">
moviereview-moviecls-file-include(26063)</ref></refs><vuln_soft><prod name="Movie Review" vendor="Built2Go"><vers num="2B"/><vers num="2A"/><vers num="1A"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-2009" published="2006-04-25" seq="2006-2009" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in agenda.php3 in phpMyAgenda 3.0 Final and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootagenda parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431862/100/0/threaded">20060424 [MajorSecurity] phpMyAgenda 3.0 Final - Remote File Include Vulnerability</ref><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/phpMyAgenda_fi.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17670">17670</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1509">ADV-2006-1509</ref><ref source="OSVDB" url="http://www.osvdb.org/24943">24943</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015984">1015984</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19748">19748</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433995/100/0/threaded">20060515 tyree[at]users.sourceforge.net</ref><ref source="" url="http://sourceforge.net/forum/forum.php?forum_id=569237"></ref><ref source="" url="http://osvdb.org/ref/29/2914x-phpmyagenda.txt"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26062">
phpmyagenda-rootagenda-file-include(26062)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/787">787</ref></refs><vuln_soft><prod name="phpMyAgenda" vendor="phpMyAgenda"><vers num="3.0 Final"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-2010" published="2006-04-25" seq="2006-2010" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in check_login.asp in Bloggage allow remote attackers to execute arbitrary SQL commands via the (1) acc_name and (2) password parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://colander.altervista.org/advisory/bloggage.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1448">ADV-2006-1448</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19751">19751</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431673/100/0/threaded">20060421 bloggage Remote SQL Injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/17639">17639</ref><ref source="OSVDB" url="http://www.osvdb.org/24797">24797</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25955">
bloggage-checklogin-sql-injection(25955)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/751">751</ref></refs><vuln_soft><prod name="Bloggage" vendor="Paras Chopra"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-2011" published="2006-04-25" seq="2006-2011" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in member.php in 4images 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the nickname, probably involving the user_name parameter in register.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431599/100/0/threaded">20060420 4images &lt;= 1.7 XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/17625">17625</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1449">ADV-2006-1449</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19745">19745</ref><ref source="OSVDB" url="http://www.osvdb.org/24796">24796</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25987">
4images-member-xss(25987)</ref></refs><vuln_soft><prod name="4images" vendor="4homepages"><vers num="1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-2012" published="2006-04-25" seq="2006-2012" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in Skulltag 0.96f and earlier allows remote attackers to cause a denial of service via the version string.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://aluigi.altervista.org/adv/skulltagfs-adv.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1479">ADV-2006-1479</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19767">19767</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431872/100/0/threaded">20060423 Format string bug in Skulltag 0.96f</ref><ref source="BID" url="http://www.securityfocus.com/bid/17659">17659</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25988">
skulltag-version-format-string(25988)</ref></refs><vuln_soft><prod name="Skulltag" vendor="Skulltag Team"><vers num="0.96f" prev="1"/><vers num="0.96d"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-2013" published="2006-04-25" seq="2006-2013" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in page.php in SL_site 1.0 allows remote attackers to execute arbitrary SQL commands via the id_page parameter. NOTE: this issue could be used to produce resultant XSS from an error message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1015972">1015972</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19792">19792</ref><ref source="BID" url="http://www.securityfocus.com/bid/17667">17667</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1487">ADV-2006-1487</ref><ref source="OSVDB" url="http://www.osvdb.org/24896">24896</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26036">
slsite-page-sql-injection(26036)</ref></refs><vuln_soft><prod name="SL_site" vendor="Web-provence"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-2014" published="2006-04-25" seq="2006-2014" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in gallerie.php in SL_site 1.0 allows remote attackers to list images in arbitrary directories via &quot;..&quot; sequences in the rep parameter, which is used to construct a directory name in admin/config.inc.php.  NOTE: this issue could be used to produce resultant XSS from an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1015972">1015972</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19792">19792</ref><ref source="BID" url="http://www.securityfocus.com/bid/17667">17667</ref><ref source="BID" url="http://www.securityfocus.com/bid/17672">17672</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1487">ADV-2006-1487</ref><ref source="OSVDB" url="http://www.osvdb.org/24897">24897</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26037">
slsite-gallerie-directory-traversal(26037)</ref></refs><vuln_soft><prod name="SL_site" vendor="Web-provence"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-2015" published="2006-04-25" seq="2006-2015" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in SL_site 1.0 allows remote attackers to inject arbitrary web script or HTML via the recherche parameter in recherche.php.  NOTE: other XSS vectors, as reported in the original disclosure, are resultant from other primary vulnerabilities that have separate CVE names.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1015972">1015972</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19792">19792</ref><ref source="BID" url="http://www.securityfocus.com/bid/17667">17667</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1487">ADV-2006-1487</ref><ref source="OSVDB" url="http://www.osvdb.org/24898">24898</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26038">
slsite-recherche-xss(26038)</ref></refs><vuln_soft><prod name="SL_site" vendor="Web-provence"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-2016" published="2006-04-25" seq="2006-2016" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin 0.9.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dn parameter in (a) compare_form.php, (b) copy_form.php, (c) rename_form.php, (d) template_engine.php, and (e) delete_form.php; (2) scope parameter in (f) search.php; and (3) Container DN, (4) Machine Name, and (5) UID Number fields in (g) template_engine.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/phpldapadmin-multiple-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17643">17643</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1450">ADV-2006-1450</ref><ref source="OSVDB" url="http://www.osvdb.org/24788">24788</ref><ref source="OSVDB" url="http://www.osvdb.org/24789">24789</ref><ref source="OSVDB" url="http://www.osvdb.org/24790">24790</ref><ref source="OSVDB" url="http://www.osvdb.org/24792">24792</ref><ref source="OSVDB" url="http://www.osvdb.org/24793">24793</ref><ref source="OSVDB" url="http://www.osvdb.org/24794">24794</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19747">19747</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1057">DSA-1057</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20124">20124</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25959">
phpldapadmin-templateengine-xss(25959)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25958">
phpldapadmin-scope-dn-xss(25958)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/phpldapadmin-multiple-vuln.html"></ref></refs><vuln_soft><prod name="phpLDAPadmin" vendor="phpLDAPadmin"><vers num="0.9.8"/><vers num="0.9.7.2"/><vers num="0.9.7.1"/><vers num="0.9.7"/><vers num="0.9.6c"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.4b"/><vers num="0.9.4a"/><vers num="0.9.4"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers num="0.9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-2017" published="2006-04-25" seq="2006-2017" severity="Medium" type="CVE"><desc><descript source="cve">Dnsmasq 2.29 allows remote attackers to cause a denial of service (application crash) via a DHCP client broadcast reply request.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
version 2.30</sol></sols><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://thekelleys.org.uk/dnsmasq/CHANGELOG"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17662">17662</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19760">19760</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1494">ADV-2006-1494</ref><ref source="OSVDB" url="http://www.osvdb.org/24884">24884</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26005">dnsmasq-dhcp-dos(26005)</ref></refs><vuln_soft><prod name="Dnsmasq" vendor="Dnsmasq"><vers num="2.29"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-04-23" modified="2007-08-13" name="CVE-2006-2018" published="2006-04-25" seq="2006-2018" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parameter.  NOTE: the affected version has been disputed by the vendor.  It appears that this is the same issue as CVE-2004-0036, which was fixed in 2.3.4.</descript></desc><sols><sol source="nvd">This vulnerability has been disputed by the vendor.  The affected version has been disputed by the vendor via e-mail to CVE.  It appears that this is the same issue as CVE-2004-0036, which was fixed in 2.3.4.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/431901">20060423 vbulletin&lt;--3.0.x SQL Injection</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431951/30/5370/threaded">20060424 Re: vbulletin&lt;--3.0.x SQL Injection</ref></refs><vuln_soft><prod name="vBulletin" vendor="Jelsoft"><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.12"/><vers num="3.0.1"/><vers num="3.0.0 RC4"/><vers num="3.0.0 can4"/><vers num="3.0.0 Beta 2"/><vers num="3.0.0"/><vers num="3.0 beta 2"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-2019" published="2006-04-25" seq="2006-2019" severity="Medium" type="CVE"><desc><descript source="cve">Apple Mac OS X Safari 2.0.3, 1.3.1, and possibly other versions allows remote attackers to cause a denial of service (CPU consumption and crash) via a TD element with a large number in the rowspan attribute.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431874/100/0/threaded">20060424 Apple Mac OS X Safari 2.0.3 Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431944/100/0/threaded">20060424 Re: Apple Mac OS X Safari 2.0.3 Vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045472.html">20060424 Apple Mac OS X Safari 2.0.3 Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17674">17674</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1508">ADV-2006-1508</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015982">1015982</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19763">19763</ref><ref source="" url="http://www.milw0rm.com/exploits/1715"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1715">
1715</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25998">
macosx-safari-table-dos(25998)</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num="2.0.3"/><vers num="1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-21" modified="2006-04-26" name="CVE-2006-2020" published="2006-04-25" seq="2006-2020" severity="High" type="CVE"><desc><descript source="cve">Asterisk Recording Interface (ARI) in Asterisk@Home before 2.8 stores recordings/includes/main.conf under the web document root with insufficient access control, which allows remote attackers to obtain password information.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product releases:
Littlejohn Consulting, Asterisk Recording Interface, 0.10.00 and higher</sol></sols><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431655/100/0/threaded">20060421 [SecuriWeb 2006.1] directory traversal in Asterisk@Home and ARI</ref><ref source="SecuriWeb" url="http://www.securiweb.net/wiki/Ressources/AvisDeSecurite/2006.1">2006.1 - directory traversal in Asterisk@Home</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1457">ADV-2006-1457</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/24805">24805</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19744">19744</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25993">
asterisk-mail-disclose-information(25993)</ref></refs><vuln_soft><prod name="AsteriskatHome" vendor="AsteriskatHome"><vers num="2.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-21" modified="2006-04-26" name="CVE-2006-2021" published="2006-04-25" seq="2006-2021" severity="Medium" type="CVE"><desc><descript source="cve">Absolute path traversal vulnerability in recordings/misc/audio.php in the Asterisk Recording Interface (ARI) web interface in Asterisk@Home before 2.8 allows remote attackers to read arbitrary MP3, WAV, and GSM files via a full pathname in the recording parameter.  NOTE: this issue can also be used to determine existence of files.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Asterisk@Home, Asterisk@Home, 2.8
</sol></sols><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431655/100/0/threaded">20060421 [SecuriWeb 2006.1] directory traversal in Asterisk@Home and ARI</ref><ref source="SecuriWeb" url="http://www.securiweb.net/wiki/Ressources/AvisDeSecurite/2006.1">2006.1 - directory traversal in Asterisk@Home</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17641">17641</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1457">ADV-2006-1457</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/24805">24805</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19744">19744</ref><ref source="OSVDB" url="http://www.osvdb.org/24806">24806</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25996">
asterisk-audio-directory-traversal(25996)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/750">750</ref></refs><vuln_soft><prod name="AsteriskatHome" vendor="AsteriskatHome"><vers num="2.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-23" modified="2006-04-26" name="CVE-2006-2022" published="2006-04-25" seq="2006-2022" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the parse_url function in the RTSP module (rtsp/parse_url.c) in Fenice 1.10 and earlier allows remote attackers to execute arbitrary code via a long URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431870/100/0/threaded">20060423 Buffer-overflow and crash in Fenice OMS 1.10</ref><ref source="BID" url="http://www.securityfocus.com/bid/17678">17678</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19770">19770</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432002/100/0/threaded">20060425 Fenice - Open Media Streaming Server remote BOF exploit</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1491">ADV-2006-1491</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/436256/100/0/threaded">20060607 Re: Buffer-overflow and crash in Fenice OMS 1.10</ref><ref source="" url="http://aluigi.altervista.org/adv/fenicex-adv.txt"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26078">
fenice-parseurl-bo(26078)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/794">794</ref></refs><vuln_soft><prod name="Fenice" vendor="LS3"><vers num="1.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-23" modified="2006-04-26" name="CVE-2006-2023" published="2006-04-25" seq="2006-2023" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the RTSP_msg_len function in rtsp/RTSP_msg_len.c in Fenice 1.10 and earlier allows remote attackers to cause a denial of service (application crash) via a large HTTP Content-Length value, which leads to an invalid memory access.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431870/100/0/threaded">20060423 Buffer-overflow and crash in Fenice OMS 1.10</ref><ref source="BID" url="http://www.securityfocus.com/bid/17678">17678</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19770">19770</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1491">ADV-2006-1491</ref><ref source="OSVDB" url="http://www.osvdb.org/24882">24882</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/436256/100/0/threaded">20060607 Re: Buffer-overflow and crash in Fenice OMS 1.10</ref><ref source="" url="http://aluigi.altervista.org/adv/fenicex-adv.txt"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26080">
fenice-contentlength-dos(26080)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/794">794</ref></refs><vuln_soft><prod name="Fenice" vendor="LS3"><vers num="1.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-03" modified="2006-04-26" name="CVE-2006-2024" published="2006-04-25" seq="2006-2024" severity="Medium" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors in (1) the TIFFFetchAnyArray function in (a) tif_dirread.c; (2) certain &quot;codec cleanup methods&quot; in (b) tif_lzw.c, (c) tif_pixarlog.c, and (d) tif_zip.c; (3) and improper restoration of setfield and getfield methods in cleanup functions within (e) tif_jpeg.c, tif_pixarlog.c, (f) tif_fax3.c, and tif_zip.c.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
libTIFF, libTIFF, 3.8.1</sol></sols><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="Bugzilla" url="http://bugzilla.remotesensing.org/show_bug.cgi?id=1102">Bugzilla Bug 1102 </ref><ref patch="1" source="Bugzilla" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189933">Bugzilla Bug 189933</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1563">ADV-2006-1563</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19838">19838</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_28.html">SUSE-SR:2006:009</ref><ref source="BID" url="http://www.securityfocus.com/bid/17730">17730</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19851">19851</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19897">19897</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:082">MDKSA-2006:082</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-277-1">USN-277-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19936">19936</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19949">19949</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0024">2006-0024</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1054">DSA-1054</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19964">19964</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0425.html">RHSA-2006:0425</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20021">20021</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20023">20023</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-17.xml">GLSA-200605-17</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20345">20345</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-119.htm"></ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20667">
20667</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26133">
libtiff-tifffetchanyarray-dos(26133)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:082">MDKSA-2006:082</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103099-1">103099</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201332-1">201332</ref></refs><vuln_soft><prod name="libTIFF" vendor="libTIFF"><vers num="3.8.0" prev="1"/><vers num="3.7.1"/><vers num="3.7.0"/><vers num="3.6.1"/><vers num="3.6.0"/><vers num="3.5.7"/><vers num="3.5.6"/><vers num="3.5.5"/><vers num="3.5.4"/><vers num="3.5.3"/><vers num="3.5.2"/><vers num="3.5.1"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-2025" published="2006-04-25" seq="2006-2025" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the TIFFFetchData function in tif_dirread.c for libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a crafted TIFF image.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
libTIFF, libTIFF, 3.8.1</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="Bugzilla" url="http://bugzilla.remotesensing.org/show_bug.cgi?id=1102">Bugzilla Bug 1102 </ref><ref patch="1" source="Bugzilla" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189933"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17732">17732</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1563">ADV-2006-1563</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19838">19838</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_28.html">SUSE-SR:2006:009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19897">19897</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:082">MDKSA-2006:082</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-277-1">USN-277-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19936">19936</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19949">19949</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0024">2006-0024</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1054">DSA-1054</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19964">19964</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0425.html">RHSA-2006:0425</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20021">20021</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20023">20023</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-17.xml">GLSA-200605-17</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20345">20345</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-119.htm"></ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20667">
20667</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26134">
libtiff-tifffetchdata-overflow(26134)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:082">MDKSA-2006:082</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103099-1">103099</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201332-1">201332</ref></refs><vuln_soft><prod name="libTIFF" vendor="libTIFF"><vers num="3.8.0" prev="1"/><vers num="3.7.1"/><vers num="3.7.0"/><vers num="3.6.1"/><vers num="3.6.0"/><vers num="3.5.7"/><vers num="3.5.6"/><vers num="3.5.5"/><vers num="3.5.4"/><vers num="3.5.3"/><vers num="3.5.2"/><vers num="3.5.1"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-26" name="CVE-2006-2026" published="2006-04-25" seq="2006-2026" severity="Medium" type="CVE"><desc><descript source="cve">Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers errors related to &quot;setfield/getfield methods in cleanup functions.&quot;</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
libTIFF, libTIFF, 3.8.1</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Bugzilla" url="http://bugzilla.remotesensing.org/show_bug.cgi?id=1102">Bugzilla Bug 1102</ref><ref patch="1" source="Bugzilla" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189933">Bugzilla Bug 189933</ref><ref source="BID" url="http://www.securityfocus.com/bid/17733">17733</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1563">ADV-2006-1563</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19838">19838</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_28.html">SUSE-SR:2006:009</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19897">19897</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:082">MDKSA-2006:082</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-277-1">USN-277-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19936">19936</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19949">19949</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0024">2006-0024</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1054">DSA-1054</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19964">19964</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0425.html">RHSA-2006:0425</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20021">20021</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20023">20023</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-17.xml">GLSA-200605-17</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20345">20345</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-119.htm"></ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">20060501-01-U</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20210">20210</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20667">20667</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26135">libtiff-tifjpeg-doublefree-memory-corruption(26135)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:082">MDKSA-2006:082</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103099-1">103099</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201332-1">201332</ref></refs><vuln_soft><prod name="libTIFF" vendor="libTIFF"><vers num="3.8.0" prev="1"/><vers num="3.7.1"/><vers num="3.7.0"/><vers num="3.6.1"/><vers num="3.6.0"/><vers num="3.5.7"/><vers num="3.5.6"/><vers num="3.5.5"/><vers num="3.5.4"/><vers num="3.5.3"/><vers num="3.5.2"/><vers num="3.5.1"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-26" modified="2006-04-27" name="CVE-2006-2027" published="2006-04-25" seq="2006-2027" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Unicode processing in the logging functionality in Pablo Software Solutions Quick &apos;n Easy FTP Server Professional and Lite, probably 3.0, allows remote authenticated users to execute arbitrary code by sending a command with a long argument, which triggers a buffer overflow when an admin selects the Logging section in the FTP server main window.  NOTE: the original researcher claims that the vendor disputes this issue.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431920/100/0/threaded">20060424 Quick &apos;n Easy FTP Server pro/lite Logging unicode stack overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/17681">17681</ref><ref source="OSVDB" url="http://www.osvdb.org/25235">25235</ref><ref source="SREASON" url="http://securityreason.com/securityalert/788">788</ref></refs><vuln_soft><prod name="Quick &apos;n Easy FTP Server" vendor="Pablo Software Solutions"><vers edition="Professional" num="3.0"/><vers edition="Lite" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-11" name="CVE-2006-2028" published="2006-04-25" seq="2006-2028" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in imagelist.php in Jeremy Ashcraft Simplog 0.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the imagedir parameter.  NOTE: this issue might be resultant from directory traversal.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431760/100/0/threaded">20060421 Advisory: Simplog &lt;= 0.93 Multiple Remote Vulnerabilities.</ref><ref source="" url="http://www.nukedx.com/?getxpl=25"></ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0649.html">20060423 RE: Advisory: Simplog &lt;= 0.93 Multiple Remote Vulnerabilities.</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1493">ADV-2006-1493</ref><ref source="OSVDB" url="http://www.osvdb.org/24880">24880</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19764">19764</ref><ref source="BID" url="http://www.securityfocus.com/bid/17653">17653</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25984">
simplog-imagelist-xss(25984)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/799">799</ref></refs><vuln_soft><prod name="Simplog" vendor="Simplog"><vers num="0.9.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-11" name="CVE-2006-2029" published="2006-04-25" seq="2006-2029" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter in (a) preview.php; the (2) cid, (3) pid, and (4) eid parameters in (b) archive.php; and the (5) pid parameter in (c) comments.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431760/100/0/threaded">20060421 Advisory: Simplog &lt;= 0.93 Multiple Remote Vulnerabilities.</ref><ref source="" url="http://www.nukedx.com/?getxpl=25"></ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0649.html">20060423 RE: Advisory: Simplog &lt;= 0.93 Multiple Remote Vulnerabilities.</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1493">ADV-2006-1493</ref><ref source="OSVDB" url="http://www.osvdb.org/24877">24877</ref><ref source="OSVDB" url="http://www.osvdb.org/24878">24878</ref><ref source="OSVDB" url="http://www.osvdb.org/24879">24879</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015976">1015976</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19764">19764</ref><ref source="" url="http://www.simplog.org/archive.php?blogid=1&amp;pid=57"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25982">
simplog-multiple-sql-injection(25982)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/799">799</ref></refs><vuln_soft><prod name="Simplog" vendor="Simplog"><vers num="0.9.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-27" name="CVE-2006-2030" published="2006-04-25" seq="2006-2030" severity="Medium" type="CVE"><desc><descript source="cve">The Allied Telesyn AT-9724TS switch allows remote attackers to cause a denial of service via a large amount of UDP data to the switch, which leads to unstable operation and possibly failure of the management interface or routing.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431586/100/0/threaded">20060419 Allied Telesyn Switch UDP Data Flood Management Denial Of Service Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25938">
telesyn-udp-dos(25938)</ref></refs><vuln_soft><prod name="AT-9724TS" vendor="Allied Telesis"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-27" name="CVE-2006-2031" published="2006-04-25" seq="2006-2031" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin 2.8.0.3, 2.8.0.2, 2.8.1-dev, and 2.9.0-dev allows remote attackers to inject arbitrary web script or HTML via the lang parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/phpmyadmin-xss-vuln.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19659">19659</ref><ref source="" url="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2006-2"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25954">
phpmyadmin-index-xss(25954)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/phpmyadmin-xss-vuln.html"></ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.8.0.3"/><vers num="2.8.0.2"/><vers num="2.8.1 dev"/><vers num="2.9.0 dev"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-27" name="CVE-2006-2032" published="2006-04-25" seq="2006-2032" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Core CoreNews 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) icon_id and (2) userid parameters in preview.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431761/100/0/threaded">20060421 Advisory: CoreNews &lt;= 2.0.1 Multiple Remote Vulnerabilities.</ref><ref source="" url="http://www.nukedx.com/?getxpl=24"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17655">17655</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045372.html">
20060421 Advisory: CoreNews &lt;= 2.0.1 Multiple Remote Vulnerabilities.</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25977">
corenews-preview-sql-injection(25977)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/797">797</ref></refs><vuln_soft><prod name="CoreNews" vendor="CoreNews"><vers num="2.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-27" name="CVE-2006-2033" published="2006-04-25" seq="2006-2033" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in Core CoreNews 2.0.1 and earlier allows remote authenticated users to execute arbitrary commands via the show parameter.  NOTE: this is a different vector than CVE-2006-1212, although it might be the same primary issue.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431761/100/0/threaded">20060421 Advisory: CoreNews &lt;= 2.0.1 Multiple Remote Vulnerabilities.</ref><ref source="" url="http://www.nukedx.com/?getxpl=24"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17655">17655</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045372.html">
20060421 Advisory: CoreNews &lt;= 2.0.1 Multiple Remote Vulnerabilities.</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25979">
corenews-index-file-include(25979)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/797">797</ref></refs><vuln_soft><prod name="CoreNews" vendor="CoreNews"><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-27" name="CVE-2006-2034" published="2006-04-25" seq="2006-2034" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in function/showprofile.php in FlexBB 0.5.5 allows remote attackers to execute arbitrary SQL commands, and view all usernames and passwords, via the id parameter to the showprofile page in index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431793/100/0/threaded">20060421 FlexBB 0.5.5 Exploit [ function/showprofile.php ] Remote SQL Injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/17574">17574</ref><ref source="OSVDB" url="http://www.osvdb.org/24867">24867</ref></refs><vuln_soft><prod name="FlexBB" vendor="FlexBB"><vers num="0.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-27" name="CVE-2006-2035" published="2006-04-25" seq="2006-2035" severity="Low" type="CVE"><desc><descript source="cve">Websense, when configured to permit access to the dynamic content category, allows local users to bypass intended blocking of the Uncategorized category by appending a &quot;/?&quot; sequence to a URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431600/100/0/threaded">20060420 Websense Filter Bypass</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431685/100/0/threaded">20060421 RE: [BULK] - Websense Filter Bypass</ref><ref source="OSVDB" url="http://www.osvdb.org/25211">
25211</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25980">
websense-uncategorized-filter-bypass(25980)</ref></refs><vuln_soft><prod name="Websense" vendor="Websense"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-22" modified="2006-04-27" name="CVE-2006-2036" published="2006-04-25" seq="2006-2036" severity="Low" type="CVE"><desc><descript source="cve">iOpus Secure Email Attachments (SEA), probably 1.0, does not properly handle passwords that consist of repetitions of a substring, which allows attackers to decrypt files by entering only the substring.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431904/100/0/threaded">20060422 ADVISORY FOR IOPUS SECURE EMAIL ATTACHMENTS</ref><ref source="BID" url="http://www.securityfocus.com/bid/17656">17656</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/431989/100/0/threaded">20060425 Re: ADVISORY FOR IOPUS SECURE EMAIL ATTACHMENTS</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015980">1015980</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19771">19771</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26266">
iopus-insecure-passwords(26266)</ref></refs><vuln_soft><prod name="Secure Email Attachments" vendor="iOpus"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-20" modified="2006-04-27" name="CVE-2006-2037" published="2006-04-26" seq="2006-2037" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Thwboard 3.0 Beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the navpath parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431509/100/0/threaded">20060420 ThWboard 3 Beta 2.84 Cross Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/17627">17627</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25953">
thwboard-index-xss(25953)</ref></refs><vuln_soft><prod name="Thwboard" vendor="Thwboard"><vers num="3.0 Beta 2.84"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-27" name="CVE-2006-2038" published="2006-04-26" seq="2006-2038" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in ampleShop 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) RecordID parameter in (a) Customeraddresses_RecordAction.cfm and (b) youraccount.cfm; (2) solus parameter in (c) detail.cfm; and (3) cat parameter in (d) category.cfm.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/ampleshop-ecommerce-software-vuln.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19806">19806</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1512">ADV-2006-1512</ref><ref source="OSVDB" url="http://www.osvdb.org/24934">24934</ref><ref source="OSVDB" url="http://www.osvdb.org/24935">24935</ref><ref source="OSVDB" url="http://www.osvdb.org/24936">24936</ref><ref source="OSVDB" url="http://www.osvdb.org/24937">24937</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26064">
ampleshop-multiple-sql-injection(26064)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/ampleshop-ecommerce-software-vuln.html"></ref></refs><vuln_soft><prod name="ampleShop" vendor="Amplecom"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-05" name="CVE-2006-2039" published="2006-04-26" seq="2006-2039" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in the osTicket module in Help Center Live before 2.1.0 allow remote attackers to execute arbitrary SQL commands via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=411859"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17676">17676</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1492">ADV-2006-1492</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19776">19776</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26040">
helpcenterlive-osticket-sql-injection(26040)</ref></refs><vuln_soft><prod name="Help Center Live" vendor="UberTec"><vers num="2.0"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-25" modified="2006-04-27" name="CVE-2006-2040" published="2006-04-26" seq="2006-2040" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in photokorn 1.53 and 1.542 allow remote attackers to execute arbitrary SQL commands via the (1) cat, (2) pic and (3) page parameter in index.php; (4) id parameter in postcard.php; and (5) cat parameter in print.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431982/100/0/threaded">20060425 photokorn 1.53 , 1.542 &lt;&lt; Sql</ref><ref source="BID" url="http://www.securityfocus.com/bid/17683">17683</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1525">ADV-2006-1525</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19836">19836</ref><ref source="OSVDB" url="http://www.osvdb.org/24981">24981</ref><ref source="OSVDB" url="http://www.osvdb.org/24982">24982</ref><ref source="OSVDB" url="http://www.osvdb.org/24983">24983</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26066">photokorn-multiple-sql-injection(26066)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/789">789</ref></refs><vuln_soft><prod name="photokorn" vendor="photokorn"><vers num="1.53"/><vers num="1.542"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-27" name="CVE-2006-2041" published="2006-04-26" seq="2006-2041" severity="Medium" type="CVE"><desc><descript source="cve">PhpWebGallery before 1.6.0RC1 allows remote attackers to obtain arbitrary pictures via a request to picture.php without specifying the cat parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1515">ADV-2006-1515</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19801">19801</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26079">
phpwebgallery-picture-bypass-security(26079)</ref></refs><vuln_soft><prod name="PhpWebGallery" vendor="PhpWebGallery"><vers num="1.5.1"/><vers num="1.4.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-10" name="CVE-2006-2042" published="2006-05-09" seq="2006-2042" severity="High" type="CVE"><desc><descript source="cve">Adobe Dreamweaver 8 before 8.0.2 and MX 2004 can generate code that allows SQL injection attacks in the (1) ColdFusion, (2) PHP mySQL, (3) ASP, (4) ASP.NET, and (5) JSP server models.</descript></desc><sols><sol source="nvd">This vulnerability affects all versions of Adobe, Dreamweaver, 8.0 before 8.0.2
This vulnerability is addressed in the following product releases:
Adobe, Dreamweaver, 8.0.2
Code update for Macromedia, Dreamweaver MX, 2004</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ADOBE" url="http://www.adobe.com/support/security/bulletins/apsb06-07.html">APSB06-07</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-05/0194.html">20060509 Multiple SQL Injection Vulnerabilities in Dreamweaver Generated Code</ref><ref source="BID" url="http://www.securityfocus.com/bid/17928">17928</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1753">ADV-2006-1753</ref><ref source="OSVDB" url="http://www.osvdb.org/25361">25361</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016050">1016050</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20054">20054</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26339">dreamweaver-server-sql-injection(26339)</ref></refs><vuln_soft><prod name="Dreamweaver MX" vendor="Adobe"><vers num="2004"/></prod><prod name="Dreamweaver" vendor="Adobe"><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-24" modified="2006-04-27" name="CVE-2006-2043" published="2006-04-26" seq="2006-2043" severity="Medium" type="CVE"><desc><descript source="cve">na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 allows local users to gain Unix shell access via &quot;`&quot; (backtick) characters in the appliance&apos;s command line interface (CLI).</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432007/100/0/threaded">20060424 Multiple vulnerabilities in IP3 Networks &apos;NetAccess&apos; NA75 appliance</ref><ref source="BID" url="http://www.securityfocus.com/bid/17698">17698</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1540">ADV-2006-1540</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19818">19818</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26108">
ip3-na75-backtick-command-injection(26108)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/793">793</ref></refs><vuln_soft><prod name="IP3 NetAccess 75" vendor="IP3 Networks"><vers num="4.0.34"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-24" modified="2006-04-27" name="CVE-2006-2044" published="2006-04-26" seq="2006-2044" severity="High" type="CVE"><desc><descript source="cve">na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 has a default username of admin and a default password of admin.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432007/100/0/threaded">20060424 Multiple vulnerabilities in IP3 Networks &apos;NetAccess&apos; NA75 appliance</ref><ref source="BID" url="http://www.securityfocus.com/bid/17698">17698</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1540">ADV-2006-1540</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19818">19818</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26112">
ip3-na75-default-account(26112)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/793">793</ref></refs><vuln_soft><prod name="IP3 NetAccess 75" vendor="IP3 Networks"><vers num="4.0.34"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-2045" published="2006-04-26" seq="2006-2045" severity="Low" type="CVE"><desc><descript source="cve">The (1) shadow password file in na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 has world readable permissions, which allows local users to view encrypted passwords; and the (2) NetAccess database file has world readable and writable permissions, which allows local users to view sensitive information and modify data.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432007/100/0/threaded">20060424 Multiple vulnerabilities in IP3 Networks &apos;NetAccess&apos; NA75 appliance</ref><ref source="BID" url="http://www.securityfocus.com/bid/17698">17698</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1540">ADV-2006-1540</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19818">19818</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26110">
ip3-na75-database-file-permission(26110)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26109">
ip3-na75-shadow-file-permission(26109)</ref></refs><vuln_soft><prod name="IP3 NetAccess 75" vendor="IP3 Networks"><vers num="4.0.34 firmware"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-27" name="CVE-2006-2046" published="2006-04-26" seq="2006-2046" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) keywords parameters in (a) Results.cfm, and the (3) ProdID parameter in (b) Details.cfm.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/cartweaver-coldfusion-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1513">ADV-2006-1513</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19812">19812</ref><ref source="OSVDB" url="http://www.osvdb.org/24961">24961</ref><ref source="OSVDB" url="http://www.osvdb.org/24962">24962</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26060">cartweaver-multiple-sql-injection(26060)</ref><ref source="BID" url="http://www.securityfocus.com/bid/17941">
17941</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4264">4264</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/cartweaver-coldfusion-vuln.html"></ref><ref source="" url="http://www.techfeed.net/blog/index.cfm/2006/4/26/cartweaver-holes"></ref><ref source="BID" url="http://www.securityfocus.com/bid/25210">25210</ref></refs><vuln_soft><prod name="Cartweaver ColdFusion" vendor="Application Dynamics"><vers num="2.16.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-25" modified="2006-04-27" name="CVE-2006-2047" published="2006-04-26" seq="2006-2047" severity="Medium" type="CVE"><desc><descript source="cve">Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allows remote attackers to obtain sensitive information via an invalid (1) secondary, (2) PageNum_Results, (3) category, or (4) keywords parameter in (a) Results.cfm; or an invalid (5) ProdID parameter in (b) Details.cfm; which reveal the path in various error messages. NOTE: the behavior for the category, keywords, and ProdID parameters might be resultant from SQL injection.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/cartweaver-coldfusion-vuln.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19812">19812</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1513">ADV-2006-1513</ref><ref source="OSVDB" url="http://www.osvdb.org/24963">24963</ref><ref source="OSVDB" url="http://www.osvdb.org/24964">24964</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26061">cartweaver-multiple-path-disclosure(26061)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/cartweaver-coldfusion-vuln.html"></ref></refs><vuln_soft><prod name="Cartweaver ColdFusion" vendor="Application Dynamics"><vers num="2.16.11"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-25" modified="2006-04-27" name="CVE-2006-2048" published="2006-04-26" seq="2006-2048" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in Edwin van Wijk phpWebFTP 2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) port, (2) server, and (3) user parameters.  NOTE: it is possible that the affected version is actually 3.2.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431985/100/0/threaded">20060425 PhpWebFtp Cross Site Scripting Vulnerability</ref><ref source="" url="http://www.subjectzero.net/research/phpwebftpxss.htm"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17688">17688</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1530">ADV-2006-1530</ref><ref source="OSVDB" url="http://www.osvdb.org/24975">24975</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19827">19827</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26067">
phpwebftp-index-xss(26067)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/786">786</ref></refs><vuln_soft><prod name="phpWebFTP" vendor="phpWebFTP"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-25" modified="2006-04-27" name="CVE-2006-2049" published="2006-04-26" seq="2006-2049" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in dcboard.cgi in DCScripts DCForumLite 3.0 allows remote attackers to inject arbitrary web script or HTML via the az parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432010/100/0/threaded">20060425 DCForumLite V 3.0&lt;--XSS/SQL Injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/17697">17697</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1532">ADV-2006-1532</ref><ref source="OSVDB" url="http://www.osvdb.org/24988">24988</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19815">19815</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26083">
dcforumlite-dcboard-xss(26083)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/792">792</ref></refs><vuln_soft><prod name="DCForumLite" vendor="DCScripts"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-25" modified="2006-04-27" name="CVE-2006-2050" published="2006-04-26" seq="2006-2050" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in dcboard.cgi in DCScripts DCForumLite 3.0 allows remote attackers to execute arbitrary SQL commands via the az parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432010/100/0/threaded">20060425 DCForumLite V 3.0&lt;--XSS/SQL Injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/17697">17697</ref><ref source="OSVDB" url="http://www.osvdb.org/24989">24989</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26084">
deforumlite-dcboard-sql-injection(26084)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/792">792</ref></refs><vuln_soft><prod name="DCForumLite" vendor="DCScripts"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-25" modified="2006-04-27" name="CVE-2006-2051" published="2006-04-26" seq="2006-2051" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in myadmin/index.php in NextAge Shopping Cart allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password parameters.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431983/100/0/threaded">20060425 NextAge Shopping Cart Software</ref><ref adv="1" source="" url="http://www.aria-security.net/advisory/nextage/nextageshoppingcart.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17685">17685</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26065">
nextageshoppingcart-index-xss(26065)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/791">791</ref></refs><vuln_soft><prod name="NextAge Shopping Cart" vendor="NextAge"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-25" modified="2006-05-03" name="CVE-2006-2052" published="2006-04-26" seq="2006-2052" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Verosky Media Instant Photo Gallery allows remote attackers to inject arbitrary web script or HTML via the member parameter in a viewpro action in member.php. NOTE: the original report may be inaccurate, since the &quot;viewpro&quot; string does not appear in the source code for version 1.0.2 of the product.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432022/100/0/threaded">20060425 Instant Photo Gallery &lt;= Multiple XSS</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432241/100/0/threaded">20060427 Re: Instant Photo Gallery &lt;= Multiple XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/17696">17696</ref><ref source="OSVDB" url="http://www.osvdb.org/24984">24984</ref><ref source="SREASON" url="http://securityreason.com/securityalert/790">790</ref></refs><vuln_soft><prod name="Instant Photo Gallery" vendor="Verosky Media"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-25" modified="2006-04-27" name="CVE-2006-2053" published="2006-04-26" seq="2006-2053" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in QuickEStore 7.9 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the OrderID parameter in (a) shipping.cfm and (b) checkout.cfm, (2) ItemID parameter in (c) proddetail.cfm, (3) SubCatID parameter in (d) index.cfm, the (4) CategoryID parameter in (e) prodpage.cfm, and (5) ProdID parameter in (f) Details.cfm.  NOTE: these issues can also be exploited for path disclosure.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/quickestore-79-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1514">ADV-2006-1514</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19817">19817</ref><ref source="OSVDB" url="http://www.osvdb.org/24976">24976</ref><ref source="OSVDB" url="http://www.osvdb.org/24977">24977</ref><ref source="OSVDB" url="http://www.osvdb.org/24978">24978</ref><ref source="OSVDB" url="http://www.osvdb.org/24979">24979</ref><ref source="OSVDB" url="http://www.osvdb.org/24980">24980</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26045">
quickestore-multiple-sql-injection(26045)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/quickestore-79-vuln.html"></ref></refs><vuln_soft><prod name="QuickEStore" vendor="QuickEStore"><vers num="7.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-27" name="CVE-2006-2054" published="2006-04-26" seq="2006-2054" severity="Medium" type="CVE"><desc><descript source="cve">3Com Baseline Switch 2848-SFP Plus Model #3C16486 with firmware before 1.0.2.0 allows remote attackers to cause a denial of service (unstable operation) via long DHCP packets.</descript></desc><sols><sol source="nvd">Update to firmware version 1.0.2.0.
http://www.3com.com/products/en_...e&amp;order=desc&amp;prodcat=all</sol></sols><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://support.3com.com/infodeli/tools/switches/baseline/3C16486_V1_0_2_0_readme.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17686">17686</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1510">ADV-2006-1510</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19756">19756</ref><ref source="OSVDB" url="http://www.osvdb.org/24942">24942</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015997">1015997</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26076">3com-baseline-dhcp-dos(26076)</ref></refs><vuln_soft><prod name="Baseline Switch 2848-SFP Plus" vendor="3Com"><vers num="1.0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-08-13" name="CVE-2006-2055" published="2006-04-26" seq="2006-2055" severity="Medium" type="CVE"><desc><descript source="cve">Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via &quot; (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment.  NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://ingehenriksen.blogspot.com/2006/04/office-2003-file-attachment-exploit.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19819">19819</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1538">ADV-2006-1538</ref><ref source="OSVDB" url="http://www.osvdb.org/25003">25003</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26118">office-mailto-obtain-information(26118)</ref></refs><vuln_soft><prod name="Outlook" vendor="Microsoft"><vers num="2003 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-2056" published="2006-04-26" seq="2006-2056" severity="Medium" type="CVE"><desc><descript source="cve">Argument injection vulnerability in Internet Explorer 6 for Windows XP SP2 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via &quot; (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment.  NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://ingehenriksen.blogspot.com/2006/04/office-2003-file-attachment-exploit.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1538">
ADV-2006-1538</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26118">
office-mailto-obtain-information(26118)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows XP SP2" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-24" modified="2006-08-28" name="CVE-2006-2057" published="2006-04-26" seq="2006-2057" severity="Medium" type="CVE"><desc><descript source="cve">Argument injection vulnerability in Mozilla Firefox 1.0.6 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via &quot; (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment.  NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432009/100/0/threaded">20060424 Multiple browsers Windows mailto protocol Office 2003 file attachment exploit</ref><ref source="" url="http://ingehenriksen.blogspot.com/2006/04/office-2003-file-attachment-exploit.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1538">
ADV-2006-1538</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26118">
office-mailto-obtain-information(26118)</ref></refs><vuln_soft><prod name="Avant Browser" vendor="Avant Force"><vers num="10.1 Build 17"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="2003 SP1"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0 SP2"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-20" name="CVE-2006-2058" published="2006-04-26" seq="2006-2058" severity="Medium" type="CVE"><desc><descript source="cve">Argument injection vulnerability in Avant Browser 10.1 Build 17 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via &quot; (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment.  NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432009/100/0/threaded">20060424 Multiple browsers Windows mailto protocol Office 2003 file attachment exploit</ref><ref source="" url="http://ingehenriksen.blogspot.com/2006/04/office-2003-file-attachment-exploit.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1538">
ADV-2006-1538</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26118">
office-mailto-obtain-information(26118)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/785">785</ref></refs><vuln_soft><prod name="Avant Browser" vendor="Avant Force"><vers num="10.1 Build 17"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-27" name="CVE-2006-2059" published="2006-04-26" seq="2006-2059" severity="Medium" type="CVE"><desc><descript source="cve">action_public/search.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary PHP code via a search with a crafted value of the lastdate parameter, which alters the behavior of a regular expression to add a &quot;#e&quot; (execute) modifier.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431990/100/0/threaded">20060425 Invision Vulnerabilities, including remote code execution</ref><ref patch="1" source="" url="http://forums.invisionpower.com/index.php?showtopic=213374"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17695">17695</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432226/100/0/threaded">20060427 Re: Invision Vulnerabilities, including remote code execution</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1534">ADV-2006-1534</ref><ref source="OSVDB" url="http://www.osvdb.org/25005">25005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19830">19830</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432451/100/0/threaded">20060427 Invision Power Board 2.1.5 POC</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/439607/100/0/threaded">20060710 Re: RE: Invision Vulnerabilities, including remote code execution</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26070">
invision-search-file-include(26070)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/796">796</ref></refs><vuln_soft><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.1.5 2006-03-08"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-27" name="CVE-2006-2060" published="2006-04-26" seq="2006-2060" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in action_admin/paysubscriptions.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote authenticated administrators to include and execute arbitrary local PHP files via a .. (dot dot) in the name parameter, preceded by enough backspace (%08) characters to erase the initial static portion of a filename.</descript></desc><sols><sol source="nvd">If you&apos;ve downloaded IPB 2.1.5 since the time of this post, there is no need to update your installation as the main download has been updated.</sol></sols><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431990/100/0/threaded">20060425 Invision Vulnerabilities, including remote code execution</ref><ref patch="1" source="" url="http://forums.invisionpower.com/index.php?showtopic=213374"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432226/100/0/threaded">20060427 Re: Invision Vulnerabilities, including remote code execution</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1534">ADV-2006-1534</ref><ref source="OSVDB" url="http://www.osvdb.org/25008">25008</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19830">19830</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/439607/100/0/threaded">20060710 Re: RE: Invision Vulnerabilities, including remote code execution</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26072">
invision-admin-file-include(26072)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/796">796</ref></refs><vuln_soft><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.1.x"/><vers num="2.0.x"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-27" name="CVE-2006-2061" published="2006-04-26" seq="2006-2061" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary SQL commands via the ck parameter, which can inject at most 32 characters.</descript></desc><sols><sol source="nvd">The vendor has released an update to address this and other versions.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431990/100/0/threaded">20060425 Invision Vulnerabilities, including remote code execution</ref><ref source="" url="http://forums.invisionpower.com/index.php?showtopic=213374"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17690">17690</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432226/100/0/threaded">20060427 Re: Invision Vulnerabilities, including remote code execution</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1534">ADV-2006-1534</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19830">19830</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26071">
invision-index-ck-sql-injection(26071)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/796">796</ref></refs><vuln_soft><prod name="Invision Board" vendor="Invision Power Services"><vers num="2.1.5"/><vers num="2.1 Alpha2"/><vers num="2.1"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0 PF2"/><vers num="2.0 PF1"/><vers num="2.0 PDR3"/><vers num="2.0 Alpha 3"/><vers num="2.0"/></prod><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.1.5 2006-03-08"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" discovered="2006-04-18" modified="2007-01-05" name="CVE-2006-2062" published="2006-04-26" seq="2006-2062" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Leadhound Full and LITE 2.1, and probably the Network Version &quot;Full Version&quot;, allow remote attackers to execute arbitrary SQL commands via the (1) banner parameter in agent_links.pl; the offset parameter in (2) agent_links.pl, (3) agent_transactions.pl, (4) agent_subaffiliates.pl, and (5) agent_summary.pl; the camp_id parameter in (6) agent_transactions_csv.pl, (7) agent_subaffiliates.pl, and (8) agent_camp_det.pl; the (9) login parameter in agent_commission_statement.pl; the logged parameter in (10) agent_commission_statement.pl and (11) agent_camp_det.pl; the (12) agent_id parameter in agent_commission_statement.pl; and the (13) sub parameter in unspecified files.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Blogspot" url="http://pridels.blogspot.com/2006/04/leadhound-multiple-vuln.html">Leadhound multiple vuln</ref><ref source="OSVDB" url="http://www.osvdb.org/25023">25023</ref><ref source="OSVDB" url="http://www.osvdb.org/25024">25024</ref><ref source="OSVDB" url="http://www.osvdb.org/25025">25025</ref><ref source="OSVDB" url="http://www.osvdb.org/25026">25026</ref><ref source="OSVDB" url="http://www.osvdb.org/25027">25027</ref><ref source="OSVDB" url="http://www.osvdb.org/25028">25028</ref><ref source="OSVDB" url="http://www.osvdb.org/25029">25029</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19867">19867</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/leadhound-multiple-vuln.html"></ref></refs><vuln_soft><prod name="Leadhound Full" vendor="Leadhound Network"><vers num="2.1"/><vers num="2.1 Network Version"/></prod><prod name="Leadhound Lite" vendor="Leadhound Network"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-04-18" modified="2007-01-05" name="CVE-2006-2063" published="2006-04-26" seq="2006-2063" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Leadhound Full and LITE 2.1, and probably the Network Version &quot;Full Version&quot;, allow remote attackers to inject arbitrary web script or HTML via the login parameter in (1) agent_affil.pl, (2) agent_help.pl, (3) agent_faq.pl, (4) agent_help_insert.pl, (5) sign_out.pl, (6) members.pl, (7) modify_agent_1.pl, (8) modify_agent_2.pl, (9) modify_agent.pl, (10) agent_links.pl, (11) agent_stats_pending_leads.pl, (12) agent_logoff.pl, (13) agent_rev_det.pl, (14) agent_subaffiliates.pl, (15) agent_stats_pending_leads.pl, (16) agent_transactions.pl, (17) agent_payment_history.pl, (18) agent_summary.pl, (19) agent_camp_all.pl, (20) agent_camp_new.pl, (21) agent_camp_notsub.pl, (22) agent_campaign.pl, (23) agent_camp_expired.pl, (24) agent_stats_det.pl, (25) agent_stats.pl, (26) agent_camp_det.pl, (27) agent_camp_sub.pl, (28) agent_affil_list.pl, and (29) agent_affil_code.pl; the logged parameter in (30) agent_faq.pl, (31) agent_help_insert.pl, (32) members.pl, (33) modify_agent_1.pl, (34) modify_agent_2.pl, (35) modify_agent.pl, (36) agent_links.pl, (37) agent_subaffiliates.pl, (38) agent_stats_pending_leads.pl, (39) agent_transactions.pl, (40) agent_summary.pl, (41) agent_camp_all.pl, (42) agent_camp_new.pl, (43) agent_camp_notsub.pl, (44) agent_campaign.pl, (45) agent_camp_expired.pl, (46) agent_stats.pl, (47) agent_camp_det.pl, (48) agent_camp_sub.pl, (49) agent_affil_list.pl, and (50) agent_affil_code.pl; the camp_id parameter in (51) agent_links.pl, (52) agent_subaffiliates.pl, and (53) agent_camp_det.pl; the (54) banner parameter in agent_links.pl; the offset parameter in (55) agent_links.pl, (56) agent_subaffiliates.pl, (57) agent_transactions.pl, and (58) agent_summary.pl; the date parameter in (59) agent_subaffiliates.pl, (60) agent_transactions.pl, and (61) agent_summary.pl; the dates parameter in (62) agent_rev_det.pl and (63) agent_stats_det.pl; the (64) page parameter in agent_camp_det.pl; the (65) agent_id parameter in agent_commission_statement.pl; and the (66) lost password field in lost_pwd.pl.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Blogspot" url="http://pridels.blogspot.com/2006/04/leadhound-multiple-vuln.html">Leadhound multiple vuln.</ref><ref source="OSVDB" url="http://www.osvdb.org/25030">25030</ref><ref source="OSVDB" url="http://www.osvdb.org/25032">25032</ref><ref source="OSVDB" url="http://www.osvdb.org/25033">25033</ref><ref source="OSVDB" url="http://www.osvdb.org/25034">25034</ref><ref source="OSVDB" url="http://www.osvdb.org/25035">25035</ref><ref source="OSVDB" url="http://www.osvdb.org/25036">25036</ref><ref source="OSVDB" url="http://www.osvdb.org/25038">25038</ref><ref source="OSVDB" url="http://www.osvdb.org/25039">25039</ref><ref source="OSVDB" url="http://www.osvdb.org/25041">25041</ref><ref source="OSVDB" url="http://www.osvdb.org/25042">25042</ref><ref source="OSVDB" url="http://www.osvdb.org/25043">25043</ref><ref source="OSVDB" url="http://www.osvdb.org/25044">25044</ref><ref source="OSVDB" url="http://www.osvdb.org/25045">25045</ref><ref source="OSVDB" url="http://www.osvdb.org/25046">25046</ref><ref source="OSVDB" url="http://www.osvdb.org/25047">25047</ref><ref source="OSVDB" url="http://www.osvdb.org/25048">25048</ref><ref source="OSVDB" url="http://www.osvdb.org/25049">25049</ref><ref source="OSVDB" url="http://www.osvdb.org/25050">25050</ref><ref source="OSVDB" url="http://www.osvdb.org/25051">25051</ref><ref source="OSVDB" url="http://www.osvdb.org/25052">25052</ref><ref source="OSVDB" url="http://www.osvdb.org/25053">25053</ref><ref source="OSVDB" url="http://www.osvdb.org/25054">25054</ref><ref source="OSVDB" url="http://www.osvdb.org/25055">25055</ref><ref source="OSVDB" url="http://www.osvdb.org/25056">25056</ref><ref source="OSVDB" url="http://www.osvdb.org/25057">25057</ref><ref source="OSVDB" url="http://www.osvdb.org/25058">25058</ref><ref source="OSVDB" url="http://www.osvdb.org/25059">25059</ref><ref source="OSVDB" url="http://www.osvdb.org/25060">25060</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19867">19867</ref><ref source="OSVDB" url="http://www.osvdb.org/25031">25031</ref><ref source="OSVDB" url="http://www.osvdb.org/25037">25037</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/leadhound-multiple-vuln.html"></ref></refs><vuln_soft><prod name="Leadhound Full" vendor="Leadhound Network"><vers num="2.1 Network Version"/><vers num="2.1"/></prod><prod name="Leadhound Lite" vendor="Leadhound Network"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-2064" published="2006-04-27" seq="2006-2064" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the libpkcs11 library in Sun Solaris 10 might allow local users to gain privileges or cause a denial of service (application failure) via unknown attack vectors that involve the getpwnam family of non-reentrant functions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102316-1">102316</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17687">17687</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1504">ADV-2006-1504</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015987">1015987</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19789">19789</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26075">
solaris-libpkcs11-privilege-escalation(26075)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="10.0"/><vers edition="x86" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-30" name="CVE-2006-2065" published="2006-04-27" seq="2006-2065" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in save.php in PHPSurveyor 0.995 and earlier allows remote attackers to execute arbitrary SQL commands via the surveyid cookie.  NOTE: this issue could be leveraged to execute arbitrary PHP code, as demonstrated by inserting directory traversal sequences into the database, which are then processed by the thissurvey[&apos;language&apos;] variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://retrogod.altervista.org/phpsurveyor_0995_xpl.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015970">1015970</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19761">19761</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431508/100/0/threaded">20060420 PHPSurveyor &lt;= 0.995 %27save.php/surveyid%27 remote cmmnds xctn</ref><ref source="BID" url="http://www.securityfocus.com/bid/17633">17633</ref><ref source="OSVDB" url="http://www.osvdb.org/24787">24787</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25970">
phpsurveyor-surveyid-shell-execution(25970)</ref></refs><vuln_soft><prod name="PHPSurveyor" vendor="PHPSurveyor"><vers num="0.995"/><vers num="0.993"/><vers num="0.992"/><vers num="0.991"/><vers num="0.99"/><vers num="0.98 stable"/><vers num="0.98 Beta"/><vers num="0.97 Beta"/><vers num="0.96 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-21" modified="2006-10-04" name="CVE-2006-2066" published="2006-04-27" seq="2006-2066" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities pm_popup.php in MKPortal 1.1 Rc1 and earlier, as used with vBulletin 3.5.4 and earlier, allow remote attackers to inject arbitary web script or HTML via the (1) u1, (2) m1, (3) m2, (4) m3, (5) m4 parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431759/100/0/threaded">20060421 vBulletin &lt;= 3.5.4 with MKPortal 1.1 Remote SQL Injection Vulnerability.</ref><ref adv="1" source="" url="http://www.nukedx.com/?viewdoc=26"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1485">ADV-2006-1485</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015977">1015977</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19786">19786</ref><ref source="BID" url="http://www.securityfocus.com/bid/17651">17651</ref><ref source="OSVDB" url="http://www.osvdb.org/24901">24901</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/447195/100/0/threaded">20060927 MkPortal Cross Site Scripting (All versions) xSS</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/447303/100/0/threaded">20060928 Re: xxs in MKPortal M1.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/20232">20232</ref><ref source="SREASON" url="http://securityreason.com/securityalert/801">801</ref></refs><vuln_soft><prod name="MKPortal" vendor="MKPortal"><vers num="1.1 RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-21" modified="2006-04-28" name="CVE-2006-2067" published="2006-04-27" seq="2006-2067" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in vb_board_functions.php in MKPortal 1.1, as used with vBulletin 3.5.4 and earlier, allows remote attackers to execute arbitrary SQL commands via the userid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431759/100/0/threaded">20060421 vBulletin &lt;= 3.5.4 with MKPortal 1.1 Remote SQL Injection Vulnerability.</ref><ref adv="1" source="" url="http://www.nukedx.com/?viewdoc=26"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015977">1015977</ref><ref source="BID" url="http://www.securityfocus.com/bid/17651">17651</ref><ref source="SREASON" url="http://securityreason.com/securityalert/801">801</ref></refs><vuln_soft><prod name="MKPortal" vendor="MKPortal"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-2068" published="2006-04-27" seq="2006-2068" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Hitachi JP1 products allow remote attackers to cause a denial of service (application stop or fail) via unexpected requests or data.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS06-007_e/index-e.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1524">ADV-2006-1524</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19841">19841</ref><ref source="BID" url="http://www.securityfocus.com/bid/17706">17706</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26087">
hitachi-jp1-request-dos(26087)</ref></refs><vuln_soft><prod name="JP1-Cm2-Network Node Manager" vendor="Hitachi"><vers edition="Enterprise" num="05_20" prev="1"/></prod><prod name="JPI Security Integrated Manager" vendor="Hitachi"><vers num=""/></prod><prod name="JP1-Cm2-Network Node Manager 250" vendor="Hitachi"><vers num="05_20"/><vers num="06_00"/></prod><prod name="JPI Performance Management" vendor="Hitachi"><vers num=""/></prod><prod name="JPI Server Conductor Server Manager" vendor="Hitachi"><vers num=""/></prod><prod name="JPI PFM SNMP System Observer" vendor="Hitachi"><vers num=""/></prod><prod name="JPI Automatic Job Management System 2" vendor="Hitachi"><vers num=""/><vers edition="Agent" num=""/></prod><prod name="JPI Server System Observer - Report Feature" vendor="Hitachi"><vers num=""/></prod><prod name="JPI Server Conductor Blade Server Manager" vendor="Hitachi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-08-13" name="CVE-2006-2069" published="2006-04-27" seq="2006-2069" severity="Medium" type="CVE"><desc><descript source="cve">The recursor in PowerDNS before 3.0.1 allows remote attackers to cause a denial of service (application crash) via malformed EDNS0 packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://doc.powerdns.com/changelog.html#CHANGELOG-RECURSOR-3-0-1"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1527">ADV-2006-1527</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19831">19831</ref><ref source="BID" url="http://www.securityfocus.com/bid/17711">17711</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html">SUSE-SR:2006:010</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20117">20117</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26100">powerdns-recursor-ednso-dos(26100)</ref></refs><vuln_soft><prod name="PowerDNS" vendor="PowerDNS"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-2070" published="2006-04-27" seq="2006-2070" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in member.php in DevBB 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the member parameter in a viewpro action.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432096/100/0/threaded">20060426 DevBB &lt;= 1.0.0 XSS</ref><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/DevBB-1.0.0-xss.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17703">17703</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1544">ADV-2006-1544</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19855">19855</ref><ref source="OSVDB" url="http://www.osvdb.org/24994">24994</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26091">
devbb-member-xss(26091)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/800">800</ref></refs><vuln_soft><prod name="DevBB" vendor="MyBB"><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-2071" published="2006-04-27" seq="2006-2071" severity="Low" type="CVE"><desc><descript source="cve">Linux kernel 2.4.x and 2.6.x up to 2.6.16 allows local users to bypass IPC permissions and modify a readonly attachment of shared memory by using mprotect to give write permission to the attachment.  NOTE: some original raw sources combined this issue with CVE-2006-1524, but they are different bugs.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.6"></ref><ref source="" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=b78b6af66a5fbaf17d7e6bfc32384df5e34408c8"></ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=190073"></ref><ref source="OSVDB" url="http://www.osvdb.org/24714">24714</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:086">MDKSA-2006:086</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20157">20157</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-302-1">USN-302-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20716">20716</ref><ref source="OSVDB" url="http://www.osvdb.org/25139">25139</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0579.html">RHSA-2006:0579</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0580.html">RHSA-2006:0580</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21035">21035</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0689.html">RHSA-2006:0689</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22292">22292</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0710.html">RHSA-2006:0710</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22497">22497</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451404/100/0/threaded">20061113 VMSA-2006-0006 - VMware ESX Server 2.5.3 Upgrade Patch 4</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-249.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/22945">22945</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451419/100/200/threaded">20061113 VMSA-2006-0005 - VMware ESX Server 2.5.4 Upgrade Patch 1</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451417/100/200/threaded">20061113 VMSA-2006-0007 - VMware ESX Server 2.1.3 Upgrade Patch 2</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451426/100/200/threaded">20061113 VMSA-2006-0008 - VMware ESX Server 2.0.2 Upgrade Patch 2</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-254.htm"></ref><ref source="" url="http://www.vmware.com/download/esx/esx-202-200610-patch.html"></ref><ref source="" url="http://www.vmware.com/download/esx/esx-213-200610-patch.html"></ref><ref source="" url="http://www.vmware.com/download/esx/esx-254-200610-patch.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4502">ADV-2006-4502</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22875">22875</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23064">23064</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1391">
ADV-2006-1391</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26169">
linux-mprotect-security-bypass(26169)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:086">MDKSA-2006:086</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.16"/><vers num="2.6.15.5"/><vers num="2.6.15.4"/><vers num="2.6.15.3"/><vers num="2.6.15.2"/><vers num="2.6.15.1"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.15"/><vers num="2.6.14.5"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.14"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13-rc7"/><vers num="2.6.13-rc6"/><vers num="2.6.13-rc4"/><vers num="2.6.13-rc1"/><vers num="2.6.13"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12-rc5"/><vers num="2.6.12-rc4"/><vers num="2.6.12-rc1"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11-rc4"/><vers num="2.6.11-rc3"/><vers num="2.6.11-rc2"/><vers num="2.6.11"/><vers num="2.6.10-rc2"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1-rc2"/><vers num="2.6.1-rc1"/><vers num="2.6.1"/><vers num="2.6 test 9 CVS"/><vers num="2.6-test9"/><vers num="2.6-test8"/><vers num="2.6-test7"/><vers num="2.6-test6"/><vers num="2.6-test5"/><vers num="2.6-test4"/><vers num="2.6-test3"/><vers num="2.6-test2"/><vers num="2.6-test11"/><vers num="2.6-test10"/><vers num="2.6-test1"/><vers num="2.6"/><vers num="2.4.33-pre1"/><vers num="2.4.32-pre2"/><vers num="2.4.32-pre1"/><vers num="2.4.32"/><vers num="2.4.31-pre1"/><vers num="2.4.31"/><vers num="2.4.30-rc3"/><vers num="2.4.30-rc2"/><vers num="2.4.30"/><vers num="2.4.29-rc2"/><vers num="2.4.29-rc1"/><vers num="2.4.29"/><vers num="2.4.28"/><vers num="2.4.27-pre5"/><vers num="2.4.27-pre4"/><vers num="2.4.27-pre3"/><vers num="2.4.27-pre2"/><vers num="2.4.27-pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24-ow1"/><vers num="2.4.24"/><vers num="2.4.23-pre9"/><vers num="2.4.23-ow2"/><vers num="2.4.23"/><vers num="2.4.22"/><vers num="2.4.21-pre7"/><vers num="2.4.21-pre4"/><vers num="2.4.21-pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.19-pre6"/><vers num="2.4.19-pre5"/><vers num="2.4.19-pre4"/><vers num="2.4.19-pre3"/><vers num="2.4.19-pre2"/><vers num="2.4.19-pre1"/><vers num="2.4.19"/><vers num="2.4.18-pre-8"/><vers num="2.4.18-pre-7"/><vers num="2.4.18-pre-6"/><vers num="2.4.18-pre-5"/><vers num="2.4.18-pre-4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3"/><vers num="2.4.2"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-2072" published="2006-04-27" seq="2006-2072" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in DeleGate 9.x before 9.0.6 and 8.x before 8.11.6 allow remote attackers to cause a denial of service via crafted DNS responses messages that cause (1) a buffer over-read or (2) infinite recursion, which can trigger a segmentation fault or invalid memory access, as demonstrated by the OUSPG PROTOS DNS test suite.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="" url="http://www.niscc.gov.uk/niscc/docs/re-20060425-00312.pdf?lang=en"></ref><ref adv="1" source="" url="http://www.niscc.gov.uk/niscc/docs/br-20060425-00311.html?lang=en"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17691">17691</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1505">ADV-2006-1505</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1506">ADV-2006-1506</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015991">1015991</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19750">19750</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/955777">VU#955777</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26081">
dns-improper-request-handling(26081)</ref></refs><vuln_soft><prod name="DeleGate" vendor="DeleGate"><vers num="9.0.5"/><vers num="9.0.4"/><vers num="9.0.3"/><vers num="9.0.2"/><vers num="9.0.1"/><vers num="9.0"/><vers num="8.11.5"/><vers num="8.11.4"/><vers num="8.11.3"/><vers num="8.11.2"/><vers num="8.11.1"/><vers num="8.11"/><vers num="8.10.6"/><vers num="8.10.5"/><vers num="8.10.4"/><vers num="8.10.3"/><vers num="8.10.2"/><vers num="8.10.1"/><vers num="8.10"/><vers num="8.9.6"/><vers num="8.9.5"/><vers num="8.9.4"/><vers num="8.9.3"/><vers num="8.9.2"/><vers num="8.9.1"/><vers num="8.9"/><vers num="8.5.0"/><vers num="8.4.0"/><vers num="8.3.4"/><vers num="8.3.3"/><vers num="7.9.11"/><vers num="7.8.2"/><vers num="7.8.1"/><vers num="7.8.0"/><vers num="7.7.1"/><vers num="7.7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-2073" published="2006-04-27" seq="2006-2073" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a &quot;broken&quot; TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.niscc.gov.uk/niscc/docs/re-20060425-00312.pdf?lang=en"></ref><ref adv="1" source="" url="http://www.niscc.gov.uk/niscc/docs/br-20060425-00311.html?lang=en"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17692">17692</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1505">ADV-2006-1505</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1537">ADV-2006-1537</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19808">19808</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015993">1015993</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/955777">VU#955777</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26081">
dns-improper-request-handling(26081)</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="9.3.2"/><vers num="9.3.1"/><vers num="9.3"/><vers num="9.2.3"/><vers num="9.2.2"/><vers num="9.2.1"/><vers num="9.2.0"/><vers num="9.1.3"/><vers num="9.1.2"/><vers num="9.1.1"/><vers num="9.1"/><vers num="9.0.1"/><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-2074" published="2006-04-27" seq="2006-2074" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Juniper Networks JUNOSe E-series routers before 7-1-1 has unknown impact and remote attack vectors related to the DNS &quot;client code,&quot; as demonstrated by the OUSPG PROTOS DNS test suite.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.niscc.gov.uk/niscc/docs/re-20060425-00312.pdf?lang=en"></ref><ref adv="1" source="" url="http://www.niscc.gov.uk/niscc/docs/br-20060425-00311.html?lang=en"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17693">17693</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1505">ADV-2006-1505</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1526">ADV-2006-1526</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015992">1015992</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19822">19822</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/955777">VU#955777</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26081">
dns-improper-request-handling(26081)</ref></refs><vuln_soft><prod name="JUNOSe" vendor="Juniper"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-2075" published="2006-04-27" seq="2006-2075" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in MyDNS 1.1.0 allows remote attackers to cause a denial of service via a crafted DNS message, aka &quot;Query-of-death,&quot; as demonstrated by the OUSPG PROTOS DNS test suite.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="" url="http://www.niscc.gov.uk/niscc/docs/re-20060425-00312.pdf?lang=en"></ref><ref adv="1" source="" url="http://www.niscc.gov.uk/niscc/docs/br-20060425-00311.html?lang=en"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1505">ADV-2006-1505</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015990">1015990</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/955777">VU#955777</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26081">
dns-improper-request-handling(26081)</ref></refs><vuln_soft><prod name="MyDNS" vendor="Don Moore"><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-2076" published="2006-04-27" seq="2006-2076" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in Paul Rombouts pdnsd before 1.2.4 allows remote attackers to cause a denial of service (memory consumption) via a DNS query with an unsupported (1) QTYPE or (2) QCLASS, as demonstrated by the OUSPG PROTOS DNS test suite.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.niscc.gov.uk/niscc/docs/re-20060425-00312.pdf?lang=en"></ref><ref adv="1" source="" url="http://www.niscc.gov.uk/niscc/docs/br-20060425-00311.html?lang=en"></ref><ref source="" url="http://www.phys.uu.nl/~rombouts/pdnsd.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17694">17694</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1505">ADV-2006-1505</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1528">ADV-2006-1528</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015989">1015989</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19835">19835</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-10.xml">GLSA-200605-10</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20055">20055</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/955777">VU#955777</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26081">
dns-improper-request-handling(26081)</ref></refs><vuln_soft><prod name="pdnsd" vendor="pdnsd"><vers num="1.2.3 par"/><vers num="1.2.2 par"/><vers num="1.2.1 par"/><vers num="1.1.11 par"/><vers num="1.1.10 par"/><vers num="1.1.8b1 par8"/><vers num="1.1.8b1 par6"/><vers num="1.1.8b1 par5"/><vers num="1.1.7a"/><vers num="1.1.6"/><vers num="1.1.5"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0.15"/><vers num="1.0.13"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-2077" published="2006-04-27" seq="2006-2077" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Paul Rombouts pdnsd before 1.2.4 has unknown impact and attack vectors.  NOTE: this issue might be related to the OUSPG PROTOS DNS test suite.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.phys.uu.nl/~rombouts/pdnsd.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17720">17720</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-10.xml">GLSA-200605-10</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20055">20055</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/955777">VU#955777</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26081">
dns-improper-request-handling(26081)</ref></refs><vuln_soft><prod name="pdnsd" vendor="pdnsd"><vers num="1.2.3 par"/><vers num="1.2.2 par"/><vers num="1.2.1 par"/><vers num="1.1.11 par"/><vers num="1.1.10 par"/><vers num="1.1.8b1 par8"/><vers num="1.1.8b1 par6"/><vers num="1.1.8b1 par5"/><vers num="1.1.7a"/><vers num="1.1.6"/><vers num="1.1.5"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0.15"/><vers num="1.0.13"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-2078" published="2006-04-27" seq="2006-2078" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in multiple FITELnet products, including FITELnet-F40, F80, F100, F120, F1000, and E20/E30, allow remote attackers to cause a denial of service via crafted DNS messages that trigger errors in (1) ProxyDNS or (2) PKI-Resolver, as demonstrated by the OUSPG PROTOS DNS test suite.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="NISCC" url="http://www.niscc.gov.uk/niscc/docs/re-20060425-00312.pdf?lang=en">NISCC Vulnerability Advisory 144154</ref><ref patch="1" source="NISCC" url="http://www.niscc.gov.uk/niscc/docs/br-20060425-00311.html?lang=en">Id: 20060425-00311</ref><ref source="Furukawa" url="http://www.furukawa.co.jp/fitelnet/topic/dns2_attacks.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17710">17710</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1505">ADV-2006-1505</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1536">ADV-2006-1536</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19820">19820</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/955777">VU#955777</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26081">
dns-improper-request-handling(26081)</ref></refs><vuln_soft><prod name="FITELnet" vendor="Furukawa Electric"><vers num="F80"/><vers num="F40"/><vers num="F3000"/><vers num="F120"/><vers num="F1000"/><vers num="F100"/><vers num="E30"/><vers num="E20"/></prod><prod name="MUCHO-EV_PK" vendor="Furukawa Electric"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-20" name="CVE-2006-2079" published="2006-04-27" seq="2006-2079" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in portfolio.php in Verosky Media Instant Photo Gallery, possibly before 1.0.2, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/432024/100/0/threaded">20060425 Instant Photo Gallery &lt;= Multiple XSS</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432241/100/0/threaded">20060427 Re: Instant Photo Gallery &lt;= Multiple XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/17696">17696</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-April/000733.html">[VIM] 20060427 Instant Photo Gallery &lt;= Multiple XSS (fwd)</ref><ref source="OSVDB" url="http://www.osvdb.org/24985">24985</ref><ref source="SREASON" url="http://securityreason.com/securityalert/803">803</ref></refs><vuln_soft><prod name="Instant Photo Gallery" vendor="Verosky Media"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-20" name="CVE-2006-2080" published="2006-04-27" seq="2006-2080" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in portfolio_photo_popup.php in Verosky Media Instant Photo Gallery 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter, which is not cleansed before calling the count_click function in includes/functions/fns_std.php.  NOTE: this issue could produce resultant XSS.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/432024/100/0/threaded">20060425 Instant Photo Gallery &lt;= Multiple XSS</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432241/100/0/threaded">20060427 Re: Instant Photo Gallery &lt;= Multiple XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/17696">17696</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1533">ADV-2006-1533</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-April/000733.html">[VIM] 20060427 Instant Photo Gallery &lt;= Multiple XSS (fwd)</ref><ref source="OSVDB" url="http://www.osvdb.org/24986">24986</ref><ref source="OSVDB" url="http://www.osvdb.org/24987">24987</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19813">19813</ref><ref source="SREASON" url="http://securityreason.com/securityalert/803">803</ref></refs><vuln_soft><prod name="Instant Photo Gallery" vendor="Verosky Media"><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2006-2081" published="2006-04-27" seq="2006-2081" severity="Medium" type="CVE"><desc><descript source="cve">Oracle Database Server 10g Release 2 allows local users to execute arbitrary SQL queries via the GET_DOMAIN_INDEX_METADATA function in the DBMS_EXPORT_EXTENSION package.  NOTE: this issue was originally linked to DB05 (CVE-2006-1870), but a reliable third party has claimed that it is not the same issue.  Based on details of the problem, the primary issue appears to be insecure privileges that facilitate the introduction of SQL in a way that is not releated to special characters, so this is not &quot;SQL injection&quot; per se.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431353/100/0/threaded">20060419 Oracle 10g 10.2.0.2.0 DBA exploit</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432078/100/0/threaded">20060426 Recent Oracle exploit is _actually_ an 0day with no patch</ref><ref source="" url="http://www.red-database-security.com/exploits/oracle-sql-injection-oracle-dbms_export_extension.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432354/100/0/threaded">20060427 Re: Recent Oracle exploit is _actually_ an 0day with no patch</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432355/100/0/threaded">20060427 Re: Recent Oracle exploit is _actually_ an 0day with no patch</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/932124">VU#932124</ref><ref source="BID" url="http://www.securityfocus.com/bid/17699">17699</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015999">1015999</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19860">19860</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26048">oracle-dbmsexportextension-sql-injection(26048)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432632/30/5250/threaded">
20060501 RE: Oracle 10g 10.2.0.2.0 DBA exploit</ref><ref source="SREASON" url="http://securityreason.com/securityalert/802">802</ref></refs><vuln_soft><prod name="Oracle10g Database Server Release 2" vendor="Oracle"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-10" name="CVE-2006-2082" published="2006-05-09" seq="2006-2082" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein: Enemy Territory, and Star Trek Voyager: Elite Force, when the sv_allowdownload cvar is enabled, allows remote attackers to read arbitrary files from the server via &quot;..&quot; sequences in a .pk3 file request.</descript></desc><sols><sol source="nvd">id Software has released patches to address this and other issues.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433349/100/0/threaded">20060508 Two independent vulnerabilities (client and server side) in Quake3 engine and many derived games</ref><ref source="BID" url="http://www.securityfocus.com/bid/17924">17924</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-May/045906.html">
20060508 Two independent vulnerabilities (client and server side) in Quake3 engine and many derived games</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26347">
quake3-sv-allowdownload-directory-traversal(26347)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/880">880</ref></refs><vuln_soft><prod name="Quake 3 engine" vendor="id software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-22" name="CVE-2006-2083" published="2006-04-28" seq="2006-2083" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the receive_xattr function in the extended attributes patch (xattr.c) for rsync before 2.6.8 might allow attackers to execute arbitrary code via crafted extended attributes that trigger a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://samba.anu.edu.au/ftp/rsync/rsync-2.6.8-NEWS"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1606">ADV-2006-1606</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19920">19920</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0024">2006-0024</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-05.xml">GLSA-200605-05</ref><ref source="BID" url="http://www.securityfocus.com/bid/17788">17788</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19964">19964</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20011">20011</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26208">
rsync-xattr-overflow(26208)</ref></refs><vuln_soft><prod name="rsync" vendor="Andrew Tridgell"><vers num="2.6.7"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1"/><vers num="2.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-30" name="CVE-2006-2084" published="2006-04-29" seq="2006-2084" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in FarsiNews 2.5.3 Pro and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameters in (a) index.php, and the (3) mod parameter in (b) admin.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432109/100/0/threaded">20060426 XXS Attack On FarsiNews</ref><ref source="" url="http://www.aria-security.net/advisory/farsinews/farsinews0420062.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17701">17701</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26097">
farsinews-index-admin-xss(26097)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/812">812</ref></refs><vuln_soft><prod name="FarsiNews" vendor="FarsiNews"><vers num="2.5.3 Pro"/><vers num="2.5"/><vers num="2.1 Beta2"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-03-31" modified="2006-08-28" name="CVE-2006-2085" published="2006-04-29" seq="2006-2085" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in (1) CxAce60.dll and (2) CxAce60u.dll in SpeedProject Squeez 5.10 Build 4460, and SpeedCommander 10.52 Build 4450 and 11.01 Build 4450, allow user-assisted remote attackers to execute arbitrary code via an ACE archive that contains a file with a long filename.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432101/100/0/threaded">20060426 Secunia Research: SpeedProject Products ACE Archive HandlingBuffer Overflow</ref><ref source="" url="http://www.speedproject.de/enu/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17709">17709</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19473">19473</ref><ref source="" url="http://secunia.com/secunia_research/2006-23/advisory"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1535">ADV-2006-1535</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016003">1016003</ref><ref source="OSVDB" url="http://www.osvdb.org/24990">24990</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016002">1016002</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26115">
speedproject-ace-bo(26115)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/820">820</ref></refs><vuln_soft><prod name="SpeedCommander" vendor="SpeedProject"><vers num="10.52 Build4450"/><vers num="11.01 Build4450"/></prod><prod name="Squeez" vendor="SpeedProject"><vers num="5.10 Build 4460"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-30" name="CVE-2006-2086" published="2006-04-29" seq="2006-2086" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juniper NetScreen IVE device running IVE OS before 4.2r8.1, 5.0 before 5.0r6.1, 5.1 before 5.1r8, 5.2 before 5.2r4.1, or 5.3 before 5.3r2.1, allows remote attackers to execute arbitrary code via a long argument in the ProductName parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432155/100/0/threaded">20060426 [EEYEB-20060227] Juniper Networks SSL-VPN Client Buffer Overflow</ref><ref source="" url="http://www.eeye.com/html/research/advisories/AD20060424.html"></ref><ref source="" url="http://www.juniper.net/support/security/alerts/PSN-2006-03-013.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17712">17712</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1543">ADV-2006-1543</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016000">1016000</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19842">19842</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/477604">VU#477604</ref><ref source="OSVDB" url="http://www.osvdb.org/25001">25001</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26077">
juniper-ive-activex-bo(26077)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/819">819</ref></refs><vuln_soft><prod name="JuniperSetup Control" vendor="Juniper"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-30" name="CVE-2006-2087" published="2006-04-29" seq="2006-2087" severity="Medium" type="CVE"><desc><descript source="cve">The Gmax Mail client in Hitachi Groupmax before 20060426 allows remote attackers to cause a denial of service (application hang or erroneous behavior) via an attachment with an MS-DOS device filename.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS06-006_e/01-e.html"></ref><ref source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS06-006_e/index-e.html"></ref><ref source="" url="http://jvn.jp/jp/JVN%2389344424/index.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19840">19840</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1539">ADV-2006-1539</ref><ref source="OSVDB" url="http://www.osvdb.org/24969">24969</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26099">
hitachi-groupmax-client-dos(26099)</ref></refs><vuln_soft><prod name="Groupmax World Wide Web" vendor="Hitachi"><vers num=""/></prod><prod name="Groupmax World Wide Web Desktop" vendor="Hitachi"><vers num=""/></prod><prod name="Groupmax Mail" vendor="Hitachi"><vers num=""/></prod><prod name="Groupmax Integrated Desktop" vendor="Hitachi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-2088" published="2006-04-29" seq="2006-2088" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Devsyn Open Bulletin Board (OpenBB) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via (1) the FID parameter in board.php and (2) the TID parameter in read.php.  NOTE: the SQL injection issues are already covered by CVE-2005-1612 (read.php) and CVE-2005-2566 (board.php).</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432106/100/0/threaded">20060426 Open Bulletin Board &lt; Multiple Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26095">
openbb-board-read-xss(26095)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/806">806</ref></refs><vuln_soft><prod name="Open Bulletin Board" vendor="Devsyn"><vers num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-2089" published="2006-04-29" seq="2006-2089" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in misc.php in MySmartBB 1.1.x allow remote attackers to inject arbitrary web script or HTML via the (1) id and (2) username parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432095/100/0/threaded">20060426 MySmartBB&lt;---v 1.1.x SQL Injection/XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/17707">17707</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26089">
mysmartbb-misc-xss(26089)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/807">807</ref></refs><vuln_soft><prod name="MySmartBB" vendor="MySmartBB"><vers num="1.1.3"/><vers num="1.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-2090" published="2006-04-29" seq="2006-2090" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in misc.php in MySmartBB 1.1.x allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) username parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432095/100/0/threaded">20060426 MySmartBB&lt;---v 1.1.x SQL Injection/XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/17707">17707</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26088">
mysmartbb-misc-sql-injection(26088)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/807">807</ref></refs><vuln_soft><prod name="MySmartBB" vendor="MySmartBB"><vers num="1.1.3"/><vers num="1.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-2091" published="2006-04-29" seq="2006-2091" severity="Medium" type="CVE"><desc><descript source="cve">admin.php in Virtual War (VWar) 1.5 and versions before 1.2 allows remote attackers to obtain sensitive information via an invalid vwar_root parameter, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431900/100/0/threaded">20060423 VWar Path Disclosure</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26006">
virtualwar-admin-path-disclosure(26006)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/818">818</ref></refs><vuln_soft><prod name="Virtual War" vendor="VWar"><vers num="1.5"/><vers num="1.1.8"/><vers num="1.1.7"/><vers num="1.1.6"/><vers num="1.1.5"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1.0"/><vers num="1.0.9"/><vers num="1.0.8"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-2092" published="2006-04-29" seq="2006-2092" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in HP StorageWorks Secure Path for Windows 4.0C-SP2 before 20060419 allows remote attackers to cause an unspecified denial of service via unknown vectors.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00642089">HPSBST02112</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1458">ADV-2006-1458</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015969">1015969</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19752">19752</ref><ref source="BID" url="http://www.securityfocus.com/bid/17638">17638</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25939">
hp-storageworks-win-dos(25939)</ref></refs><vuln_soft><prod name="StorageWorks Secure Path Windows" vendor="HP"><vers edition="Windows" num="4.0C SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-20" modified="2006-08-28" name="CVE-2006-2093" published="2006-04-29" seq="2006-2093" severity="Low" type="CVE"><desc><descript source="cve">Nessus before 2.2.8, and 3.x before 3.0.3, allows user-assisted attackers to cause a denial of service (memory consumption) via a NASL script that calls split with an invalid sep parameter.  NOTE: a design goal of the NASL language is to facilitate sharing of security tests by guaranteeing that a script &quot;can not do anything nasty.&quot;  This issue is appropriate for CVE only if Nessus users have an expectation that a split statement will not use excessive memory.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431987/100/0/threaded">20060425 NASL &apos;Split&apos; function Buffer overflow Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431993/100/0/threaded">20060425 Re: NASL &apos;Split&apos; function Buffer overflow Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431994/100/0/threaded">20060425 Re: NASL &apos;Split&apos; function Buffer overflow Vulnerability</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1541">ADV-2006-1541</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015996">1015996</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-279-1">USN-279-1</ref><ref source="OSVDB" url="http://www.osvdb.org/25084">25084</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26034">
nessus-nasl-split-dos(26034)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/817">817</ref></refs><vuln_soft><prod name="Nessus" vendor="Nessus"><vers num="3.0.2" prev="1"/><vers num="2.2.7" prev="1"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.1"/><vers num="2.2.0"/><vers num="2.2.0 RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-10-20" modified="2006-08-28" name="CVE-2006-2094" published="2006-04-29" seq="2006-2094" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking an object or pressing keys that are actually applied to a &quot;Yes&quot; approval for executing the control.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><race/></vuln_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0264.html">20040407 Race conditions in security dialogs</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0759.html">20060426 Internet Explorer User Interface Races, Redeux</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0019.html">20060427 PoC for Internet Explorer Modal Dialog Issue</ref><ref adv="1" source="" url="http://student.missouristate.edu/m/matthew007/advisories.asp?adv=2006-02"></ref><ref source="" url="http://www.squarefree.com/2004/07/01/race-conditions-in-security-dialogs/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17713">17713</ref><ref source="OSVDB" url="http://www.osvdb.org/22351">22351</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015720">1015720</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1559">ADV-2006-1559</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045589.html">
20060427 PoC for Internet Explorer Modal Dialog Issue</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26111">
ie-modal-dialog-code-execution(26111)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5 preview"/><vers num="5.5"/><vers num="5.0.1 SP4"/><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers edition="Windows NT 4.0" num="5.0.1"/><vers edition="Windows 98" num="5.0.1"/><vers edition="Windows 95" num="5.0.1"/><vers edition="Windows 2000" num="5.0.1"/><vers num="5.0.1"/><vers edition="Windows NT 4.0" num="50"/><vers edition="Windows 98" num="5.0"/><vers edition="Windows 95" num="5.0"/><vers edition="Windows 2000" num="5.0"/><vers num="5.0"/><vers num="7.0 Beta2"/><vers num="7.0 Beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-2095" published="2006-04-29" seq="2006-2095" severity="Medium" type="CVE"><desc><descript source="cve">Phex before 2.8.6 allows remote attackers to cause a denial of service (application hang) by initiating multiple chat requests to a single user and then logging off.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=412751"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1560">ADV-2006-1560</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19824">19824</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26124">
phex-request-dos(26124)</ref></refs><vuln_soft><prod name="Phex" vendor="Phex"><vers num="2.8.4"/><vers num="2.8.2"/><vers num="2.8"/><vers num="2.6.4"/><vers num="2.6.2"/><vers num="2.6"/><vers num="2.4.4"/><vers num="2.4.2"/><vers num="2.4"/><vers num="2.2.2"/><vers num="2.2"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-21" modified="2006-09-20" name="CVE-2006-2096" published="2006-04-29" seq="2006-2096" severity="Medium" type="CVE"><desc><descript source="cve">plug.php in Land Down Under (LDU) 802 and earlier allows remote attackers to obtain sensitive information via an invalid (1) month or (2) year parameter, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432235/100/0/threaded">20060427 Land Down Under 802 and below version Path Disclosure Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26143">
landdownunder-monthyear-path-disclosure(26143)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/814">814</ref></refs><vuln_soft><prod name="Land Down Under" vendor="Neocrome"><vers num="802" prev="1"/><vers num="801"/><vers num="800"/><vers num="701"/><vers num="700.05"/><vers num="700.04"/><vers num="700.03"/><vers num="700.02"/><vers num="700.01"/><vers num="602"/><vers num="601"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-27" modified="2006-05-01" name="CVE-2006-2097" published="2006-04-29" seq="2006-2097" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in func_msg.php in Invision Power Board (IPB) 2.1.4 allows remote attackers to execute arbitrary SQL commands via the from_contact field in a private message (PM).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432248/100/0/threaded">20060427 SQL injection exploit IPB &lt;= 2.1.4</ref><ref source="BID" url="http://www.securityfocus.com/bid/17719">17719</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19861">19861</ref><ref source="OSVDB" url="http://www.osvdb.org/25021">25021</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26107">
invision-fromcontact-sql-injection(26107)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/813">813</ref></refs><vuln_soft><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.1.4" prev="1"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1.0"/><vers num="2.1 RC1"/><vers num="2.1 BETA5"/><vers num="2.1 BETA4"/><vers num="2.1 BETA3"/><vers num="2.1 BETA2"/><vers num="2.1 Alpha2"/><vers num="2.1"/><vers num="2.0.x"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/><vers num="1.3.1 Final"/><vers num="1.3 Final"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-2098" published="2006-04-29" seq="2006-2098" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in Thumbnail AutoIndex before 2.0 allows remote attackers to execute arbitrary PHP code via (1) README.html or (2) HEADER.html.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://staff.xiaoka.com/smoku/stuff/ThAutoIndex/ChangeLog"></ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/24873">24873</ref></refs><vuln_soft><prod name="PHP Thumbnail AutoIndex" vendor="PHP Thumbnail AutoIndex"><vers num="1.4"/><vers num="1.3"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-18" modified="2006-05-02" name="CVE-2006-2099" published="2006-04-29" seq="2006-2099" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in UltraISO 8.0.0.1392 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432359/100/0/threaded">20060428 WinISO/UltraISO/MagicISO/PowerISO Directory Traversal Vulnerability</ref><ref source="" url="http://secway.org/advisory/AD20060428.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1569">ADV-2006-1569</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19857">19857</ref><ref source="BID" url="http://www.securityfocus.com/bid/17724">17724</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016009">1016009</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26140">
iso-dotdot-directory-traversal(26140)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/815">815</ref></refs><vuln_soft><prod name="UltraISO" vendor="EZB Systems"><vers num="8.0.0.1392"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-18" modified="2006-05-01" name="CVE-2006-2100" published="2006-04-29" seq="2006-2100" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Magic ISO 5.0 Build 0166 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432359/100/0/threaded">20060428 WinISO/UltraISO/MagicISO/PowerISO Directory Traversal Vulnerability</ref><ref adv="1" source="SECWAY" url="http://secway.org/advisory/AD20060428.txt">20060428 WinISO/UltraISO/MagicISO/PowerISO Directory Traversal Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1568">ADV-2006-1568</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19864">19864</ref><ref source="BID" url="http://www.securityfocus.com/bid/17725">17725</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016007">1016007</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26140">
iso-dotdot-directory-traversal(26140)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/815">815</ref></refs><vuln_soft><prod name="Magic ISO Maker" vendor="Magic ISO Maker"><vers num="5.0 Build 0166" prev="1"/><vers num="5.2 build 190" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-18" modified="2006-05-01" name="CVE-2006-2101" published="2006-04-29" seq="2006-2101" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in WinISO 5.3 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432359/100/0/threaded">20060428 WinISO/UltraISO/MagicISO/PowerISO Directory Traversal Vulnerability</ref><ref adv="1" source="" url="http://secway.org/advisory/AD20060428.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1567">ADV-2006-1567</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19816">19816</ref><ref source="BID" url="http://www.securityfocus.com/bid/17721">17721</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016010">1016010</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26140">
iso-dotdot-directory-traversal(26140)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/815">815</ref></refs><vuln_soft><prod name="WinISO" vendor="WinISO Computing"><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-18" modified="2006-05-01" name="CVE-2006-2102" published="2006-04-29" seq="2006-2102" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in PowerISO 2.9 allows remote attackers to write artibrary files via a .. (dot dot) in a filename in an ISO image.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432359/100/0/threaded">20060428 WinISO/UltraISO/MagicISO/PowerISO Directory Traversal Vulnerability</ref><ref adv="1" source="SECWAY" url="http://secway.org/advisory/AD20060428.txt">20060428 WinISO/UltraISO/MagicISO/PowerISO Directory Traversal Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1570">ADV-2006-1570</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19858">19858</ref><ref source="BID" url="http://www.securityfocus.com/bid/17726">17726</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016008">1016008</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26140">
iso-dotdot-directory-traversal(26140)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/815">815</ref></refs><vuln_soft><prod name="PowerISO" vendor="PowerISO"><vers num="2.9"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_version="2.0" discovered="2006-04-27" modified="2007-08-13" name="CVE-2006-2103" published="2006-04-29" seq="2006-2103" severity="Low" type="CVE"><desc><descript source="cve">SQL injection vulnerability in MyBB (MyBulletinBoard) 1.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the (1) query string ($querystring variable) in (a) admin/adminlogs.php, which is not properly handled by adminfunctions.php; or (2) setid, (3) expand, (4) title, or (5) sid2 parameters to (b) admin/templates.php.</descript></desc><sols><sol source="nvd">Successful exploitation requires access to the admin section.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432229/100/0/threaded">20060427 MyBB 1.1.1 Local SQL Injections</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19865">19865</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1566">ADV-2006-1566</ref><ref source="OSVDB" url="http://www.osvdb.org/25074">25074</ref><ref source="OSVDB" url="http://www.osvdb.org/25075">25075</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26103">mybb-adminfunctions-templates-sql-injection(26103)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/808">808</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-28" modified="2006-05-01" name="CVE-2006-2104" published="2006-04-29" seq="2006-2104" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Kamgaing Email System (kmail) 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) d parameter to main.php, ordner parameter to (2) main.php, or (3) webdisk.php, (4) draft parameter to compose.php, or (5) m, or (6) y parameter to calendar.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BLOGSPOT" url="http://pridels.blogspot.com/2006/04/kmail-23-vuln.html">Kmail &lt;=2.3 vuln. </ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1564">ADV-2006-1564</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19755">19755</ref><ref source="OSVDB" url="http://www.osvdb.org/25061">25061</ref><ref source="OSVDB" url="http://www.osvdb.org/25062">25062</ref><ref source="OSVDB" url="http://www.osvdb.org/25063">25063</ref><ref source="OSVDB" url="http://www.osvdb.org/25064">25064</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26117">
kmail-multiple-scripts-xss(26117)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/kmail-23-vuln.html"></ref></refs><vuln_soft><prod name="KMail" vendor="KMail"><vers num="2.3" prev="1"/><vers num="1.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-27" modified="2006-05-01" name="CVE-2006-2105" published="2006-04-29" seq="2006-2105" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in Jupiter CMS 1.1.4 and 1.1.5 allows remote attackers to read arbitrary files via &quot;..&quot; sequences terminated by a %00 (null) character in the n parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/jupitercms-lteq1.1.5-local-file-include.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17716">17716</ref></refs><vuln_soft><prod name="Jupiter CMS" vendor="Jupiter CMS"><vers num="1.1.4"/><vers num="1.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-25" modified="2006-05-01" name="CVE-2006-2106" published="2006-04-29" seq="2006-2106" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Edgewall Software Trac 0.9.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors related to a &quot;wiki macro.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.edgewall.com/blog/news/trac_0_9_5.html"></ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1557">ADV-2006-1557</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015986">1015986</ref><ref source="BID" url="http://www.securityfocus.com/bid/17741">17741</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19870">19870</ref><ref source="" url="http://jvn.jp/jp/JVN%2384091359/index.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26125">
trac-wiki-engine-xss(26125)</ref></refs><vuln_soft><prod name="Trac" vendor="Edgewall Software"><vers num="0.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-04-27" modified="2007-05-02" name="CVE-2006-2107" published="2006-04-29" seq="2006-2107" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in BL4 SMTP Server 0.1.4 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long argument to the (1) EHLO, (2) MAIL FROM, and (3) RCPT TO commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432329/100/0/threaded">20060427 BL4&apos;s SMTP server BufferOverflow Vulnerable</ref><ref adv="1" source="ECHO" url="http://advisories.echo.or.id/adv/adv30-theday-2006.txt">ECHO_ADV_30$2006</ref><ref source="BID" url="http://www.securityfocus.com/bid/17714">17714</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26114">bl4-smtp-bo(26114)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/809">809</ref></refs><vuln_soft><prod name="SMTP Server" vendor="BL4"><vers num="0.1.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" discovered="2006-03-29" modified="2008-08-18" name="CVE-2006-2108" published="2006-04-29" seq="2006-2108" severity="High" type="CVE"><desc><descript source="cve">parser.exe in Oc&amp;#xe9; (OCE) 3121/3122 Printer allows remote attackers to cause a denial of service (crash or reboot) via a long request, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://milw0rm.com/exploits/1718">exploit 1718</ref><ref source="BID" url="http://www.securityfocus.com/bid/17715">17715</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19847">19847</ref><ref source="OSVDB" url="http://www.osvdb.org/25000">25000</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26123">oce-printer-url-dos(26123)</ref></refs><vuln_soft><prod name="3121 Printer" vendor="Oc&amp;#xe9; North America"><vers num=""/></prod><prod name="3122 Printer" vendor="Oc&amp;#xe9; North America"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-2109" published="2006-05-02" seq="2006-2109" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the parse_query_str function in include/print.php in JSBoard 2.0.10 and 2.0.11, and possibly other versions before 2.0.12, allows remote attackers to inject arbitrary web script or HTML via parameters that are set as global variables within the program, as demonstrated using the table parameter to login.php.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
JSBoard, JSBoard, 2.0.12</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="KLINK" url="https://www.klink.name/security/aklink-sa-2006-001-jsboard-xss.txt">Security Advisory AKLINK-SA-2006-001</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432714/100/0/threaded">20060502 JSBoard XSS vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17778">17778</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1636">ADV-2006-1636</ref><ref source="OSVDB" url="http://www.osvdb.org/25222">25222</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19937">19937</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26211">jsboard-login-xss(26211)</ref></refs><vuln_soft><prod name="JSBoard" vendor="JSBoard"><vers num="2.0.11" prev="1"/><vers num="2.0.10"/><vers num="2.0.9"/><vers num="2.0.8"/><vers num="2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2006-2110" published="2006-05-01" seq="2006-2110" severity="Low" type="CVE"><desc><descript source="cve">Virtual Private Server (Vserver) 2.0.x before 2.0.2-rc18 and 2.1.x before 2.1.1-rc18 provides certain context capabilities (ccaps) that allow local guest users to perform operations that were only intended to be allowed by the guest-root.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product releases:
Virtual Private Server, Vserver, 2.0.2-rc18
Virtual Private Server, Vserver, 2.1.1-rc18</sol></sols><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref patch="1" source="MLIST" url="http://list.linux-vserver.org/archive/vserver/msg13167.html">[Vserver] 20060428 [SECURITY] ccaps not limited to root inside a guest</ref><ref patch="1" source="" url="http://dev.croup.de/proj/gentoo-vps/browser/vserver-sources/2.0.1-r4/4915_vs2.0.1-vxcapable-fix.patch"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1661">ADV-2006-1661</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19961">19961</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1060">DSA-1060</ref><ref source="BID" url="http://www.securityfocus.com/bid/17842">17842</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20206">20206</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26285">
linux-vserver-ccaps-privilege-escalation(26285)</ref></refs><vuln_soft><prod name="Vserver" vendor="Virtual Private Server"><vers num="2.0.2"/><vers num="2.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-05-19" name="CVE-2006-2111" published="2006-05-01" seq="2006-2111" severity="Medium" type="CVE"><desc><descript source="cve">A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections with the mhtml: URI handler, as originally reported for Internet Explorer 6 and 7, aka &quot;URL Redirect Cross Domain Information Disclosure Vulnerability.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref source="SECUNIA" url="http://secunia.com/Internet_Explorer_Arbitrary_Content_Disclosure_Vulnerability_Test/">Internet Explorer Arbitrary Content Disclosure Vulnerability Test</ref><ref source="BID" url="http://www.securityfocus.com/bid/17717">17717</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1558">ADV-2006-1558</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016005">1016005</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19738">19738</ref><ref source="OSVDB" url="http://www.osvdb.org/25073">25073</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/22477">22477</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/449917/100/0/threaded">20061025 IE7 status: 8 days after release, 3 unfixed issues</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/449883/100/200/threaded">20061026 IE7 is a Source of Problem - Secunia IE7 Release Incident of October 2006</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26281">ie-mhtml-information-disclosure(26281)</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded">HPSBST02231</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-034.mspx">MS07-034</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html">TA07-163A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/783761">VU#783761</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2154">ADV-2007-2154</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1605">oval:org.mitre.oval:def:1605</ref></refs><vuln_soft><prod name="Outlook Express" vendor="Microsoft"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-30" name="CVE-2006-2112" published="2006-08-24" seq="2006-2112" severity="High" type="CVE"><desc><descript source="cve">Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Network Option Card firmware before 5.13, allows remote attackers to use the FTP printing interface as a proxy (&quot;FTP bounce&quot;) by using arbitrary PORT arguments to connect to systems for which access would be otherwise restricted.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://itso.iu.edu/20060824_FXPS_Print_Engine_Vulnerabilities"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3401">ADV-2006-3401</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=115652437223454&amp;w=2">20060825 Indiana University Security Advisory: Fuji Xerox Printing Systems (FXPS) print engine vulnerabilitie</ref><ref source="BID" url="http://www.securityfocus.com/bid/19711">19711</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/28637">fxps-port-security-bypass(28637)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/444321/100/0/threaded">20060825 Indiana University Security Advisory: Fuji Xerox Printing Systems (FXPS) print engine vulnerabilities</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21630">21630</ref><ref source="OSVDB" url="http://www.osvdb.org/28249">28249</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22463">22463</ref></refs><vuln_soft><prod name="DocuPrint 181 Network Option Card" vendor="Fuji Xerox"><vers num=""/></prod><prod name="DocuPrint C2535A" vendor="Fuji Xerox"><vers num=""/></prod><prod name="3000cn" vendor="Dell"><vers num=""/></prod><prod name="DocuPrint C525A Network Option Card" vendor="Fuji Xerox"><vers num=""/></prod><prod name="3110cn" vendor="Dell"><vers num=""/></prod><prod name="DocuPrint C830 Network Option Card" vendor="Fuji Xerox"><vers num=""/></prod><prod name="Fuji Xerox Printing Systems print engine" vendor="Fuji Xerox"><vers num=""/></prod><prod name="DocuPrint C1616 Network Option Card" vendor="Fuji Xerox"><vers num=""/></prod><prod name="Phaser 6201J" vendor="Fuji Xerox"><vers num=""/></prod><prod name="DocuPrint 211 Network Option Card" vendor="Fuji Xerox"><vers num=""/></prod><prod name="5110cn" vendor="Dell"><vers num=""/></prod><prod name="DocuPrint C1616" vendor="Fuji Xerox"><vers num=""/></prod><prod name="DocuPrint 181" vendor="Fuji Xerox"><vers num=""/></prod><prod name="5100cn" vendor="Dell"><vers num=""/></prod><prod name="DocuPrint 211" vendor="Fuji Xerox"><vers num=""/></prod><prod name="3010cn" vendor="Dell"><vers num=""/></prod><prod name="DocuPrint C525A" vendor="Fuji Xerox"><vers num=""/></prod><prod name="DocuPrint C830" vendor="Fuji Xerox"><vers num=""/></prod><prod name="3100cn" vendor="Dell"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-30" name="CVE-2006-2113" published="2006-08-24" seq="2006-2113" severity="Medium" type="CVE"><desc><descript source="cve">The embedded HTTP server in Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Network Option Card firmware before 5.13, does not properly perform authentication for HTTP requests, which allows remote attackers to modify system configuration via crafted requests, including changing the administrator password or causing a denial of service to the print server.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://itso.iu.edu/20060824_FXPS_Print_Engine_Vulnerabilities"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3401">ADV-2006-3401</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=115652437223454&amp;w=2">20060825 Indiana University Security Advisory: Fuji Xerox Printing Systems (FXPS) print engine vulnerabilitie</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/444321/100/0/threaded">20060825 Indiana University Security Advisory: Fuji Xerox Printing Systems (FXPS) print engine vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/19716">19716</ref><ref source="OSVDB" url="http://www.osvdb.org/28250">28250</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21630">21630</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22463">22463</ref></refs><vuln_soft><prod name="DocuPrint 181 Network Option Card" vendor="Fuji Xerox"><vers num=""/></prod><prod name="DocuPrint C2535A" vendor="Fuji Xerox"><vers num=""/></prod><prod name="3000cn" vendor="Dell"><vers num=""/></prod><prod name="DocuPrint C525A Network Option Card" vendor="Fuji Xerox"><vers num=""/></prod><prod name="3110cn" vendor="Dell"><vers num=""/></prod><prod name="DocuPrint C830 Network Option Card" vendor="Fuji Xerox"><vers num=""/></prod><prod name="Fuji Xerox Printing Systems print engine" vendor="Fuji Xerox"><vers num=""/></prod><prod name="DocuPrint C1616 Network Option Card" vendor="Fuji Xerox"><vers num=""/></prod><prod name="Phaser 6201J" vendor="Fuji Xerox"><vers num=""/></prod><prod name="DocuPrint 211 Network Option Card" vendor="Fuji Xerox"><vers num=""/></prod><prod name="5110cn" vendor="Dell"><vers num=""/></prod><prod name="DocuPrint C1616" vendor="Fuji Xerox"><vers num=""/></prod><prod name="DocuPrint 181" vendor="Fuji Xerox"><vers num=""/></prod><prod name="5100cn" vendor="Dell"><vers num=""/></prod><prod name="DocuPrint 211" vendor="Fuji Xerox"><vers num=""/></prod><prod name="3010cn" vendor="Dell"><vers num=""/></prod><prod name="DocuPrint C525A" vendor="Fuji Xerox"><vers num=""/></prod><prod name="DocuPrint C830" vendor="Fuji Xerox"><vers num=""/></prod><prod name="3100cn" vendor="Dell"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-28" modified="2006-05-01" name="CVE-2006-2114" published="2006-05-01" seq="2006-2114" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SWS web Server 0.1.7 allows remote attackers to execute arbitrary code via a long request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432362/100/0/threaded">20060428 [ECHO_ADV_31$2006] Sws Web Server 0.1.7 Strcpy() &amp; Syslog() Format String Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17737">17737</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26159">
sws-webserver-syslog-bo(26159)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/816">816</ref></refs><vuln_soft><prod name="SWS Simple Web Server" vendor="SWS"><vers num="0.1.7"/><vers num="0.1.6"/><vers num="0.1.5"/><vers num="0.1.4"/><vers num="0.1.3"/><vers num="0.1.2"/><vers num="0.1.1"/><vers num="0.1"/><vers num="0.0.4"/><vers num="0.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-28" modified="2006-05-01" name="CVE-2006-2115" published="2006-05-01" seq="2006-2115" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in SWS web Server 0.1.7 allows remote attackers to execute arbitrary code via unspecified vectors that are not properly handled in a syslog function call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432362/100/0/threaded">20060428 [ECHO_ADV_31$2006] Sws Web Server 0.1.7 Strcpy() &amp; Syslog() Format String Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17737">17737</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26158">
sws-webserver-syslog-format-string(26158)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/816">816</ref></refs><vuln_soft><prod name="SWS Simple Web Server" vendor="SWS"><vers num="0.1.7"/><vers num="0.1.6"/><vers num="0.1.5"/><vers num="0.1.4"/><vers num="0.1.3"/><vers num="0.1.2"/><vers num="0.1.1"/><vers num="0.1"/><vers num="0.0.4"/><vers num="0.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-01" modified="2006-05-02" name="CVE-2006-2116" published="2006-05-01" seq="2006-2116" severity="High" type="CVE"><desc><descript source="cve">planetGallery allows remote attackers to gain administrator privileges via a direct request to admin/gallery_admin.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432576/100/0/threaded">20060501 planetGallery admin login</ref><ref source="BID" url="http://www.securityfocus.com/bid/17753">17753</ref><ref source="" url="http://www.planetc.de/download/planetgallery/planetgallery.html"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/825">825</ref></refs><vuln_soft><prod name="planetGallery" vendor="PlaNet Concept"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-29" modified="2006-05-02" name="CVE-2006-2117" published="2006-05-01" seq="2006-2117" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Thyme 1.3 allows remote attackers to inject arbitrary web script or HTML via the search page.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432588/100/0/threaded">20060429 Thyme 1.3 Cross Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/17746">17746</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1602">ADV-2006-1602</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19909">19909</ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-September/001019.html">[VIM] 20060908 Vendor ACK for CVE-2006-2117 (Thyme)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26188">
thyme-index-xss(26188)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/822">822</ref></refs><vuln_soft><prod name="Thyme" vendor="Extrosoft"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-01" modified="2006-05-02" name="CVE-2006-2118" published="2006-05-01" seq="2006-2118" severity="High" type="CVE"><desc><descript source="cve">JMK&apos;s Picture Gallery allows remote attackers to bypass authentication via a direct request to admin_gallery.php3, possibly related to the add action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432575/100/0/threaded">20060501 JMK&apos;s Picture Gallery admin login</ref><ref source="BID" url="http://www.securityfocus.com/bid/17755">17755</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26210">
jmk-admingallery-unauth-access(26210)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/821">821</ref></refs><vuln_soft><prod name="JMK Picture Gallery" vendor="JMK Web Scripts"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-01" modified="2006-05-02" name="CVE-2006-2119" published="2006-05-01" seq="2006-2119" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in event/index.php in Artmedic Event allows remote attackers to execute arbitrary code via a URL in the page parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://kurdishsecurity.blogspot.com/2006/04/artmedic-event-remote-file-include.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432397/100/0/threaded">20060428 [Kurdish Security #2] Artmedic Event Remote File Include Vulnerability</ref><ref adv="1" source="" url="http://www.lobnan.de/advisories/artmedic.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17736">17736</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1588">ADV-2006-1588</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19907">19907</ref><ref source="OSVDB" url="http://www.osvdb.org/25130">25130</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26150">
artmedic-event-index-file-include(26150)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/811">811</ref></refs><vuln_soft><prod name="Artmedic Event" vendor="Artmedic Webdesign"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-26" modified="2006-05-02" name="CVE-2006-2120" published="2006-05-01" seq="2006-2120" severity="Low" type="CVE"><desc><descript source="cve">The TIFFToRGB function in libtiff before 3.8.1 allows remote attackers to cause a denial of service (crash) via a crafted TIFF image with Yr/Yg/Yb values that exceed the YCR/YCG/YCB values, which triggers an out-of-bounds read.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://bugzilla.remotesensing.org/show_bug.cgi?id=1065"></ref><ref patch="1" source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189974"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:082">MDKSA-2006:082</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-277-1">USN-277-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/17809">17809</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19936">19936</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19949">19949</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0024">2006-0024</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19964">19964</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0425.html">RHSA-2006:0425</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20023">20023</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1078">DSA-1078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20330">20330</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-119.htm"></ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20667">
20667</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:082">MDKSA-2006:082</ref></refs><vuln_soft><prod name="libTIFF" vendor="libTIFF"><vers num="3.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-28" modified="2006-05-02" name="CVE-2006-2121" published="2006-05-01" seq="2006-2121" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in admin/config_settings.tpl.php in I-RATER Platinum allows remote attackers to execute arbitrary code via a URL in the include_path parameter.  NOTE: this is a different vector, and possibly a different vulnerability, than CVE-2006-1929.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432596/100/0/threaded">20060429 I-RATER Platinum Remote File Inclusion exploit Cod3d by R@1D3N</ref><ref source="BID" url="http://www.securityfocus.com/bid/17731">17731</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432404/100/0/threaded">20060428 [Kurdish Secure Advisory #1] I-RATER Platinum %22Admin/configsettings.tpl.php%22 Remote File Include Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26203">
irater-configsettingtpl-file-include(26203)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/824">824</ref></refs><vuln_soft><prod name="I-Rater Platinum" vendor="I-Rater"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-04-28" modified="2008-03-05" name="CVE-2006-2122" published="2006-05-01" seq="2006-2122" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in CoolMenus allows remote attackers to execute arbitrary code via a URL in the page parameter.  NOTE: the original report for this issue is probably erroneous, since CoolMenus does not appear to be written in PHP.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432597/100/0/threaded">20060429 CoolMenus Event Remote File Inclusion exploit</ref><ref source="" url="http://kurdishsecurity.blogspot.com/2006/04/coolmenus-event-remote-file-include.html"></ref><ref source="" url="http://www.dhtmlcentral.com/projects/coolmenus/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17738">17738</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432395/100/0/threaded">20060428 [Kurdish Security #3] CoolMenus Event Remote File Include Vulnerability (For PHP)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432630/100/0/threaded">20060501 Re: CoolMenus Event Remote File Inclusion exploit</ref><ref source="SREASON" url="http://securityreason.com/securityalert/823">823</ref></refs><vuln_soft><prod name="CoolMenus" vendor="CoolMenus"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-28" modified="2006-05-02" name="CVE-2006-2123" published="2006-05-01" seq="2006-2123" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in the report interface in Network Administration Visualized (NAV) before 3.0.1 allow remote attackers to execute arbitrary SQL commands via unknown vectors.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=413412"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17734">17734</ref><ref source="OSVDB" url="http://www.osvdb.org/25066">25066</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1572">ADV-2006-1572</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19849">19849</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26151">
nav-report-interface-sql-injection(26151)</ref></refs><vuln_soft><prod name="Network Administration Visualized" vendor="Network Administration Visualized"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-01" modified="2006-05-02" name="CVE-2006-2124" published="2006-05-01" seq="2006-2124" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SunShop 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prevaction, (2) previd, (3) prevstart, (4) itemid, (5) id, and (6) action parameters in index.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/05/sunshop-xss-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1582">ADV-2006-1582</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19871">19871</ref><ref source="BID" url="http://www.securityfocus.com/bid/17770">17770</ref><ref source="OSVDB" url="http://www.osvdb.org/25119">25119</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26180">
sunshop-multiple-parameters-xss(26180)</ref><ref source="" url="http://pridels0.blogspot.com/2006/05/sunshop-xss-vuln.html"></ref></refs><vuln_soft><prod name="SunShop Shopping Cart" vendor="Turnkey Solutions"><vers num="3.5"/><vers num="3.0"/></prod></vuln_soft></entry><entry discovered="2005-11-11" modified="2006-05-04" name="CVE-2006-2125" published="2006-05-01" reject="1" seq="2006-2125" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-3779.  Reason: This candidate is a duplicate of CVE-2005-3779.  Notes: All CVE users should reference CVE-2005-3779 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><refs/><vuln_soft><prod name="HP-UX" vendor="HP"><vers edition="IA64 64-bit" num="B.11.23"/><vers num="B.11.11"/><vers num="B.11.00"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-30" modified="2006-05-02" name="CVE-2006-2126" published="2006-05-01" seq="2006-2126" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in pocategories.php in MaxTrade 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) categori and (2) stranica parameters.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/maxtrade-sql-inj.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1581">ADV-2006-1581</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19876">19876</ref><ref source="BID" url="http://www.securityfocus.com/bid/17765">17765</ref><ref source="OSVDB" url="http://www.osvdb.org/25122">25122</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26171">
maxtrade-pocategories-sql-injection(26171)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/maxtrade-sql-inj.html"></ref></refs><vuln_soft><prod name="MaxTrade" vendor="Avalon Ltd"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-29" modified="2006-05-02" name="CVE-2006-2127" published="2006-05-01" seq="2006-2127" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in weblog_posting.php in Blog Mod 0.2.x allows remote attackers to execute arbitrary SQL commands via the r parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432602/100/0/threaded">20060429 Blog Mod &lt;= 0.2.x SQL Injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/17744">17744</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-164A.html">TA06-164A</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26198">
blogmod-weblogposting-sql-injection(26198)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/810">810</ref></refs><vuln_soft><prod name="Blog Mod" vendor="Blog Mod"><vers num="0.2.4"/><vers num="0.2.3"/><vers num="0.2.4b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-30" modified="2006-06-08" name="CVE-2006-2128" published="2006-05-01" seq="2006-2128" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Pro Publish 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameter to (a) admin/login.php, (3) find_str parameter to (b) search.php, or (4) artid parameter to (c) art.php, or (5) catid parameter to (d) cat.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/130/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17762">17762</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1578">ADV-2006-1578</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19882">19882</ref><ref source="OSVDB" url="http://www.osvdb.org/25124">25124</ref><ref source="OSVDB" url="http://www.osvdb.org/25126">25126</ref><ref source="OSVDB" url="http://www.osvdb.org/25127">25127</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435787/100/0/threaded">20060602 Pro Publish SQL Injection and XSS Vulnerabilities</ref><ref source="" url="http://soot.shabgard.org/bugs/propublish.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/25125">
25125</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26148">
propublish-multiple-sql-injection(26148)</ref></refs><vuln_soft><prod name="Pro Publish" vendor="DeltaScripts"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="4.9" CVSS_score="5.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-30" modified="2006-05-02" name="CVE-2006-2129" published="2006-05-01" seq="2006-2129" severity="Medium" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in Pro Publish 2.0 allows rmeote authenticated adminitrators to execute arbitrary PHP code by editing certain settings, which are stored in set_inc.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/130/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17762">17762</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1578">ADV-2006-1578</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19882">19882</ref><ref source="OSVDB" url="http://www.osvdb.org/25128">25128</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26149">
propublish-setinc-file-include(26149)</ref></refs><vuln_soft><prod name="Pro Publish" vendor="DeltaScripts"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-2130" published="2006-05-01" seq="2006-2130" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in include/class_poll.php in Advanced Poll 2.0.4 allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.</descript></desc><sols><sol source="nvd">Successful exploitation requires that magic_quotes_gpc is set to off.
</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="EVULN" url="http://evuln.com/vulns/131/summary.html">EV0131</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1603">ADV-2006-1603</ref><ref source="OSVDB" url="http://www.osvdb.org/25167">25167</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19899">19899</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26152">advancedpoll-classpoll-sql-injection(26152)</ref></refs><vuln_soft><prod name="Advanced Poll" vendor="Advanced Poll"><vers num="2.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-2131" published="2006-05-01" seq="2006-2131" severity="Medium" type="CVE"><desc><descript source="cve">include/class_poll.php in Advanced Poll 2.0.4 uses the HTTP_X_FORWARDED_FOR (X-Forwarded-For HTTP header) to identify the IP address of a client, which makes it easier for remote attackers to spoof the source IP and bypass voting restrictions.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="EVULN" url="http://evuln.com/vulns/131/summary.html">EV0131</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1603">ADV-2006-1603</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19899">19899</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26154">
advancedpoll-header-spoofing(26154)</ref></refs><vuln_soft><prod name="Advanced Poll" vendor="Advanced Poll"><vers num="2.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-01-05" name="CVE-2006-2132" published="2006-05-01" seq="2006-2132" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in detail.asp in DUclassified allows remote attackers to execute arbitrary SQL commands via the iPro parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECURITY FOCUS" url="http://downloads.securityfocus.com/vulnerabilities/exploits/duclassified-detail.asp-sql-inj.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17722">17722</ref></refs><vuln_soft><prod name="DUclassified" vendor="DUware"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-2133" published="2006-05-01" seq="2006-2133" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in BoonEx Barracuda 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) link_dir_target and (2) link_id_target parameter, possibly involving the link_edit functionality.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BLOGSPOT" url="http://pridels.blogspot.com/2006/04/barracuda-vuln.html">Barracuda vuln. </ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26175">
barracuda-index-sql-injection(26175)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/barracuda-vuln.html"></ref></refs><vuln_soft><prod name="Barracuda" vendor="BoonEx"><vers num="1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-29" modified="2006-05-02" name="CVE-2006-2134" published="2006-05-02" seq="2006-2134" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.</descript></desc><sols><sol source="nvd">Successful exploitation requires that &quot;register_globals&quot; is enabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://milw0rm.com/exploits/1728">exploit 1728</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1585">ADV-2006-1585</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19892">19892</ref><ref source="BID" url="http://www.securityfocus.com/bid/17763">17763</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26279">kbmod-phpbb-kbconstants-file-include(26279)</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.2" prev="1"/><vers num="2.0.1"/><vers num="2.0.0"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta1"/><vers num="1.4.4"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4.0"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.0.1"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-2135" published="2006-05-02" seq="2006-2135" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.php in Ruperts News allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript></desc><sols><sol source="nvd">Successful exploitation requires that magic_quotes_gpc is set to off.
</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="EVULN" url="http://evuln.com/vulns/128/">EV0128</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1580">ADV-2006-1580</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19895">19895</ref><ref source="BID" url="http://www.securityfocus.com/bid/17758">17758</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26144">rupertsnewsscript-login-sql-injection(26144)</ref></refs><vuln_soft><prod name="Ruperts News" vendor="Ruperts News"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-2136" published="2006-05-02" seq="2006-2136" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in news.php in AZNEWS allows remote attackers to execute arbitrary SQL commands via the ID parameter.</descript></desc><sols><sol source="nvd">Other versions of this product may also be affected by this vulnerability.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="EVULN" url="http://evuln.com/vulns/126/">EV0126</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1579">ADV-2006-1579</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19888">19888</ref><ref source="BID" url="http://www.securityfocus.com/bid/17761">17761</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016036">1016036</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26136">aznews-news-sql-injection(26136)</ref></refs><vuln_soft><prod name="AZNEWS" vendor="AZNEWS"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-29" modified="2006-05-02" name="CVE-2006-2137" published="2006-05-02" seq="2006-2137" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in master.php in OpenPHPNuke and 2.3.3 earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
OpenPHPNuke, OpenPHPNuke, 2.3.5</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://milw0rm.com/exploits/1727">exploit 1727</ref><ref patch="1" source="OPEN PHP NUKE" url="http://www.openphpnuke.com/system/article/index.php?opnparams=B3YBZAI3BWgEbFU0"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1575">ADV-2006-1575</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19893">19893</ref><ref source="BID" url="http://www.securityfocus.com/bid/17772">17772</ref><ref source="OSVDB" url="http://www.osvdb.org/25140">25140</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26183">openphpnuke-master-file-include(26183)</ref></refs><vuln_soft><prod name="OpenPHPNuke" vendor="OpenPHPNuke"><vers num="2.3.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-28" modified="2006-05-03" name="CVE-2006-2138" published="2006-05-02" seq="2006-2138" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.29 allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432398/100/0/threaded">20060428 Neomail.pl Local Cross Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/17728">17728</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19906">19906</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1590">ADV-2006-1590</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26127">neomail-sessionid-xss(26127)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/827">827</ref></refs><vuln_soft><prod name="NeoMail" vendor="NeoMail"><vers num="1.29"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-30" modified="2006-05-03" name="CVE-2006-2139" published="2006-05-02" seq="2006-2139" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in PHP Newsfeed 20040723 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to (a) deltables.php, (2) select, (3) header, (4) url, (5) source, or (6) time parameters to (b) manualsubmit.php, (7) num parameter to (c) delete.php, or (8) tablename parameter to (d) searchnews.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/129/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1574">ADV-2006-1574</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19904">19904</ref><ref source="BID" url="http://www.securityfocus.com/bid/17757">17757</ref><ref source="OSVDB" url="http://www.osvdb.org/25132">25132</ref><ref source="OSVDB" url="http://www.osvdb.org/25133">25133</ref><ref source="OSVDB" url="http://www.osvdb.org/25134">25134</ref><ref source="OSVDB" url="http://www.osvdb.org/25135">25135</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26205">phpnewsfeed-multiple-sql-injection(26205)</ref></refs><vuln_soft><prod name="PHP Newsfeed" vendor="WilsonNCAreaBusinesses"><vers num="2004-07-23"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-30" modified="2006-05-03" name="CVE-2006-2140" published="2006-05-02" seq="2006-2140" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in OrbitHYIP 2.0 and earlier allow remote attackers to inject arbitrary web script via the (1) referral parameter to signup.php or (2) id parameter to members.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/orbithyip-xss.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1583">ADV-2006-1583</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19877">19877</ref><ref source="BID" url="http://www.securityfocus.com/bid/17766">17766</ref><ref source="OSVDB" url="http://www.osvdb.org/25141">25141</ref><ref source="OSVDB" url="http://www.osvdb.org/25142">25142</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26163">orbithyip-signup-members-xss(26163)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/orbithyip-xss.html"></ref></refs><vuln_soft><prod name="OrbitHYIP" vendor="Orbitscripts"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-30" modified="2006-05-03" name="CVE-2006-2141" published="2006-05-02" seq="2006-2141" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in popup_image in Collaborative Portal Server (CPS) 3.4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the pos argument.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/cps-340-xss.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19879">19879</ref><ref source="BID" url="http://www.securityfocus.com/bid/17774">17774</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1589">ADV-2006-1589</ref><ref source="OSVDB" url="http://www.osvdb.org/25144">25144</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26155">cps-pos-parameter-xss(26155)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/cps-340-xss.html"></ref></refs><vuln_soft><prod name="Collaborative Portal Server" vendor="Collaborative Portal Server Project"><vers num="3.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-01" modified="2006-05-03" name="CVE-2006-2142" published="2006-05-02" seq="2006-2142" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in classes/adodbt/sql.php in Limbo CMS 1.04 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/1729"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1584">ADV-2006-1584</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19891">19891</ref><ref source="BID" url="http://www.securityfocus.com/bid/17760">17760</ref><ref source="OSVDB" url="http://www.osvdb.org/25155">25155</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26196">webinsta-limbo-sql-fil-include(26196)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/446142/100/0/threaded">20060913 Limbo - Lite Mambo CMS Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="Limbo CMS" vendor="Limbo CMS"><vers num="1.0.4.2"/><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-29" modified="2006-05-04" name="CVE-2006-2143" published="2006-05-02" seq="2006-2143" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in TextFileBB 1.0.16 allow remote attackers to inject arbitrary web script or HTML via Javascript events such as &quot;onmouseover&quot; in the (1) color, (2) size, or (3) url bbcode tags.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432461/100/0/threaded">20060429 TextFileBB 1.0.16 Multiple XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/17750">17750</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19883">19883</ref><ref source="OSVDB" url="http://www.osvdb.org/25123">25123</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016013">1016013</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26129">textfilebb-bbcode-tags-xss(26129)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/828">828</ref></refs><vuln_soft><prod name="TextFileBB" vendor="Jcink"><vers num="1.0.16"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-01" modified="2006-05-03" name="CVE-2006-2144" published="2006-05-02" seq="2006-2144" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in kopf.php in DMCounter 0.9.2-b allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432572/100/0/threaded">20060501 DMCounter Remote File Include</ref><ref source="BID" url="http://www.securityfocus.com/bid/17756">17756</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1599">ADV-2006-1599</ref><ref source="OSVDB" url="http://www.osvdb.org/25152">25152</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016014">1016014</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19918">19918</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-05/0181.html">20060509 Hackmaster Group DMCounter Remote File Include</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26207">dmcounter-kopf-file-include(26207)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/826">826</ref></refs><vuln_soft><prod name="DMCounter" vendor="DMCounter"><vers num="0.9.2b"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-29" modified="2006-05-03" name="CVE-2006-2145" published="2006-05-02" seq="2006-2145" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in index.php in HB-NS 1.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) topic or (2) id parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/127/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17759">17759</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19896">19896</ref><ref source="OSVDB" url="http://www.osvdb.org/25163">25163</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016037">1016037</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26139">hbns-index-sql-injection(26139)</ref></refs><vuln_soft><prod name="HB-NS" vendor="Harold Bakker"><vers num="1.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-29" modified="2006-05-03" name="CVE-2006-2146" published="2006-05-02" seq="2006-2146" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in HB-NS 1.1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) poster_name, (2) poster_email, (3) poster_homepage, or (4) message parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/127/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17759">17759</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19896">19896</ref><ref source="OSVDB" url="http://www.osvdb.org/25164">25164</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016037">1016037</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26138">hbns-index-xss(26138)</ref></refs><vuln_soft><prod name="HB-NS" vendor="Harold Bakker"><vers num="1.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-30" modified="2006-05-03" name="CVE-2006-2147" published="2006-05-02" seq="2006-2147" severity="Low" type="CVE"><desc><descript source="cve">resmgrd in resmgr for SUSE Linux and other distributions does not properly handle when access to a USB device is granted by using &quot;usb:&lt;bus&gt;,&lt;dev&gt;&quot; notation, which grants access to all USB devices and allows local users to bypass intended restrictions.  NOTE: this is a different vulnerability than CVE-2005-4788.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Feb/0008.html">SUSE-SR:2006:004</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1047">DSA-1047</ref><ref source="BID" url="http://www.securityfocus.com/bid/17752">17752</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1592">ADV-2006-1592</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19887">19887</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19898">19898</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26160">resmgr-security-bypass(26160)</ref></refs><vuln_soft><prod name="resmgrd" vendor="resmgr"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-30" modified="2006-05-03" name="CVE-2006-2148" published="2006-05-02" seq="2006-2148" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in client.c in CGI:IRC (CGIIRC) before 0.5.8 might allow remote attackers to execute arbitrary code via (1) cookies or (2) the query string.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://cvs.cgiirc.org/chngview?cn=263"></ref><ref source="" url="http://cvs.cgiirc.org/chngview?cn=283"></ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=365680"></ref><ref source="" url="http://cvs.cgiirc.org/timeline?d=300&amp;e=2006-Apr-30&amp;c=2&amp;px=&amp;s=0&amp;dm=1&amp;x=1&amp;m=1"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1607">ADV-2006-1607</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19922">19922</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1052">DSA-1052</ref><ref source="BID" url="http://www.securityfocus.com/bid/17799">17799</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19985">19985</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26173">cgiirc-client-bo(26173)</ref></refs><vuln_soft><prod name="CGIIRC" vendor="CGIIRC"><vers num="0.5.7"/><vers num="0.5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-01" modified="2006-05-03" name="CVE-2006-2149" published="2006-05-03" seq="2006-2149" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in sources/lostpw.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the CONFIG[path] parameter, as demonstrated by including a GIF that contains PHP code.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/1732"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1587">ADV-2006-1587</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19911">19911</ref><ref source="OSVDB" url="http://www.osvdb.org/25158">25158</ref><ref source="BID" url="http://www.securityfocus.com/bid/17940">
17940</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26189">
aardvark-lostpw-join-file-include(26189)</ref></refs><vuln_soft><prod name="Aardvark Topsites PHP" vendor="Avatic"><vers num="4.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-28" modified="2006-05-03" name="CVE-2006-2150" published="2006-05-03" seq="2006-2150" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in top/list.php in phpBB TopList 1.3.8 and earlier allows remote attackers to include arbitrary files via the returnpath parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432453/100/0/threaded">20060428 TopList &lt;= 1.3.8 (PHPBB Hack) Remote File Inclusion Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/25294">25294</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26172">toplist-toplist-list-file-include(26172)</ref></refs><vuln_soft><prod name="phpBB TopList" vendor="phpBB Group"><vers num="1.3.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-03" name="CVE-2006-2151" published="2006-05-03" seq="2006-2151" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/1724"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1601">ADV-2006-1601</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19884">19884</ref><ref source="OSVDB" url="http://www.osvdb.org/25260">25260</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26172">toplist-toplist-list-file-include(26172)</ref></refs><vuln_soft><prod name="phpBB TopList" vendor="phpBB Group"><vers num="1.3.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-03" name="CVE-2006-2152" published="2006-05-03" seq="2006-2152" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/1725"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1600">ADV-2006-1600</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19905">19905</ref><ref source="BID" url="http://www.securityfocus.com/bid/17745">17745</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26217">adv-guestbook-addentry-file-include(26217)</ref></refs><vuln_soft><prod name="phpBB Advanced Guestbook" vendor="phpBB Group"><vers num="2.4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-03" name="CVE-2006-2153" published="2006-05-03" seq="2006-2153" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in HTM_PASSWD in DirectAdmin Hosting Management allows remote attackers to inject arbitrary web script or HTML via the domain parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432459/100/0/threaded">20060427 XSS Attack On DirectAdmin Hosting Managment</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1576">ADV-2006-1576</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19885">19885</ref><ref source="SREASON" url="http://securityreason.com/securityalert/830">830</ref></refs><vuln_soft><prod name="DirectAdmin" vendor="JBMC Software"><vers num="1.26.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-03" name="CVE-2006-2154" published="2006-05-03" seq="2006-2154" severity="High" type="CVE"><desc><descript source="cve">EMC Retrospect for Windows 6.5 before 6.5.382, 7.0 before 7.0.344, and 7.5 before 7.5.1.105 does not drop privileges before opening files, which allows local users to execute arbitrary code via the File&gt;Open dialog.</descript></desc><sols><sol source="nvd">Apply Retrospect Driver Update 7.5.1.105.
Apply Application Security Update 7.0.344 (requires Retrospect 7.0.326 or Retrospect Express 7.0.301).
Apply Application Security Update 6.5.382 (requires Retrospect 6.5.350 or Retrospect Express 6.5.350).</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1612">ADV-2006-1612</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19850">19850</ref><ref source="BID" url="http://www.securityfocus.com/bid/17798">17798</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26226">retrospect-fileopen-privilege-escalation(26226)</ref></refs><vuln_soft><prod name="Retrospect" vendor="EMC Corporation"><vers edition="Windows" num="6.5" prev="1"/><vers edition="Windows" num="7.0" prev="1"/><vers edition="Windows" num="7.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-03" name="CVE-2006-2155" published="2006-05-03" seq="2006-2155" severity="Medium" type="CVE"><desc><descript source="cve">EMC Retrospect for Windows 6.5 before 6.5.382, 7.0 before 7.0.344, and 7.5 before 7.5.1.105 allows local users to execute arbitrary code by replacing the Retrospect.exe file, possibly due to improper file permissions.</descript></desc><sols><sol source="nvd">Retrospect 7.5:
Apply Retrospect Driver Update 7.5.1.105.
http://ftp.dantz.com/pub/updates/ru751105.exe

Retrospect 7.0:
Apply Application Security Update 7.0.344 (requires Retrospect 7.0.326 or Retrospect Express 7.0.301).
http://download.dantz.com/archives/Retro-EN_7_0_344.exe

Retrospect 6.5:
Apply Application Security Update 6.5.382 (requires Retrospect 6.5.350 or Retrospect Express 6.5.350).
http://download.dantz.com/archives/Retro-EN_6_5_382.exe</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref source="" url="http://kb.dantz.com/display/2n/articleDirect/index.asp?aid=9507&amp;r=0.7344324"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1612">ADV-2006-1612</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19850">19850</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26227">retrospect-code-execution(26227)</ref></refs><vuln_soft><prod name="Retrospect" vendor="EMC Corporation"><vers edition="Windows" num="6.5" prev="1"/><vers edition="Windows" num="7.0" prev="1"/><vers edition="Windows" num="7.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-03" name="CVE-2006-2156" published="2006-05-03" seq="2006-2156" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in help/index.php in X7 Chat 2.0 and earlier allows remote attackers to include arbitrary files via .. (dot dot) sequences in the help_file parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432716/100/0/threaded">20060502 X7 Chat &lt;=2.0 remote commands execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/17777">17777</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19886">19886</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1608">ADV-2006-1608</ref><ref source="OSVDB" url="http://www.osvdb.org/25149">25149</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26218">x7chat-index-file-include(26218)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1738">
1738</ref><ref source="SREASON" url="http://securityreason.com/securityalert/829">829</ref></refs><vuln_soft><prod name="X7 Chat" vendor="X7 Group"><vers num="1.3.6"/><vers num="1.3.5b"/><vers num="1.3.4b"/><vers num="1.3.3b"/><vers num="1.3.2b"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-03" name="CVE-2006-2157" published="2006-05-03" seq="2006-2157" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in gallery.php in Plogger Beta 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter, when the level is set to &quot;slideshow&quot;.  NOTE: This is a different vulnerability than CVE-2005-4246.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://retrogod.altervista.org/plogger_b21_sql_xpl.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26273">plogger-gallery-sql-injection(26273)</ref></refs><vuln_soft><prod name="Plogger" vendor="Plogger"><vers num="2.1 Beta" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-03" name="CVE-2006-2158" published="2006-05-03" seq="2006-2158" severity="Medium" type="CVE"><desc><descript source="cve">Dynamic variable evaluation vulnerability in index.php in Stadtaus Guestbook Script 1.7 and earlier, when register_globals is enabled, allows remote attackers to modify arbitrary program variables via parameters, which are evaluated as PHP variable variables, as demonstrated by performing PHP remote file inclusion using the include_files array parameter.</descript></desc><sols><sol source="nvd">Download Guestbook Script 1.9 </sol></sols><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://retrogod.altervista.org/gbs_17_xpl_pl.html"></ref><ref source="" url="http://www.stadtaus.com/forum/t-2600.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17845">17845</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1660">ADV-2006-1660</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19957">19957</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26252">guestbook-includefiles-file-include(26252)</ref></refs><vuln_soft><prod name="Guestbook Script" vendor="Stadtaus"><vers num="1.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-02" modified="2006-05-03" name="CVE-2006-2159" published="2006-05-03" seq="2006-2159" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in help.php in Russcom Network Loginphp allows remote attackers to spoof e-mails and inject MIME headers via CRLF sequences in the email address.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432729/100/0/threaded">20060502 Russcom.net Loginphp multiple vulnerabilties</ref><ref source="BID" url="http://www.securityfocus.com/bid/17787">17787</ref><ref source="OSVDB" url="http://www.osvdb.org/25214">25214</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19930">19930</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26250">russcom-loginphp-help-mail-relay(26250)</ref></refs><vuln_soft><prod name="Loginphp" vendor="Russcom Network"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-02" modified="2006-05-09" name="CVE-2006-2160" published="2006-05-03" seq="2006-2160" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Russcom Network Loginphp (Russcom.Loginphp) allows remote attackers to inject arbitrary web script or HTML via the username field when registering.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432729/100/0/threaded">20060502 Russcom.net Loginphp multiple vulnerabilties</ref><ref source="BID" url="http://www.securityfocus.com/bid/17785">17785</ref><ref source="OSVDB" url="http://www.osvdb.org/25213">25213</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19930">19930</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26249">russcom-loginphp-register-xss(26249)</ref></refs><vuln_soft><prod name="Loginphp" vendor="Russcom Network"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-03" modified="2006-08-28" name="CVE-2006-2161" published="2006-05-09" seq="2006-2161" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in (1) TZipBuilder 1.79.03.01, (2) Abakt 0.9.2 and 0.9.3-beta1, (3) CAM UnZip 4.0 and 4.3, and possibly other products, allows user-assisted attackers to execute arbitrary code via a ZIP archive that contains a file with a long file name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433257/100/0/threaded">20060508 Secunia Research: TZipBuilder ZIP File Handling Buffer OverflowVulnerability</ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2006-26/advisory"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17880">17880</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1687">ADV-2006-1687</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19945">19945</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016064">1016064</ref><ref adv="1" patch="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=114771024009857&amp;w=2">20060515 Secunia Research: Abakt ZIP File Handling Buffer</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/434019/100/0/threaded">20060515 Secunia Research: Abakt ZIP File Handling Buffer OverflowVulnerability</ref><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2006-31/advisory/"></ref><ref source="" url="http://www.xs4all.nl/~edienske/abakt/releases.html#0.9.3-RC1"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1805">ADV-2006-1805</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016107">1016107</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20068">20068</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/434520/100/0/threaded">20060519 Secunia Research: CAM UnZip ZIP File Handling Buffer OverflowVulnerability</ref><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2006-34/advisory/"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1865">ADV-2006-1865</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19946">19946</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/26549">camunzip-archive-bo(26549)</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/26435">abakt-zip-bo(26435)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26275">
tzipbuilder-zip-bo(26275)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/853">853</ref></refs><vuln_soft><prod name="Abakt" vendor="Erik Dienske"><vers num="0.9.3 Beta1"/><vers num="0.9.2"/></prod><prod name="TZipBuilder" vendor="Roger Aelbrecht"><vers num="1.79.03.01"/></prod><prod name="CAM UnZip" vendor="CAM Development"><vers num="4.3"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-03" name="CVE-2006-2162" published="2006-05-03" seq="2006-2162" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in CGI scripts in Nagios 1.x before 1.4 and 2.x before 2.3 allows remote attackers to execute arbitrary code via a negative content length (Content-Length) HTTP header.</descript></desc><sols><sol source="nvd">Upgrade to versions 1.4 and 2.3</sol></sols><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="https://sourceforge.net/mailarchive/forum.php?thread_id=10297806&amp;forum_id=7890"></ref><ref source="" url="http://www.nagios.org/development/changelog.php"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-07.xml">GLSA-200605-07</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-282-1">USN-282-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/17879">17879</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1662">ADV-2006-1662</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19991">19991</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19998">19998</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20013">20013</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1072">DSA-1072</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_05_19.html">SUSE-SR:2006:011</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20215">20215</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20247">20247</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26253">
nagios-multiple-scripts-bo(26253)</ref></refs><vuln_soft><prod name="Nagios" vendor="Nagios"><vers num="1.3" prev="1"/><vers num="2.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-04" name="CVE-2006-2163" published="2006-05-04" seq="2006-2163" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart 3.33 and earlier allows remote attackers to inject arbitrary web script or HTML via the setbackurl parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/pinnacle-cart-xss.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17794">17794</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1609">ADV-2006-1609</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19878">19878</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26162">
pinnaclecart-setbackurl-xss(26162)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/pinnacle-cart-xss.html"></ref></refs><vuln_soft><prod name="Pinnacle Cart" vendor="Desert Dog Software"><vers num="3.33"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-04" name="CVE-2006-2164" published="2006-05-04" seq="2006-2164" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category_id parameter in (a) store_special_offers.php and (b) store.php, and (2) prod_id parameter in (c) cart.php and (d) product_info.php.  NOTE: this issue also produces resultant full path disclosure from invalid SQL queries.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/05/avactis-shopping-cart-vuln.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/25637">
25637</ref><ref source="OSVDB" url="http://www.osvdb.org/25638">
25638</ref><ref source="OSVDB" url="http://www.osvdb.org/25639">
25639</ref><ref source="OSVDB" url="http://www.osvdb.org/25640">
25640</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26178">
avactis-multiple-scripts-sql-injection(26178)</ref><ref source="" url="http://pridels0.blogspot.com/2006/05/avactis-shopping-cart-vuln.html"></ref></refs><vuln_soft><prod name="Avactis Shopping Cart" vendor="Pentasoft Corp."><vers num="0.1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-04" name="CVE-2006-2165" published="2006-05-04" seq="2006-2165" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) category_id parameter in (a) store_special_offers.php and (b) store.php and (2) prod_id parameter in (c) product_info.php.  NOTE: this issue might be resultant from SQL injection.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/05/avactis-shopping-cart-vuln.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/25641">
25641</ref><ref source="OSVDB" url="http://www.osvdb.org/25642">
25642</ref><ref source="OSVDB" url="http://www.osvdb.org/25643">
25643</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26179">
avactis-multiple-scripts-xss(26179)</ref><ref source="" url="http://pridels0.blogspot.com/2006/05/avactis-shopping-cart-vuln.html"></ref></refs><vuln_soft><prod name="Avactis Shopping Cart" vendor="Pentasoft Corp."><vers num="0.1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-23" name="CVE-2006-2166" published="2006-05-04" seq="2006-2166" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the HTTP management interface in Cisco Unity Express (CUE) 2.2(2) and earlier, when running on any CUE Advanced Integration Module (AIM) or Network Module (NM), allows remote authenticated attackers to reset the password for any user with an expired password.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20060501-cue.shtml">20060501 Cisco Unity Express Expired Password Reset Privilege Escalation</ref><ref source="BID" url="http://www.securityfocus.com/bid/17775">17775</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1613">ADV-2006-1613</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016015">1016015</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19881">19881</ref><ref source="OSVDB" url="http://www.osvdb.org/25165">
25165</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26165">
cisco-cue-privilege-escalation(26165)</ref></refs><vuln_soft><prod name="Cisco Unity Express" vendor="Cisco"><vers num="2.2(2)"/><vers num="2.1(1)"/><vers num="1.1(1)"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-04" name="CVE-2006-2167" published="2006-05-04" seq="2006-2167" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in SloughFlash SF-Users 1.0, possibly in register.php, allows remote attackers to inject arbitrary web script or HTML by setting the username field to contain JavaScript in the SRC attribute of an IMG element.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432727/100/0/threaded">20060502 SF-Users V1.0 XSS injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/17783">17783</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1637">ADV-2006-1637</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19932">19932</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26215">
sfusers-register-xss(26215)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/831">831</ref></refs><vuln_soft><prod name="SF-Users" vendor="SloughFlash"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-10" name="CVE-2006-2168" published="2006-05-04" seq="2006-2168" severity="High" type="CVE"><desc><descript source="cve">FileProtection Express 1.0.1 and earlier allows remote attackers to bypass authentication via a cookie with an Admin value of 1.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432728/100/0/threaded">20060502 FileProtection Express &lt;= 1.0.1 authentification bypass</ref><ref source="BID" url="http://www.securityfocus.com/bid/17786">17786</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26225">
fileprotectionexpress-bypass-auth(26225)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/835">835</ref></refs><vuln_soft><prod name="FileProtection Express" vendor="FileProtection Express"><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-04" name="CVE-2006-2169" published="2006-05-04" seq="2006-2169" severity="Medium" type="CVE"><desc><descript source="cve">RT: Request Tracker 3.5.HEAD allows remote attackers to obtain sensitive information via the Rows parameter in Dist/Display.html, which reveals the installation path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/04/rt-request-tracker-vuln.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26164">
rtrequesttracker-display-info-disclosure(26164)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/rt-request-tracker-vuln.html"></ref></refs><vuln_soft><prod name="Request Tracker" vendor="Best Practical Solutions"><vers num="3.5.HEAD"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0" discovered="2005-11-12" modified="2007-08-13" name="CVE-2006-2170" published="2006-05-04" seq="2006-2170" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in ArgoSoft FTP Server 1.4.3.6 allows remote attackers to execute arbitrary code via Unicode in the RNTO command, as demonstrated by the Infigo FTPStress Fuzzer.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><access/><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=114658586018818&amp;w=2">20060502 FTP Fuzzer</ref><ref source="" url="http://www.infigo.hr/en/in_focus/tools"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17789">17789</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1639">ADV-2006-1639</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19934">19934</ref><ref source="OSVDB" url="http://www.osvdb.org/25216">25216</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26197">argosoft-ftp-rnto-bo(26197)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-05/0139.html">20060508 INFIGO-2006-05-03: Multiple FTP Servers vulnerabilities</ref><ref source="" url="http://www.infigo.hr/hr/in_focus/advisories/INFIGO-2006-05-03"></ref></refs><vuln_soft><prod name="FTP Server" vendor="ArGoSoft"><vers num="1.4.3.5"/><vers num="1.4.2.8"/><vers num="1.4.2.7"/><vers num="1.4.2.2"/><vers num="1.4.2.1"/><vers num="1.4.2"/><vers num="1.4.1.9"/><vers num="1.4.1.8"/><vers num="1.4.1.7"/><vers num="1.4.1.6"/><vers num="1.4.1.5"/><vers num="1.4.1.4"/><vers num="1.4.1.3"/><vers num="1.4.1.2"/><vers num="1.4.1.1"/><vers num="1.4.2.29"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-11-12" modified="2006-05-04" name="CVE-2006-2171" published="2006-05-04" seq="2006-2171" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in WDM.exe in WarFTPD allows remote attackers to execute arbitrary code via unspecified arguments, as demonstrated by the Infigo FTPStress Fuzzer.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=114658586018818&amp;w=2">20060502 FTP Fuzzer</ref><ref source="" url="http://www.infigo.hr/en/in_focus/tools"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17803">17803</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-05/0139.html">
20060508 INFIGO-2006-05-03: Multiple FTP Servers vulnerabilities</ref><ref source="" url="http://www.infigo.hr/hr/in_focus/advisories/INFIGO-2006-05-03"></ref><ref source="OSVDB" url="http://www.osvdb.org/25220">
25220</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26304">
warftpd-wdm-bo(26304)</ref></refs><vuln_soft><prod name="WarFTPd" vendor="Jgaa"><vers num="1.82 RC9"/><vers num="1.82 RC10"/><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-11-12" modified="2006-05-04" name="CVE-2006-2172" published="2006-05-04" seq="2006-2172" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Gene6 FTP Server 3.1.0 allows remote authenticated attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to (1) MKD or (2) XMKD, as demonstrated by the Infigo FTPStress Fuzzer.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432839/100/0/threaded">20060503 Re: FTP Fuzzer</ref><ref source="" url="http://www.infigo.hr/en/in_focus/tools"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17810">17810</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1658">ADV-2006-1658</ref><ref source="OSVDB" url="http://www.osvdb.org/25238">25238</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19965">19965</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26237">gene6-ftp-mkd-xmkd-dos(26237)</ref></refs><vuln_soft><prod name="G6 FTP Server" vendor="Gene6"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" discovered="2005-11-12" modified="2007-08-13" name="CVE-2006-2173" published="2006-05-04" seq="2006-2173" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in FileZilla FTP Server 2.2.22 allows remote authenticated attackers to cause a denial of service and possibly execute arbitrary code via a long (1) PORT or (2) PASS followed by the MLSD command, or (2) the remote server interface, as demonstrated by the Infigo FTPStress Fuzzer.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=114658586018818&amp;w=2">20060502 FTP Fuzzer</ref><ref source="" url="http://www.infigo.hr/en/in_focus/tools"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17802">17802</ref><ref source="OSVDB" url="http://www.osvdb.org/25221">25221</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-05/0139.html">20060508 INFIGO-2006-05-03: Multiple FTP Servers vulnerabilities</ref><ref source="" url="http://www.infigo.hr/hr/in_focus/advisories/INFIGO-2006-05-03"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26303">filezilla-port-pass-dos(26303)</ref></refs><vuln_soft><prod name="FileZilla Server" vendor="FileZilla"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-02" modified="2006-05-04" name="CVE-2006-2174" published="2006-05-04" seq="2006-2174" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in admin/server_day_stats.php in Virtual Hosting Control System (VHCS) allow remote attackers to inject arbitrary web script or HTML via the (1) day, (2) month, or (3) year parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/432711">20060502 VHCS --- Virtual Hosting Control System Cross Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/17790">17790</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19940">19940</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1634">ADV-2006-1634</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26209">
vhcs-serverdaystats-xss(26209)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/832">832</ref></refs><vuln_soft><prod name="Virtual Hosting Control System" vendor="Virtual Hosting Control System"><vers num="2.4.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-03" modified="2006-05-04" name="CVE-2006-2175" published="2006-05-04" seq="2006-2175" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in FtrainSoft Fast Click 2.3.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) show.php or (2) top.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref source="" url="http://www.aria-security.net/advisory/fc/fastclick.txt"></ref><ref source="" url="http://milw0rm.com/exploits/1740"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1631">ADV-2006-1631</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19923">19923</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432963/100/0/threaded">20060502 Fast Click &lt;= 2.3.8 Remote File Inclusion</ref><ref source="BID" url="http://www.securityfocus.com/bid/17813">17813</ref><ref source="OSVDB" url="http://www.osvdb.org/25192">25192</ref><ref source="OSVDB" url="http://www.osvdb.org/25289">25289</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016021">1016021</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26235">fastclick-multiple-file-include(26235)</ref></refs><vuln_soft><prod name="Fast Click" vendor="FtrainSoft"><vers num="2.3.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-02" modified="2006-05-04" name="CVE-2006-2176" published="2006-05-04" seq="2006-2176" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in links.php in PHP Linkliste 1.0b allow remote attackers to inject arbitrary web script or HTML via the (1) new_input, (2) new_url, or (3) new_name parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://d4igoro.blogspot.com/2006/05/php-linkliste-10b-xss.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1627">ADV-2006-1627</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19925">19925</ref><ref source="BID" url="http://www.securityfocus.com/bid/17828">17828</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26229">
phplinkliste-linkliste-xss(26229)</ref></refs><vuln_soft><prod name="PHP Linkliste" vendor="PHP Design X"><vers num="1.0b"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-02" modified="2006-05-04" name="CVE-2006-2177" published="2006-05-04" seq="2006-2177" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in viewcat.php in geoBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432720/100/0/threaded">20060502 geoBlog Mutiple XSS Vulnerability</ref><ref source="" url="http://www.subjectzero.net/research/geoblog.htm"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17784">17784</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26204">
geoblog-viewcat-xss(26204)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/833">833</ref></refs><vuln_soft><prod name="geoBlog" vendor="BitDamaged"><vers num="MOD_1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-01" modified="2006-06-05" name="CVE-2006-2178" published="2006-05-04" seq="2006-2178" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to login.asp, (2) ProductIndex parameter to browse0.htm, (3) rowcolor parameter to result.asp, or (4) heading parameter to result.asp.  NOTE: vectors 1 and 2 might be resultant from SQL injection.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/05/cyberbuild-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1630">ADV-2006-1630</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19889">19889</ref><ref source="BID" url="http://www.securityfocus.com/bid/17829">17829</ref><ref source="OSVDB" url="http://www.osvdb.org/25197">25197</ref><ref source="OSVDB" url="http://www.osvdb.org/25198">25198</ref><ref source="OSVDB" url="http://www.osvdb.org/25199">25199</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26202">
cyberbuild-multiple-xss(26202)</ref><ref source="" url="http://pridels0.blogspot.com/2006/05/cyberbuild-vuln.html"></ref></refs><vuln_soft><prod name="CyberOffice Warehouse Builder" vendor="SmartWin Technology"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-01" modified="2006-05-04" name="CVE-2006-2179" published="2006-05-04" seq="2006-2179" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in CyberBuild allow remote attackers to execute arbitrary SQL commands via the (1) SessionID parameter to login.asp or (2) ProductIndex parameter to browse0.htm.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/05/cyberbuild-vuln.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1630">ADV-2006-1630</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19889">19889</ref><ref source="BID" url="http://www.securityfocus.com/bid/17829">17829</ref><ref source="OSVDB" url="http://www.osvdb.org/25195">25195</ref><ref source="OSVDB" url="http://www.osvdb.org/25196">25196</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26201">
cyberbuild-multiple-sql-injection(26201)</ref><ref source="" url="http://pridels0.blogspot.com/2006/05/cyberbuild-vuln.html"></ref></refs><vuln_soft><prod name="CyberOffice Warehouse Builder" vendor="SmartWin Technology"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" discovered="2005-11-12" modified="2008-01-03" name="CVE-2006-2180" published="2006-05-04" seq="2006-2180" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Golden FTP Server Pro 2.70 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long argument to the (1) NLST or (2) APPE commands, as demonstrated by the Infigo FTPStress Fuzzer.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=114658586018818&amp;w=2">20060502 FTP Fuzzer</ref><ref source="" url="http://www.infigo.hr/en/in_focus/tools"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17801">17801</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1640">ADV-2006-1640</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19917">19917</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-05/0139.html">20060508 INFIGO-2006-05-03: Multiple FTP Servers vulnerabilities</ref><ref source="" url="http://www.infigo.hr/hr/in_focus/advisories/INFIGO-2006-05-03"></ref><ref source="OSVDB" url="http://www.osvdb.org/25217">25217</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26195">goldenftp-nlst-appe-bo(26195)</ref></refs><vuln_soft><prod name="Golden FTP Server" vendor="KMiNT21 Software"><vers num="2.70"/><vers num="1.32b"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" discovered="2006-05-03" modified="2007-08-13" name="CVE-2006-2181" published="2006-05-04" seq="2006-2181" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Albinator 2.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to dlisting.php or (2) preloadSlideShow parameter to showpic.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/05/albinator-208-remote-file-inclusion.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17826">17826</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1643">ADV-2006-1643</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19952">19952</ref><ref source="OSVDB" url="http://www.osvdb.org/25242">25242</ref><ref source="OSVDB" url="http://www.osvdb.org/25243">25243</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26240">albinator-multiple-xss(26240)</ref><ref source="" url="http://pridels0.blogspot.com/2006/05/albinator-208-remote-file-inclusion.html"></ref></refs><vuln_soft><prod name="Albinator" vendor="Albinator"><vers num="2.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-03" modified="2006-05-04" name="CVE-2006-2182" published="2006-05-04" seq="2006-2182" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in (1) eday.php, (2) eshow.php, or (3) forgot.php in albinator 2.0.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the Config_rootdir parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2006/05/albinator-208-remote-file-inclusion.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17825">17825</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1643">ADV-2006-1643</ref><ref source="OSVDB" url="http://www.osvdb.org/25239">25239</ref><ref source="OSVDB" url="http://www.osvdb.org/25240">25240</ref><ref source="OSVDB" url="http://www.osvdb.org/25241">25241</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19952">19952</ref><ref source="" url="http://pridels0.blogspot.com/2006/05/albinator-208-remote-file-inclusion.html"></ref></refs><vuln_soft><prod name="Albinator" vendor="Albinator"><vers num="2.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-12-14" modified="2006-05-04" name="CVE-2006-2183" published="2006-05-04" seq="2006-2183" severity="High" type="CVE"><desc><descript source="cve">Untrusted search path vulnerability in Truecrypt 4.1, when running suid root on Linux, allows local users to execute arbitrary commands and gain privileges via a modified PATH environment variable that references a malicious mount command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><local/></range><refs><ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2006-April/003152.html">[Dailydave] 20060430 Non disclosure from security vendors: Truecrypt exemple</ref><ref patch="1" source="" url="http://www.truecrypt.org/history.php"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1591">ADV-2006-1591</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/25131">25131</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19903">19903</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26191">
truecrypt-execvp-gain-privileges(26191)</ref></refs><vuln_soft><prod name="TrueCrypt" vendor="TrueCrypt Foundation"><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-06-01" name="CVE-2006-2184" published="2006-05-04" seq="2006-2184" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in PHPKB Knowledge Base allows remote attackers to inject arbitrary web script or HTML via the searchkeyword parameter.  NOTE: the issue was originally disputed by the vendor, but on 20060519, the vendor notified CVE that &quot;We have fixed all the mentioned issues and now the search section of PHPKB script is free from any XSS issues.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://d4igoro.blogspot.com/2006/05/phpkb-knowledge-base-xss.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1628">ADV-2006-1628</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19913">19913</ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-May/000753.html">[VIM] 20060512 Vendor dispute of CVE-2006-2184</ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-May/000775.html">[VIM] 20060519 Resolved PHPKB vendor dispute (CVE-2006-2184)</ref></refs><vuln_soft><prod name="phpkb Knowledge Base" vendor="Chadha Software Technologies"><vers num="1.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-22" name="CVE-2006-2185" published="2006-05-22" seq="2006-2185" severity="Medium" type="CVE"><desc><descript source="cve">PORTAL.NLM in Novell Netware 6.5 SP5 writes the username and password in cleartext to the abend.log log file when the groupOperationsMethod function fails, which allows context-dependent attackers to gain privileges.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="NOVELL" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?2973698.htm">TID2973698</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1829">ADV-2006-1829</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016106">1016106</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/26488">netware-portal-information-disclosure(26488)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20288">20288</ref><ref source="BID" url="http://www.securityfocus.com/bid/18017">18017</ref><ref source="OSVDB" url="http://www.osvdb.org/25780">25780</ref></refs><vuln_soft><prod name="Netware" vendor="Novell"><vers num="6.5 SP5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-10" name="CVE-2006-2186" published="2006-05-04" seq="2006-2186" severity="Medium" type="CVE"><desc><descript source="cve">zenphoto 1.0.1 beta and earlier allow remote attackers to obtain sensitive information via a direct request for the (1) /photos/themes/default/ and (2) /photos/themes/testing/ URIs, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432718/100/0/threaded">20060502 zenphoto Multiple Path Disclosure and Cross Site Scripting Vulnerabilities</ref><ref patch="1" source="" url="http://zone14.free.fr/advisories/2/"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17779">17779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26220">
zenphoto-i-path-disclosure(26220)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/834">834</ref></refs><vuln_soft><prod name="zenphoto" vendor="Zenphoto"><vers num="1.0.1 Beta"/><vers num="1.0 Beta"/><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-04-02" modified="2006-05-05" name="CVE-2006-2187" published="2006-05-04" seq="2006-2187" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) a parameter in i.php, and the (2) album and (3) image parameters in index.php.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
zenphoto, zenphoto, 1.0.2 beta</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432718/100/0/threaded">20060502 zenphoto Multiple Path Disclosure and Cross Site Scripting Vulnerabilities</ref><ref adv="1" patch="1" source="ZONE14" url="http://zone14.free.fr/advisories/2/">zenphoto Multiple Path Disclosure and Cross Site Scripting Vulnerabilities</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17779">17779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26219">
zenphoto-index-i-xss(26219)</ref></refs><vuln_soft><prod name="Zenphoto" vendor="Zenphoto"><vers num="1.0.1 Beta" prev="1"/><vers num="1.0 Beta"/><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-05-02" modified="2007-01-05" name="CVE-2006-2188" published="2006-05-04" seq="2006-2188" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in CMScout 1.10 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Body field of a private message (PM), (2) BBCode, or (3) a forum post.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
CMScout, CMScout, 1.21</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432725/100/0/threaded">20060502 Cmscout &lt;= V1.10 multiple XSS attack vectors</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17796">17796</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016023">1016023</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19933">19933</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/25246">25246</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/25247">25247</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26223">
cmscout-messageform-xss(26223)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/838">838</ref></refs><vuln_soft><prod name="CMScout" vendor="CMScout"><vers num="1.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-02" modified="2006-05-05" name="CVE-2006-2189" published="2006-05-04" seq="2006-2189" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in search.php in Servous sBLOG 0.7.2 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.  NOTE: this issue can be used to trigger path disclosure.  In addition, it might be primary to vector 1 in CVE-2006-1135.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432724/100/0/threaded">20060502 sBlog SQL Injection and Path Disclosure Vulnerability</ref><ref source="SUBJECTZERO" url="http://www.subjectzero.net/research/sblog.htm">Vulnerability :sBlog SQL Injection and Path Disclosure Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/17782">17782</ref><ref source="OSVDB" url="http://www.osvdb.org/25612">25612</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26212">sblog-search-sql-injection(26212)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26213">
sblog-search-path-disclosure(26213)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/836">836</ref></refs><vuln_soft><prod name="sBLOG" vendor="Servous"><vers num="0.7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-05" name="CVE-2006-2190" published="2006-05-04" seq="2006-2190" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in ow-shared.pl in OpenWebMail (OWM) 2.51 and earlier allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter in (1) openwebmail-send.pl, (2) openwebmail-advsearch.pl, (3) openwebmail-folder.pl, (4) openwebmail-prefs.pl, (5) openwebmail-abook.pl, (6) openwebmail-read.pl, (7) openwebmail-cal.pl, and (8) openwebmail-webdisk.pl.  NOTE: the openwebmail-main.pl vector is already covered by CVE-2005-2863.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Open WebMail, Open WebMail, 2.52</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BLOGSPOT" url="http://pridels.blogspot.com/2006/04/open-webmail-251-xss-vuln.html">Open WebMail &lt;=2.51 XSS vuln.</ref><ref patch="1" source="MLIST" url="http://openwebmail.acatysmoof.com/archive/html/owm-announce/owm-announce.200605/msg00000.html">[owm-announce] 20060502 OpenWebMail version 2.52</ref><ref source="OPENWEBMAIL" url="http://openwebmail.acatysmoof.com/dev/svn/index.pl/openwebmail/log/trunk/?rev=233&amp;limit=33"></ref><ref source="OPENWEBMAIL" url="http://openwebmail.acatysmoof.com/dev/svn/index.pl/openwebmail/diff/trunk/src/cgi-bin/openwebmail/shares/ow-shared.pl?rev1=232;rev2=233"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16734">16734</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26105">openwebmail-multiple-scripts-xss(26105)</ref><ref source="" url="http://pridels0.blogspot.com/2006/04/open-webmail-251-xss-vuln.html"></ref></refs><vuln_soft><prod name="Open WebMail" vendor="Open WebMail"><vers num="2.51" prev="1"/><vers num="2.50"/><vers num="2.41"/><vers num="2.40"/><vers num="2.32"/><vers num="2.31"/><vers num="2.30"/><vers num="2.21"/><vers num="2.20"/><vers num="2.10"/><vers num="2.01"/><vers num="2.00"/><vers num="1.90"/><vers num="1.81"/><vers num="1.8"/><vers num="1.71"/><vers num="1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-28" name="CVE-2006-2191" published="2006-09-19" seq="2006-2191" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Format string vulnerability in Mailman before 2.1.9 allows attackers to execute arbitrary code via unspecified vectors. NOTE: the vendor has disputed this vulnerability, stating that it is &quot;unexploitable.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://mail.python.org/pipermail/mailman-announce/2006-September/000087.html">[Mailman-Announce] 20060913 RELEASED: Mailman 2.1.9</ref><ref source="MLIST" url="http://people.debian.org/~terpstra/message/20060906.155339.0c0732a4.en.html">[security] 20060906 Re: mailman 2.1.5-8sarge3: screwup between security and maintainer upload</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_25_sr.html">SUSE-SR:2006:025</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22639">22639</ref></refs><vuln_soft><prod name="Mailman" vendor="Gnu"><vers num="2.1.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-10" modified="2006-06-09" name="CVE-2006-2193" published="2006-06-08" seq="2006-2193" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TIFF file with a DocumentName tag that contains UTF-8 characters, which triggers the overflow when a character is sign extended to an integer that produces more digits than expected in an sprintf call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="DEBIAN" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=370355">Debian Bug - #370355</ref><ref patch="1" source="BUGZILLA" url="http://bugzilla.remotesensing.org/show_bug.cgi?id=1196">Bugzilla Bug 1196 </ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1091">DSA-1091</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2197">ADV-2006-2197</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20488">20488</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-289-1">USN-289-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20501">20501</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20520">20520</ref><ref source="BID" url="http://www.securityfocus.com/bid/18331">18331</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:102">MDKSA-2006:102</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20693">20693</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Jun/0008.html">SUSE-SR:2006:014</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20766">20766</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200607-03.xml">GLSA-200607-03</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21002">21002</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26991">
libtiff-tiff2pdf-bo(26991)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:102">MDKSA-2006:102</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103099-1">103099</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103160-1">103160</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3486">ADV-2007-3486</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/4034">ADV-2007-4034</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27181">27181</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27222">27222</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27832">27832</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201331-1">201331</ref></refs><vuln_soft><prod name="libTIFF" vendor="libTIFF"><vers num="3.8.2" prev="1"/><vers num="3.8.1"/><vers num="3.8.0"/><vers num="3.7.1"/><vers num="3.7.0"/><vers num="3.6.1"/><vers num="3.6.0"/><vers num="3.5.7"/><vers num="3.5.6"/><vers num="3.5.5"/><vers num="3.5.4"/><vers num="3.5.3"/><vers num="3.5.2"/><vers num="3.5.1"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-07-21" name="CVE-2006-2194" published="2006-07-05" seq="2006-2194" severity="High" type="CVE"><desc><descript source="cve">The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents the winbind NTLM authentication helper from dropping privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-310-1">USN-310-1</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18849">18849</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1106">DSA-1106</ref><ref source="OSVDB" url="http://www.osvdb.org/26994">26994</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20963">20963</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20967">20967</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20996">20996</ref><ref adv="1" patch="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:119">MDKSA-2006:119</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20987">20987</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:119">MDKSA-2006:119</ref></refs><vuln_soft><prod name="ppp" vendor="Samba"><vers num="2.4.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-13" name="CVE-2006-2195" published="2006-06-15" seq="2006-2195" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in horde 3 (horde3) before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) templates/problem/problem.inc and (2) test.php.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Horde, Horde, 3.1.1</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1098">DSA-1098</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20672">20672</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20750">20750</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200606-28.xml">GLSA-200606-28</ref><ref source="BID" url="http://www.securityfocus.com/bid/18436">18436</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016310">1016310</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20849">20849</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_16_sr.html">SUSE-SR:2006:016</ref><ref source="" url="http://overlays.gentoo.org/dev/chtekk/browser/horde/www-apps/horde/files/horde-3.1.1-xss.diff?rev=4&amp;format=txt"></ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=136830"></ref><ref source="" url="http://cvs.horde.org/diff.php?f=horde%2Ftest.php&amp;r1=1.145&amp;r2=1.146"></ref><ref source="" url="http://cvs.horde.org/diff.php?r1=2.25&amp;r2=2.26&amp;f=horde%2Ftemplates%2Fproblem%2Fproblem.inc"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2356">ADV-2006-2356</ref><ref source="OSVDB" url="http://www.osvdb.org/26513">26513</ref><ref source="OSVDB" url="http://www.osvdb.org/26514">26514</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20661">20661</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20960">20960</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27168">horde-test-problem-xss(27168)</ref></refs><vuln_soft><prod name="Horde" vendor="Horde"><vers num="3.0.9" prev="1"/><vers num="3.0.8"/><vers num="3.0.7"/><vers num="3.0.6"/><vers num="3.0.4 RC2"/><vers num="3.0.4 RC1"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-06-27" name="CVE-2006-2196" published="2006-06-26" seq="2006-2196" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in pinball 0.3.1 allows local users to gain privileges via unknown attack vectors that cause pinball to load plugins from an attacker-controlled directory while operating at raised privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1102">DSA-1102</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2535">ADV-2006-2535</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20778">20778</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20834">20834</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27420">emilia-pinball-plugins-privilege-escalation(27420)</ref><ref source="OSVDB" url="http://www.osvdb.org/26829">26829</ref></refs><vuln_soft><prod name="pinball" vendor="Jochen Friedrich"><vers num="0.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-22" name="CVE-2006-2197" published="2006-06-15" seq="2006-2197" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in wv2 before 0.2.3 might allow context-dependent attackers to execute arbitrary code via a crafted Microsoft Word document.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Debian, wv2, 0.2.2-1</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1100">DSA-1100</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-300-1">USN-300-1</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18437">18437</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2350">ADV-2006-2350</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20665">20665</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20688">20688</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20689">20689</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200606-24.xml">GLSA-200606-24</ref><ref adv="1" patch="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:109">MDKSA-2006:109</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016313">1016313</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20826">20826</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20844">20844</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_38_security.html">SUSE-SR:2006:015</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20899">20899</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?group_id=10501&amp;release_id=424094"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27184">
wvware-wv2-word-overflow(27184)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:109">MDKSA-2006:109</ref></refs><vuln_soft><prod name="wv2" vendor="wvWare"><vers num="0.2.3" prev="1"/><vers num="0.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-09" name="CVE-2006-2198" published="2006-06-30" seq="2006-2198" severity="High" type="CVE"><desc><descript source="cve">OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an OpenOffice document with a malicious BASIC macro, which is executed without prompting the user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://www.openoffice.org/security/CVE-2006-2199.html"></ref><ref patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102490-1">102490</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1104">DSA-1104</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0573.html">RHSA-2006:0573</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_40_openoffice.html">SUSE-SA:2006:040</ref><ref source="BID" url="http://www.securityfocus.com/bid/18738">18738</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2607">ADV-2006-2607</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2621">ADV-2006-2621</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016414">1016414</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20867">20867</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20893">20893</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20911">20911</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:118">MDKSA-2006:118</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-313-1">USN-313-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20913">20913</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20910">20910</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20975">20975</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27564">openoffice-macro-code-execution(27564)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20995">20995</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-313-2">USN-313-2</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/170113">VU#170113</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200607-12.xml">GLSA-200607-12</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21278">21278</ref><ref source="" url="https://issues.rpath.com/browse/RPL-475"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/22129">22129</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2343">FEDORA-2007-005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23620">23620</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/447035/100/0/threaded">20060926 rPSA-2006-0173-1 openoffice.org</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:118">MDKSA-2006:118</ref></refs><vuln_soft><prod name="OpenOffice" vendor="OpenOffice"><vers num="1.1.5"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1a"/><vers num="1.1.1b"/><vers num="1.1.1"/><vers num="1.1.0"/><vers num="2.0.3 RC6"/><vers num="2.0.3 RC5"/><vers num="2.0.3 RC4"/><vers num="2.0.3 RC3"/><vers num="2.0.2"/><vers num="2.0.2 RC4"/><vers num="2.0.2 RC3"/><vers num="2.0.2 RC2"/><vers num="2.0.2 RC1"/><vers num="2.0.1"/><vers num="2.0.0"/><vers num="2.0.0 RC3"/><vers num="2.0.0 RC2"/><vers num="2.0.0 RC1"/></prod><prod name="StarOffice" vendor="Sun"><vers num="7.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-09" name="CVE-2006-2199" published="2006-06-30" seq="2006-2199" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to escape the Java sandbox and conduct unauthorized activities via certain applets in OpenOffice documents.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.openoffice.org/security/CVE-2006-2199.html"></ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102475-1">102475</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1104">DSA-1104</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0573.html">RHSA-2006:0573</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_40_openoffice.html">SUSE-SA:2006:040</ref><ref source="BID" url="http://www.securityfocus.com/bid/18737">18737</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2607">ADV-2006-2607</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2621">ADV-2006-2621</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016414">1016414</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20867">20867</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20893">20893</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20911">20911</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:118">MDKSA-2006:118</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-313-1">USN-313-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20913">20913</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20910">20910</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20975">20975</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27569">openoffice-applet-sandbox-bypass(27569)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20995">20995</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-313-2">USN-313-2</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/243681">VU#243681</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200607-12.xml">GLSA-200607-12</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21278">21278</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2343">FEDORA-2007-005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23620">23620</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/447035/100/0/threaded">20060926 rPSA-2006-0173-1 openoffice.org</ref><ref source="" url="https://issues.rpath.com/browse/RPL-475"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:118">MDKSA-2006:118</ref></refs><vuln_soft><prod name="OpenOffice" vendor="OpenOffice"><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/><vers num="1.1.5"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1.0"/></prod><prod name="StarOffice" vendor="Sun"><vers num="6.0"/><vers num="7.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-07-25" name="CVE-2006-2200" published="2006-06-27" seq="2006-2200" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in libmms, as used by (a) MiMMS 0.0.9 and (b) xine-lib 1.1.0 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via the (1) send_command, (2) string_utf16, (3) get_data, and (4) get_media_packet functions, and possibly other functions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=374577"></ref><ref source="BID" url="http://www.securityfocus.com/bid/18608">18608</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2487">ADV-2006-2487</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20749">20749</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-309-1">USN-309-1</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:117">MDKSA-2006:117</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20948">20948</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20964">20964</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:121">MDKSA-2006:121</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-315-1">USN-315-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21023">21023</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21036">21036</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200607-07.xml">GLSA-200607-07</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21139">21139</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=468432"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23218">23218</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.433842">SSA:2006-357-05</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23512">23512</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:117">MDKSA-2006:117</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:121">MDKSA-2006:121</ref></refs><vuln_soft><prod name="mimms" vendor="MiMMS"><vers num="0.0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="6.4" CVSS_score="4.3" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-05" name="CVE-2006-2201" published="2006-05-04" seq="2006-2201" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in CA Resource Initialization Manager (CAIRIM) 1.x before 20060502, as used in z/OS Common Services and the LMP component in multiple products, allows attackers to violate integrity via a certain &quot;problem state program&quot; that uses SVC to gain access to supervisor state, key 0.</descript></desc><sols><sol source="nvd">This vulnerability affects all z/OS releases of this product prior to May 
